Skip to main content
Back to all guides

Compliance

203 guides

Privacy regulation compliance guides

Cookie Consent for Telecom and ISP Websites

The EU cookie law started as a telecoms rule. Telecom operators and ISPs carry a double obligation: consent for cookies on their websites, and consent for the traffic and location data their networks generate. Here's how to handle both.

6 min read

GPP, MSPA & US State Signals: A Publisher's Guide

The US Privacy String you built for CCPA was deprecated in January 2024. GPP, the US National string, and the MSPA replaced it, and getting the signal wrong can be a misrepresentation. Here's how the new US privacy signals move through the ad stack.

7 min read

Cookie Consent for Online Marketplaces and Multi-Vendor Platforms

A marketplace tracks two audiences at once, buyers and sellers, and the platform and its sellers can end up as joint controllers of the same data. Here's how multi-vendor platforms handle cookie consent, controller roles, and the DSA's advertising limits.

5 min read

Laravel Cookie Consent: Blade Setup Guide 2026

Laravel renders Blade on the server, so the tag your team pasted into the master layout head fires on every request before consent. Here's how to control script placement with Blade stacks, gate server-side tracking, and read a JS-set consent cookie past Laravel's cookie encryption.

5 min read

Implementing the IAB GPP __gpp() API

How the Global Privacy Platform's __gpp() function actually works: the six synchronous generic commands, the PingReturn object, applicableSections, and why the stub has to load first.

5 min read

Data Portability Requests: What You Actually Have to Provide

Data portability is the most misunderstood data subject right. It is narrower than access, it only covers certain data, and a scanned PDF does not count. Here is exactly what GDPR Article 20 requires, what to leave out, and how the CCPA version differs.

7 min read

Is Your Analytics Vendor a Controller or Processor?

When you run Google Analytics, is Google acting on your instructions or its own? The answer decides who's liable, what contract you need, and whether the setup is even lawful. It varies by vendor, and sometimes by a single checkbox.

6 min read

Cookie Data Retention: How Long Should You Keep the Data?

GDPR's storage limitation principle says personal data can't sit around forever. This guide covers how long cookies should live, how long the data they collect can be kept, and how to write a retention schedule that survives a regulator's question.

6 min read

Consent Receipts and ISO/IEC 27560: A Standard for Provable Consent

GDPR Article 7 says you must be able to demonstrate consent. ISO/IEC 27560 gives that record a defined structure, and a receipt you can hand back to the user. Here's what the standard covers and how to use it without over-engineering.

6 min read

The California Delete Act and DROP: 2026 Data Broker Rules

California's Delete Act lets consumers erase their data from every registered broker with one request through DROP. Here is how it works, who counts as a broker, and the 2026 deadlines.

5 min read

YouTube & Vimeo Embeds: Consent Without Breaking Video

A standard YouTube or Vimeo embed connects to Google or Vimeo and sets storage before the visitor does anything. Here is how to gate video embeds properly, including what youtube-nocookie and dnt=1 actually do.

5 min read

Virginia VCDPA Cookie Compliance for 2026

Virginia was the second state after California to pass a broad consumer privacy law, live since January 1, 2023. It uses an opt-out model, requires opt-in for sensitive data, and, unlike Colorado or Texas, does not make you honor the Global Privacy Control.

5 min read

Cookie Consent for Video Game Studios

Epic Games paid $520 million to the FTC over Fortnite, and Genshin Impact's developer paid $20 million in 2025. Here's how game studios handle cookie consent on their marketing sites, web stores, and account pages, with COPPA and age-gating built in.

5 min read

Verifying a Data Subject's Identity for a Privacy Request

Verify too little and you hand someone's data to an impostor. Verify too much and you break the law you are trying to follow. This is how to set the identity bar correctly under GDPR and the CCPA, including the requests where you are not allowed to verify at all.

8 min read

Answering Vendor Privacy Questionnaires Without the Panic

Enterprise deals stall on a spreadsheet: the security and privacy questionnaire. Here's what SIG and CAIQ ask, which documents actually close the loop, and how the cookie consent questions get answered from your logs instead of a guess.

5 min read

Utah UCPA Cookie Compliance: The 2026 Guide

Utah wrote the most business-friendly privacy law in the country. Live since December 31, 2023, the UCPA skips the universal opt-out mandate, asks only for notice-and-opt-out on sensitive data, and covers far fewer companies thanks to a $25 million revenue gate.

5 min read

Universal Opt-Out Mechanisms: Which States Require Them

A universal opt-out mechanism lets people opt out of data sales across every site at once. Roughly a dozen states now make honoring one legally mandatory. Here is the map and how to comply.

5 min read

Turkey KVKK Cookie Consent: 2026 Guide

Turkey's data authority published dedicated cookie guidance in June 2022 and amended the underlying law in 2024. Here's how the KVKK treats cookies: explicit consent by default, two narrow exceptions, and what the reforms changed.

5 min read

Thailand PDPA Cookie Consent: 2026 Rules

Thailand's PDPA has been fully enforceable since June 2022, and the PDPC moved to active enforcement in 2024 and 2025. Here's how the law treats cookies: explicit opt-in consent, no implied consent from browsing, and records you have to keep.

5 min read

Texas TDPSA Cookie Compliance: The 2026 Rules

Texas has no cookie-banner law. It has the TDPSA (live since July 1, 2024), a universal opt-out mandate that turned on January 1, 2025, and an attorney general running one of the most aggressive privacy enforcement operations in the country.

6 min read

How to Test Your Cookie Banner Is Compliant

A 2023 study found most EU cookie banners still fail. Building one right and verifying it works are different jobs. This is the QA pass you run after launch: the network-tab tests, the button rules, and the signals that trip up real audits.

5 min read

The TCF and GPP Stub: Async Loading Done Right

Vendor scripts call the CMP API before the CMP finishes loading. The stub is what keeps those early calls from throwing. Here's how the stub, the locator iframe, and the command queue work together.

5 min read

TCF and Google Additional Consent Explained

Google runs ad tech partners that aren't on the IAB Global Vendor List, so TCF alone can't signal consent for them. The Additional Consent (AC) string fills the gap. Here's the format and how a CMP produces it.

5 min read

Managing the TCF Global Vendor List (GVL)

The Global Vendor List is a large JSON document that changes weekly. Here's how to load it without slowing every page, why the slim and full variants exist, and how the version field ties back to the TC String.

5 min read

Building a TCF CMP That Passes IAB Validation

What it takes for a Consent Management Platform to pass IAB Europe's TCF checks: a registered CMP ID, a cleanly decodable TC String, event-listener delivery, and encoding against the right GVL version.

5 min read

Switzerland's Revised FADP: Cookie Consent in 2026

Switzerland isn't in the EU, and its cookie rules follow a different logic: risk-based, opt-out for low-risk cookies, opt-in for advertising and profiling. Here's how the revised FADP and the 2025 FDPIC guidance actually work.

5 min read

Switching Analytics or Marketing Vendors? Handle the Cookie Changes

Replacing one tracking tool with another quietly rewrites your cookie inventory and your data recipients. Here's how to swap vendors without leaking trackers or orphaning cookies.

