Cookies
Cookie Consent & ePrivacy Checklist for Websites
A consent-UX checklist for cookies, SDKs, and tracking: notices, prior consent, rejection ease, and records.
- Estimated time
- 3–8 Weeks
- Audience
- Web, Marketing, and Privacy Engineering Teams
- Last updated
Operational reference for cookie/ePrivacy readiness. Supervisory and ePrivacy rules vary by Member State; this is not legal advice.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Inventory
Phase 2: Consent UX
Phase 3: CMP & Records
Phase 4: Governance
FAQ
Are strictly necessary cookies exempt?+–
Typically yes if they are essential for the service the user requested. Analytics is usually not strictly necessary.
Is a CMP mandatory?+–
Not named in law, but you need a lawful, demonstrable consent mechanism. AdSense in the EEA requires a certified CMP for personalized ads.
Does US-only traffic need a banner?+–
ePrivacy is EU/UK-focused. US sites still need CPRA notices/opt-outs if they sell/share PI.
What about server-side tagging?+–
If it still sets advertising identifiers based on user tracking, consent analysis still applies.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer