ConsentBit makes it easy to manage cookie consent and stay compliant with GDPR, CCPA, and other privacy regulations.
Get Started FreeA cookie banner is the on-page notice a website shows to inform visitors about cookies and request or record their consent. It's how websites satisfy ePrivacy Article 5(3)'s prior consent rule β the term itself isn't in the law. Core components: informational text, "Accept All" and "Reject All" at equal prominence, a preferences panel, and a link to the cookie or privacy policy. EDPB, CNIL, and ICO guidance ban dark patterns β buried "Reject All" buttons, pre-ticked toggles, and cookies firing before any interaction. California's model differs β a "Do Not Sell or Share" link plus GPC honoring replaces the EU-style banner.
A privacy policy is the public-facing document that tells users how a business collects, uses, shares, and protects their personal data. Under GDPR Articles 13 and 14, it must disclose the controller's identity, purposes, lawful basis, recipients, retention periods, and data subject rights. Under CCPA/CPRA Β§1798.130, it must also list categories of PI collected, sold/shared, and California residents' opt-out mechanisms. It should link from every page footer and the cookie banner, and be updated whenever processing materially changes. A privacy policy is distinct from a privacy notice (just-in-time at collection) and terms of service (a contract).
A Data Processing Agreement (DPA) β also called a Data Processing Addendum β is the GDPR Article 28 contract between a data controller and a data processor handling personal data on its behalf. Article 28(3) requires the processor to act only on documented instructions, apply Article 32 security measures, assist with data subject rights and breach notifications, delete or return data at the end of the contract, and use sub-processors only with permission. Where processing involves international transfers, the DPA typically includes Standard Contractual Clauses (SCCs). Note: "DPA" also stands for Data Protection Authority β different concept, same acronym.
A data controller is the entity β person, company, or public authority β that determines the purposes and means of processing personal data. It's defined in GDPR Article 4(7), distinct from a data processor (Article 4(8)) who processes data on the controller's behalf. Controllers carry primary accountability under GDPR: choosing a lawful basis (Article 6), providing transparency notices (Articles 13-14), fulfilling data subject rights, notifying breaches within 72 hours, and appointing a DPO where required. Contract labels don't decide the role β regulators look at who actually decides the purposes and means. Two or more parties can be joint controllers under Article 26.
The IAB Europe Transparency and Consent Framework (TCF) is the technical standard for passing user consent across programmatic advertising. Current version: TCF v2.3, mandatory since November 2023. It uses a TC String β a Base64-encoded consent signal sent with every bid request β plus the Global Vendor List (GVL) registering vendors and their declared purposes. Publishers monetising EU/EEA traffic through IAB-integrated ad tech need a TCF-registered CMP. v2.3 tightened rules after the Belgian DPA's 2022 GDPR ruling β disclosed vendors are mandatory, and legitimate interest is no longer allowed for purposes 1-6. TCF signals consent β it doesn't create legal compliance by itself.
Google Consent Mode v2 is Google's framework for adjusting how Google Ads, GA4, and other services behave based on user consent. Mandatory for EEA, UK, and Swiss traffic since March 2024 for anyone using remarketing or conversion measurement. It uses four parameters β ad_storage, analytics_storage, ad_user_data, ad_personalization β in Basic mode (tags don't fire until consent) or Advanced mode (tags fire but send cookieless pings when denied, enabling conversion modelling). Consent Mode v2 doesn't replace GDPR consent β it only adjusts what Google does with the consent signal you send. Setting parameters to "granted" by default is a common compliance failure.
A Consent Management Platform (CMP) is software β SaaS or self-hosted β that captures, records, and enforces user consent for cookies and tracking on a website. Core functions: displays the cookie banner, blocks non-essential scripts until consent is given, stores audit-ready consent logs for GDPR Article 7(1), and passes signals to Google Consent Mode v2 and IAB TCF. Well-configured CMPs also detect the visitor's region and adapt the banner β opt-in for GDPR, opt-out for CCPA. Enterprise players include OneTrust, Didomi, Usercentrics; SMB-focused include Cookiebot, Termly, ConsentBit. No law explicitly requires a CMP, but compliance at scale without one is effectively impossible.
Legitimate interest is a GDPR Article 6(1)(f) lawful basis for processing personal data without consent. It requires a three-part test: the controller has a real business interest, the processing is necessary to achieve it, and that interest isn't overridden by the data subject's rights. It has to be documented in a Legitimate Interest Assessment (LIA), and data subjects retain the Article 21 right to object. Recital 47 explicitly recognises direct marketing as a possible legitimate interest. But there's a critical limit: for non-essential cookies, ePrivacy Article 5(3) is lex specialis β consent is required, and legitimate interest can't replace it.