6 min read

SvelteKit Cookie Consent: The 2026 Setup Guide

SvelteKit renders on the server and hydrates on the client, which means a tracker in app.html or an onMount call can fire before consent. Here's where the consent loader belongs, how to block scripts until opt-in, and how to check consent in hooks.server.ts.

5 min read

Cookie Consent for Streaming and Video Sites: The VPPA Problem

A 1988 law written for video-rental stores now drives class actions against any website that puts a tracking pixel near a video player. Here's how streaming and video sites handle the Video Privacy Protection Act alongside GDPR and state consent rules.

5 min read

South Korea's PIPA: Cookie Consent Rules for 2026

South Korea is one of the strictest consent regimes on the planet, and its regulator proves it. The PIPC has fined Google and Meta a combined 100 billion won for behavioral-ad tracking without consent. Here's how PIPA treats cookies after the 2023 overhaul.

5 min read

Social Embeds and Consent: The Click-to-Load Pattern

Instagram, X, TikTok, and Facebook embeds load third-party scripts and set cookies before anyone interacts. A CJEU ruling makes you a joint controller for that data flow. Click-to-load fixes it.

5 min read

SOC 2 and Privacy: What the Report Says About Cookies

SOC 2 is the report enterprise buyers ask for first, but its Privacy category is the one most companies skip. Here's what SOC 2 actually attests, how the Privacy criterion works, and why your cookie consent records show up in the audit.

6 min read

Singapore PDPA Cookie Consent: 2026 Guide

Since October 2022, Singapore's regulator can fine organisations up to 10% of local turnover for data breaches. Here's how the PDPA treats cookies, how deemed consent works, and why ignored browser settings don't count as agreement.

5 min read

How to Set Up Google Consent Mode With a CMP

Consent Mode v2 has been required since March 2024 to keep Google ad and measurement features working in the EEA. Here's the end-to-end setup wiring your CMP to Google's seven consent signals, step by step.

4 min read

Sensitive Data Under US State Privacy Laws in 2026

Health data, precise location, and other sensitive categories get special treatment under US state laws, and the rules split between opt-in consent and a right to limit. Here is how to handle them.

5 min read

Safari ITP Explained for Marketers

Safari blocks every third-party cookie and deletes JavaScript-set cookies after seven days. Here's what Intelligent Tracking Prevention does to your measurement, and what it doesn't.

6 min read

ROPA for Cookies: Building an Article 30 Record for Your Trackers

GDPR Article 30 requires most organisations to keep a written record of their processing activities. Here's how to turn a cookie and tracker inventory into ROPA entries a supervisory authority will accept.

6 min read

The Right to Be Forgotten: Handling Erasure Requests in Practice

The right to erasure is not a delete button, and it is not absolute. Here is how to work an Article 17 request end to end: the six grounds, the exemptions that let you keep data, backups, the Article 19 downstream notification, and the CCPA right to delete in parallel.

9 min read

Cookie Consent for Job Boards and Recruitment Sites

The EU AI Act makes recruitment AI high-risk from August 2026, and the ICO has put automated hiring decisions on its enforcement list. Here's how job boards and career sites should handle cookie consent for candidate data.

6 min read

Quebec's Law 25: Cookie Consent Rules for 2026

Federal PIPEDA is flexible about cookies. Quebec's Law 25 is not. Section 8.1 requires profiling and tracking technology to be switched off by default, and the CAI can levy penalties up to CAD $25 million. Here's the Quebec-specific model, layer by layer.

6 min read

Your Quarterly Cookie Consent Review: A Recurring Checklist

A full audit once a year isn't enough when your site changes weekly. Here's a lighter quarterly review that keeps consent current between audits, with a repeatable agenda.

5 min read

How to Build a Privacy Trust Center That Closes Deals

A trust center turns your three-week security questionnaire into a link. Here's what to publish openly, what to gate behind an NDA, and how your subprocessor list and consent records fit, so buyers self-serve their due diligence.

5 min read

Privacy Sandbox Is Over: What Google's 2025 Shutdown Means for Consent

On 17 October 2025 Google retired most Privacy Sandbox technologies and kept third-party cookies in Chrome. Here's the verified timeline and why consent banners now matter more, not less.

5 min read

How to Build a Privacy Request Intake Form That Complies

The intake form is where a privacy request is won or lost. Get the fields, methods, and routing right and the rest of the process runs itself. Here is what the CCPA and GDPR require, the fields to capture, and the traps that turn a form into a dark pattern.

7 min read

POPIA Cookie Consent in South Africa: 2026 Guide

South Africa's Information Regulator issued its first POPIA fine (R5 million) in 2023 and has warned that more are coming. Here's how POPIA treats cookies, what section 69 means for tracking, and what the 2025 amended Regulations changed.

5 min read

Do Plausible & Fathom Need Consent? Cookieless, Explained

Cookieless analytics like Plausible and Fathom store nothing on the device, so the ePrivacy cookie rule generally doesn't apply and you can usually skip the banner. But GDPR still does, and no EU regulator has formally certified them. Here's the honest picture.

6 min read

Cookie Consent for Pharma and Life Sciences Websites

Drug makers usually aren't HIPAA covered entities, but their sites still handle health data that GDPR treats as a special category and that Meta throttles automatically. Here's how pharma and life-sciences companies run cookie consent across brand sites, HCP portals, and adverse-event forms.

6 min read

Oregon Consumer Privacy Act: Cookies in 2026

Oregon's privacy law turned on two things in 2026: a universal opt-out mandate that went live January 1, and the end of the cure period on the same day. It also gives residents a right most states don't, the names of the specific third parties that got their data.

5 min read

Nigeria NDPA Cookie Consent: 2026 Guide

Nigeria's NDPC now says cookie banners belong at the top of the page, not the bottom, and wants opt-in before non-essential cookies. Here's what the 2023 Act and the 2025 GAID require, and what enforcement looks like.

5 min read

My Health My Data Act: Website Compliance Guide

Washington's My Health My Data Act reaches far past hospitals and HIPAA. A cannabis retailer was sued in November 2025 over a website tracking pixel. Here's the two-permission structure, the geofencing ban, the separate homepage policy, and the private right of action that makes it dangerous.

7 min read

Montana, Delaware, Iowa, Nebraska: Cookie Rules

Four state privacy laws went live around 2025, and they don't agree with each other. Three require you to honor the Global Privacy Control; Iowa doesn't and skips the targeted-ad opt-out entirely. Here's how cookies work under each.

5 min read

Monitoring for Consent Violations and Tag Drift

A consent setup that passed testing last quarter can be leaking today. Here's what consent drift looks like, why point-in-time scans miss it, and how to monitor continuously.

8 min read

Mixpanel & Amplitude Consent: Opt-Out Isn't Enough

Product analytics tools store a device ID in localStorage or a cookie, and their opt-out APIs stop the data send while often still writing that identifier. Here's why that gap matters for ePrivacy and how to gate Mixpanel and Amplitude properly.

