Continuous scanning finds every cookie, pixel and third-party script on your domains — including the ones a CMS plugin or a tag manager container added without telling the privacy team. Classify them, present a DPDP notice in any of the 22 Eighth Schedule languages, and keep a signed record of every choice.
The common failure is not a missing banner. It is a perfectly good banner installed on a site where analytics and advertising tags load on first paint, before anyone has clicked anything. The interface says the visitor was asked. The network tab says otherwise.
It usually is not anyone's fault. A marketing team adds a pixel through the tag manager. A developer installs a plugin that sets its own cookie. A vendor script loads a second script you never saw. None of these route through the privacy team, and none of them appear in the cookie list somebody compiled by hand eight months ago.
Then there is language. Consent has to be specific and informed, given on the basis of a notice in clear and plain language (DPDP Act 2023, s.5 and s.6; DPDP Rules 2025, Rule 3(b)). A visitor in Coimbatore reading an English-only banner has not been given a fair account of what she is agreeing to, whatever she clicked.
You do not have to take our word for any of this, and you do not need Consiva to find out.
Open your own site in a private window. Open DevTools, go to the Network tab, filter to your analytics or advertising domain, and hard-refresh. If you see requests to those domains before you interact with the banner, your tags are firing pre-consent.
We wrote the full test up, with what to look for and the common causes: → Your Tags Are Firing Before Consent. Here's How to Check in 10 Minutes
Four steps, run continuously rather than once at setup — shown here as a workflow before the detail below.
Presents the notice in the right language. All 22 Eighth Schedule languages on Pro and Enterprise; English and Hindi on Free.
Re-scans on a schedule. A tracker added next month shows up in the next cycle, with a difference report against the last one.
This is the Banner Builder. On the left you configure purposes — Strictly Necessary is always on and cannot be switched off, because a visitor cannot refuse the cookies that make the site function. Analytics and Marketing are opt-in, each named against the actual tag it governs, so a visitor is consenting to something specific rather than to a category. The language selector is set to Hindi here; the live preview on the right updates as you type, including on the mobile simulation. Below the preview is the script key. Nothing goes live until you publish, and publishing writes a new banner version — so a consent record captured today can be tied to the exact notice text that was on screen when it was captured.
This is the real per-domain cookie inventory the scan populates — name, DPDP category, type, provider, whether it's third-party, and the vendor it belongs to where known. “Unclassified” findings (like the legacy agency script here) are the ones worth a conversation with whoever owns the tag manager — a cookie nobody can name is usually a cookie nobody is still using on purpose.
Rule 3 is short and specific about what a notice has to do, and most banners in the Indian market miss part of it (DPDP Rules 2025, Rule 3). The requirements:
| Rule 3 requires | What that means for a banner |
|---|---|
| 3(a) Presented and understandable independently of any other information | The notice must stand on its own. A banner that says “see our privacy policy” and nothing else does not satisfy this. |
| 3(b)(i) In clear and plain language, an itemised description of the personal data | Not “we use cookies”. Which data, itemised. |
| 3(b)(ii) The specified purpose, with a specific description of the goods, services or uses enabled | Purpose-by-purpose, tied to something concrete the visitor gets. |
| 3(c) The communication link and other means by which she may withdraw consent, exercise her rights, and complain to the Board | Three separate routes, all reachable from the notice. |
| 3(c)(i) Withdrawal with ease comparable to that with which consent was given | If accepting is one click, withdrawing has to be one click. A one-click accept and a five-step withdrawal is a Rule 3 failure. |
Consiva's default banner template is built against all five. The withdrawal path is deliberately the same number of steps as acceptance — which is why the preference centre is reachable directly from the banner rather than buried in a footer.
On the 22 languages. The Eighth Schedule to the Constitution lists 22 languages. Rule 3(b) requires clear and plain language, and the Act requires that a notice be available in English or any Eighth Schedule language (DPDP Act 2023, s.5(3)). Consiva ships banner templates in all 22 on Pro and Enterprise.
| Free (₹0) | Pro (₹5,999/mo) | Enterprise | |
|---|---|---|---|
| Domains | 1 | 5 + add-on packs | Unlimited |
| Cookie consents / month | 1,000 | 15,000 | Unlimited |
| Form consents / month | 50 | 1,500 | Unlimited |
| Cookie scanning | Basic | Scheduled, automatic | Scheduled, automatic |
| Banner languages | English, Hindi | All 22 | All 22 + regional |
| Signed consent log | ● | ● | ● |
| Consent analytics | Basic | Enhanced + CSV | Enhanced + CSV |
| Webhooks and REST API | — | ● | ● |
Add-on packs on annual Pro: Domain Pack +10 domains ₹80,000/yr · Cookie Consent Pack +10,000/mo ₹14,400/yr · Form Consent Pack +1,000/mo ₹3,360/yr.