Global Privacy Control (GPC) is a browser-level signal that automatically tells every website the visitor wants to opt out of data sale, sharing, and targeted advertising. Developed by an EFF-led consortium in 2020, it replaces clicking "Do Not Sell" on every site. Under CCPA/CPRA, businesses must honor GPC as a valid opt-out. Sephora's $1.2 million settlement (2022) was the first major enforcement for ignoring it. Colorado, Connecticut, and other states require the same. Brave and Firefox ship it by default; Chrome and Safari don't. The EU hasn't formally recognized GPC as consent.
A cookie wall is a design pattern that blocks access to a website unless the user "accepts" cookies β sometimes offered as a binary "accept or pay" choice. Under the GDPR's freely-given-consent standard (Article 4(11), Recital 32), most cookie walls fail: if the user has no genuine alternative, the consent isn't valid. EDPB Guidelines 5/2020 and Opinion 08/2024 make this explicit β including for large platforms running pay-or-consent models like Meta's Facebook/Instagram. Austria's DPA has ruled cookie walls unlawful outright. A "soft wall" offering an equivalent free alternative can be lawful, but pure blockers typically aren't.
Opt-out is the default-allowed model used under CCPA/CPRA and other US state privacy laws: businesses can collect and process personal information unless the user actively opts out. California requires the mandatory "Do Not Sell or Share My Personal Information" link on every regulated site, plus a "Limit the Use of My Sensitive Personal Information" option under CPRA. Businesses must also honor Global Privacy Control (GPC) as a valid universal opt-out signal. Similar frameworks apply in Colorado (CPA), Virginia (VCDPA), Connecticut (CTDPA), and others. Under GDPR, opt-out is not enough for non-essential cookies β Europe uses opt-in.
Opt-in consent is the affirmative model where a user must actively agree β through a clear, deliberate action β before data collection or processing begins. Under GDPR Article 4(11) and Recital 32, consent must be freely given, specific, informed, and unambiguous, expressed by a positive act. Pre-ticked boxes, silence, inactivity, and continued scrolling don't count. It's the default model under GDPR and ePrivacy for all non-essential cookies, marketing tracking, and profiling. Contrast with opt-out (CCPA), where processing is allowed until the user says no. Opt-in also requires the option to withdraw consent as easily as it was given β Article 7(3).
Strictly necessary cookies are the narrow category exempt from prior consent under ePrivacy Article 5(3) β cookies essential to deliver a service the user explicitly asked for. Typical examples: session IDs, authentication tokens, load-balancing cookies, CSRF tokens, shopping cart contents, and the cookie consent state itself. The ICO and EDPB apply the test narrowly: analytics, marketing, personalization, chatbot, embedded video, and social media cookies do not qualify β even if the site couldn't function "as well" without them. Convenience is not necessity. Under CCPA, strictly necessary cookies are still personal information but usually don't trigger sale-or-sharing opt-out unless the data is shared.
Marketing cookies β also called advertising, targeting, or retargeting cookies β track visitors across sites to build ad profiles, retarget them, and measure campaign performance. Named examples: Meta's _fbp and fr, Google Ads' IDE and _gcl_au, LinkedIn's bcookie, plus TikTok, Twitter, and Pinterest tags. They always require opt-in consent under GDPR and ePrivacy Article 5(3) β never strictly necessary. Under CCPA and CPRA, sharing marketing cookie data with ad networks typically counts as "sale" or "sharing," triggering opt-out rights and GPC honoring. Marketing cookies are the number one target of CNIL, Garante, and ICO enforcement actions for pre-consent firing.
Functional cookies support non-essential website features beyond basic operation β remembering user preferences, chatbot state, embedded video settings, social sharing widgets. They cover a broader category that often includes customization cookies (user-chosen settings like language and theme) as a sub-type. Under GDPR and ePrivacy Article 5(3), functional cookies generally need opt-in consent β the ICO and EDPB take a narrow view of strictly necessary, and "improves user experience" isn't enough. A common misclassification is treating chatbot or personalization cookies as functional-and-therefore-necessary. Under CCPA, functional cookie data usually stays out of the sale/sharing definition unless shared with third parties.