6 min read

Does Matomo Need Consent? It Depends on the Config

Matomo can run without a cookie banner, but only in a specific configuration. Turn on cookies, heatmaps, User ID, or session recording and you're back to needing consent. Here's exactly where the line sits and how to stay on the right side of it.

6 min read

Live Chat Widgets and Consent: Intercom, Drift, Crisp

Chat widgets load third-party code and set cookies the moment your page opens. Whether that needs consent depends on how you use chat. Here is how to decide, and how to load the widget only when someone wants it.

5 min read

Legitimate Interest vs Consent for Cookies

Teams often try to justify analytics or ad cookies under "legitimate interest" to skip the banner. For cookies on an EU visitor's device, that reasoning fails at the first gate. Here's when consent is the only option, and the narrow cases where legitimate interest genuinely fits.

6 min read

Japan's APPI: Cookies and Consent in 2026

Japan treats a bare cookie ID differently from Europe: on its own it usually isn't personal data. The consent obligation kicks in at a specific point, when you hand cookie-based data to a third party who can tie it to a person. Here's the personally-referable-information rule and what's changing.

6 min read

ISO 27701 Explained: The Privacy Standard Buyers Ask For

On 14 October 2025, ISO/IEC 27701 became a standalone privacy management standard, so you no longer need an ISO 27001 certificate first. Here's what it certifies, how it maps to GDPR, and why enterprise buyers keep asking for it.

6 min read

Pre-Ticked Boxes and Other Invalid Cookie Consent

Pre-ticked boxes, "by using this site you agree," and scroll-to-consent all look like consent and none of them are. Here's what makes cookie consent legally invalid, with the case law behind each one.

5 min read

Cookie Consent for Insurance Websites

Insurers are financial institutions under GLBA and regulated by 50 state insurance departments, and their quote forms collect health and financial data. Here's how to run cookie consent on an insurance site without leaking regulated information.

6 min read

In-App Browser Consent: When Visitors Arrive via WebView

A large slice of your social traffic never opens Safari or Chrome. It opens your site inside Instagram's or TikTok's embedded browser, where cookies are isolated, third-party cookies are off by default, and a consent choice may not survive the next tap.

6 min read

Implementing Global Privacy Control (GPC) in Your Banner

A technical guide to honoring Global Privacy Control: detect the signal via navigator.globalPrivacyControl and the Sec-GPC header, auto-apply the opt-out, and meet California's 2026 requirement to display that the signal was honored.

5 min read

Cookie Consent for iGaming and Online Gambling Sites

Licensed betting and casino operators answer to a gambling regulator and a data protection authority at the same time. Here's how to run cookie consent on an iGaming site without breaking marketing rules, affiliate tracking, or self-exclusion.

8 min read

Write a Cookie Policy That Matches Your Cookies

A cookie policy copied from a template describes someone else's website. This guide shows how to build one from your real inventory: what each entry needs, the table format regulators expect, and how to keep it accurate as scripts change.

5 min read

How to Process an Opt-Out (Do Not Sell) Request Operationally

The Do Not Sell link is the front door. This is the back office: what has to happen across your systems and vendor chain once someone opts out, the 15-business-day clock, who you must notify downstream, and why a preference that keeps the pixels firing is the exact failure regulators fine.

8 min read

How Often Should You Re-Scan Your Site for New Cookies?

Your cookie inventory drifts the moment you ship a new page or a marketer adds a tag. Here's a practical re-scan cadence, plus the events that should trigger an off-cycle scan.

6 min read

Hotjar & Clarity Consent: Recordings Are Personal Data

Session recordings capture what people type, beyond where they click. Microsoft Clarity started requiring consent in Europe on 31 October 2025, and Hotjar records the moment it loads. Here's how to gate both and why masking is on you.

6 min read

GTM Containers Are Becoming Google Tags: What It Means for Cookie Consent

Google is merging GTM and Google Tag into a unified product. Destinations replace separate gtag.js loads, settings get centralized, and the UI gets a redesign. Here's what changes for consent management and what stays the same.

12 min read

The GPP US National (usnat) String Explained

The usnat section (GPP Section 7) encodes MSPA opt-outs for a dozen US state laws in one string. Here's what each field means, how the opt-out values are encoded, and where GPC lives.

5 min read

Google Maps Embeds Need Consent: Here's the Fix

The Google Maps embed iframe sets non-essential cookies and sends visitor data to Google the moment your page loads. Gate it with a click-to-load facade, or drop Google for a cookieless map.

5 min read

Google Fonts, the GDPR, and the German Court Ruling

A Munich court awarded a website visitor damages because a site loaded Google Fonts from Google's servers and leaked their IP address. Self-hosting removes the problem entirely, and it is faster.

5 min read

Google's Certified CMP Requirement for AdSense, Ad Manager and AdMob

If you run Google ads on your site or app in the EEA, UK or Switzerland, Google requires a certified CMP integrated with the IAB TCF. Here's what that means, the enforcement dates, and the revenue cost of ignoring it.

5 min read

Cookie Consent Laws Around the World: 2026 Guide

More than 140 countries now have a data protection law, and they split into two broad camps on cookies: opt-in and opt-out. Here's a country-by-country map of who requires what, and how to run one site across all of them.

6 min read

Germany's TDDDG: Cookie Consent Rules for 2026

Germany renamed its cookie law in May 2024, and §25 TDDDG still governs every read or write to a visitor's device. Here's how the two-layer German model works, what the new consent-management ordinance changes, and which of the 16 regulators actually enforces it.

8 min read

GDPR Consent Withdrawal: Making Opt-Out as Easy as Opt-In

If a visitor can accept cookies in one click but needs to email your DPO to refuse them later, your banner breaks GDPR. Article 7(3) requires withdrawal to be as easy as consent. Here's what that means in practice, and the classic failure of logging a withdrawal while the tag keeps firing.

5 min read

GDPR Certification and Europrivacy: The Official Seal

GDPR has its own certification route under Article 42, separate from ISO and SOC 2. Only one scheme has been approved as a pan-European seal so far: Europrivacy. Here's how the mechanism works and what a seal does (and doesn't) buy you.

5 min read

Cookie Consent for Fitness, Wellness, and Gym Websites

Gyms and fitness apps aren't HIPAA covered entities, but the FTC has fined health and wellness apps for sharing workout and cycle data with Facebook and Google. Here's how fitness businesses run cookie consent across booking flows, member portals, and wearable sync.

5 min read

Firefox Total Cookie Protection and ETP

Firefox gives every website its own cookie jar and blocks fingerprinters and cross-site cookies by default. Here's how Total Cookie Protection and Enhanced Tracking Protection work, and what they mean for your tracking.

5 min read

The EU Digital Omnibus: How Cookie Consent Changes in 2026

In November 2025 the European Commission proposed moving cookie rules out of the ePrivacy Directive and into the GDPR through a new Article 88a. Here is what the Digital Omnibus would change for consent banners, and what is still just a proposal.

