Skip to main content

Guides & Documentation

Everything you need to implement cookie consent on your website

Showing 203 guides in Compliance

5 min read

Nigeria NDPA Cookie Consent: 2026 Guide

Nigeria's NDPC now says cookie banners belong at the top of the page, not the bottom, and wants opt-in before non-essential cookies. Here's what the 2023 Act and the 2025 GAID require, and what enforcement looks like.

7 min read

My Health My Data Act: Website Compliance Guide

Washington's My Health My Data Act reaches far past hospitals and HIPAA. A cannabis retailer was sued in November 2025 over a website tracking pixel. Here's the two-permission structure, the geofencing ban, the separate homepage policy, and the private right of action that makes it dangerous.

5 min read

Montana, Delaware, Iowa, Nebraska: Cookie Rules

Four state privacy laws went live around 2025, and they don't agree with each other. Three require you to honor the Global Privacy Control; Iowa doesn't and skips the targeted-ad opt-out entirely. Here's how cookies work under each.

8 min read

Monitoring for Consent Violations and Tag Drift

A consent setup that passed testing last quarter can be leaking today. Here's what consent drift looks like, why point-in-time scans miss it, and how to monitor continuously.

6 min read

Mixpanel & Amplitude Consent: Opt-Out Isn't Enough

Product analytics tools store a device ID in localStorage or a cookie, and their opt-out APIs stop the data send while often still writing that identifier. Here's why that gap matters for ePrivacy and how to gate Mixpanel and Amplitude properly.

6 min read

Does Matomo Need Consent? It Depends on the Config

Matomo can run without a cookie banner, but only in a specific configuration. Turn on cookies, heatmaps, User ID, or session recording and you're back to needing consent. Here's exactly where the line sits and how to stay on the right side of it.

5 min read

Live Chat Widgets and Consent: Intercom, Drift, Crisp

Chat widgets load third-party code and set cookies the moment your page opens. Whether that needs consent depends on how you use chat. Here is how to decide, and how to load the widget only when someone wants it.

6 min read

Legitimate Interest vs Consent for Cookies

Teams often try to justify analytics or ad cookies under "legitimate interest" to skip the banner. For cookies on an EU visitor's device, that reasoning fails at the first gate. Here's when consent is the only option, and the narrow cases where legitimate interest genuinely fits.

6 min read

Japan's APPI: Cookies and Consent in 2026

Japan treats a bare cookie ID differently from Europe: on its own it usually isn't personal data. The consent obligation kicks in at a specific point, when you hand cookie-based data to a third party who can tie it to a person. Here's the personally-referable-information rule and what's changing.

6 min read

ISO 27701 Explained: The Privacy Standard Buyers Ask For

On 14 October 2025, ISO/IEC 27701 became a standalone privacy management standard, so you no longer need an ISO 27001 certificate first. Here's what it certifies, how it maps to GDPR, and why enterprise buyers keep asking for it.

5 min read

Pre-Ticked Boxes and Other Invalid Cookie Consent

Pre-ticked boxes, "by using this site you agree," and scroll-to-consent all look like consent and none of them are. Here's what makes cookie consent legally invalid, with the case law behind each one.

6 min read

Cookie Consent for Insurance Websites

Insurers are financial institutions under GLBA and regulated by 50 state insurance departments, and their quote forms collect health and financial data. Here's how to run cookie consent on an insurance site without leaking regulated information.

6 min read

In-App Browser Consent: When Visitors Arrive via WebView

A large slice of your social traffic never opens Safari or Chrome. It opens your site inside Instagram's or TikTok's embedded browser, where cookies are isolated, third-party cookies are off by default, and a consent choice may not survive the next tap.

5 min read

Implementing Global Privacy Control (GPC) in Your Banner

A technical guide to honoring Global Privacy Control: detect the signal via navigator.globalPrivacyControl and the Sec-GPC header, auto-apply the opt-out, and meet California's 2026 requirement to display that the signal was honored.

8 min read

Cookie Consent for iGaming and Online Gambling Sites

Licensed betting and casino operators answer to a gambling regulator and a data protection authority at the same time. Here's how to run cookie consent on an iGaming site without breaking marketing rules, affiliate tracking, or self-exclusion.

5 min read

Write a Cookie Policy That Matches Your Cookies

A cookie policy copied from a template describes someone else's website. This guide shows how to build one from your real inventory: what each entry needs, the table format regulators expect, and how to keep it accurate as scripts change.

8 min read

How to Process an Opt-Out (Do Not Sell) Request Operationally

The Do Not Sell link is the front door. This is the back office: what has to happen across your systems and vendor chain once someone opts out, the 15-business-day clock, who you must notify downstream, and why a preference that keeps the pixels firing is the exact failure regulators fine.

6 min read

How Often Should You Re-Scan Your Site for New Cookies?

Your cookie inventory drifts the moment you ship a new page or a marketer adds a tag. Here's a practical re-scan cadence, plus the events that should trigger an off-cycle scan.

6 min read

Hotjar & Clarity Consent: Recordings Are Personal Data

Session recordings capture what people type, beyond where they click. Microsoft Clarity started requiring consent in Europe on 31 October 2025, and Hotjar records the moment it loads. Here's how to gate both and why masking is on you.

12 min read

GTM Containers Are Becoming Google Tags: What It Means for Cookie Consent

Google is merging GTM and Google Tag into a unified product. Destinations replace separate gtag.js loads, settings get centralized, and the UI gets a redesign. Here's what changes for consent management and what stays the same.

5 min read

The GPP US National (usnat) String Explained

The usnat section (GPP Section 7) encodes MSPA opt-outs for a dozen US state laws in one string. Here's what each field means, how the opt-out values are encoded, and where GPC lives.

5 min read

Google Maps Embeds Need Consent: Here's the Fix

The Google Maps embed iframe sets non-essential cookies and sends visitor data to Google the moment your page loads. Gate it with a click-to-load facade, or drop Google for a cookieless map.

5 min read

Google Fonts, the GDPR, and the German Court Ruling

A Munich court awarded a website visitor damages because a site loaded Google Fonts from Google's servers and leaked their IP address. Self-hosting removes the problem entirely, and it is faster.

5 min read

Google's Certified CMP Requirement for AdSense, Ad Manager and AdMob

If you run Google ads on your site or app in the EEA, UK or Switzerland, Google requires a certified CMP integrated with the IAB TCF. Here's what that means, the enforcement dates, and the revenue cost of ignoring it.