Dabish Digital
Security

Cookie consent: what to get right first

We end up explaining this on discovery calls often enough that it deserved writing down. If you only fix one thing about cookie consent this quarter, make it the first item below.

The cheapest security work is the boring kind done on a schedule. Assume whoever inherits this will have half your context and none of your patience.

Start here

A banner does not make non-compliant tracking compliant. The cost of getting this wrong is rarely visible on the day it happens. It is the sort of thing that looks like polish right up until it costs you an enquiry.

Then this

Non-essential scripts must wait for consent. The teams that handle this well are rarely the ones with the biggest budgets. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.

Eventually

Make refusing as easy as accepting. That sounds obvious written down. It is still the thing most often skipped. Assume whoever inherits this will have half your context and none of your patience.

How to tell if yours is fine

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about cookie consent before you move on:

  • Someone can say what the current setup is without going to look
  • A banner does not make non-compliant tracking compliant — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If any of that sounds like a description of your current setup, it is fixable.