Skip to main content

Guides & Documentation

Everything you need to implement cookie consent on your website

Showing 212 guides in Compliance

6 min read

Quebec's Law 25: Cookie Consent Rules for 2026

Federal PIPEDA is flexible about cookies. Quebec's Law 25 is not. Section 8.1 requires profiling and tracking technology to be switched off by default, and the CAI can levy penalties up to CAD $25 million. Here's the Quebec-specific model, layer by layer.

5 min read

Your Quarterly Cookie Consent Review: A Recurring Checklist

A full audit once a year isn't enough when your site changes weekly. Here's a lighter quarterly review that keeps consent current between audits, with a repeatable agenda.

5 min read

How to Build a Privacy Trust Center That Closes Deals

A trust center turns your three-week security questionnaire into a link. Here's what to publish openly, what to gate behind an NDA, and how your subprocessor list and consent records fit, so buyers self-serve their due diligence.

5 min read

Privacy Sandbox Is Over: What Google's 2025 Shutdown Means for Consent

On 17 October 2025 Google retired most Privacy Sandbox technologies and kept third-party cookies in Chrome. Here's the verified timeline and why consent banners now matter more, not less.

7 min read

How to Build a Privacy Request Intake Form That Complies

The intake form is where a privacy request is won or lost. Get the fields, methods, and routing right and the rest of the process runs itself. Here is what the CCPA and GDPR require, the fields to capture, and the traps that turn a form into a dark pattern.

5 min read

POPIA Cookie Consent in South Africa: 2026 Guide

South Africa's Information Regulator issued its first POPIA fine (R5 million) in 2023 and has warned that more are coming. Here's how POPIA treats cookies, what section 69 means for tracking, and what the 2025 amended Regulations changed.

6 min read

Do Plausible & Fathom Need Consent? Cookieless, Explained

Cookieless analytics like Plausible and Fathom store nothing on the device, so the ePrivacy cookie rule generally doesn't apply and you can usually skip the banner. But GDPR still does, and no EU regulator has formally certified them. Here's the honest picture.

6 min read

Cookie Consent for Pharma and Life Sciences Websites

Drug makers usually aren't HIPAA covered entities, but their sites still handle health data that GDPR treats as a special category and that Meta throttles automatically. Here's how pharma and life-sciences companies run cookie consent across brand sites, HCP portals, and adverse-event forms.

5 min read

Oregon Consumer Privacy Act: Cookies in 2026

Oregon's privacy law turned on two things in 2026: a universal opt-out mandate that went live January 1, and the end of the cure period on the same day. It also gives residents a right most states don't, the names of the specific third parties that got their data.

5 min read

Nigeria NDPA Cookie Consent: 2026 Guide

Nigeria's NDPC now says cookie banners belong at the top of the page, not the bottom, and wants opt-in before non-essential cookies. Here's what the 2023 Act and the 2025 GAID require, and what enforcement looks like.

7 min read

My Health My Data Act: Website Compliance Guide

Washington's My Health My Data Act reaches far past hospitals and HIPAA. A cannabis retailer was sued in November 2025 over a website tracking pixel. Here's the two-permission structure, the geofencing ban, the separate homepage policy, and the private right of action that makes it dangerous.

5 min read

Montana, Delaware, Iowa, Nebraska: Cookie Rules

Four state privacy laws went live around 2025, and they don't agree with each other. Three require you to honor the Global Privacy Control; Iowa doesn't and skips the targeted-ad opt-out entirely. Here's how cookies work under each.

8 min read

Monitoring for Consent Violations and Tag Drift

A consent setup that passed testing last quarter can be leaking today. Here's what consent drift looks like, why point-in-time scans miss it, and how to monitor continuously.

6 min read

Mixpanel & Amplitude Consent: Opt-Out Isn't Enough

Product analytics tools store a device ID in localStorage or a cookie, and their opt-out APIs stop the data send while often still writing that identifier. Here's why that gap matters for ePrivacy and how to gate Mixpanel and Amplitude properly.

6 min read

Does Matomo Need Consent? It Depends on the Config

Matomo can run without a cookie banner, but only in a specific configuration. Turn on cookies, heatmaps, User ID, or session recording and you're back to needing consent. Here's exactly where the line sits and how to stay on the right side of it.

5 min read

Live Chat Widgets and Consent: Intercom, Drift, Crisp

Chat widgets load third-party code and set cookies the moment your page opens. Whether that needs consent depends on how you use chat. Here is how to decide, and how to load the widget only when someone wants it.

6 min read

Legitimate Interest vs Consent for Cookies

Teams often try to justify analytics or ad cookies under "legitimate interest" to skip the banner. For cookies on an EU visitor's device, that reasoning fails at the first gate. Here's when consent is the only option, and the narrow cases where legitimate interest genuinely fits.

6 min read

Japan's APPI: Cookies and Consent in 2026

Japan treats a bare cookie ID differently from Europe: on its own it usually isn't personal data. The consent obligation kicks in at a specific point, when you hand cookie-based data to a third party who can tie it to a person. Here's the personally-referable-information rule and what's changing.

6 min read

ISO 27701 Explained: The Privacy Standard Buyers Ask For

On 14 October 2025, ISO/IEC 27701 became a standalone privacy management standard, so you no longer need an ISO 27001 certificate first. Here's what it certifies, how it maps to GDPR, and why enterprise buyers keep asking for it.

5 min read

Pre-Ticked Boxes and Other Invalid Cookie Consent

Pre-ticked boxes, "by using this site you agree," and scroll-to-consent all look like consent and none of them are. Here's what makes cookie consent legally invalid, with the case law behind each one.

6 min read

Cookie Consent for Insurance Websites

Insurers are financial institutions under GLBA and regulated by 50 state insurance departments, and their quote forms collect health and financial data. Here's how to run cookie consent on an insurance site without leaking regulated information.

6 min read

In-App Browser Consent: When Visitors Arrive via WebView

A large slice of your social traffic never opens Safari or Chrome. It opens your site inside Instagram's or TikTok's embedded browser, where cookies are isolated, third-party cookies are off by default, and a consent choice may not survive the next tap.

5 min read

Implementing Global Privacy Control (GPC) in Your Banner

A technical guide to honoring Global Privacy Control: detect the signal via navigator.globalPrivacyControl and the Sec-GPC header, auto-apply the opt-out, and meet California's 2026 requirement to display that the signal was honored.

8 min read

Cookie Consent for iGaming and Online Gambling Sites

Licensed betting and casino operators answer to a gambling regulator and a data protection authority at the same time. Here's how to run cookie consent on an iGaming site without breaking marketing rules, affiliate tracking, or self-exclusion.