A session cookie is a temporary cookie stored only in browser memory and deleted when the browser closes. It has no Expires or Max-Age attribute β that's what distinguishes it from a persistent cookie. Typical uses: shopping cart contents, login state during a visit, CSRF tokens, and multi-step form data. Session cookies are usually strictly necessary under GDPR and ePrivacy Article 5(3), so they're exempt from consent β but only when used purely for the user-requested function. A session cookie used for analytics or profiling loses the exemption and needs consent. Security best practice: pair with HttpOnly, Secure, and SameSite attributes.
A third-party cookie is set by a domain different from the one in the browser's address bar β typically loaded via an embedded ad, iframe, script, or social widget. Common examples: IDE and _gcl_au from Google Ads, _fbp and fr from Meta, bcookie from LinkedIn. They're the backbone of cross-site retargeting, ad measurement, and social embeds. Under GDPR and ePrivacy Article 5(3), third-party cookies always require opt-in consent β they're never strictly necessary. Safari's ITP and Firefox's Total Cookie Protection block or partition them by default. Chrome's Privacy Sandbox is still phasing them out in 2026 β deprecation is partial, not complete.
The ePrivacy Directive (2002/58/EC) is the EU's sector-specific law on privacy and electronic communications β often called "the cookie law." Its Article 5(3) is the reason cookie banners exist: it requires prior consent before any information is stored on, or accessed from, a user's device β cookies, pixels, fingerprinting β unless strictly necessary to deliver the requested service. It predates the GDPR and works alongside it as lex specialis for device access. Legitimate interest under GDPR can't override the ePrivacy consent rule. The long-awaited ePrivacy Regulation was meant to replace it but remains unadopted in 2026 β Member States apply their national implementations.
The California Consumer Privacy Act (CCPA) is California's baseline privacy law, in force since January 2020 and expanded by the CPRA from January 2023. It applies to for-profit businesses in California that meet one threshold: $25M+ revenue, PI from 100,000+ California consumers, or 50%+ revenue from selling or sharing PI. Consumers have rights to know, delete, correct, opt out of sale and sharing, and limit use of sensitive personal information. The California Privacy Protection Agency (CPPA) and Attorney General enforce it β up to $2,500 per violation, $7,500 for intentional or minors' cases, plus $100β$750 per consumer for breaches.
The General Data Protection Regulation (GDPR) is EU Regulation 2016/679, in force since May 2018. It governs how organisations process the personal data of individuals in the EU and EEA β including non-EU businesses that target or monitor EU residents. GDPR sets out six lawful bases for processing and grants a set of enforceable data subject rights including access, erasure, portability, and objection. Fines run in two tiers: up to β¬10 million or 2% of global turnover, and β¬20 million or 4% for breaches of core principles or rights. National data protection authorities enforce it, coordinated by the EDPB.
Default cookie settings can mean two things. Browser-level: what Chrome, Safari, and Brave allow out of the box β Chrome still permits third-party cookies in 2026, while Safari and Brave block them. Site-level: what a consent banner pre-selects before the user chooses. Under GDPR Recital 32, pre-ticked boxes don't count as consent β the EDPB requires non-essential cookies off by default until the user actively opts in. CNIL and the ICO have fined sites where "Reject All" is buried or analytics tags fire before consent. CCPA flips this: the default is allowed unless the user opts out, including via Global Privacy Control.
Third-party data is personal or behavioural data collected by an entity with no direct relationship to the individual, then sold or licensed for targeting, lookalikes, or B2B enrichment. Common sources include data brokers like Acxiom, Experian, and LiveRamp. It contrasts with first-party data (collected directly from your visitors) and zero-party data (explicitly shared by the user). The category has collapsed in 2024-2026 β Chrome's cookie deprecation, Apple ATT, and GDPR consent pushed brands toward first-party strategies and data clean rooms like Snowflake and InfoSum. Under GDPR, third-party data still needs a lawful basis; under CCPA, sharing it usually triggers opt-out rights.
Personalization cookies store behaviour, history, and inferred preferences to tailor the content, recommendations, or experience a visitor sees β recommended products, "people who watched this also liked," personalised homepage layouts. They're distinct from customization cookies: customization stores settings the user explicitly chose (language, theme), while personalization is derived from behaviour. Under GDPR and ePrivacy, personalization cookies are not strictly necessary and require opt-in consent before firing. The EDPB is clear: "improves UX" doesn't make behavioural profiling exempt. Under CCPA and CPRA, when personalization uses cross-context data, it can count as targeted advertising β meaning opt-out rights and honoring GPC signals.
