Guides & Documentation
Everything you need to implement cookie consent on your website
Showing 203 guides in Compliance
Nigeria NDPA Cookie Consent: 2026 Guide
Nigeria's NDPC now says cookie banners belong at the top of the page, not the bottom, and wants opt-in before non-essential cookies. Here's what the 2023 Act and the 2025 GAID require, and what enforcement looks like.
My Health My Data Act: Website Compliance Guide
Washington's My Health My Data Act reaches far past hospitals and HIPAA. A cannabis retailer was sued in November 2025 over a website tracking pixel. Here's the two-permission structure, the geofencing ban, the separate homepage policy, and the private right of action that makes it dangerous.
Montana, Delaware, Iowa, Nebraska: Cookie Rules
Four state privacy laws went live around 2025, and they don't agree with each other. Three require you to honor the Global Privacy Control; Iowa doesn't and skips the targeted-ad opt-out entirely. Here's how cookies work under each.
Monitoring for Consent Violations and Tag Drift
A consent setup that passed testing last quarter can be leaking today. Here's what consent drift looks like, why point-in-time scans miss it, and how to monitor continuously.
Mixpanel & Amplitude Consent: Opt-Out Isn't Enough
Product analytics tools store a device ID in localStorage or a cookie, and their opt-out APIs stop the data send while often still writing that identifier. Here's why that gap matters for ePrivacy and how to gate Mixpanel and Amplitude properly.
Does Matomo Need Consent? It Depends on the Config
Matomo can run without a cookie banner, but only in a specific configuration. Turn on cookies, heatmaps, User ID, or session recording and you're back to needing consent. Here's exactly where the line sits and how to stay on the right side of it.
Live Chat Widgets and Consent: Intercom, Drift, Crisp
Chat widgets load third-party code and set cookies the moment your page opens. Whether that needs consent depends on how you use chat. Here is how to decide, and how to load the widget only when someone wants it.
Legitimate Interest vs Consent for Cookies
Teams often try to justify analytics or ad cookies under "legitimate interest" to skip the banner. For cookies on an EU visitor's device, that reasoning fails at the first gate. Here's when consent is the only option, and the narrow cases where legitimate interest genuinely fits.
Japan's APPI: Cookies and Consent in 2026
Japan treats a bare cookie ID differently from Europe: on its own it usually isn't personal data. The consent obligation kicks in at a specific point, when you hand cookie-based data to a third party who can tie it to a person. Here's the personally-referable-information rule and what's changing.
ISO 27701 Explained: The Privacy Standard Buyers Ask For
On 14 October 2025, ISO/IEC 27701 became a standalone privacy management standard, so you no longer need an ISO 27001 certificate first. Here's what it certifies, how it maps to GDPR, and why enterprise buyers keep asking for it.
Pre-Ticked Boxes and Other Invalid Cookie Consent
Pre-ticked boxes, "by using this site you agree," and scroll-to-consent all look like consent and none of them are. Here's what makes cookie consent legally invalid, with the case law behind each one.
Cookie Consent for Insurance Websites
Insurers are financial institutions under GLBA and regulated by 50 state insurance departments, and their quote forms collect health and financial data. Here's how to run cookie consent on an insurance site without leaking regulated information.
In-App Browser Consent: When Visitors Arrive via WebView
A large slice of your social traffic never opens Safari or Chrome. It opens your site inside Instagram's or TikTok's embedded browser, where cookies are isolated, third-party cookies are off by default, and a consent choice may not survive the next tap.
Implementing Global Privacy Control (GPC) in Your Banner
A technical guide to honoring Global Privacy Control: detect the signal via navigator.globalPrivacyControl and the Sec-GPC header, auto-apply the opt-out, and meet California's 2026 requirement to display that the signal was honored.
Cookie Consent for iGaming and Online Gambling Sites
Licensed betting and casino operators answer to a gambling regulator and a data protection authority at the same time. Here's how to run cookie consent on an iGaming site without breaking marketing rules, affiliate tracking, or self-exclusion.
Write a Cookie Policy That Matches Your Cookies
A cookie policy copied from a template describes someone else's website. This guide shows how to build one from your real inventory: what each entry needs, the table format regulators expect, and how to keep it accurate as scripts change.
How to Process an Opt-Out (Do Not Sell) Request Operationally
The Do Not Sell link is the front door. This is the back office: what has to happen across your systems and vendor chain once someone opts out, the 15-business-day clock, who you must notify downstream, and why a preference that keeps the pixels firing is the exact failure regulators fine.
How Often Should You Re-Scan Your Site for New Cookies?
Your cookie inventory drifts the moment you ship a new page or a marketer adds a tag. Here's a practical re-scan cadence, plus the events that should trigger an off-cycle scan.
Hotjar & Clarity Consent: Recordings Are Personal Data
Session recordings capture what people type, beyond where they click. Microsoft Clarity started requiring consent in Europe on 31 October 2025, and Hotjar records the moment it loads. Here's how to gate both and why masking is on you.
GTM Containers Are Becoming Google Tags: What It Means for Cookie Consent
Google is merging GTM and Google Tag into a unified product. Destinations replace separate gtag.js loads, settings get centralized, and the UI gets a redesign. Here's what changes for consent management and what stays the same.
The GPP US National (usnat) String Explained
The usnat section (GPP Section 7) encodes MSPA opt-outs for a dozen US state laws in one string. Here's what each field means, how the opt-out values are encoded, and where GPC lives.
Google Maps Embeds Need Consent: Here's the Fix
The Google Maps embed iframe sets non-essential cookies and sends visitor data to Google the moment your page loads. Gate it with a click-to-load facade, or drop Google for a cookieless map.
Google Fonts, the GDPR, and the German Court Ruling
A Munich court awarded a website visitor damages because a site loaded Google Fonts from Google's servers and leaked their IP address. Self-hosting removes the problem entirely, and it is faster.
Google's Certified CMP Requirement for AdSense, Ad Manager and AdMob
If you run Google ads on your site or app in the EEA, UK or Switzerland, Google requires a certified CMP integrated with the IAB TCF. Here's what that means, the enforcement dates, and the revenue cost of ignoring it.