Skip to content

Cookies

Cookie Consent & ePrivacy Checklist for Websites

A consent-UX checklist for cookies, SDKs, and tracking: notices, prior consent, rejection ease, and records.

Estimated time
3–8 Weeks
Audience
Web, Marketing, and Privacy Engineering Teams
Last updated

Operational reference for cookie/ePrivacy readiness. Supervisory and ePrivacy rules vary by Member State; this is not legal advice.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Inventory

Phase 2: Consent UX

Phase 3: CMP & Records

Phase 4: Governance

FAQ

Are strictly necessary cookies exempt?+

Typically yes if they are essential for the service the user requested. Analytics is usually not strictly necessary.

Is a CMP mandatory?+

Not named in law, but you need a lawful, demonstrable consent mechanism. AdSense in the EEA requires a certified CMP for personalized ads.

Does US-only traffic need a banner?+

ePrivacy is EU/UK-focused. US sites still need CPRA notices/opt-outs if they sell/share PI.

What about server-side tagging?+

If it still sets advertising identifiers based on user tracking, consent analysis still applies.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer