Dabish Digital
Security

A short guide to cookie consent

Every audit we run turns up some version of this. Everything we would tell a client about cookie consent in the time it takes to drink a coffee.

Security is a maintenance habit rather than a purchase, which is why it drifts. The failure mode is not doing it wrong, it is doing it once and assuming it stays done.

Why it matters

A banner does not make non-compliant tracking compliant. The teams that handle this well are rarely the ones with the biggest budgets. It is the sort of thing that looks like polish right up until it costs you an enquiry.

The practical version

Non-essential scripts must wait for consent. The reasoning matters more than the rule, because the rule has exceptions. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.

Where it usually goes wrong

Make refusing as easy as accepting. That sounds obvious written down. It is still the thing most often skipped. The practical test is whether someone new to the project could tell, in a minute, that it had been handled.

How to tell if yours is fine

The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about cookie consent before you move on:

  • Someone can say what the current setup is without going to look
  • A banner does not make non-compliant tracking compliant — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

None of this needs a rewrite. Most of it is a morning's work once someone decides to do it.