Now Reading
Consent Fatigue: How Indian Publishers Are Redesigning CMPs a Year Into DPDP Enforcement

Consent Fatigue: How Indian Publishers Are Redesigning CMPs a Year Into DPDP Enforcement

Open any major Indian news site today and the ritual is the same. A grey scrim drops over the homepage before the headline even loads. A box appears, asking permission to remember you, to profile you, to sell your attention to the highest bidder in a programmatic auction that will run in the time it takes you to blink. You tap “Accept All,” because you always do, because the alternative is a maze of toggles you didn’t ask for and don’t have time to navigate. Then you read your article, and by tomorrow you won’t remember consenting to anything at all.

This is consent fatigue, and it has quietly become one of the defining UX problems of Indian digital publishing. It is also, increasingly, a business problem — one that sits squarely at the intersection of law, revenue and trust, and one that publishers can no longer treat as a compliance afterthought bolted onto the footer of a website.

The Digital Personal Data Protection Act was notified in phases starting November 2025, and the industry has spent the better part of the year since living in a strange in-between state: the law exists, the Data Protection Board exists on paper, but the machinery for real enforcement — consent manager registration, the full penalty schedule, adjudication — arrives in stages through November 2026 and May 2027. For publishers, that gap has not meant inaction. If anything, the opposite has happened. Legal teams that once treated the DPDP Act as a distant deadline have spent this year in genuine anticipation of it, rebuilding consent infrastructure not because a regulator forced their hand this month, but because nobody wants to be the test case when enforcement does land.

What has emerged from that anticipation is a strange paradox. Publishers built Consent Management Platforms to protect user rights and insulate themselves from regulatory risk. Instead, in many cases, they built friction machines — multi-layered pop-ups, nested toggles, pre-ticked boxes disguised as neutral choices — that users learned to click through without reading. The consent was technically valid. It was also, in any meaningful sense, meaningless.

The First Wave Got It Wrong, and Everyone Knew It

Talk to anyone who sat in the war rooms when Indian publishers first rushed to deploy CMPs — largely borrowing frameworks built for Europe’s GDPR regime and skinning them for an Indian audience — and you will hear a version of the same confession: speed took precedence over design. Legal and compliance teams needed something live, and the fastest path was to license an off-the-shelf consent banner, populate it with the standard list of vendors and purposes, and ship it before the next audit.

The result looked compliant on paper and felt hostile in practice. Consent banners appeared as full-screen interstitials on mobile, where screen real estate is already scarce, burying the actual article beneath a wall of checkboxes labelled with adtech jargon — “personalised advertising,” “measure ad performance,” “store and/or access information on a device” — that meant nothing to the average reader scrolling through a cricket score update on a metro commute. Reject-all options, where they existed, were buried two or three clicks deeper than Accept-all, a pattern regulators and privacy advocates the world over have long flagged as a dark pattern, even when no single element of it technically breaks any rule.

Indian publishers were not naive about this. Product and UX teams inside newsrooms watched bounce rates spike the moment a new consent layer went live, watched session times dip, watched readers abandon articles rather than parse a form that looked more like a terms-of-service document than a website preference. The data told a consistent story: friction converts into fatigue, and fatigue converts into either blind acceptance or outright exit. Neither outcome served the reader, and neither, longer term, served the publisher.

“We realised we had built a legal shield, not a product. A shield doesn’t have to be usable. A product does. That distinction cost us almost a year of bad engagement data before we started over.”

That line, echoed in various forms across conversations with digital heads at Indian news and lifestyle publishers over the past several months, captures the pivot now underway. The rebuild isn’t about loosening compliance. It’s about accepting that a consent flow is, whether anyone likes it or not, the first product experience a reader has with a publication every single session — and that a bad first impression compounds, article after article, visit after visit.

Redesigning for Comprehension, Not Just Compliance

The second-generation CMPs now rolling out across Indian publisher stacks look markedly different from their predecessors, and the differences are instructive because they reveal what publishers have learned the hard way.

The first shift is language. Instead of listing IAB-standard purpose categories verbatim, several large Indian digital newsrooms have rewritten consent copy in plain, conversational language — explaining in a single line what “personalised advertising” actually buys the reader (fewer irrelevant ads, in theory) rather than assuming familiarity with adtech taxonomy. Some have gone further, localising banner copy into Hindi and regional languages for markets where English comprehension of legal terminology cannot be assumed, a move that doubles as both an accessibility improvement and a genuine attempt at informed consent rather than nominal consent.

