{"id":996,"date":"2020-10-27T12:38:00","date_gmt":"2020-10-27T12:38:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=996"},"modified":"2026-03-12T09:15:01","modified_gmt":"2026-03-12T08:15:01","slug":"cookie-control","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/cookie-control\/","title":{"rendered":"Cookie Control"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-cookie-control-in-the-eu\">Cookie control in the&nbsp;EU<\/h2>\n\n\n\n<p>In the EU, the use of cookies and trackers on websites is regulated by the <a href=\"\/en\/gdpr\/\">General Data Protection Regulation (GDPR)<\/a>&nbsp;that is law in all EU member states.<\/p>\n\n\n\n<p>The GDPR governs the processing of personal data of individuals inside the EU and most cookies today collect personal data from users, when they visit websites.<\/p>\n\n\n\n<p>The GDPR requires websites to obtain user consent before activating cookies that will process personal data.<\/p>\n\n\n\n<p>Websites are not allowed to activate cookies and trackers that process personal data unless the user has first consented to it, unless the cookies can be deemed strictly necessary for the basic functions of the website.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/3911\/1920px-flag_of_europesvg.png?width=411&amp;\" alt=\"Flag of European Union - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">Cookie control in EU through the General Data Protection Regulation (GDPR)<\/figcaption><\/figure>\n\n\n\n<p>Personal data is any kind of information that can be directly or indirectly related to a living individual and therefore identify the user.<\/p>\n\n\n\n<p>This includes anything from names, e-mail addresses, social security numbers, but also IP addresses, browser specifications, search history and Unique IDs that most cookies set on user browsers after a website visit.<\/p>\n\n\n\n<p><strong>If your website has visitors from inside the EU<\/strong>&nbsp;and you use cookies that process personal data, you must \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ask for consent before activating cookies and trackers that process personal data,<\/li>\n\n\n\n<li>Enable users to give clear and affirmative consent to the processing of their personal data,<\/li>\n\n\n\n<li>Make sure that user consents are granular, i.e. users must be able to consent to some cookies rather than others,<\/li>\n\n\n\n<li>Inform users of how you use cookies and the purposes of why your website processes personal data,<\/li>\n\n\n\n<li>Document all obtained consents,<\/li>\n\n\n\n<li>Consent must be renewed annually. However, some national data protection guidelines recommend more frequent renewal, e.g. 6 months. Check your local data protection guidelines for compliance<\/li>\n<\/ul>\n\n\n\n<p>Is your website GDPR compliant? <a href=\"\/\">Test for free with the Cookiebot CMP test<\/a>.<\/p>\n\n\n\n<p><a href=\"\/en\/gdpr-cookies\/\">Learn more about the GDPR and cookie consent<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-edpb-guidelines-on-valid-consent\">EDPB guidelines on valid consent<\/h3>\n\n\n\n<p>The <a href=\"https:\/\/edpb.europa.eu\/edpb_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">European Data Protection Board (EDPB)<\/a>&nbsp;is the leading supervisor of the GDPR in the EU that regularly adopts guidelines and issues decisions on how the GDPR is to be enforced by the national data protection authorities in each EU member country.<\/p>\n\n\n\n<p>On May 4, 2020, the <a href=\"\/en\/edpb-guidelines\/\">EDPB adopted guidelines on valid consent&nbsp;<\/a>that make it very clear what constitutes GDPR compliant consent for the processing of personal data on websites\u2026 and what does not.<\/p>\n\n\n\n<p>EDPB guidelines clarify that \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Consent must be a freely given, specific, informed and unambiguous indication of users\u2019 wishes, i.e. a clear and affirmative action on part of the user before any activation of cookies is allowed on your website.<\/li>\n\n\n\n<li>Pre-ticked checkboxes on cookie banners are not allowed, i.e. cookies must be deselected by default when users land on your website.<\/li>\n\n\n\n<li>Scrolling and continued browsing on your website (implied consent) does not constitute valid consent, i.e. users must actively select and activate cookies through a cookie banner before your website is allowed to process their personal data.<\/li>\n\n\n\n<li>Cookie walls (i.e. making user consent conditional for access to your domain) does not constitute valid consent, i.e. users\u2019 consent must be freely given and specific to each different processing purpose.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"\/en\/edpb-guidelines\/\">Learn more about the EDPB guidelines on valid consent<\/a><\/p>\n\n\n\n<p>In doubt whether your website is GDPR compliant? <a href=\"\/\">Test with the free Cookiebot CMP compliance test<\/a>.<\/p>\n\n\n\n<p><a href=\"https:\/\/manage.cookiebot.com\/en\/signup\">Try Cookiebot CMP free for 14 days<\/a>... or forever if you have a small website.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookie-control-with-cookiebot-cmp\">Cookie control with Cookiebot CMP<\/h2>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;is a consent management platform that makes your website compliant with the GDPR, the CCPA and other data protection laws across the world.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;works by detecting all cookies and trackers in operation on your domain using our unmatched scanning technology that finds even the hidden third-party trojan horses.