7 min read

Cookie Consent in Emerging Markets: A 2026 Global Guide

Beyond the EU, the US, and Brazil, a wave of privacy laws in the Gulf, Africa, and Southeast Asia now reach cookies and online tracking. Here is where consent is required in Saudi Arabia, the UAE, Nigeria, Vietnam, Indonesia, and Thailand in 2026.

6 min read

EDPB Cookie Guidance in 2026: What the Regulators Actually Said

The European Data Protection Board has quietly built the rulebook that DPAs now enforce against cookie banners: the Cookie Banner Taskforce report, the Article 5(3) technical-scope guidelines, and the consent-or-pay opinion. Here is what each one means for your banner.

6 min read

Cookie Consent for Klaviyo, Onsite Tracking & Cart Emails

Your abandoned-cart flow only works if you can identify the shopper, and identifying the shopper means a tracking cookie that needs consent. This guide untangles onsite tracking consent, abandoned cart vs abandoned checkout, the UK soft opt-in, and US SMS rules.

8 min read

DSAR Deadlines by Law: How Long You Have to Respond

GDPR gives you one month. California gives you 45 days. Brazil wants a first answer in 15. Every privacy law counts its own clock, and starting it late or missing an extension notice is its own violation. Here is the deadline for each major regime and how the clock actually runs.

7 min read

Do Cookies Need a DPIA? When Tracking Triggers Article 35

A DPIA is the written risk assessment GDPR requires before high-risk processing starts. Most cookie banners don't need one. Some tracking setups clearly do, and skipping a required DPIA is a breach in its own right. Here's how to tell which side you're on.

5 min read

Does GDPR Apply to US Companies? Usually, Yes

"We're US-only, GDPR is Europe's problem." Article 3(2) says otherwise. If you offer goods or services to people in the EU, or track their behaviour, the GDPR reaches you with no EU office at all.

5 min read

Do You Need a Cookie Banner in the US in 2026?

US privacy law does not demand a GDPR-style opt-in banner, but that does not mean you can skip consent tooling. Here is the state-by-state reality of what you actually need.

5 min read

How to Build a Compliant 'Do Not Sell or Share' Link

The Do Not Sell link is the most enforced control in US privacy law, and the rules are more specific than most sites realize. Here is exactly what CCPA requires and how to get it right.

5 min read

Do You Need a DPO for Cookie Compliance?

Not every website needs a data protection officer. But if tracking is central to how your business runs, GDPR may force you to appoint one, and behavioral advertising is an example regulators name directly. Here's how to read Article 37 against your cookie setup.

6 min read

Cookie Consent for Crypto Exchanges and Web3 Sites

MiCA gives EU crypto platforms a hard authorization deadline and ties their data handling to GDPR. For a global exchange, that means running cookie consent properly across every jurisdiction it serves. Here's how.

6 min read

CPRA Enforcement 2025-2026: What the CPPA Is Doing

California now enforces the CCPA/CPRA through two agencies, and the fines are getting bigger. Here is what the CPPA and the Attorney General have actually pursued in 2025 and 2026, and what it means for your site.

6 min read

Why Copying a Competitor's Cookie Banner Backfires

Cloning a competitor's cookie banner feels like a shortcut. It maps consent to their cookies, not yours, can copy a non-compliant pattern, and leaves you with no records of your own. Here's the risk breakdown.

5 min read

A Cookie Plugin Alone Won't Make You Compliant

Installing a well-known consent plugin and watching the banner appear feels like the job is done. It isn't. noyb filed 226 complaints against companies running one of the biggest CMPs. The tool isn't compliance, the configuration is.

5 min read

Cookie Consent Myths That Cost Companies Millions

"Implied consent is fine." "We're US-only, so GDPR doesn't apply." "A banner makes us compliant." Ten cookie consent myths that regulators have already fined, and what the law actually says.

5 min read

Consent Mode v2 for EEA vs Non-EEA Traffic: Regional Gating

Google only requires consent signals for EEA, UK and Swiss traffic. Here's how the region parameter scopes strict consent defaults to those visitors while preserving measurement everywhere else.

5 min read

Consent Management Is an Ongoing Process, Not a One-Time Setup

Installing a banner is day one, not the finish line. Here's the operating model for consent as a continuous discipline: what changes, how often to check it, and who owns it.

6 min read

The European Accessibility Act and Your Cookie Banner

Since 28 June 2025 the European Accessibility Act makes accessibility a legal requirement for e-commerce, banking, and many other services. Your cookie banner is part of that surface. Here's the standard, and a ten-minute test.

5 min read

Connecticut CTDPA Cookie Compliance in 2026

Connecticut's data privacy law just got a major overhaul that took effect July 1, 2026: a far lower coverage threshold, expanded sensitive data, and a blanket ban on targeted ads to teens. The GPC mandate has been live since January 2025.

5 min read

Colorado Privacy Act: Cookie Rules for 2026

Colorado was the first state to make honoring the Global Privacy Control mandatory. Since July 1, 2024, controllers have had to treat a GPC signal as an opt-out, the cure period is gone, and penalties reach $20,000 per violation.

5 min read

The Court Rulings That Shaped Cookie Consent in the EU

Most of what makes a cookie banner legal in Europe was decided by the Court of Justice, not written in a statute. These five CJEU judgments, from Planet49 to IAB Europe, are the case law your banner has to satisfy.

6 min read

Partitioned Cookies (CHIPS): Do You Still Need Consent?

CHIPS lets a third-party cookie work inside one site without being readable across sites. It's a genuine anti-tracking win. It is not a consent exemption, and treating it like one is a mistake.

5 min read

China's PIPL: Cookie Consent and Transfers in 2026

China's PIPL has no legitimate-interests basis, so tracking almost always runs on consent, and it adds a concept most laws don't: separate consent for third-party sharing, targeted ads, and sending data abroad. Here's how it works after the 2024 transfer reforms.

6 min read

Browser Fingerprinting and Why Browsers Block It

Fingerprinting identifies visitors without a cookie, which is exactly why it survives cookie clearing and why Safari, Firefox, and Brave all fight it. Here's how it works and what it means for consent.

5 min read

Brave Browser, Shields, and Your Consent Banner

Brave blocks trackers, cross-site cookies, and fingerprinting out of the box, and randomizes the signals sites use to identify visitors. Here's how Shields work and what they mean for tracking and consent.

5 min read

B2B Visitor Deanonymization and Consent: What's Legal

Person-level visitor ID tools like RB2B are US-only for a reason: naming an anonymous EU visitor without consent is too risky to operate at scale. Here's the line between company-level and person-level identification, why 'GDPR doesn't apply to B2B' is wrong, and how to deploy these tools cleanly.

7 min read

Cookie Consent for Automotive Sites and Car Dealerships

Auto dealers are financial institutions under federal law, and connected-car data just cost General Motors a five-year FTC ban. Here's what that means for cookie consent on dealership and automotive websites in 2026.

7 min read

Australia's Privacy Act Reform: Cookies in 2026

Australia has no cookie-banner law, and it isn't getting one. But the 2024 Privacy Act reforms added a statutory privacy tort, a children's code, and penalties up to AUD $50 million. Here's what actually applies to cookies, and what's still coming.

