Consent Tree Research · 2026-Q3

The DPDP Sector Pulse.
2026-Q3

Sector aggregates measured from what organisations’ public web presence actually shows. Every statistic below carries all three states — present, absent, and could not assess — and every sector states how much of its register was actually assessed.

METHODOLOGY v1 · SNAPSHOT 16 August 2026 · STATUS PUBLISHED

lending

711 of 8588 on the register were assessed

That is 8.3% of this sector's register. 16 of 18 checks cleared the publication floor this quarter; 1 did not reach the minimum panel, and 1 is withheld because the instrument for it does not measure what the check is named. Each says which, and why, in place of a number.

Do visitors get asked before tracking tools start running?

web.consent-mechanism

This checks whether a consent banner or similar mechanism appears before analytics, advertising or other tracking tools start collecting data — versus those tools just running silently on page load.

Signal present · 445 (63%) Signal absent · 260 (37%) Could not assess · 6 (1%)

DPDP requires consent to be obtained before personal data is collected for a given purpose, not retroactively.

Can someone change their mind after agreeing to tracking?

web.consent-withdrawal

This checks whether there's a lasting way for a visitor to come back later and turn off tracking or update their preferences — not just a one-time banner they can never see again.

Signal present · 24 (35%) Signal absent · 45 (65%) Could not assess · 0 (0%)

641 did not apply and are excluded from the denominator.

DPDP requires withdrawing consent to be as easy as giving it — a banner that only ever appears once fails that on its face.

Do you explain what cookies and trackers your site uses?

web.cookie-policy

Cookies and similar trackers quietly collect information about how visitors use your site (often for analytics or advertising). This checks whether you publish a page explaining what's used and why, when trackers are present.

Signal present · 29 (9%) Signal absent · 298 (89%) Could not assess · 6 (2%)

378 did not apply and are excluded from the denominator.

If a tracker collects data that can identify a person (even indirectly), DPDP's notice-and-consent duties apply to it.

Is there a named privacy contact for your organisation?

web.dpo-contact

Similar to the grievance contact, this checks for a published contact person or role responsible for data protection at your company.

INSUFFICIENT PANEL THIS QUARTER

22 organisations were assessed for this check — below the minimum panel this series publishes a percentage from. No rate is shown, because a rate from this few would not mean anything.

688 did not apply and are excluded from the denominator.

Businesses DPDP classifies as "Significant" must appoint a Data Protection Officer based in India — smaller businesses should still name someone accountable.

Do your forms explain what happens to the information people submit?

web.form-notice-proximity

When a visitor fills out a form on your site (contact, signup, checkout), this checks whether there's a nearby note or link explaining what that data will be used for.

REPORTED AS A BOUND · 326 ASSESSED

present bounded (complementary); indeterminate<3. Exact counts are withheld here: at this size a precise figure could identify the organisations behind it.

384 did not apply and are excluded from the denominator.

DPDP requires notice to accompany the request for consent — a form with no context nearby doesn't meet that.

Do tracking tools default to "off" until a visitor agrees?

web.google-consent-mode

Some tools (like Google's tag manager) support a setting where trackers stay quiet by default and only activate once someone has actually agreed. This checks whether that default-off behaviour is switched on.

Signal present · 5 (2%) Signal absent · 315 (97%) Could not assess · 5 (2%)

385 did not apply and are excluded from the denominator.

Ties directly to DPDP's requirement that processing only begin once valid consent has actually been given.

Does your site honour a visitor's browser-level "don't track me" signal?

web.gpc-declaration

Some browsers let a visitor set a single preference that says "don't sell or share my data," which sites can read automatically. This checks whether your site recognises and publishes support for that signal.

Signal present · 0 (0%) Signal absent · 325 (100%) Could not assess · 0 (0%)

385 did not apply and are excluded from the denominator.

Is there a clear way for someone to raise a privacy complaint?

web.grievance-contact

This checks whether your site publishes a named contact (a "grievance officer" or equivalent) that a visitor can write to about how their data is handled.

Signal present · 194 (27%) Signal absent · 496 (70%) Could not assess · 21 (3%)

DPDP s.13 requires a named Grievance Officer who must respond to complaints within a defined period.

Does your site limit what scripts are allowed to run on it?

web.header.csp

This is a server setting (CSP) that restricts which scripts and resources a page is allowed to load, so if an attacker manages to inject malicious code, its damage is limited.

Signal present · 255 (36%) Signal absent · 444 (64%) Could not assess · 0 (0%)

Does your server insist on staying encrypted?

web.header.hsts

This is a small instruction (HSTS) your server can send telling browsers "always use the encrypted connection for this site, never fall back to unencrypted." Without it, there's a brief window where a visitor's first connection could be downgraded.

Signal present · 229 (33%) Signal absent · 470 (67%) Could not assess · 0 (0%)

A technical detail under the same DPDP security-safeguards duty as encryption itself.