The second shift is structural symmetry. Where reject-all once required navigating a sub-menu, most redesigned banners now place accept and reject as equally weighted, equally accessible buttons on the first screen. This is not a purely voluntary act of goodwill — India’s evolving consent-manager framework under the DPDP Rules leans explicitly on the idea of free, specific and informed consent, and asymmetric UX sits uncomfortably close to violating that spirit even before enforcement teeth are fully in place. Publishers redesigning now are, in effect, hedging against a future where “we technically offered a reject option” is no longer a defence a regulator or a court finds persuasive.

The third shift, and arguably the most consequential for revenue teams, is granularity without overload. Rather than forcing a binary accept-everything-or-reject-everything choice, several platforms now offer a middle layer — essential functionality always on, analytics and personalisation as a single toggle, and a clearly separated, optional layer for third-party ad partners. This lets publishers preserve a meaningful slice of first-party and contextual monetisation even from readers who decline the full advertising stack, rather than losing that inventory entirely to a blunt binary choice.

The Revenue Conversation Publishers Didn’t Want to Have

None of this redesign work happens in a vacuum, and the uncomfortable truth inside most Indian publisher boardrooms this year has been that consent architecture is now, unavoidably, a revenue lever. Programmatic advertising, still the dominant monetisation engine for the bulk of Indian digital news and lifestyle publishing, depends on the ability to pass signal — device identifiers, behavioural segments, third-party cookie data where it still functions — into real-time bidding auctions. Every reader who declines tracking-based consent is a reader whose impression sells for less, sometimes dramatically less, in an open auction.

That has pushed publishers toward strategies that would have seemed unusual even two years ago. Contextual advertising — targeting based on the content of the page rather than the identity of the reader — has moved from a fallback option to an active investment area, with several Indian publisher ad-ops teams rebuilding taxonomy and content classification specifically to make contextual inventory more attractive to buyers who might otherwise write it off as low-value “consent-declined” traffic. First-party data strategies, built around logged-in experiences, newsletters and loyalty programmes, have gained fresh urgency, because a reader who logs in and consents directly to a publisher relationship is a far more durable asset than one whose consent lives inside a third-party cookie that a browser could delete tomorrow.

There is also a quieter shift toward consent-gated premium experiences — the idea that declining tracking consent might mean seeing a lighter, more contextual ad experience, while accepting it unlocks a more “personalised,” and to some readers more relevant, one. Framed well, this reintroduces something the first wave of CMPs stripped out entirely: the sense that consent is an actual choice with actual, visible consequences, rather than a legal formality standing between the reader and the content they came for.

What Good Now Looks Like

Ask consent-design practitioners working across Indian newsrooms what a well-built CMP looks like heading into full DPDP enforcement, and a rough consensus emerges around a handful of principles.

  • Consent requests should be legible in one read, in the reader’s own language, without requiring familiarity with adtech vocabulary.
  • Accepting and declining should require equal effort — same number of taps, same visual prominence, no dark-pattern colour contrast steering the eye toward one option.
  • Consent should be genuinely revisitable, not a one-time gate that vanishes after the first session — readers should be able to find and change their preferences without hunting through footer links.
  • The monetisation strategy behind the banner should not depend on the banner being ignored — if the entire ad stack collapses the moment readers actually understand and exercise their choices, that is a signal the strategy, not the consent design, needs rethinking.

That last point is, in many ways, the real story here. The DPDP Act has functioned less as a compliance checklist and more as a forcing mechanism, pushing Indian publishers to confront a dependency on invisible, low-friction data extraction that was always going to be fragile — legally, technically and reputationally. Third-party cookies were already eroding under browser-level pressure well before DPDP entered the picture. Regulation has simply made explicit what the technology stack was already signalling: that consent, done honestly, changes the economics of the business, and publishers who wait for enforcement to force the issue will have far less runway to adapt than those redesigning now.

The irony sitting underneath all of this is worth naming plainly. Consent fatigue was never really about too many pop-ups. It was about pop-ups that asked for permission while assuming the answer didn’t matter. The publishers now rebuilding their CMPs from the ground up — rewriting copy, rebalancing buttons, diversifying revenue away from a single point of tracking-dependent failure — are, whether they frame it this way internally or not, making a bet that the answer does matter, and that readers who feel genuinely asked, rather than merely notified, are the readers who stick around long after the next auction closes.

A year into this new regulatory reality, with full enforcement still ahead and the Data Protection Board only beginning to find its footing, the publishers furthest along are not the ones who built the most airtight legal defence. They are the ones who stopped treating the consent banner as an obstacle between the reader and the page, and started treating it as the first line of the relationship.

© 2026 Hemito Media Pvt Ltd
All Rights Reserved

Scroll To Top