Before you invest in cookie consent
It comes up on almost every project, usually later than it should. Before you spend anything on cookie consent, it is worth confirming a few things are already true.
The cheapest security work is the boring kind done on a schedule. If two people in the business would answer this differently, that gap is the actual problem.
Prerequisites
- You can describe the outcome you want in one sentence
- Someone owns it after the work is done
- A banner does not make non-compliant tracking compliant
- You have a way to tell whether it worked
Warning signs
Non-essential scripts must wait for consent. Getting it slightly wrong is survivable. Ignoring it entirely is not. Budget a little time for it every quarter and it never becomes a project of its own.
Make refusing as easy as accepting. There is a version of this that is over-engineered, and it is worth avoiding. Doing this properly once is usually cheaper than doing it approximately three times.
The short version
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about cookie consent before you move on:
- Someone can say what the current setup is without going to look
- Non-essential scripts must wait for consent — and you know whether that is true here
- There is a way to tell whether the last change to this helped
The point is not perfection, it is knowing which of these you have consciously chosen to skip.