Guides & Documentation
Everything you need to implement cookie consent on your website
Showing 212 guides in Compliance
Global Privacy Control (GPC) Explained: What It Is and Why Your Site Must Honor It
Global Privacy Control is a browser signal that lets users opt out of data sale and sharing automatically. In several US states, ignoring it is a legal violation. Here is how GPC works and how to respect it.
GA4 Privacy Settings Audit: Every Setting That Affects Your GDPR Compliance
A setting-by-setting walkthrough of every GA4 configuration that affects GDPR compliance: data collection, retention, sharing, Consent Mode integration, data deletion, BigQuery exports, and a 20-item audit checklist you can run today.
GA4 and Google Ads Split Consent Controls on June 15, 2026: ad_storage Is Now the Single Authority
On 15 June 2026 Google made Consent Mode's ad_storage signal the single control over what advertising data GA4 collects and passes to Google Ads. Google Signals no longer gates Ads data. Here is what changed, what breaks if your banner is misconfigured, and how to audit your setup.
FinTech and Cookie Consent: Navigating PCI DSS, PSD2, and GDPR Together
Fintech companies face a triple compliance burden: PCI DSS 4.0 script controls on payment pages, PSD2 Strong Customer Authentication requirements, and GDPR consent obligations. This guide covers how these frameworks interact, what cookies are essential for payment processing, and how to implement consent without breaking payment flows.
Cookie Consent for Event and Ticketing Websites: A Practical Guide
A practical guide for event organizers and ticketing platform operators on managing cookie consent across high-urgency checkout flows, queue systems, embedded venue maps, marketing retargeting, and email integrations under GDPR and global privacy laws.
EU-US Data Transfers & the Data Privacy Framework: A Website Owner's Guide
Sending EU visitors' data to US-based tools is one of the trickiest parts of GDPR compliance. This guide explains why transfers are restricted, what the Data Privacy Framework and SCCs do, and how to keep your stack lawful.
The ePrivacy Regulation: What's Coming After the Cookie Directive
The ePrivacy Regulation is meant to replace the 2002 Cookie Directive, but it's been stuck in political limbo since 2017. Here's where it stands in 2026, what it would change for cookie consent, and what compliance officers should do right now.
Cookie Consent for Education Websites: FERPA, COPPA, and Student Privacy in 2026
Education websites face layered consent obligations under FERPA, COPPA, state student privacy laws, and general privacy regulations. This guide covers what K-12 schools, universities, and EdTech vendors need to know about cookies, analytics, and parent vs. student consent in 2026.
E-Commerce Cookie Consent: How to Stay Compliant Without Killing Conversions
A practical guide for e-commerce teams on balancing cookie consent compliance with conversion performance. Covers essential cookies, marketing consent, server-side recovery, cross-border rules, and CookieBeam's auto-categorization for online stores.
DSAR Handling for Website Owners: A Practical Guide
A practical guide to handling Data Subject Access Requests under GDPR: the rights involved, how to verify identity, the one-month deadline, valid reasons to refuse, and a repeatable workflow.
Do I Need a Cookie Banner? When Cookie Consent Is Actually Required
Not every website legally needs a cookie banner, and many that show one are doing it wrong. Learn what actually triggers a consent requirement, which visitors it depends on, and how to tell whether your site needs one.
Data Processing Agreements (DPAs): What Website Owners Need to Know
Every third-party tool that handles your visitors' data needs a Data Processing Agreement. This guide explains what a DPA is, when GDPR requires one, what it must contain, and how to manage them across your stack.
Data Processing Agreements with Your CMP: What GDPR Article 28 Requires
Your CMP processes consent records, IP addresses, and device data on your behalf, making it a GDPR processor that needs a proper DPA. This guide covers what to look for, what to avoid, and how to evaluate a CMP's data processing agreement before you sign.
Data Breach and Cookie Consent: What Happens When Your CMP Gets It Wrong
Cookie consent failures don't always equal data breaches, but sometimes they do. This guide covers when unconsented cookies cross the line into a notifiable breach under GDPR, what the real enforcement landscape looks like, and how to respond when you discover cookies were set without valid consent.
Cross-Domain Consent Sharing: How to Sync Cookie Consent Across Multiple Websites
If you run several domains or a network of brand sites, asking visitors to consent again on each one is bad UX and inconsistent compliance. This guide explains how cross-domain consent sharing works and when it is legally appropriate.
Cross-Domain Consent Sharing: Technical Implementation Patterns for Multi-Site Organizations
Four concrete implementation patterns for sharing cookie consent across domains: parent-domain cookies, postMessage bridges, server-side API sync, and signed URL tokens. Covers code, security pitfalls, Consent Mode v2 per-domain firing, iframe propagation, and how CookieBeam's domain groups handle it.
Cookie Walls and "Pay or Consent": What's Actually Legal in 2026
Cookie walls and "pay or consent" models force visitors to choose between accepting tracking or losing access. Learn what the EDPB, CJEU, and national regulators have ruled, and how to design a lawful alternative.
Cookie Walls in 2026: Are 'Pay or Consent' Models Actually Legal?
The legality of cookie walls and 'pay or consent' models varies wildly across Europe. This jurisdiction-by-jurisdiction guide covers the CJEU precedent, EDPB opinion, and where each country draws the line in 2026.
Cookie Scanning vs Manual Audit: Which Approach Actually Keeps You Compliant?
Manually cataloguing every cookie your site sets is slow, error-prone, and outdated the moment you finish. Automated cookie scanning solves the discovery problem at scale. Here is how the two methods compare and when each makes sense.
Cookie Policy vs Privacy Policy: What's the Difference and Do You Need Both?
A cookie policy and a privacy policy are related but distinct legal documents. This guide explains what each one covers, why most websites need both, and exactly what to include in each.
Cookie Consent for Single-Page Apps (React, Vue, Angular): The 2026 Developer Guide
SPAs break the assumptions that cookie consent platforms were built on. This developer guide covers race conditions, route-change consent, React/Vue/Angular integration patterns, SSR hydration timing, script gating with dynamic imports, and Consent Mode v2 sequencing for SPA navigation.
Cookie Consent Penalties by Country: Maximum Fines and Enforcement in 2026
A country-by-country breakdown of cookie consent and data privacy penalties in 2026, covering maximum fines, enforcing authorities, and recent enforcement trends across GDPR, CCPA, LGPD, PIPL, DPDP, and more.
The Developer's Cookie Consent Implementation Checklist: 30 Steps to Get It Right
A 30-step technical checklist covering the full CMP implementation lifecycle: planning, script integration, Consent Mode, regional rules, testing, launch, and ongoing maintenance.
Cookie Consent for Agencies: Managing Compliance Across Multiple Client Websites
A practical guide for digital agencies managing cookie consent across 10-100+ client websites. Covers multi-client dashboards, white-label solutions, compliance templates, client reporting, pricing models, and how to turn consent management into a billable service.