Guides & Documentation
Everything you need to implement cookie consent on your website
Showing 212 guides in Compliance
Write a Cookie Policy That Matches Your Cookies
A cookie policy copied from a template describes someone else's website. This guide shows how to build one from your real inventory: what each entry needs, the table format regulators expect, and how to keep it accurate as scripts change.
How to Process an Opt-Out (Do Not Sell) Request Operationally
The Do Not Sell link is the front door. This is the back office: what has to happen across your systems and vendor chain once someone opts out, the 15-business-day clock, who you must notify downstream, and why a preference that keeps the pixels firing is the exact failure regulators fine.
How Often Should You Re-Scan Your Site for New Cookies?
Your cookie inventory drifts the moment you ship a new page or a marketer adds a tag. Here's a practical re-scan cadence, plus the events that should trigger an off-cycle scan.
Hotjar & Clarity Consent: Recordings Are Personal Data
Session recordings capture what people type, beyond where they click. Microsoft Clarity started requiring consent in Europe on 31 October 2025, and Hotjar records the moment it loads. Here's how to gate both and why masking is on you.
GTM Containers Are Becoming Google Tags: What It Means for Cookie Consent
Google is merging GTM and Google Tag into a unified product. Destinations replace separate gtag.js loads, settings get centralized, and the UI gets a redesign. Here's what changes for consent management and what stays the same.
The GPP US National (usnat) String Explained
The usnat section (GPP Section 7) encodes MSPA opt-outs for a dozen US state laws in one string. Here's what each field means, how the opt-out values are encoded, and where GPC lives.
Google Maps Embeds Need Consent: Here's the Fix
The Google Maps embed iframe sets non-essential cookies and sends visitor data to Google the moment your page loads. Gate it with a click-to-load facade, or drop Google for a cookieless map.
Google Fonts, the GDPR, and the German Court Ruling
A Munich court awarded a website visitor damages because a site loaded Google Fonts from Google's servers and leaked their IP address. Self-hosting removes the problem entirely, and it is faster.
Google's Certified CMP Requirement for AdSense, Ad Manager and AdMob
If you run Google ads on your site or app in the EEA, UK or Switzerland, Google requires a certified CMP integrated with the IAB TCF. Here's what that means, the enforcement dates, and the revenue cost of ignoring it.
Cookie Consent Laws Around the World: 2026 Guide
More than 140 countries now have a data protection law, and they split into two broad camps on cookies: opt-in and opt-out. Here's a country-by-country map of who requires what, and how to run one site across all of them.
Germany's TDDDG: Cookie Consent Rules for 2026
Germany renamed its cookie law in May 2024, and §25 TDDDG still governs every read or write to a visitor's device. Here's how the two-layer German model works, what the new consent-management ordinance changes, and which of the 16 regulators actually enforces it.
GDPR Consent Withdrawal: Making Opt-Out as Easy as Opt-In
If a visitor can accept cookies in one click but needs to email your DPO to refuse them later, your banner breaks GDPR. Article 7(3) requires withdrawal to be as easy as consent. Here's what that means in practice, and the classic failure of logging a withdrawal while the tag keeps firing.
GDPR Certification and Europrivacy: The Official Seal
GDPR has its own certification route under Article 42, separate from ISO and SOC 2. Only one scheme has been approved as a pan-European seal so far: Europrivacy. Here's how the mechanism works and what a seal does (and doesn't) buy you.
Cookie Consent for Fitness, Wellness, and Gym Websites
Gyms and fitness apps aren't HIPAA covered entities, but the FTC has fined health and wellness apps for sharing workout and cycle data with Facebook and Google. Here's how fitness businesses run cookie consent across booking flows, member portals, and wearable sync.
Firefox Total Cookie Protection and ETP
Firefox gives every website its own cookie jar and blocks fingerprinters and cross-site cookies by default. Here's how Total Cookie Protection and Enhanced Tracking Protection work, and what they mean for your tracking.
The EU Digital Omnibus: How Cookie Consent Changes in 2026
In November 2025 the European Commission proposed moving cookie rules out of the ePrivacy Directive and into the GDPR through a new Article 88a. Here is what the Digital Omnibus would change for consent banners, and what is still just a proposal.
Cookie Consent in Emerging Markets: A 2026 Global Guide
Beyond the EU, the US, and Brazil, a wave of privacy laws in the Gulf, Africa, and Southeast Asia now reach cookies and online tracking. Here is where consent is required in Saudi Arabia, the UAE, Nigeria, Vietnam, Indonesia, and Thailand in 2026.
EDPB Cookie Guidance in 2026: What the Regulators Actually Said
The European Data Protection Board has quietly built the rulebook that DPAs now enforce against cookie banners: the Cookie Banner Taskforce report, the Article 5(3) technical-scope guidelines, and the consent-or-pay opinion. Here is what each one means for your banner.
Cookie Consent for Klaviyo, Onsite Tracking & Cart Emails
Your abandoned-cart flow only works if you can identify the shopper, and identifying the shopper means a tracking cookie that needs consent. This guide untangles onsite tracking consent, abandoned cart vs abandoned checkout, the UK soft opt-in, and US SMS rules.
DSAR Deadlines by Law: How Long You Have to Respond
GDPR gives you one month. California gives you 45 days. Brazil wants a first answer in 15. Every privacy law counts its own clock, and starting it late or missing an extension notice is its own violation. Here is the deadline for each major regime and how the clock actually runs.
Do Cookies Need a DPIA? When Tracking Triggers Article 35
A DPIA is the written risk assessment GDPR requires before high-risk processing starts. Most cookie banners don't need one. Some tracking setups clearly do, and skipping a required DPIA is a breach in its own right. Here's how to tell which side you're on.
Does GDPR Apply to US Companies? Usually, Yes
"We're US-only, GDPR is Europe's problem." Article 3(2) says otherwise. If you offer goods or services to people in the EU, or track their behaviour, the GDPR reaches you with no EU office at all.
Do You Need a Cookie Banner in the US in 2026?
US privacy law does not demand a GDPR-style opt-in banner, but that does not mean you can skip consent tooling. Here is the state-by-state reality of what you actually need.
How to Build a Compliant 'Do Not Sell or Share' Link
The Do Not Sell link is the most enforced control in US privacy law, and the rules are more specific than most sites realize. Here is exactly what CCPA requires and how to get it right.