Guides & Documentation
Everything you need to implement cookie consent on your website
Showing 203 guides in Compliance
Cookie Consent Laws Around the World: 2026 Guide
More than 140 countries now have a data protection law, and they split into two broad camps on cookies: opt-in and opt-out. Here's a country-by-country map of who requires what, and how to run one site across all of them.
Germany's TDDDG: Cookie Consent Rules for 2026
Germany renamed its cookie law in May 2024, and §25 TDDDG still governs every read or write to a visitor's device. Here's how the two-layer German model works, what the new consent-management ordinance changes, and which of the 16 regulators actually enforces it.
GDPR Consent Withdrawal: Making Opt-Out as Easy as Opt-In
If a visitor can accept cookies in one click but needs to email your DPO to refuse them later, your banner breaks GDPR. Article 7(3) requires withdrawal to be as easy as consent. Here's what that means in practice, and the classic failure of logging a withdrawal while the tag keeps firing.
GDPR Certification and Europrivacy: The Official Seal
GDPR has its own certification route under Article 42, separate from ISO and SOC 2. Only one scheme has been approved as a pan-European seal so far: Europrivacy. Here's how the mechanism works and what a seal does (and doesn't) buy you.
Cookie Consent for Fitness, Wellness, and Gym Websites
Gyms and fitness apps aren't HIPAA covered entities, but the FTC has fined health and wellness apps for sharing workout and cycle data with Facebook and Google. Here's how fitness businesses run cookie consent across booking flows, member portals, and wearable sync.
Firefox Total Cookie Protection and ETP
Firefox gives every website its own cookie jar and blocks fingerprinters and cross-site cookies by default. Here's how Total Cookie Protection and Enhanced Tracking Protection work, and what they mean for your tracking.
The EU Digital Omnibus: How Cookie Consent Changes in 2026
In November 2025 the European Commission proposed moving cookie rules out of the ePrivacy Directive and into the GDPR through a new Article 88a. Here is what the Digital Omnibus would change for consent banners, and what is still just a proposal.
Cookie Consent in Emerging Markets: A 2026 Global Guide
Beyond the EU, the US, and Brazil, a wave of privacy laws in the Gulf, Africa, and Southeast Asia now reach cookies and online tracking. Here is where consent is required in Saudi Arabia, the UAE, Nigeria, Vietnam, Indonesia, and Thailand in 2026.
EDPB Cookie Guidance in 2026: What the Regulators Actually Said
The European Data Protection Board has quietly built the rulebook that DPAs now enforce against cookie banners: the Cookie Banner Taskforce report, the Article 5(3) technical-scope guidelines, and the consent-or-pay opinion. Here is what each one means for your banner.
Cookie Consent for Klaviyo, Onsite Tracking & Cart Emails
Your abandoned-cart flow only works if you can identify the shopper, and identifying the shopper means a tracking cookie that needs consent. This guide untangles onsite tracking consent, abandoned cart vs abandoned checkout, the UK soft opt-in, and US SMS rules.
DSAR Deadlines by Law: How Long You Have to Respond
GDPR gives you one month. California gives you 45 days. Brazil wants a first answer in 15. Every privacy law counts its own clock, and starting it late or missing an extension notice is its own violation. Here is the deadline for each major regime and how the clock actually runs.
Do Cookies Need a DPIA? When Tracking Triggers Article 35
A DPIA is the written risk assessment GDPR requires before high-risk processing starts. Most cookie banners don't need one. Some tracking setups clearly do, and skipping a required DPIA is a breach in its own right. Here's how to tell which side you're on.
Does GDPR Apply to US Companies? Usually, Yes
"We're US-only, GDPR is Europe's problem." Article 3(2) says otherwise. If you offer goods or services to people in the EU, or track their behaviour, the GDPR reaches you with no EU office at all.
Do You Need a Cookie Banner in the US in 2026?
US privacy law does not demand a GDPR-style opt-in banner, but that does not mean you can skip consent tooling. Here is the state-by-state reality of what you actually need.
How to Build a Compliant 'Do Not Sell or Share' Link
The Do Not Sell link is the most enforced control in US privacy law, and the rules are more specific than most sites realize. Here is exactly what CCPA requires and how to get it right.
Do You Need a DPO for Cookie Compliance?
Not every website needs a data protection officer. But if tracking is central to how your business runs, GDPR may force you to appoint one, and behavioral advertising is an example regulators name directly. Here's how to read Article 37 against your cookie setup.
Cookie Consent for Crypto Exchanges and Web3 Sites
MiCA gives EU crypto platforms a hard authorization deadline and ties their data handling to GDPR. For a global exchange, that means running cookie consent properly across every jurisdiction it serves. Here's how.
CPRA Enforcement 2025-2026: What the CPPA Is Doing
California now enforces the CCPA/CPRA through two agencies, and the fines are getting bigger. Here is what the CPPA and the Attorney General have actually pursued in 2025 and 2026, and what it means for your site.
Why Copying a Competitor's Cookie Banner Backfires
Cloning a competitor's cookie banner feels like a shortcut. It maps consent to their cookies, not yours, can copy a non-compliant pattern, and leaves you with no records of your own. Here's the risk breakdown.
A Cookie Plugin Alone Won't Make You Compliant
Installing a well-known consent plugin and watching the banner appear feels like the job is done. It isn't. noyb filed 226 complaints against companies running one of the biggest CMPs. The tool isn't compliance, the configuration is.
Cookie Consent Myths That Cost Companies Millions
"Implied consent is fine." "We're US-only, so GDPR doesn't apply." "A banner makes us compliant." Ten cookie consent myths that regulators have already fined, and what the law actually says.
Consent Mode v2 for EEA vs Non-EEA Traffic: Regional Gating
Google only requires consent signals for EEA, UK and Swiss traffic. Here's how the region parameter scopes strict consent defaults to those visitors while preserving measurement everywhere else.
Consent Management Is an Ongoing Process, Not a One-Time Setup
Installing a banner is day one, not the finish line. Here's the operating model for consent as a continuous discipline: what changes, how often to check it, and who owns it.
The European Accessibility Act and Your Cookie Banner
Since 28 June 2025 the European Accessibility Act makes accessibility a legal requirement for e-commerce, banking, and many other services. Your cookie banner is part of that surface. Here's the standard, and a ten-minute test.