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4333\/consent_en.png?width=500&amp;\" alt=\"Cookieboot Pop Up Banner - Cookiebot\" width=\"770\" height=\"449\"\/><figcaption class=\"wp-element-caption\">Granular cookie control with Cookiebot CMP.<\/figcaption><\/figure>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;auto-blocks all cookies and personal data processing on your domain until users have given their granular consent to which trackers, they will allow activated \u2013 ensuring that your website fully lives up to the GDPR requirements for prior consent.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;also offers full CCPA compliance for websites.<\/p>\n\n\n\n<p><a href=\"https:\/\/manage.cookiebot.com\/en\/signup\">Try Cookiebot CMP free for 14 days<\/a>\u2026 or forever if you have a small website.<\/p>\n\n\n\n<p><a href=\"\/en\/gdpr-cookies\/\">Learn more about GDPR and cookie consent<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/ccpa\/\">Learn more about CCPA compliance<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookie-control-in-the-us\">Cookie control in the US<\/h2>\n\n\n\n<p>In the US, the use of cookies and the processing of personal information is not regulated on a federal level as it is in the EU by the GDPR.<\/p>\n\n\n\n<p>Instead, some states have their own set of laws governing personal information collection and digital privacy, while other states have no real protection for users.<\/p>\n\n\n\n<p>The biggest data protection in the US that covers cookie control is the <a href=\"\/en\/ccpa\/\">California Consumer Privacy Act (CCPA)<\/a>&nbsp;that took effect in January 2020.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/3912\/1920px-flag_of_the_united_statessvg.png?width=409&amp;\" alt=\"Flag of United States - Cookiebot\" width=\"770\" height=\"405\"\/><figcaption class=\"wp-element-caption\">Cookie control in the US through the California Consumer Privacy Act (CCPA).<\/figcaption><\/figure>\n\n\n\n<p>The CCPA grants consumers the right to request disclosure of the categories and specific pieces of personal information that a business has collected on them. It also grants consumers the right to request deletion, as well as the right to opt out of having their data sold to third parties.<\/p>\n\n\n\n<p>The CCPA requires that users are informed of what cookies are in operation on a website, what kind of personal information they collect and for what purposes.<\/p>\n\n\n\n<p>CCPA also requires websites to inform users of what third parties they share their personal information with.<\/p>\n\n\n\n<p><a href=\"\/en\/ccpa\/\">Learn more about the California Consumer Privacy Act (CCPA)<\/a><\/p>\n\n\n\n<p><a href=\"\/en\/ccpa\/\">Learn more about CCPA compliance with Cookiebot CMP<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookie-control-in-the-uk-after-brexit\">Cookie control in the UK after Brexit<\/h2>\n\n\n\n<p>The UK left the EU in January 2020 and by the end of this year will no longer be governed by the EU\u2019s General Data Protection Regulation.<\/p>\n\n\n\n<p>However, the UK has adopted new data protection laws that mirror the GDPR and that will ensure a continued equivalent data protection regime.<\/p>\n\n\n\n<p><a href=\"\/en\/uk-gdpr\/\">Learn more about Brexit and cookie control in the UK<\/a><\/p>\n\n\n\n<p>The Information Commissioner\u2019s Office (ICO) is the leading data protection authority in the UK, responsible for enforcement and supervision of the country\u2019s data protection laws.<\/p>\n\n\n\n<p>The UK\u2019s data protection laws after Brexit is <a href=\"\/en\/uk-gdpr\/\">the UK-GDPR&nbsp;<\/a>and <a href=\"\/en\/data-protection-act-2018\/\">the Data Protection Act 2018<\/a>.<\/p>\n\n\n\n<p>In the summer of 2019, the <a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-pecr\/guidance-on-the-use-of-cookies-and-similar-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\">ICO has updated its guidelines for the use of cookies<\/a>&nbsp;and trackers and put a significantly tighter cookie control in place in the UK.<\/p>\n\n\n\n<p>When it comes to a website\u2019s cookie management, implied consent as we know it today \u2013 the soft opt-in that allows websites to interpret as consent the continued browsing of its users \u2013 do not meet the requirements for valid consent, ICO has ruled.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/3628\/uk-flag.png?width=426&amp;\" alt=\"Flag of United Kingdom - Cookiebot\" width=\"770\" height=\"385\"\/><figcaption class=\"wp-element-caption\">Cookie control in the UK through the UK-GDPR and Data Protection Act 2018.<\/figcaption><\/figure>\n\n\n\n<p>Instead, users must give their affirmative consent to anything that is not necessary cookies (or non-essential, as ICO calls them) and it is the legal responsibility of websites to have a cookie manager in place that enables this for their users.<\/p>\n\n\n\n<p>Pre-ticked boxes (or any equivalent) are not lawful to use on anything but necessary cookies, according to the new ICO guidelines.<\/p>\n\n\n\n<p>This means that preference, statistics and marketing cookies must abide by the same rules: they all need to be un-ticked and now require affirmative opt-in to be viewed as valid consent.<\/p>\n\n\n\n<p>In other words, users must now choose to tick the boxes of preference, statistics and marketing cookies alike, in order for these categories of cookies to be activated.