How I'd redesign the way Zomato asks for your data β€” so it follows India's new privacy law, without making the app annoying to use.

My role: Product Manager for data & privacy (case study) App: Zomato Β· What I focused on: the consent experience (how the app asks permission for your data) When: July 2026


The short version

Right now, when you open Zomato, there's one small line at the bottom of the login screen: "By continuing, you agree to our Terms, Privacy & Content Policy." That single tap says yes to everything β€” your live location, your order history being used for ads, your data being shared with Blinkit and District β€” forever, with no record and no way to undo it.

India's new privacy law (the DPDP Act) makes this illegal starting May 2027, with fines up to β‚Ή250 crore. So this has to change.

I redesigned how Zomato asks for permission. The new version is clear, in your own language, and you can undo any choice with one tap. The catch most companies get wrong: they make it slow and annoying. Mine adds one screen, shown once, that takes about 15 seconds β€” and it never stops you from ordering food.

πŸ’‘ The hard part: Following the law and keeping the app fast are usually enemies. Every extra screen loses some users β€” and in food delivery, people switch apps in a second. My whole job was to make the app follow the law and stay quick. Not pick one.


1. What's actually wrong

I opened the real Zomato app and took screenshots myself. Three things stood out:

πŸ“Έ I've attached my screenshots of Zomato's real login and OTP screens. That "By continuing, you agree…" line at the bottom is the exact problem β€” it's live in the app right now.

Why this matters:

The law Fines up to β‚Ή250 crore. The deadline is real: May 2027.
Trust If ordering food feels creepy (spam calls, ads following you around), people just switch apps.
Kids The law bans tracking under-18s β€” but Zomato can't even tell who they are today.

A few things I assumed (since I don't have Zomato's internal data):