The section that matters if the Board ever asks.
The consent record. Append-only, one row per decision, carrying: an anonymised visitor identifier, the timestamp to the second, the action (granted, partially granted, withdrawn), the exact purpose set, the notice version that was on screen, the channel (web, mobile SDK, API) and the region. Exportable as CSV. Because the notice version is on the record, you can demonstrate not just that consent was given but what the visitor was shown when she gave it — which is the question that actually gets asked.
The scan record. Every cycle, timestamped, with a difference report. If a tracker appeared in March and was categorised in March, the record shows it. This is what makes “we did not know it was there” a defensible statement for a specific window rather than a general admission.
The withdrawal trail. A withdrawal is recorded against the same notice version as the original grant, so the pair reads as a single history rather than two unrelated events.
What Consiva cannot see, stated plainly. Consent taken offline, in a call centre, or on paper does not appear in these records unless it is submitted through the API. Exports say so. An evidence pack that silently omits its own blind spots will be relied on, and that is worse than no evidence pack.
Any site, one script tag. Copy one <script> tag into your <head>. Works with React, Next.js, Vue, Angular, plain HTML, PHP and via Google Tag Manager.
Honest timing. The banner itself is genuinely a same-day job: register, verify, review the first scan, configure, deploy. What takes longer is the classification review — deciding what each tracker is actually for, and whether you still need it. Budget an afternoon with whoever owns the tag manager. Most of the value is in that conversation, not in the install.
A D2C brand runs one storefront and three campaign microsites. The privacy team knows about Google Analytics and the Meta pixel. The first Consiva scan returns nineteen distinct trackers, eleven of which fire before any consent decision — including two from an abandoned-cart vendor whose contract ended the previous year and a session-recording script a former agency installed on a microsite nobody had looked at in months.
The team removes the two dead vendors outright, classifies the remainder, and publishes banners in English, Hindi, Tamil and Marathi to match where their orders actually come from. The recording script is reclassified as analytics and held until consent. The next scheduled scan flags a new tracker within the cycle; it turns out to be a partner tag added for a Diwali campaign, which is categorised before the campaign goes live rather than after.
Illustrative. Not based on a named Consiva customer.
Most teams run cookie consent themselves — it is the part of a privacy programme that genuinely does not need outside help. Where a Managed Privacy Officer engagement adds something is the recurring hygiene nobody has time for: reviewing each scan cycle, chasing the owner of a new tag, keeping banner copy current as purposes change, and keeping the consent evidence in a state where it could be handed over tomorrow.
Software that discovers the cookies and trackers on your website, classifies them by purpose, presents a consent notice to visitors, holds non-essential scripts until the visitor agrees to the relevant purpose, and keeps a durable record of every decision. The last two are what distinguish a consent platform from a banner: a banner asks the question, a platform enforces the answer and can prove it was asked.
A crawler scans your domain and returns every cookie, pixel and third-party script it observes, noting which ones fire before any consent decision. You confirm a DPDP purpose category for each. A single script tag in your <head> then presents the notice, holds non-essential scripts until the matching purpose is consented to, and writes a signed record of the visitor's choice. Scheduled re-scans catch anything added later.
Because most trackers on a typical Indian site process personal data, and under DPDP that requires notice and consent unless a specific exemption applies. The practical risk is narrower than the legal one: a banner that fires after your tags have already loaded gives you the appearance of consent without the substance, and it is trivially disprovable by anyone who opens DevTools. Note that the substantive DPDP obligations and the penalty regime commence on 13 May 2027, so this is a window to get right rather than an emergency.
Automatic and repeated discovery rather than a manual list; purpose-level classification; genuine script blocking until consent, not just a banner; withdrawal as easy as acceptance, which Rule 3(c)(i) requires explicitly; notices in the languages your visitors actually read; and an exportable consent record that includes the notice version, so you can show what the visitor was looking at when she agreed.
Consent Mode v2 and DPDP consent are different things and it is worth being precise about it. Consent Mode communicates a visitor's choice to Google's tags. It does not obtain consent, does not produce a record you could show the Data Protection Board, and does not govern non-Google tags on your site. It is a signalling mechanism downstream of consent, not a substitute for it. We wrote this up at /blog/consent-mode-v2-is-not-consent.
Free, permanently, with no card required and no expiry: one domain, 1,000 cookie consents and 50 form consents a month, basic scanning, English and Hindi banners, and manual rights request handling. It is not a trial of Pro — there is no free trial of the paid plans. Automated scanning, all 22 languages, multi-domain support and breach tracking are what Pro adds.
Free plan, one domain, 1,000 cookie consents a month — no credit card, live in minutes.