A practical checklist for cookie consent
The gap between knowing this and actually doing it is where most teams lose ground. Run through this the next time cookie consent comes up.
The realistic threat for most small businesses is automated and opportunistic, not targeted. If two people in the business would answer this differently, that gap is the actual problem.
The checklist
- A banner does not make non-compliant tracking compliant
- Non-essential scripts must wait for consent
- Make refusing as easy as accepting
- Someone is named as the owner
- There is a date to review it again
Why it matters
A banner does not make non-compliant tracking compliant. The teams that handle this well are rarely the ones with the biggest budgets. Budget a little time for it every quarter and it never becomes a project of its own.
In practice
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about cookie consent before you move on:
- Someone can say what the current setup is without going to look
- Make refusing as easy as accepting — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Most of the value here comes from doing the first two things, not all of them.