Skip to content
FaceOff Technologies

Data Privacy · Module 01

Cookie Management

A continuous governance loop that finds cookies, classifies them, gates them behind consent and watches for drift. Shipped as part of Consent Management.

Platform capabilities

  • Scheduled estate-wide scanning
  • AI + rules classification
  • Prior-blocking script

Primary DPDP sectionsSec. 6(1)

Known cookies catalogued

98.7%

Known cookies catalogued

Scan-to-policy refresh

< 24h

Scan-to-policy refresh

Tags gated pre-consent

100%

Tags gated pre-consent

Categories auto-mapped

4

Categories auto-mapped

Figures illustrative.

How it works

Cookie Management, end to end

Five repeatable stages turn raw discovery into a live, geo-aware banner that blocks before it asks — then keep watching for drift.

  1. 01

    Scan

    Crawl pages, SPAs, subdomains and authenticated journeys

  2. 02

    Classify

    Map each cookie to category, vendor, purpose and duration

  3. 03

    Generate

    Build the banner UI and the auto-block script

  4. 04

    Deploy

    One snippet, or through your tag manager

  5. 05

    Monitor

    Re-scan, detect drift, refresh the policy

Non-essential tags stay dormant until the visitor opts in — the default-deny behaviour Sec. 6(1) requires.

Capability

What Cookie Management does

Deep scanning

Scheduled crawls across pages, SPAs, subdomains and authenticated journeys find every cookie, pixel, tag and storage entry.

  • Single-page apps and authenticated journeys
  • Subdomain and multi-property coverage
  • Pixels, tags and local storage, not just cookies
  • Scheduled rescans rather than a one-off audit

Auto-classification & prior blocking

AI and rules map each cookie to Necessary, Functional, Analytics or Marketing — and non-essential tags stay dormant until the visitor opts in.

  • Vendor, purpose and duration resolved per cookie
  • Default-deny behaviour regulators expect
  • Equal Accept and Reject prominence
  • No pre-ticked boxes, granular per-category toggles

Drift monitoring

New or rogue cookies trigger DPO alerts and auto-refresh the cookie policy and banner declarations.

  • Alerts on cookies no scan previously saw
  • Policy and declarations refreshed automatically
  • Geo-targeted banners for DPDP, GDPR and CCPA
  • Withdrawal as easy as the original consent

Outcome

The banner stops being a decorative overlay and becomes an enforcement point — nothing non-essential fires before the affirmative action.

DPDP alignment

Cookie Management — section by section

What the Digital Personal Data Protection Act, 2023 requires, and the control that satisfies it.

SectionWhat the Act requiresHow the product satisfies it
Sec. 6(1)Consent must be by clear affirmative action, and processing may not begin before it is given.Prior blocking is the control that makes this real: a tag firing before the affirmative action means processing began without consent, and no receipt can retrofit it.
Sec. 6(4)Withdrawal must be as easy as giving consent.The banner exposes a persistent re-open control with equal Accept and Reject prominence, so withdrawal is the same number of clicks as the original grant.
Sec. 5Notice must itemise what is collected and for what purpose.Cookie declarations are generated from the live scan, so the published policy matches what the site actually sets rather than what it set at launch.

Exposure avoided

A tag that fires pre-consent is unlawful processing from the first pageview, and it is the single easiest defect for a regulator or a journalist to verify from outside your perimeter.

Solutions by industry

Where Cookie Management lands first

The sectors carrying the most DPDP exposure for this control, each with its own threat model and regulators.

See it running against your estate.

A DPDP readiness walkthrough maps your obligations to the controls that already exist, and names the gaps that do not.