Website & App Legal Audit
A legal audit of a website or app checks that what it tells users, what it collects and what it does all meet Indian law: the privacy notice and consent, cookies, terms of service, grievance handling, the rules for platforms and online sellers, and the ownership of the code and content it is built on.
The result is a written report of the gaps, in order of priority, with the fixes for each. It is most useful before a launch, before a fundraise or acquisition, and before the duties under the Digital Personal Data Protection Act, 2023 apply from 13 May 2027.
When you need it
Before a launch
Fixing the notices, consent flows and terms before users arrive is far easier than changing them afterwards.
Before a fundraise or acquisition
Investors and buyers review a product’s legal position in due diligence. An audit finds the gaps first, so they can be fixed or explained.
When the product changes
Adding payments, subscriptions, user-generated content, advertising pixels or users in new countries each brings new rules.
Before the DPDP deadline
The core duties under the DPDP Act apply from 13 May 2027. An audit shows how far the current website or app is from them.
After a complaint or notice
A user complaint, a regulator’s query or an app store rejection is often the first sign of a wider problem worth checking properly.
How the process works
Six stages, from an inventory of the product to a report of prioritised fixes. Timings are typical, not promised.
- 1
Inventory
Usually about a weekList the pages, forms, accounts, payment flows, third-party tools, software kits and trackers the website or app uses, and where personal data goes.
Documents
- Access to the website, or a test build of the app
- A list of third-party tools, vendors and hosting providers
- The agreements with the agency or developers who built it
- 2
User-facing documents
Alongside the inventoryReview the privacy policy, terms of service, cookie notice and refund or cancellation policy against each other and against what the product actually does.
- 3
Personal data and consent
One to two weeksCheck the notices, consent wording, consent withdrawal, children’s data, retention and contracts with processors against the DPDP Act and Rules and the current IT Act rules.
- 4
Platform and sector rules
Alongside the data reviewCheck the rules that apply to the business model: the intermediary rules for platforms that host user content, the e-commerce rules for online sellers, and sector rules such as those for lending, health or education.
- 5
Ownership of code and content
Alongside the data reviewConfirm that the business owns, or is licensed to use, its domain, code, design, images, fonts and content. Work done by an outside agency or freelancer usually needs a written assignment to belong to the business.
- 6
Report and fixes
About a week after the reviewDeliver a written report of the gaps, ranked by risk, with the fix for each, and redraft the documents that need it.
Common questions
The privacy policy and consent, cookies, terms of service, refund and grievance policies, the rules that apply to the business model, and the ownership of the domain, code and content. It ends in a written report of gaps and fixes.
For a business that collects personal information through its website, the rules under the Information Technology Act, 2000 require a published privacy policy, and the DPDP Act requires a notice before consent is asked for. Platforms and online sellers have further duties to publish policies.
Most apps need a privacy policy and terms of use, valid consent for the personal data they collect, and a grievance contact. Depending on what the app does, it may also be subject to the intermediary rules, the e-commerce rules or sector rules, and the app stores add their own requirements.
Not automatically the business that paid for it. Under the Copyright Act, 1957, work created by an independent agency or freelancer generally belongs to them unless it is assigned in writing. The development agreement should contain a clear assignment of the code, design and content.
Many online businesses do. The IT Act rules require a grievance officer for handling complaints about personal information, and online sellers and intermediaries must publish grievance contacts under their own rules.
Before launch, before a fundraise or acquisition, and after major product changes. For most businesses in India, a review before the DPDP duties apply on 13 May 2027 is also sensible.
Related
To discuss a legal audit, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 29 September 2026.