6 min read

Astro Cookie Consent: Islands and Script Blocking

Astro ships zero JavaScript by default, but the moment you drop in a Google Analytics snippet or a Meta Pixel it fires on render, before any consent. Here's how Astro processes scripts, how to block trackers until a visitor opts in, and how to wire up Consent Mode v2.

6 min read

Angular Cookie Consent: The 2026 Developer Guide

Angular bootstraps one JavaScript bundle and never reloads the page on a route change, so a tracker in index.html or the angular.json scripts array runs before your app decides anything. Here's where the consent loader belongs, how to block scripts, and how to expose consent through a service.

5 min read

AI Chatbot Consent: LLM Widgets and Third-Party Data

An AI chat widget does two things a plain chat widget doesn't: it writes storage the moment it loads, and it ships whatever a visitor types to an LLM provider that often sits in another country. Both carry consent consequences.

6 min read

Agency Liability: Controller or Processor for Consent?

When a client's cookie banner is non-compliant, agencies assume it's the client's problem. Fashion ID says otherwise. Here's how controller vs processor status decides your liability, when you become a joint controller, and the contract structure that actually protects you.

7 min read

Age Assurance for Cookie Consent: When Self-Declaration Isn't Enough

If children might use your site, a checkbox saying 'I am over 16' won't satisfy COPPA, GDPR Article 8, or UK regulators. Here's how age assurance methods actually stack up, and what they mean for the cookies you set.

6 min read

Adobe Analytics Consent: Gate It the Right Way

Adobe's Web SDK ships a real consent mechanism, defaultConsent and setConsent, so you don't have to bolt one on. Here's how to wire it to a banner, what the legacy AppMeasurement library needs instead, and where teams still leak the ECID cookie.

6 min read

Adding a New Tracking Tool? A Consent Runbook Before You Go Live

A new analytics tool, pixel, or chat widget can drop cookies before anyone consents. This is the step-by-step process to add a tracker without breaking compliance.

6 min read

Ad Blockers vs Cookie Consent: Do You Still Need a Banner?

Ad blockers stop many trackers, and can even hide your banner. They still don't meet your legal obligation. Here's why you need a consent banner regardless, and how to keep it working when blockers strip it.

5 min read

The Accountability Principle Applied to Cookies

GDPR's accountability principle means it isn't enough to comply, you have to be able to prove it. For cookies, that turns a banner into a paper trail. Here's the documentation stack that survives a regulator's "show us," and why a perfect banner with no records looks the same as a broken one.

6 min read

Why 'Accept All' Only Banners Keep Getting Fined

A banner with a one-click "Accept All" and no equally easy way to refuse is the single most-fined cookie pattern in Europe. Google, Facebook, Microsoft, TikTok and Yahoo all paid for it. Here's the mechanism.

5 min read

Global Privacy Control (GPC) Explained: The New Standard for Opting Out

Discover what Global Privacy Control (GPC) is, how it works as a universal opt-out signal, and why compliance is now mandatory under CCPA and emerging privacy laws.

9 min read

How Cookie Scanners Work: Deep Scanning, Live Monitoring, and Why Most CMPs Only Do Half the Job

Learn how automated cookie scanners detect cookies, scripts, and network connections, and why periodic scanning alone leaves compliance gaps. See how CookieBeam's two-layer detection system combines headless Chrome deep scanning with real-time client-side drift monitoring for cookies, scripts, and connections to catch every tracker, every time.

20 min read

Inside Automated Cookie Scanning: How CDP, Headless Browsers, and Drift Detection Actually Work

Most CMPs scan your site once and hand you a list. This article tears open the machinery: Chrome DevTools Protocol instrumentation, headless browser orchestration, three-channel client-side drift detection, and the auto-promote loop that keeps a cookie inventory accurate without human intervention.

14 min read

WordPress Cookie Consent in 2026: The Complete Implementation Guide

A practical guide to implementing cookie consent on WordPress in 2026. Covers plugin-based cookies, CMP installation, server-side consent enforcement with wp_enqueue_script, WooCommerce checkout handling, Google Consent Mode v2 with GTM, and caching pitfalls.

16 min read

Wix Cookie Consent & GDPR: How to Make Your Wix Site Compliant in 2026

A practical guide to GDPR cookie compliance on Wix. Covers the built-in banner's limitations, adding a third-party CMP, Google Consent Mode v2, Velo consent APIs, and checkout consent for Wix Stores and Bookings.

12 min read

Why 78% of Cookie Banners Still Fail Compliance in 2026

A 2025 study of 10,000 EU websites found 78% had non-compliant cookie banners. This article breaks down the most common failure modes, the enforcement landscape, technical requirements, and a self-audit checklist.

13 min read

US State Privacy Laws 2026: Complete Guide to All 20+ Active Laws

A full reference to every US state full privacy law active in 2026, covering all 20+ states, enforcement dates, opt-out vs opt-in models, GPC requirements, and practical compliance strategies.

15 min read

UK GDPR After Brexit: How It Differs from EU GDPR

Since Brexit, the UK runs its own version of the GDPR. This guide explains what the UK GDPR is, how it differs from the EU GDPR, the role of the ICO and PECR, and what the reforms mean for your cookie banner.

7 min read

Third-Party Cookies Aren't Dead: What Chrome's User-Choice Model Means for Consent

Google reversed third-party cookie deprecation in Chrome, dropped the planned user-choice prompt, and wound down the Privacy Sandbox. Here's what that means for consent management, Consent Mode v2, and your marketing stack in 2026.

11 min read

TCF for Publishers: Implementing IAB's Transparency & Consent Framework (2.2 and 2.3)

A practical guide to the IAB Transparency & Consent Framework for publishers: who needs it, what TCF 2.2 changed, the TCF 2.3 technical update with its March 2026 deadline, and how to stay compliant.

7 min read

IAB TCF 2.2 vs Google Consent Mode v2: How They Differ and Work Together

TCF 2.2 and Google Consent Mode v2 are often confused, but they solve different problems. Learn what each one does, why most publishers need both, and how a CMP wires them together.

7 min read

TCF 2.2 Implementation for Publishers: The Complete Technical Walkthrough

A hands-on implementation guide for TCF 2.2: TC String structure, the __tcfapi CMP API, Global Vendor List management, publisher restrictions, and integration with Google Consent Mode, with working code examples.

13 min read

Session Replay & Heatmap Tools: The Consent and Privacy Risks Nobody Mentions

Session recording and heatmap tools capture far more personal data than most teams realize. Learn why they require consent, what regulators have flagged, and how to deploy them lawfully.

6 min read

SaaS Cookie Consent: Balancing Product Analytics with Privacy Compliance

SaaS products face unique consent challenges: auth tokens live alongside product analytics, customer success tools need gating, and B2B contracts muddy who actually consents. A practical guide for founders and product managers.

