Cookie Consent Management
Cookies fired before anyone agreed, and no way to refuse.
What Is Cookie Consent Management?
A regulator's sweep finds non-essential cookies set before consent and a banner with no way to refuse. A crawl lists every cookie with the moment it was written, two of them wearing a strictly necessary label they have not earned, and three uncategorised ones that need filing correctly because the banner switches categories on those labels. You will rebuild the banner, remove implied-consent wording and default-on categories, publish with a documented reason, and re-crawl to find the embedded video player that needs a different fix.
What You'll Learn in Cookie Consent Management
- Explain why cookie rules come from the ePrivacy Directive and the GDPR together, and what each one governs
- Apply the strictly necessary test correctly, and recognise that analytics, A/B testing and session recording never pass it
- Sort cookies into necessary, functional, analytics and marketing, and see why a wrong label makes the banner honour the wrong choice
- Identify banner dark patterns, including implied consent wording, unequal refusal, and on-by-default categories
- Configure prior blocking so non-essential tags are held rather than merely announced
- Provide withdrawal that is as easy as consent was, and record the consent proof needed to demonstrate compliance
- Recognise why directly embedded third parties escape tag-manager control, and why click to load is the fix
- Verify a configuration change by re-crawling rather than trusting the settings screen
Cookie Consent Management — Training Steps
-
Introduction
Today you will work through cookie consent: which cookies a website may set before anyone agrees to anything, how the four categories differ, and what turns a consent banner from a legal notice into a legal problem. The rules here come from two places at once. The ePrivacy Directive governs storing or reading anything on someone's device, and the GDPR governs what counts as valid consent.
-
The Regulator's Enquiry
Alice opens her inbox to find a message from Helena Ruzicka, the Data Protection Officer. A supervisory authority sweep has flagged the Brackwell Media website. The letter is specific about what the automated check found.
-
Opening the Consent Platform
Helena's email links straight to the consent management platform, where the fresh scan is waiting.
-
Signing In
The consent platform holds the cookie inventory, the banner configuration and the consent log for every Brackwell Media property.
-
Reading the Scan
The scan lists twelve cookies set by the Brackwell Media homepage, with the moment each one is written and who writes it. Alice starts with the two columns the regulator's crawler was reading.
-
The Strictly Necessary Myth
Three cookies are correctly marked strictly necessary: the sign-in session, the CSRF token, and the cookie that stores the consent choice itself. Two more are marked strictly necessary and should not be. This is the most common cookie compliance error there is.
-
Which One Is Necessary
Before Alice recategorises anything, she checks her own understanding of where the line sits.
-
Correcting the Categories
Alice works down the uncategorised rows. Each cookie has to sit in the category that matches what it actually does, because the banner will switch whole categories on and off based on these labels. Getting a marketing cookie filed as functional means it will fire for someone who refused marketing.
-
The Banner as It Stands
With the inventory corrected, Alice opens the banner configuration. The live banner is shown exactly as a visitor sees it. This is the design the regulator called out.
-
Making Refusal Real
Alice has seen the three defects. Before she changes the configuration, she thinks through what a compliant banner actually has to offer.
Security Framework Coverage
CIS Controls
- CIS 3 Data Protection
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.DS Data Security
GDPR
- Art. 7 Conditions for consent