Need to learn more about the GDPR?

    Achieve GDPR compliance easily

    Cookie compliance requires that users be informed and have consent choices for their data. Cookiebot CMP enables this with three powerful and automatic core functions.

    • Monitoring: stay up to date on the cookies and tracking technologies your website uses, enabling user notification and consent
    • Control: When required, prevent cookies from being used unless user consent has been obtained
    • Consent: Obtain and store informed, granular consent from users to be compliant with laws like the GDPR
    Cookie checker

    Frequently asked questions

    The GDPR is "extraterritorial", which means that the law protect residents of the European Union. If your company does business with residents of its member countries (e.g. providing products or services) and/or if your website collects data from those residents, then this data privacy law applies to you. It does not matter if your company is based in the EU or not.

    The EU's GDPR does not differ much at all from the UK GDPR, since the UK adopted a version of the GDPR with few changes. Since the UK left the European Union in 2020 (Brexit) the GDPR no longer regulated UK data privacy because it was no longer a member state. The UK GDPR took effect January 30, 2020, along with an amended version of the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).

    Like the EU's GDPR, the UK GDPR also:

    • provides UK residents with a set of rights regarding their personal data and data privacy
    • requires obtaining valid consent from users, e.g. for cookie and tracker use on your website prior to collecting or processing personal data
    • requires secure storage and documentation of consent
    • requires users to be able to change or revoke their consent as easily as to give it

    Both regulations use an "opt in" model for consent, which means that in most cases user consent must be obtained before data can be collected or processed. Companies must also have a legal basis for data processing, like user consent, or other options like fulfilling a contract.

    Under the EU's GDPR, each member country has its own Data Protection Authority (DPA) that handles enforcement. The enforcement authority for the UK GDPR is the Information Commissioner, representing the Information Commissioner's Office (ICO), so one centralized authority. Like the EU's GDPR, the UK GDPR does not provide consumers with private right of action, which is the ability to sue for data breaches or other violations.

    Three areas that the UK GDPR covers that the EU's GDPR does not are:

    • national security
    • intelligence services
    • immigration

    We cannot provide legal advice or guarantee data privacy compliance under any regulation, and recommend consulting qualified legal counsel regarding your specific business and privacy compliance needs.

    However, the GDPR provides clear guidelines and best practices. Companies must have a legal basis for processing personal data. User consent is a common legal basis, but there are others, like fulfilling a contract or public interest. The safest legal basis for many types and purposes of data processing is obtaining and securely managing user consent, as with a consent management solution.

    When using consent as a legal basis, companies must obtain user consent before collecting and processing their personal data in many cases. To be valid, consent must be freely given, specific, informed and unambiguous. Users must be able to understand at a granular level what data usage they are consenting to, and websites cannot use tricks to encourage consent.

    Companies must always provide clear information, like on a Privacy Policy page, that tells users what data is collected, for what purposes, and how it may be shared, sold, or used. Users must also be told their data privacy rights under the law and advised on how to exercise those rights.

    Installing a Consent Management Platform (CMP) like Cookiebot CMP is easy and setup is user-friendly. It enables companies to provide data privacy information and obtain and store valid consent from users. The CMP will also scan websites to determine what cookies and tracking technologies are in use, and block their usage until user consent for them is obtained, thus helping with privacy compliance.

    With Geolocation features, the CMP can customize messaging and functions based on where the user is located, to enable specific compliance with GDPR, for example. Thanks to automated consent management, the CMP will also stay up to date with the legal landscape and technology to help maintain compliance.

    Show more

    Learn how easy it is to get your website privacy-compliant

    If you want to get your website compliant with the GDPR, Cookiebot CMP is easy to set up, user-friendly to customize and uses powerful scanning technology to help you achieve and maintain privacy compliance for cookie use with regulations like the GDPR. Best of all, you can get started for free. Here's how.

    Trackpad icon - Cookiebot
    Icon shield
    Pepco
    rural-king
    orbico
    credit-exchange
    canon
    bauhaus
    Cookiebot bg shield