A first-party cookie is set by the same domain shown in the browser's address bar β used for session management, authentication, preferences, shopping carts, and first-party analytics. Google Analytics' _ga is first-party β even though Google processes the data, the cookie itself is scoped to your domain. Third-party cookies are set by a different domain β an ad network or embed. First-party doesn't mean exempt from consent. Under GDPR and ePrivacy, a first-party analytics or marketing cookie still needs opt-in consent before firing β only "strictly necessary" cookies are exempt. Safari's ITP caps JavaScript-set first-party cookies at around 7 days, whatever the expiry.
Customization cookies store user-chosen preferences like language, region, currency, theme, font size, or accessibility settings, so the site remembers them across pages and visits. Common examples include lang, _locale, theme, and currency. Vocabulary varies: most CMPs treat customization as a sub-type of "functionality cookies," alongside "personalization cookies" (which involve broader behavioural data). Under GDPR and ePrivacy Article 5(3), customization cookies are exempt from consent if the preference was actively chosen by the user and the cookie only delivers that choice. If the preference is inferred or used for profiling, opt-in consent is required. CCPA treats them as opt-out, lower risk.
Unauthorised disclosure is when personal data is shared or made available to someone who has no lawful basis to receive it. Under GDPR Article 4(12), it's one form of personal data breach β alongside accidental loss, destruction, or unauthorised access. The most common cause isn't hackers; it's a misaddressed email, a reply-all to a mailing list, or an S3 bucket left on "anyone with the link." If the disclosure risks people's rights, Article 33 requires notifying the supervisory authority within 72 hours of becoming aware β not of when it happened β and Article 34 adds notification to affected individuals where the risk is high.
A Data Protection Authority (DPA) is an independent public body that enforces data protection law in a given jurisdiction β what GDPR Article 51 formally calls a "supervisory authority." Each EU member state has at least one: France's CNIL, Italy's Garante, Spain's AEPD, Ireland's DPC. Germany has 17. Major non-EU regulators include the UK's ICO, California's CPPA, Australia's OAIC, and Brazil's ANPD. DPAs investigate complaints, audit organisations, issue binding decisions, and fine up to β¬20 million or 4% of global turnover. One catch: "DPA" also stands for Data Processing Agreement β the Article 28 contract between controller and processor.
A disclaimer is a statement that limits a publisher's liability or warns visitors about how to rely on a website's content, products, or services. Common types include no-guarantee, professional advice (medical, legal, financial), affiliate, copyright and fair use, and β increasingly β AI-generated content disclaimers. Placement matters: clickwrap acceptance is strongest, a dedicated page or terms of service is solid, a footer link is weakest. Disclaimers can shield against ordinary negligence, but they can't disclaim fraud, gross negligence, or statutory consumer protections under the UK Consumer Rights Act or US FTC rules. A copy-paste boilerplate from a similar site rarely holds up.
A subject access request (SAR) is a request to see what personal data an organisation holds about you under UK GDPR Article 15. The response must include a copy of the data plus information on purposes, recipients, retention, and automated decisions. The ICO requires a reply within one calendar month, extendable by two for complex requests. The first copy is free; refusal or a fee is only allowed for manifestly unfounded or excessive requests β and the ICO sets that bar high. SARs are common in UK employment disputes. Failures can attract ICO fines up to Β£17.5 million or 4% of global turnover.
A data retention policy is the documented set of rules that defines how long an organisation keeps each category of personal data and what happens at the end β deletion, anonymisation, or archival. It's how organisations meet the GDPR Article 5(1)(e) storage limitation principle: personal data can't be kept longer than necessary for the purpose. A working policy covers categories separately: customer records, employee data, financial records tied to tax law, marketing data, and consent logs (CNIL benchmarks ~5β6 years for proof of consent). The common failure isn't writing the policy β it's enforcing it across legacy systems, backups, and third-party processors.
