惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Vulnerabilities – Threatpost
有赞技术团队
有赞技术团队
小众软件
小众软件
O
OpenAI News
C
Cyber Attacks, Cyber Crime and Cyber Security
I
Intezer
NISL@THU
NISL@THU
D
Darknet – Hacking Tools, Hacker News & Cyber Security
N
News and Events Feed by Topic
MongoDB | Blog
MongoDB | Blog
阮一峰的网络日志
阮一峰的网络日志
Hacker News: Ask HN
Hacker News: Ask HN
D
Docker
WordPress大学
WordPress大学
Security Archives - TechRepublic
Security Archives - TechRepublic
A
About on SuperTechFans
Stack Overflow Blog
Stack Overflow Blog
C
CERT Recently Published Vulnerability Notes
L
LINUX DO - 最新话题
Application and Cybersecurity Blog
Application and Cybersecurity Blog
M
MIT News - Artificial intelligence
Blog — PlanetScale
Blog — PlanetScale
S
Security @ Cisco Blogs
Cloudbric
Cloudbric
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
Hacker News - Newest:
Hacker News - Newest: "LLM"
G
Google Developers Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
W
WeLiveSecurity
Google DeepMind News
Google DeepMind News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
H
Hackread – Cybersecurity News, Data Breaches, AI and More
G
GRAHAM CLULEY
S
Schneier on Security
T
Tor Project blog
Spread Privacy
Spread Privacy
PCI Perspectives
PCI Perspectives
Microsoft Security Blog
Microsoft Security Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
F
Fortinet All Blogs
L
Lohrmann on Cybersecurity
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
The Exploit Database - CXSecurity.com
TaoSecurity Blog
TaoSecurity Blog
Apple Machine Learning Research
Apple Machine Learning Research
T
Threat Research - Cisco Blogs
T
Troy Hunt's Blog
罗磊的独立博客

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations TikTok Faces Lawsuit Over Tracking Non-Users What’s the Digital Markets Act (DMA) and how will it affect you? | iubenda Simplifying Cookie Consent: The European Commission's Approach | iubenda Google Settles Landmark Privacy Lawsuit for $5 Billion | iubenda Navigate GDPR Compliance with Confidence: Lessons from Recent Fines in Italy Simplifying the Commission's New Reporting Template for Digital Market Gatekeepers | iubenda Understanding the GDPR Complaint Against X (Twitter) for Illegal MicroTargeting | iubenda Spanish Media Giants Take On Meta in a Groundbreaking $600 Million Lawsuit | iubenda DPO Newsletter: Data Protection & Privacy News (issue #126) | iubenda Belgian DPA Mandates Cookie Banner Changes for Major Media Websites | iubenda UK's Top Websites Warned by ICO to Revise Cookie Practices | iubenda Understanding the European Union's Data Act | iubenda Google Announces Consent Mode v2 – here’s what it means for your business and advertising Noyb Challenges EU Commission Over Controversial Ad Campaign | iubenda OECD Updates AI Definition: A Step Forward in Shaping EU’s AI Law Firefox To Introduce Simplified Global Privacy Control Berlin Court Cracks Down on LinkedIn’s Privacy Violations The YouTube Ad Blocker Controversy: A Test of the ePrivacy Directive? | iubenda DPO Newsletter: Data Protection & Privacy News (issue #125) Facebook and Instagram Subscription: Meta adds a paywall | iubenda GDPR Violation: Lack of Transparency in Data Processing via Google Fonts Amazon Introduces AWS European Sovereign Cloud to Address EU Regulations | iubenda Texas New Data Privacy Law TDPSA: Everything you need to know How to Make Money with a Website Without Selling Anything Oregon Consumer Privacy Act: Overview | iubenda Google’s Move to Disable Third-Party Cookies: What Advertisers Need to Know IMY Fines H&M for GDPR Violations: A Closer Look EU Commission Requests Information from X Under Digital Services Act: What You Need to Know | iubenda Understanding California’s “Delete Act” and Data Broker Regulations TCF v 2.2 Initial Layer (Banner) Requirements | iubenda Grindr Faces €5.8 Million Fine: A Reminder on the Importance of GDPR Compliance | iubenda Newly Enacted Iowa Consumer Data Protection Act (ICDPA) | iubenda The Witch’s Brew of Privacy: A Halloween Tale of Compliance and Consequences IAB TCF 2.2 – What you need to do DPO Newsletter: Data Protection & Privacy News (issue #124) Blog Ideas That Make Money: How To Make Money From Your Blog + Examples | iubenda Maximize your Growth with Online Presence Management | iubenda Meta's New Pivot in Europe: To Pay or Not to Pay for an Ad-Free Experience? | iubenda Consumer Reports Launches Free ‘Permission Slip’ App to Protect Your Data | iubenda DAZN’s Access Request Saga Personal Brand Logo: How to Stand Out in a Crowded Marketplace UK-US Data Bridge: A New Era for Secure Data Transfers 7 Ways How to Promote Affiliate Links Effectively (And Boost Commissions) | iubenda Mastering LinkedIn Personal Branding: A Guide to More Opportunities Meta's New Approach: Pay for Your Privacy? | iubenda No Return, No Refund Policy Template & Guide GDPR in the US: a GDPR Checklist for US Companies Crafting a Niche with Branding and Identity Design | iubenda The Online Safety Bill: A Leap Towards a Safer Digital United Kingdom Understanding Google's $93m Settlement over Consumer Location Data Accusations | iubenda CCPA vs CPRA: Key Differences You Need to Know | iubenda How To Use Ecommerce Retargeting to Grow Your Business | iubenda PECR: Everything you need to know | iubenda How Mobile Apps Illegally Share Your Personal Data: A Deep Dive | iubenda Legal Spotlight: Privacy Concerns Surrounding OpenAI’s ChatGPT and Microsoft’s Involvement Legal Scrutiny Looms Over Transatlantic Data Deal: French MEP Takes Action Understanding the Digital Markets Act: A Comprehensive Guide Block AI Crawlers: Here’s How To Stop Your Site From Being Used for AI Training (OpenAI and Google Bard Irish Regulator Slaps $368M Fine on TikTok DPO Newsletter: Data Protection & Privacy News (issue #123) | iubenda The Privacy Pitfalls of Vehicle Data Collection: What You Need to Know | iubenda Twitter customer’s data on the menu for xAI models Update: Revised Swiss Privacy Law Takes Effect Fitbit and the GDPR Hurdle: What You Need to Know About Your Data Privacy | iubenda Terms of Service Template for your site | iubenda Senators Urge FTC to Investigate YouTube and Google for Violating Children's Privacy: What You Need to Google AdSense Requirements: Here's What You Need to Know | iubenda Users can’t opt out from marketing emails: FTC fines Experian $650,000 | iubenda DPO Newsletter: Data Protection & Privacy News (issue #122) | iubenda 7 Ways Business Process Automation Can Increase Your Profits
What is Cookie Compliance? | iubenda
Alice Perseval · 2024-03-26 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