12 min read

Cookie Consent for Restaurants and Food Delivery: Online Ordering and GDPR

A practical guide for restaurant owners and food service IT on managing cookie consent for online ordering, delivery platform widgets, reservation integrations, review embeds, and local SEO under GDPR and privacy laws.

9 min read

Regional Consent: Running One Cookie Banner Across a Global Audience

GDPR demands opt-in, US laws expect opt-out, and other regions have their own rules. Instead of building a separate banner for each, a region-aware consent engine adapts behavior to each visitor's location. Here's how it works.

6 min read

Cookie Consent for Real Estate Websites: Lead Generation Without Compliance Risk

A practical guide for real estate agencies and PropTech companies on managing cookie consent across property search, IDX/MLS feeds, virtual tour embeds, and CRM integrations without sacrificing lead generation.

9 min read

Cookie Consent for Publishers: Protecting Ad Revenue While Staying Compliant

How cookie consent directly impacts programmatic ad revenue for publishers: consented vs unconsented CPMs, TCF 2.2 requirements for maximum fill rates, Google's Certified CMP mandate, Prebid.js integration, and strategies to protect monetization without sacrificing compliance.

11 min read

Proof of Consent Under GDPR: What Records You Need and How to Keep Them

GDPR Article 7(1) puts the burden of proof on you. This guide walks DPOs through exactly what consent records regulators request during audits, the technical schema behind defensible proof, cross-border requirements, and how to handle withdrawal and re-consent cycles.

12 min read

Privacy by Design for Websites: A Practical Implementation Guide

Privacy by Design isn't a compliance checkbox, it's an architecture decision. This guide maps Ann Cavoukian's 7 foundational principles to concrete web development patterns: data minimization in forms, purpose limitation per cookie category, automatic storage cleanup, opt-in consent defaults, server-side processing, and structured consent logging.

13 min read

PIPEDA & Cookie Consent in Canada: A Practical Guide for Website Owners

Canada's PIPEDA governs how you handle the personal data of Canadian users, including cookies. Learn its consent model, how it differs from GDPR, and what your website needs to do.

6 min read

PECR and UK Cookie Law After Brexit: What's Different in 2026

PECR is the law that actually governs cookies in the UK, not the UK GDPR alone. This guide covers Regulation 6, the new analytics exemption under the Data (Use and Access) Act 2025, ICO enforcement, and what UK-specific CMP features you need in 2026.

11 min read

The One-Click Reject Rule: How Dark Pattern Laws Are Reshaping Cookie Banners in 2026

European regulators now demand that refusing cookies is exactly as easy as accepting them. Learn the enforcement actions, technical requirements, and banner design rules that define compliant cookie consent in 2026.

11 min read

Cookie Consent for Nonprofits: GDPR Compliance on a Limited Budget

Nonprofits aren't exempt from GDPR cookie rules, but compliance doesn't require an enterprise budget. This guide covers common nonprofit cookies, budget-friendly strategies, and how to protect donor trust through transparent consent management.

9 min read

Next.js Cookie Consent with App Router: The 2026 Developer Guide

A deep technical guide to implementing cookie consent in Next.js App Router applications. Covers Server Component limitations, next/script strategies for CMP loading, Client Component consent wrappers, dynamic imports for consent-gated analytics, middleware-level enforcement, GTM with Consent Mode v2, and CookieBeam integration.

13 min read

Mobile App Consent Management: SDKs, ATT, and GDPR for iOS and Android

Mobile apps don't use cookies, but they collect device IDs, IDFA, and GAID that trigger the same GDPR consent requirements. Learn how ATT, Privacy Sandbox, TCF mobile SDKs, and Firebase Consent Mode shape consent on iOS and Android in 2026.

11 min read

How to Migrate Your CMP Without Losing Existing Consent Records

A step-by-step technical guide to switching consent management platforms without losing consent records, triggering mass re-consent, or breaking Consent Mode. Covers export, category mapping, parallel runs, and zero-downtime migration patterns.

9 min read

Measuring the Impact of Cookie Consent on Your Analytics: A Data-Driven Guide

Learn how to quantify the analytics data you lose to cookie consent, benchmark your consent rates by region, and build a measurement framework that accounts for modeled data, server-side recovery, and first-party strategies.

13 min read

LGPD Enforcement in 2026: Brazil's Privacy Audits and What They Mean for Your Cookie Banner

Brazil's ANPD has shifted from education to enforcement. Targeted audits, specific fines for pre-ticked consent and missing Portuguese interfaces, and a narrower legitimate interest scope are changing what LGPD compliance actually looks like in 2026.

12 min read

LGPD Compliance for Websites: Brazil's Data Protection Law Explained

A practical guide to Brazil's Lei Geral de Proteção de Dados (LGPD) for website owners, legal bases, cookie consent, data-subject rights, the ANPD's enforcement powers, and how LGPD differs from GDPR.

8 min read

Cookie Consent for Law Firms: Client Confidentiality and Professional Ethics

Law firm websites face unique cookie consent obligations rooted in attorney-client privilege and professional ethics rules. Third-party tracking can expose which practice areas visitors browse, creating confidentiality risks that other industries don't face. This guide covers bar association duties, analytics risks, contact form consent, and how to configure strict defaults.

9 min read

Is Google Analytics GDPR Compliant? What Website Owners Need to Know

Google Analytics is not compliant by default, but it can be configured to meet GDPR requirements. This guide explains the legal concerns, what changed with GA4, and the concrete steps to run analytics lawfully in the EU.

6 min read

India's DPDP Act 2026: Cookie Consent in 22 Languages and What It Means for Global Websites

India's Digital Personal Data Protection Act introduces registered Consent Managers, mandatory consent in 22 official languages, and single-click withdrawal. Here's what global websites need to know before the May 2027 enforcement deadline.

12 min read

How to Audit Your Cookie Consent Implementation: A 2026 Checklist

A 25-point technical checklist for auditing whether your CMP actually works, banner behavior, Consent Mode signals, script blocking, regional rules, and how to document findings for compliance records.

13 min read

How to Debug Consent Mode v2: A Step-by-Step Troubleshooting Guide

A practical, step-by-step guide to diagnosing broken Consent Mode v2 implementations. Learn to decode gcs and gcd parameters, catch race conditions, and fix the issues causing missing conversions and empty audiences.

12 min read

Cookie Consent for Hotels and Travel: Booking Engines, OTAs, and GDPR

A practical guide for hospitality IT and marketing teams on managing cookie consent across booking engines, OTA integrations, retargeting pixels, multi-property domains, and guest Wi-Fi portals under GDPR and global privacy laws.

8 min read

Healthcare Websites and Cookie Consent: HIPAA, FTC, and the New Tracking Rules

Healthcare websites face unique cookie consent challenges under HIPAA, FTC enforcement, and state health data laws. This guide covers what went wrong with tracking pixels on hospital and telehealth sites, which cookies are safe, and how to handle consent for patient portals and appointment booking.

9 min read

Cookie Consent for Government Websites: Compliance Standards and Accessibility Requirements

Government websites face the highest bar for cookie consent compliance: mandatory accessibility standards, strict analytics restrictions, multi-language requirements, and public trust obligations. This guide covers EU, US, and UK requirements and how to meet them.