Do your page addresses leak to other websites when visitors click links?

web.header.referrer-policy

When someone clicks a link from your site to another, browsers can pass along the exact web address they came from — which, if that address contains a search term, an order ID, or a token, hands that information to the destination site.

Signal present · 121 (17%) Signal absent · 578 (83%) Could not assess · 0 (0%)

Can browsers be tricked about what type of file they're loading?

web.header.xcto

This setting (X-Content-Type-Options) stops a browser from guessing a file's type in a way that could turn an ordinary file (like an uploaded image) into something that runs as code.

Signal present · 257 (37%) Signal absent · 442 (63%) Could not assess · 0 (0%)

Can your site be secretly embedded inside another website?

web.header.xfo

This setting (X-Frame-Options) stops other sites from loading your pages inside an invisible frame to trick visitors into clicking something they didn't mean to ("clickjacking") — for example, a hidden "submit payment" button under what looks like a game.

Signal present · 173 (25%) Signal absent · 526 (75%) Could not assess · 0 (0%)

Is your website connection encrypted?

web.https

When someone visits your site, an encrypted connection (the padlock/HTTPS you see in a browser) scrambles everything sent between their browser and your server, so nobody else on the network can read it.

Signal present · 699 (98%) Signal absent · 12 (2%) Could not assess · 0 (0%)

DPDP requires "reasonable security safeguards" for personal data — encrypting the connection is the baseline, not the ceiling.

Can visitors read your notice in a language other than English?

web.language-option

This checks whether your privacy notice or consent banner offers at least one Indian language alongside English.

Signal present · 44 (6%) Signal absent · 647 (91%) Could not assess · 20 (3%)

DPDP allows notices in English or any language listed in the Constitution's Eighth Schedule (Hindi, Tamil, Bengali, and others).

Does your privacy policy actually say what it needs to say?

web.privacy-policy-content

Having a privacy policy page isn't the same as it covering the right things. This checks the actual text for the core items a real notice should include — who you are, what you collect, why, how long you keep it, who you share it with, and how someone can complain or withdraw consent.

EXCLUDED FROM THIS EDITION · 427 ASSESSED

Excluded from this edition because the instrument does not measure what this check is named. A notice scores as present only if it mentions all fourteen disclosure elements we test, and two of those fourteen are GDPR-specific — the lawful basis for processing, and automated decision-making or profiling. The DPDP Act has no equivalent of either, so an Indian organisation can publish a complete and compliant notice and still register as absent here. Publishing the resulting rate would say something about our instrument, not about the sector. The check returns in a future edition once each disclosure element is scored and published on its own.

283 did not apply and are excluded from the denominator.

DPDP sets out specific items a notice must cover — purpose, retention, sharing, rights, and how to complain or withdraw consent.

Can visitors easily find your privacy policy?

web.privacy-policy-link

A privacy policy is the page that tells visitors what personal data you collect and why. This checks whether a working link to one exists — usually in the footer.

Signal present · 380 (53%) Signal absent · 273 (38%) Could not assess · 58 (8%)

DPDP requires this notice to be given in clear, plain language before or when data is collected.

Is your site's security certificate installed correctly?

web.tls-chain

The padlock relies on a security certificate being installed completely. If part of it is missing, some visitors' browsers or apps (often older phones) may show a warning or refuse to connect, even though the site looks fine on a modern browser.

Signal present · 699 (100%) Signal absent · 0 (0%) Could not assess · 0 (0%)

Falls under the same DPDP reasonable-security-safeguards duty as the padlock check.

How to read this

What these numbers are, and are not.

They are observations of public surfaces, not audits.

This is an outside-in scan of a homepage and the standard compliance pages. DPDP compliance runs far deeper than any such scan can see — consent records, retention, breach process. Nothing here says any organisation is compliant or non-compliant, and this series carries no statutory recognition.

“Could not assess” is never counted as a failure.

A site that blocked the scanner, or that we could not reach, is published as exactly that. It degrades our own coverage figure rather than quietly inflating anyone’s failure rate.

Thin cells are withheld, not estimated.

Below the publication floor we print “insufficient panel”, never a number. Where an outcome is held by very few organisations, a bound replaces the exact figure — and the complementary figure is withheld too, so the exact count cannot be recovered by subtraction.

Measured but not presented here.

  • web.ccpa-optout-link — a US opt-out signal, not a DPDP obligation — measured, kept in the downloadable table, not presented as an India norm
The full table

Every cell, including the withheld ones.

The complete aggregate table is downloadable — every sector, every check, the three-state counts, the register size, and a flag on each cell we withheld and why. Check the arithmetic.

Download CSV ↓Download JSON ↓

Read the methodology → — the panel, the instrument, the publication rules, the coverage chain, and what this method cannot see.

Organisations may ask to be permanently excluded from the panel — honoured forever, no questions, at hello@consentree.in.