In practical terms, what does cookie compliance mean for websites? What laws should you comply with? How can you easily meet all legal requirements and avoid potential fines for non-compliance? All your questions answered in this article on what is cookie compliance.

In the digital era, privacy and data protection are paramount. Cookie compliance has emerged as a crucial aspect to regulate cookies and similar technologies by websites, used to track user behavior and preferences or serve them personalized content like ads.

This article delves into what cookie compliance is, covering main regulations like the GDPR and CCPA/CPRA and steps toward ensuring your website meets legal requirements.

In this post, we explain:

  • What is cookie compliance?
  • What are the cookie compliance regulations?
  • Are cookies allowed in the EU?
  • What is GDPR cookie compliance?
  • How do you comply with Cookie Law?
  • What is the CCPA cookie consent?
  • How do I check cookie compliance?
  • How do I become cookie compliant?

Meet legal cookie requirements the easy way

  • Custom clauses icon

    Create your free compliant cookie banner

  • Webserver module icon

    Collect and manage cookie consent

  • Clauses icon

    Store your users’ preferences

Try it now

Generate your cookie banner in minutes

compliant cookie banner

Cookie compliance is the adherence to laws and regulations like the GDPR and ePrivacy directive governing the use of cookies and similar technologies by websites online. It involves implementing a series of measures like obtaining consent before any cookies are installed via a cookie banner, providing options for managing preferences, as well as informing users via a cookie policy.

💡 As a quick reminder, cookies are small text files stored on a user’s device when they visit a website, used to remember the their actions and preferences.

Below are 3 practical and detailed examples of cookie compliance on a website:

  1. Cookie Consent Banner: Upon visiting the website, users are presented with a cookie consent banner or pop-up. This banner informs users that the site uses cookies for various purposes such as analytics, advertising, or preferences. It also includes options for users to either accept all cookies, decline all cookies except necessary ones, or customize their preferences.
  2. Cookie Policy Page: A website that uses cookies typically includes a dedicated website cookie policy page accessible from the footer and through a link in the banner mentioned previously. This page provides detailed information about the types of cookies used (including third-party cookies), their purposes, and how users can manage their preferences and opt out.
  3. Cookie Preferences Management: Generally part of the banner, the website displays a small privacy button on the page to allow users to easily go back to their cookie settings in more detail even after initially consenting. It empowers users to have more control over their privacy preferences.

The cookie compliance regulations are generally referring to two main laws that complement each other, the General Data Protection Regulation (GDPR) and the ePrivacy Directive (also known as Cookie Law) in Europe. We can also mention California’s CCPA/CPRA and PIPEDA in Canada.

In the EU, each country has a data protection authority that has been granted the duty and power to make these laws enforceable. For example, they give extensive guidance on EU cookie compliance for businesses and can distribute fines.