Cookie consent is the explicit permission a website visitor gives before cookies andsimilar tracking technologies β pixels, fingerprinting scripts, tracking links β canstore or access information on their device. Under the GDPR, the ePrivacy Directive,and laws like the CPRA, that consent must be freely given, specific, informed, andunambiguous through a clear affirmative action.Pre-ticked boxes, scrolling, and "Accept All" walls don't count. A working cookieconsent setup does three things at once: blocks non-essential trackers until the visitorchooses, logs each decision as proof of compliance, and lets people withdraw consentas easily as they gave it.β
β
Google Analytics cookies like _ga, _gid, and _gat aren't GDPR-compliant by default.They count as personal data because the identifiers can single out users, and sincethey're not strictly necessary, GA needs opt-in consent before the script fires. A propersetup has three pieces: a consent tool that blocks GA until the visitor accepts, a DataProcessing Amendment signed with Google, and reliance on the EU-US Data PrivacyFramework for transfers to US servers. Google Consent Mode v2 helps by adjustingGA's behaviour when consent is denied, but it doesn't replace any of those threepieces.β
β
Cookies and pixels are the two most common website tracking technologies, oftentreated as interchangeable. A cookie is a small text file stored in the visitor's browser,like Google Analytics' _ga. A pixel is a 1x1 invisible image or HTML snippet that firesa server request on page load and often plants a cookie via the Set-Cookie header βlike the Meta Pixel. Under ePrivacy Article 5(3) and EDPB 2023/2024 guidelines, bothrequire prior consent β pixels aren't exempt just because they don't store data on thedevice. Most cookie banners disclose cookies but ignore pixels β a gap CNIL hasstarted fining for.β
β
Persistent cookies stay on a visitor's device after the browser closes, with an explicitexpiry set through the Expires or Max-Age attribute. Lifespans range from days totwo years β Google Analytics' _ga defaults to two years; a "remember me" tokenmight last 30. Persistent doesn't mean tracking: a first-party cookie storing a languagepreference is fine; a third-party ad cookie following you across sites isn't. Under GDPRand ePrivacy, persistent cookies need opt-in consent unless strictly necessary, andCNIL caps consent validity at 13 months. Safari's ITP further caps first-party persistentcookies at 7 days, whatever expiry you set.β
β
Data minimisation is the GDPR Article 5(1)(c) principle that personal data must beadequate, relevant, and limited to what is necessary for the stated purpose. Everyfield a business collects has to pass that three-part test. Verifying a user is over 18?Ask for age confirmation, not a date of birth. Newsletter signup? Email is enough β aphone number is excess. Data minimisation pairs with purpose limitation and storagelimitation: collect for a defined reason, keep only what you need, delete when done.The 2026 EDPB AI guidelines apply the same logic to model training.β
β
A Data Protection Officer (DPO) is the independent expert who oversees anorganisation's GDPR compliance β advising on data practices, running DPIAs, andacting as the contact point for data subjects and regulators. Under GDPR Article 37, aDPO is mandatory only when an organisation is a public authority, conducts large-scale systematic monitoring, or processes special category or criminal data at scale.The DPO can be internal or outsourced but must report to top management; a CTO ormarketing head can't double up without a conflict of interest. Non-appointment risksfines up to β¬10 million or 2% of global turnover. CCPA and CPRA don't require one.β
β
A Data Subject Access Request (DSAR) is a formal request from an individual askingan organisation to confirm whether it's processing their personal data and, if so,provide a copy plus supplementary information β purposes, recipients, retention,source, and any automated decision-making. Under GDPR Article 15, organisationsmust verify identity and respond within one calendar month β free of charge unlessthe request is manifestly unfounded or excessive β with up to two months' extensionfor complex requests. Under CCPA, the parallel "right to know" has 45 days, twiceyearly. DSARs are distinct from deletion (Article 17) or portability (Article 20)requests.β
β
A No Guarantee Disclaimer is a notice on a website telling visitors that the publisherdoesn't promise the content is accurate, complete, or reliable, and that they use it attheir own risk. It usually appears in the footer, inside the terms of service, or at thetop of high-risk articles β things like health, finance, legal advice, or AI-generatedcontent. The disclaimer can protect against ordinary negligence claims, but it can'tshield against fraud, gross negligence, or statutory consumer protections. It worksbest when accepted through a clickwrap step; a quiet footer notice is the weakestversion.β
β
Consent withdrawal is the right to revoke previously given consent at any time, withno need to give a reason. It's set out in GDPR Article 7(3). The mechanism to withdrawhas to be as easy as the original opt-in β a one-click preference centre or a persistent"change preferences" button, not a buried link, email request, or login wall.Withdrawal only stops future processing; it doesn't cancel anything done lawfullybefore, and it doesn't automatically delete data β that's a separate right under Article17. Organisations also have to inform users of this right before collecting consent inthe first place.β
β
Analytics cookies record how visitors use a website β pages viewed, session length,click paths, traffic sources, device type β so site owners can measure performanceand improve UX.
Common examples include Google Analytics (_ga, _gid), Matomo, Hotjar, andMixpanel, with lifespans from a single session up to two years. Under the GDPR andePrivacy Directive, analytics cookies aren't strictly necessary, so they need opt-inconsent before firing β even first-party ones β unless they fall under the narrowCNIL/ICO exemption for fully anonymised, non-shared analytics. CCPA uses an opt-outmodel, and Google Consent Mode v2 keeps analytics_storage denied until thevisitor approves.β
β