9 min read

Google Tag Manager and Consent: The Complete Setup Guide for 2026

A deep-dive tutorial on GTM's built-in consent features: Consent Initialization triggers, custom consent templates, the Additional Consent Checks refire bug, the consent overview report, Consent Mode v2 wiring, server-side consent flow, and CookieBeam integration.

12 min read

Google Signals Removal (June 2026): What It Means for Your Consent Architecture

On June 15, 2026, Google stripped Google Signals of its authority over the GA4-to-Google Ads data flow. Ad data control now runs exclusively through Consent Mode's ad_storage parameter, placing new responsibility on your CMP.

11 min read

Google Privacy Sandbox & the Topics API Explained: Advertising After Third-Party Cookies

The Privacy Sandbox is Google's set of browser APIs meant to replace third-party cookies for advertising. Learn how the Topics API works, what it means for consent, and how to prepare.

7 min read

Google Marketing Live 2026: What Gemini-Powered Ads Mean for Consent Management

Google's Business Agent for Leads embeds a Gemini-powered chat directly inside ad units, replacing the landing page with an AI conversation. For consent management, this breaks every assumption about when and where data collection starts.

10 min read

Google's EU User Consent Policy Explained: What Advertisers and Publishers Must Do

If you use Google Ads, Analytics, or AdSense with European users, Google's EU User Consent Policy is a contractual obligation on top of the law. Learn what it requires and how to comply.

6 min read

Global Privacy Control (GPC) Explained: What It Is and Why Your Site Must Honor It

Global Privacy Control is a browser signal that lets users opt out of data sale and sharing automatically. In several US states, ignoring it is a legal violation. Here is how GPC works and how to respect it.

7 min read

GA4 Privacy Settings Audit: Every Setting That Affects Your GDPR Compliance

A setting-by-setting walkthrough of every GA4 configuration that affects GDPR compliance: data collection, retention, sharing, Consent Mode integration, data deletion, BigQuery exports, and a 20-item audit checklist you can run today.

20 min read

GA4 and Google Ads Split Consent Controls on June 15, 2026: ad_storage Is Now the Single Authority

On 15 June 2026 Google made Consent Mode's ad_storage signal the single control over what advertising data GA4 collects and passes to Google Ads. Google Signals no longer gates Ads data. Here is what changed, what breaks if your banner is misconfigured, and how to audit your setup.

9 min read

FinTech and Cookie Consent: Navigating PCI DSS, PSD2, and GDPR Together

Fintech companies face a triple compliance burden: PCI DSS 4.0 script controls on payment pages, PSD2 Strong Customer Authentication requirements, and GDPR consent obligations. This guide covers how these frameworks interact, what cookies are essential for payment processing, and how to implement consent without breaking payment flows.

10 min read

Cookie Consent for Event and Ticketing Websites: A Practical Guide

A practical guide for event organizers and ticketing platform operators on managing cookie consent across high-urgency checkout flows, queue systems, embedded venue maps, marketing retargeting, and email integrations under GDPR and global privacy laws.

9 min read

EU-US Data Transfers & the Data Privacy Framework: A Website Owner's Guide

Sending EU visitors' data to US-based tools is one of the trickiest parts of GDPR compliance. This guide explains why transfers are restricted, what the Data Privacy Framework and SCCs do, and how to keep your stack lawful.

6 min read

The ePrivacy Regulation: What's Coming After the Cookie Directive

The ePrivacy Regulation is meant to replace the 2002 Cookie Directive, but it's been stuck in political limbo since 2017. Here's where it stands in 2026, what it would change for cookie consent, and what compliance officers should do right now.

11 min read

Cookie Consent for Education Websites: FERPA, COPPA, and Student Privacy in 2026

Education websites face layered consent obligations under FERPA, COPPA, state student privacy laws, and general privacy regulations. This guide covers what K-12 schools, universities, and EdTech vendors need to know about cookies, analytics, and parent vs. student consent in 2026.

8 min read

E-Commerce Cookie Consent: How to Stay Compliant Without Killing Conversions

A practical guide for e-commerce teams on balancing cookie consent compliance with conversion performance. Covers essential cookies, marketing consent, server-side recovery, cross-border rules, and CookieBeam's auto-categorization for online stores.

12 min read

DSAR Handling for Website Owners: A Practical Guide

A practical guide to handling Data Subject Access Requests under GDPR: the rights involved, how to verify identity, the one-month deadline, valid reasons to refuse, and a repeatable workflow.

6 min read

Do I Need a Cookie Banner? When Cookie Consent Is Actually Required

Not every website legally needs a cookie banner, and many that show one are doing it wrong. Learn what actually triggers a consent requirement, which visitors it depends on, and how to tell whether your site needs one.

8 min read

Data Processing Agreements (DPAs): What Website Owners Need to Know

Every third-party tool that handles your visitors' data needs a Data Processing Agreement. This guide explains what a DPA is, when GDPR requires one, what it must contain, and how to manage them across your stack.

6 min read

Data Processing Agreements with Your CMP: What GDPR Article 28 Requires

Your CMP processes consent records, IP addresses, and device data on your behalf, making it a GDPR processor that needs a proper DPA. This guide covers what to look for, what to avoid, and how to evaluate a CMP's data processing agreement before you sign.

11 min read

Data Breach and Cookie Consent: What Happens When Your CMP Gets It Wrong

Cookie consent failures don't always equal data breaches, but sometimes they do. This guide covers when unconsented cookies cross the line into a notifiable breach under GDPR, what the real enforcement landscape looks like, and how to respond when you discover cookies were set without valid consent.

11 min read

Cross-Domain Consent Sharing: How to Sync Cookie Consent Across Multiple Websites

If you run several domains or a network of brand sites, asking visitors to consent again on each one is bad UX and inconsistent compliance. This guide explains how cross-domain consent sharing works and when it is legally appropriate.

7 min read

Cross-Domain Consent Sharing: Technical Implementation Patterns for Multi-Site Organizations

Four concrete implementation patterns for sharing cookie consent across domains: parent-domain cookies, postMessage bridges, server-side API sync, and signed URL tokens. Covers code, security pitfalls, Consent Mode v2 per-domain firing, iframe propagation, and how CookieBeam's domain groups handle it.

18 min read

Cookie Walls and "Pay or Consent": What's Actually Legal in 2026

Cookie walls and "pay or consent" models force visitors to choose between accepting tracking or losing access. Learn what the EDPB, CJEU, and national regulators have ruled, and how to design a lawful alternative.

7 min read

Cookie Walls in 2026: Are 'Pay or Consent' Models Actually Legal?

The legality of cookie walls and 'pay or consent' models varies wildly across Europe. This jurisdiction-by-jurisdiction guide covers the CJEU precedent, EDPB opinion, and where each country draws the line in 2026.

11 min read

Cookie Scanning vs Manual Audit: Which Approach Actually Keeps You Compliant?