🔎 Learn more on each cookie compliance regulation:

👉 GDPR: A regulation in EU law on data protection and privacy for all individuals. It is not specifically written for cookie compliance, but addresses everything surrounding personal data in general. An important concept from the GDPR is consent: it mandates that websites must obtain explicit consent from users before storing or accessing cookies on their devices, except for essential cookies necessary for the website’s operation.

👉 ePrivacy Directive (Cookie Law): Established to put guidelines in place for the protection of electronic privacy, including email marketing and cookie usage, and it still applies today. We can think of it as complementing the GDPR. It requires websites to obtain informed consent from users before storing or accessing cookies on their devices, with some exceptions for essential cookies. The directive has been implemented differently in each EU member state.

👉 California Consumer Privacy Act (CCPA) & California Privacy Rights Act (CPRA): Intended to enhance privacy rights and consumer protection for residents of California, United States. It requires businesses to disclose their data collection and sharing practices, including the use of cookies, and provide consumers with a right to opt out.

Are cookies allowed in the EU?

Yes, cookies are allowed in the EU. However, cookies that are not strictly necessary to browsing the site (e.g. login, account management, items saved in shopping cart), are highly regulated. The ePrivacy Directive, often referred to as the “Cookie Law,” along with the GDPR, outlines the requirements for EU cookie compliance. Websites must provide clear and detailed information about the cookies being used and obtain explicit consent from users for these non-essential cookies like analytics or ads cookies.

💡 Using Google Ads or Google Analytics cookies? Make sure to activate Google Consent Mode to preserve essential marketing features and to get accurate conversion data through modeling. More on this here.

GDPR cookie compliance is a set of practices that websites must follow to align with the GDPR’s requirements on the protection of personal data in the EU. This means that if you use cookies you must:

  • inform your users that your site/app (or any third-party service used by your site/app) uses cookies;
  • explain, in a clear and comprehensive manner, which cookies you use and what for;
  • obtain informed consent prior to the storing of those cookies on the user’s device;
  • maintain records of consent and provide users with the option to withdraw consent at any time.

Check out our software solutions for a quick and easy GDPR cookie compliance here.

compliant cookie banner

To comply with Cookie Law, you’ll need to show a compliant cookie banner (also called cookie notice or cookie popup) upon the user’s first visit, implement a cookie policy and collect user consent to these cookies – unless your website uses strictly necessary cookies only, which is highly unlikely.

Make sure to categorize cookies (i.e. necessary, performance, functionality, marketing) for clarity. And remember, as a general rule of thumb, always to provide information that is easy-to-understand, concise but precise, and unambiguous.

The CCPA cookie consent generally refers to your business’s obligation to disclose legally-required information including any non-essential cookies used via a notice to residents of California, USA. Although the CCPA does not require opt-in consent, the notice should provide them with an option to opt out.

One thing here to be aware of, the CCPA requires opt-in consent for the use of cookies if it relates to the sale and sharing of personal information of minors (individuals between 13 to 16 years old – if younger, you must obtain consent from their parents or guardians).

🔎 Types of Cookie Compliance Banners

  • Opt-in: Users must actively agree to the use of cookies before they are set, excluding strictly necessary cookies. By “actively”, we mean they need to perform a clear and positive action like clicking on an “Accept” button. This is the case for the GDPR in the EU.
  • Opt-out: Cookies are set but their use is generally disclosed in a specific notice AND users are given the option to opt-out. This is the case for the CCPA in California.
  • Notice only: Users are informed about the use of cookies without explicitly asking for consent. This approach is not compliant under GDPR but may be seen under less stringent regulations.
  1. Step 1: Use tools like this cookie scanner to identify all cookies your website sets on a user’s device.
  2. Step 2: Implement legally-required processes like a consent banner + website cookie policy.
  3. Step 3: Ensure your cookie management practices are compliant, e.g. you provide clear options to accept, reject, and manage cookies.
  4. Step 4: Test across browsers and devices to make sure compliance measures are working consistently.
  5. Step 5: Keep your processes up-to-date with how your site and EU cookie compliance regulations evolve.

To become cookie compliant, you need to understand the specific requirements of regulations that may apply to you like the GDPR and Cookie Law, depending on where you and your users are based. You most likely have to set up a compliant cookie banner on your site, as well as a cookie policy page. For the latter, you need to conduct a thorough inventory of the cookies used on your website, including types and purposes for which they are used.

A cookie policy for website is a legal document and can be tricky to draft yourself. Same for the cookie banner, which comes with various requirements like preference management, consent collection, and can be a technical challenge to create and install on your site.

To become cookie compliant in the easiest way, try out some all-in-one software solutions like iubenda. They are expert in online compliance and have everything that you need to make your site compliant with cookie regulations.

Quick and easy cookie compliance with iubenda

Leave the tricky work to us!

🚀 Cookie banner customization + straightforward integration on your site
🚀 Cookie consent collection, preference management and records
🚀 Automatic blocking of cookies before consent is obtained
🚀 Cookie policy generation with lawyer-crafted clauses to choose from
🚀 Products updated when regulations change

EU cookie compliance

The easiest start to your cookie compliance journey

Try iubenda now