Website & App Legal Audit

A legal audit of a website or app checks that what it tells users, what it collects and what it does all meet Indian law: the privacy notice and consent, cookies, terms of service, grievance handling, the rules for platforms and online sellers, and the ownership of the code and content it is built on.

The result is a written report of the gaps, in order of priority, with the fixes for each. It is most useful before a launch, before a fundraise or acquisition, and before the duties under the Digital Personal Data Protection Act, 2023 apply from 13 May 2027.

When you need it

  • Before a launch

    Fixing the notices, consent flows and terms before users arrive is far easier than changing them afterwards.

  • Before a fundraise or acquisition

    Investors and buyers review a product’s legal position in due diligence. An audit finds the gaps first, so they can be fixed or explained.

  • When the product changes

    Adding payments, subscriptions, user-generated content, advertising pixels or users in new countries each brings new rules.

  • Before the DPDP deadline

    The core duties under the DPDP Act apply from 13 May 2027. An audit shows how far the current website or app is from them.

  • After a complaint or notice

    A user complaint, a regulator’s query or an app store rejection is often the first sign of a wider problem worth checking properly.

How the process works

Six stages, from an inventory of the product to a report of prioritised fixes. Timings are typical, not promised.

  1. 1

    Inventory

    Usually about a week

    List the pages, forms, accounts, payment flows, third-party tools, software kits and trackers the website or app uses, and where personal data goes.

    Documents

    • Access to the website, or a test build of the app
    • A list of third-party tools, vendors and hosting providers
    • The agreements with the agency or developers who built it
  2. 2

    User-facing documents

    Alongside the inventory

    Review the privacy policy, terms of service, cookie notice and refund or cancellation policy against each other and against what the product actually does.

  3. 3

    Personal data and consent

    One to two weeks

    Check the notices, consent wording, consent withdrawal, children’s data, retention and contracts with processors against the DPDP Act and Rules and the current IT Act rules.

  4. 4

    Platform and sector rules

    Alongside the data review

    Check the rules that apply to the business model: the intermediary rules for platforms that host user content, the e-commerce rules for online sellers, and sector rules such as those for lending, health or education.

  5. 5

    Ownership of code and content

    Alongside the data review

    Confirm that the business owns, or is licensed to use, its domain, code, design, images, fonts and content. Work done by an outside agency or freelancer usually needs a written assignment to belong to the business.

  6. 6

    Report and fixes

    About a week after the review

    Deliver a written report of the gaps, ranked by risk, with the fix for each, and redraft the documents that need it.

Common questions

The privacy policy and consent, cookies, terms of service, refund and grievance policies, the rules that apply to the business model, and the ownership of the domain, code and content. It ends in a written report of gaps and fixes.

To discuss a legal audit, write to info@ireniclegal.com or call +91 96547 47331. Written by Adv. Kanika Marwaha Bindal; last updated 29 September 2026.