Manually cataloguing every cookie your site sets is slow, error-prone, and outdated the moment you finish. Automated cookie scanning solves the discovery problem at scale. Here is how the two methods compare and when each makes sense.

10 min read

Cookie Policy vs Privacy Policy: What's the Difference and Do You Need Both?

A cookie policy and a privacy policy are related but distinct legal documents. This guide explains what each one covers, why most websites need both, and exactly what to include in each.

6 min read

Cookie Consent for Single-Page Apps (React, Vue, Angular): The 2026 Developer Guide

SPAs break the assumptions that cookie consent platforms were built on. This developer guide covers race conditions, route-change consent, React/Vue/Angular integration patterns, SSR hydration timing, script gating with dynamic imports, and Consent Mode v2 sequencing for SPA navigation.

17 min read

Cookie Consent Penalties by Country: Maximum Fines and Enforcement in 2026

A country-by-country breakdown of cookie consent and data privacy penalties in 2026, covering maximum fines, enforcing authorities, and recent enforcement trends across GDPR, CCPA, LGPD, PIPL, DPDP, and more.

14 min read

The Developer's Cookie Consent Implementation Checklist: 30 Steps to Get It Right

A 30-step technical checklist covering the full CMP implementation lifecycle: planning, script integration, Consent Mode, regional rules, testing, launch, and ongoing maintenance.

11 min read

Cookie Consent for Agencies: Managing Compliance Across Multiple Client Websites

A practical guide for digital agencies managing cookie consent across 10-100+ client websites. Covers multi-client dashboards, white-label solutions, compliance templates, client reporting, pricing models, and how to turn consent management into a billable service.

10 min read

Cookie Consent for Connected TV and IoT: The 2026 Compliance Frontier

Connected TVs, smart speakers, and IoT devices collect personal data but lack browsers and cookie banners. Learn how consent management works on screenless and keyboard-free platforms under GDPR, CCPA, and DPDP.

10 min read

Why 67% of Consent Mode v2 Setups Fail Compliance Checks

Most Consent Mode v2 implementations fail compliance audits. This technical guide covers the common setup mistakes, the four required consent signals, Advanced vs Basic mode trade-offs, and how to test and fix your implementation.

12 min read

Consent Mode v2: Advanced vs Basic: Which Should You Use?

A decision guide for choosing between Basic and Advanced Google Consent Mode v2. Understand the data-recovery trade-off, the pre-consent privacy question, and which mode fits your risk profile.

6 min read

Consent Logging & Audit Requirements: How to Prove Consent Under GDPR

Collecting consent is only half the job, under GDPR you must be able to prove it. This guide explains what a defensible consent record contains, how long to keep it, and how to build an audit trail that survives a regulator's request.

8 min read

Cookie Consent Expiry: How Long Does Consent Last and When to Re-Ask

Consent isn't forever. Learn how long cookie consent stays valid, what regulators recommend for re-consent intervals, and the events that should always trigger a fresh prompt.

6 min read

CNIL Cookie Guidelines: France's Strict Rules Explained

France's CNIL enforces some of the toughest cookie rules in Europe, and has the fines to prove it. Learn the CNIL's specific requirements, what it has penalised, and how to make your banner France-ready.

6 min read

Children's Privacy and Cookie Consent: COPPA, Age-Gating, and GDPR's Special Rules

Websites with underage audiences face stricter cookie consent rules under COPPA, GDPR Article 8, the UK Children's Code, and California's CAADC. This guide covers what's required, what cookies are permitted, and how to configure consent for children's content.

11 min read

How to Build a Custom Consent Mode Template for Google Tag Manager

A step-by-step developer tutorial for building a custom Google Tag Manager template that implements Consent Mode v2 using the sandboxed template APIs: setDefaultConsentState, updateConsentState, permissions, wait_for_update, and testing.

11 min read

The Biggest GDPR Cookie Fines in History: Lessons for Every Website Owner

From Amazon's €746M penalty to CNIL's relentless cookie crackdowns, the enforcement record is clear: consent violations are expensive. Here are the 10 largest fines, what triggered each one, and what every site owner should learn from them.

12 min read

Best Cookie Consent Tools in 2026: An Honest Comparison for Website Owners

A practical buyer's guide to cookie consent tools in 2026. Compares free, mid-market, and enterprise CMPs on scanning, script blocking, Consent Mode, TCF, regional consent, and pricing to help you pick the right one without the sales pitch.

16 min read

A/B Testing Cookie Banners: What's Legal and What Crosses the Line in 2026

A/B testing your cookie banner can lift consent rates, but regulators draw a hard line between optimization and manipulation. This guide maps the legal boundaries, cites the EDPB and CNIL positions, and explains how to document tests for compliance audits.

11 min read

How Consent Mode v2 Affects GA4 Reporting: Behavioral Modeling and Modeled Data Explained

Understand how Google Consent Mode v2 reshapes your GA4 reports through behavioral modeling. Learn what modeled data is, when it activates, how accurate it is, and what you can do to maximize data recovery from cookie refusals.

11 min read

How to Block Scripts Until Cookie Consent

Learn how CookieBeam's automatic blocking engine prevents tracking scripts from firing until consent, plus manual tagging for inline scripts. Covers the 5-layer interception engine, connection-level blocking, drift detection, and copy-paste examples.

14 min read

How CMPs Block Scripts: Comparing Osano, Cookiebot, OneTrust, and CookieBeam

Compare how leading CMPs enforce cookie consent: automatic script interception, connection-level blocking, drift detection, and consent signalling. See how Osano, Cookiebot, OneTrust, and CookieBeam differ in real enforcement depth.

17 min read

ePrivacy Directive & Cookie Law: What Every Website Owner Needs to Know

Understand the EU's ePrivacy Directive (cookie law), how it interacts with GDPR, what the proposed ePrivacy Regulation would change, and what practical steps your website needs to take to comply today.

30 min read

What Are Cookies? The Complete Guide for Website Owners

Everything website owners need to know about cookies: what they are, how they work, the difference between first-party and third-party cookies, and what legal obligations apply to your website under GDPR.

22 min read

Cookie Types Explained: Necessary, Analytics, Marketing & Preferences

Understand the four main cookie categories, necessary, analytics, marketing, and preferences, what each does, which cookies belong where, and how to correctly disclose them in your cookie consent banner.

23 min read

GDPR vs CCPA vs PECR: Global Privacy Laws Compared

Compare GDPR, CCPA, and PECR to understand which privacy laws apply to your website, what each requires for cookie consent, and how to achieve compliance across multiple jurisdictions simultaneously.

15 min read

Google Consent Mode v2: Complete Implementation Guide

Learn how to implement Google Consent Mode v2 on your website. Configure ad_personalization and ad_user_data signals to maintain ad performance while fully respecting user privacy choices under GDPR.

13 min read

GDPR Cookie Compliance Checklist for 2026

A practical, up-to-date GDPR cookie compliance checklist for website owners. Covers prior consent, banner design, record-keeping, and the steps regulators actually look for in 2026.

11 min read
Compliance Guides | CookieBeam