Guides & Documentation
Everything you need to implement cookie consent on your website
Showing 212 guides in Compliance
Quebec's Law 25: Cookie Consent Rules for 2026
Federal PIPEDA is flexible about cookies. Quebec's Law 25 is not. Section 8.1 requires profiling and tracking technology to be switched off by default, and the CAI can levy penalties up to CAD $25 million. Here's the Quebec-specific model, layer by layer.
Your Quarterly Cookie Consent Review: A Recurring Checklist
A full audit once a year isn't enough when your site changes weekly. Here's a lighter quarterly review that keeps consent current between audits, with a repeatable agenda.
How to Build a Privacy Trust Center That Closes Deals
A trust center turns your three-week security questionnaire into a link. Here's what to publish openly, what to gate behind an NDA, and how your subprocessor list and consent records fit, so buyers self-serve their due diligence.
Privacy Sandbox Is Over: What Google's 2025 Shutdown Means for Consent
On 17 October 2025 Google retired most Privacy Sandbox technologies and kept third-party cookies in Chrome. Here's the verified timeline and why consent banners now matter more, not less.
How to Build a Privacy Request Intake Form That Complies
The intake form is where a privacy request is won or lost. Get the fields, methods, and routing right and the rest of the process runs itself. Here is what the CCPA and GDPR require, the fields to capture, and the traps that turn a form into a dark pattern.
POPIA Cookie Consent in South Africa: 2026 Guide
South Africa's Information Regulator issued its first POPIA fine (R5 million) in 2023 and has warned that more are coming. Here's how POPIA treats cookies, what section 69 means for tracking, and what the 2025 amended Regulations changed.
Do Plausible & Fathom Need Consent? Cookieless, Explained
Cookieless analytics like Plausible and Fathom store nothing on the device, so the ePrivacy cookie rule generally doesn't apply and you can usually skip the banner. But GDPR still does, and no EU regulator has formally certified them. Here's the honest picture.
Cookie Consent for Pharma and Life Sciences Websites
Drug makers usually aren't HIPAA covered entities, but their sites still handle health data that GDPR treats as a special category and that Meta throttles automatically. Here's how pharma and life-sciences companies run cookie consent across brand sites, HCP portals, and adverse-event forms.
Oregon Consumer Privacy Act: Cookies in 2026
Oregon's privacy law turned on two things in 2026: a universal opt-out mandate that went live January 1, and the end of the cure period on the same day. It also gives residents a right most states don't, the names of the specific third parties that got their data.
Nigeria NDPA Cookie Consent: 2026 Guide
Nigeria's NDPC now says cookie banners belong at the top of the page, not the bottom, and wants opt-in before non-essential cookies. Here's what the 2023 Act and the 2025 GAID require, and what enforcement looks like.
My Health My Data Act: Website Compliance Guide
Washington's My Health My Data Act reaches far past hospitals and HIPAA. A cannabis retailer was sued in November 2025 over a website tracking pixel. Here's the two-permission structure, the geofencing ban, the separate homepage policy, and the private right of action that makes it dangerous.
Montana, Delaware, Iowa, Nebraska: Cookie Rules
Four state privacy laws went live around 2025, and they don't agree with each other. Three require you to honor the Global Privacy Control; Iowa doesn't and skips the targeted-ad opt-out entirely. Here's how cookies work under each.
Monitoring for Consent Violations and Tag Drift
A consent setup that passed testing last quarter can be leaking today. Here's what consent drift looks like, why point-in-time scans miss it, and how to monitor continuously.
Mixpanel & Amplitude Consent: Opt-Out Isn't Enough
Product analytics tools store a device ID in localStorage or a cookie, and their opt-out APIs stop the data send while often still writing that identifier. Here's why that gap matters for ePrivacy and how to gate Mixpanel and Amplitude properly.
Does Matomo Need Consent? It Depends on the Config
Matomo can run without a cookie banner, but only in a specific configuration. Turn on cookies, heatmaps, User ID, or session recording and you're back to needing consent. Here's exactly where the line sits and how to stay on the right side of it.
Live Chat Widgets and Consent: Intercom, Drift, Crisp
Chat widgets load third-party code and set cookies the moment your page opens. Whether that needs consent depends on how you use chat. Here is how to decide, and how to load the widget only when someone wants it.
Legitimate Interest vs Consent for Cookies
Teams often try to justify analytics or ad cookies under "legitimate interest" to skip the banner. For cookies on an EU visitor's device, that reasoning fails at the first gate. Here's when consent is the only option, and the narrow cases where legitimate interest genuinely fits.
Japan's APPI: Cookies and Consent in 2026
Japan treats a bare cookie ID differently from Europe: on its own it usually isn't personal data. The consent obligation kicks in at a specific point, when you hand cookie-based data to a third party who can tie it to a person. Here's the personally-referable-information rule and what's changing.
ISO 27701 Explained: The Privacy Standard Buyers Ask For
On 14 October 2025, ISO/IEC 27701 became a standalone privacy management standard, so you no longer need an ISO 27001 certificate first. Here's what it certifies, how it maps to GDPR, and why enterprise buyers keep asking for it.
Pre-Ticked Boxes and Other Invalid Cookie Consent
Pre-ticked boxes, "by using this site you agree," and scroll-to-consent all look like consent and none of them are. Here's what makes cookie consent legally invalid, with the case law behind each one.
Cookie Consent for Insurance Websites
Insurers are financial institutions under GLBA and regulated by 50 state insurance departments, and their quote forms collect health and financial data. Here's how to run cookie consent on an insurance site without leaking regulated information.
In-App Browser Consent: When Visitors Arrive via WebView
A large slice of your social traffic never opens Safari or Chrome. It opens your site inside Instagram's or TikTok's embedded browser, where cookies are isolated, third-party cookies are off by default, and a consent choice may not survive the next tap.
Implementing Global Privacy Control (GPC) in Your Banner
A technical guide to honoring Global Privacy Control: detect the signal via navigator.globalPrivacyControl and the Sec-GPC header, auto-apply the opt-out, and meet California's 2026 requirement to display that the signal was honored.
Cookie Consent for iGaming and Online Gambling Sites
Licensed betting and casino operators answer to a gambling regulator and a data protection authority at the same time. Here's how to run cookie consent on an iGaming site without breaking marketing rules, affiliate tracking, or self-exclusion.