GDPR Guide

Configure CookieShift for EU/UK GDPR-style opt-in consent—laws, categories, geo rules, and proof.

Consent Setup — GDPR compliance configuration
Consent Setup — GDPR compliance configuration

This guide explains how to use CookieShift for GDPR-style opt-in programs (EU, UK, EEA, and similar). It is educational—not legal advice.

What GDPR expects (simplified)

Visitors must generally consent before non-essential cookies and similar technologies run, with clear information and easy withdrawal. You need records of consent and policies that match what the banner says.

CookieShift helps with:

  • Discovering trackers (Scanner)
  • Presenting granular choices (Consent Setup)
  • Storing consent signals (Consent logs)
  • Demonstrating crawl-time inventory (Compliance reports)
Launch GDPR-style consent on a new site
  1. 1
    Add property and install script
    Register the domain under Websites. Install via Modules and confirm Connected.
  2. 2
    Run full scan
    Complete a crawl in Scanner. Review Tracker Inventory and clear Unclassified items.
  3. 3
    Apply GDPR law template
    In Consent SetupCompliance, select GDPR or search the law registry and Apply. Review category copy in the Content tab.
  4. 4
    Configure strict prior consent
    Enable Strict mode (and related security options) so non-essential tags wait for consent where the runtime supports blocking.
  5. 5
    Set geo rules (optional)
    Add Geo → law rules if EU visitors should see GDPR while others see a different regime.
  6. 6
    Save, test, document
    Save config. Test in private browsing. Export Compliance PDF and sample Consent logs for your records.
ControlLocationPurpose
GDPR lawCompliance tabApplies template defaults
Strict modeCompliance → SecurityPrior consent for non-essential
Button layout Accept + Reject + CustomizeAppearanceMeaningful choice
Category descriptionsContentTransparency per purpose
Consent renewal (days)Compliance → TimingRe-prompt after expiry (default often 180)
Hide banner on pathsCompliance → TimingSuppress on app shells if configured

Proof and documentation

ArtifactWhere to get it
Tracker inventory snapshotCompliance export CSV/PDF
Issue remediation listScanner → Compliance Issues
Consent decisionsConsent logs / audit export
Config versionShown in Consent & Scripts tab

Retain exports with timestamps aligned to your audit period.

Regional differences inside Europe

Use Geo → law rules when:

  • UK visitors need UK PECR-aware copy while EU visitors need GDPR framing
  • You run a global site with EU-only strict mode

Test with VPN or the Implementation geo probe (engineering page) if available on your account.

FAQ

Is legitimate interest supported?

CookieShift focuses on consent UX and inventory. Legitimate interest assessments are legal determinations outside the product—document them in your policy; do not mark marketing tags as Necessary without counsel.

Do I need a cookie policy page?

You need accurate public information. Use AI Assistant policy draft only as a starting point—publish after legal review and link from the banner.

What about Google Consent Mode?

Configure supported analytics integrations in Consent SetupIntegrations so tags respect category choices where integrated.