<\/p>\n\n\n\n<p>The ICO guidelines clarify&nbsp;that \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Users must take a clear and positive action to consent to non-essential cookies,<\/li>\n\n\n\n<li>Websites and apps must tell users clearly what cookies will be set and what they do \u2013 including any third-party cookies,<\/li>\n\n\n\n<li>Pre-ticked boxes or any equivalents, such as sliders defaulted to \u201con\u201d, cannot be used for non-essential cookies,<\/li>\n\n\n\n<li>Users must have control of any non-essential cookies,<\/li>\n\n\n\n<li>Non-essential cookies must not be set on landing pages before you gain the user\u2019s consent.<\/li>\n<\/ul>\n\n\n\n<p>Inform yourself on <a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-pecr\/guidance-on-the-use-of-cookies-and-similar-technologies\/\" target=\"_blank\" rel=\"noreferrer noopener\">ICO\u2019s updated guidelines on cookies<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookie-control-in-web-browsers\">Cookie control in web browsers<\/h2>\n\n\n\n<p>Digital self-defense is also an option a lot of people are choosing in exasperation&nbsp;when learning about the ugly truth of the dismal state of privacy on the Internet today.<\/p>\n\n\n\n<p>This type of digital self-defense is essentially a version of privacy protection, where everyone has to fend for themselves, by downloading the right browser that then block cookies automatically.<\/p>\n\n\n\n<p>Privacy-friendly browsers such as <a href=\"https:\/\/www.epicbrowser.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Epic<\/a>, <a href=\"https:\/\/brave.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Brave<\/a>&nbsp;or <a href=\"https:\/\/www.mozilla.org\/en-US\/firefox\/new\/\" target=\"_blank\" rel=\"noreferrer noopener\">Firefox<\/a>&nbsp;offer cookie control through non-discriminatory, across-the-board cookie blockers that stop all cookies, even necessary and benign ones.<\/p>\n\n\n\n<p>The downside is that they often break websites, because they block cookies that support the basic functions of a domain. This full cookie stop is the default mode of both Epic and Brave, whereas Firefox utilizes <a href=\"https:\/\/disconnect.me\/trackerprotection\/blocked\/\" target=\"_blank\" rel=\"noreferrer noopener\">a tracker list from Disconnect<\/a>&nbsp;to determine which cookies they block.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/3598\/privacy-browsers.jpg?width=500&amp;\" alt=\"Epic, Brave &amp; Firefox Logos - Cookiebot\" width=\"770\" height=\"365\"\/><\/figure>\n\n\n\n<p>This digital self-defense is not a viable final solution to the privacy problems of surveillance capitalism, since most people don\u2019t have the time or the technical skills to navigate the abundant market of privacy tools, browsers, VPNs or adblockers.<\/p>\n\n\n\n<p>There is also another way to protect privacy in our digital infrastructures\u2026<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-consent-management-platform-and-cookie-control\">Consent management platform and cookie control&nbsp;<\/h2>\n\n\n\n<p>Cookie control through a cookie manager like <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;is a technology that we \u2013 obviously \u2013 have put our weight behind and think of as a vital part of a sustainable solution for protecting privacy.<\/p>\n\n\n\n<p>Using a consent solution that is specific to each website (implemented through the cloud and integrated seamlessly onto a domain) not only prevents websites from breaking by allowing them to discriminate between different categories of cookies, it also holds the potential to be fully GDPR and CCPA compliant.<\/p>\n\n\n\n<p>Cookiebot CMP makes your website fully compliant with the <a href=\"\/en\/gdpr\/\">General Data Protection Regulation (GDPR)<\/a>&nbsp;and the <a href=\"\/en\/ccpa\/\">California Consumer Privacy Act (CCPA)<\/a>.<\/p>\n\n\n\n<p>A website owner looking for cookie control can use <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;to \u2013<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>have their domains scanned for all cookies and similar trackers,<\/li>\n\n\n\n<li>enable prior consent for users through a customizable cookie,<\/li>\n\n\n\n<li>obtain a cookie declaration,<\/li>\n\n\n\n<li>feature a Do Not Sell My Personal Information link on their website,<\/li>\n\n\n\n<li>be able to be fully compliant with the GDPR and the CCPA,<\/li>\n\n\n\n<li>protect the privacy of their users against against unwanted and non-consensual third-party tracking.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/manage.cookiebot.com\/en\/signup\/\">Try Cookiebot CMP free for 14 days<\/a>... or forever if you have a small website.<\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>Cookie control in the&nbsp;EU In the EU, the use of cookies and trackers on websites is regulated by the General Data Protection Regulation (GDPR)&nbsp;that is law in all EU member states. The GDPR governs the processing of personal data of individuals inside the EU and most cookies today collect personal data from users, when they [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":998,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"inline_featured_image":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-996","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2020\/10\/building-1853330_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/996","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=996"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/996\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/998"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}