Skip to content

Compliance

Consent that holds up

Consent has to be freely given, specific, informed and unambiguous — and as easy to withdraw as to give. This is how the banner meets that bar.

How consent is asked for

Opt-in, everywhere

Nothing that needs consent runs until the visitor has said yes. CookieForever applies the opt-in model to every visitor, whichever privacy regime they fall under — there is no opt-out mode to switch on by mistake.

No pre-ticked boxes

Every category that needs consent starts switched off. A banner with a pre-ticked category cannot be published.

Reject as easy as accept

"Reject all" sits on the first layer next to "Accept all", with the same size and weight. A banner that hides it cannot be published.

No implied consent

Scrolling, clicking elsewhere or simply using the site is never taken as consent. Only a choice in the banner records one.

A choice per category

Visitors can open the settings and switch each category on or off. Strictly necessary cookies are always on, and marked as such.

Consent expires

A consent is valid for at most twelve months. After that — or when you publish a new version of the banner or the cookie policy — visitors are asked again.

Withdraw at any time

The cookie policy shows the visitor their consent ID and choices, with buttons to change or withdraw them. Withdrawing takes effect at once, and cookies from the categories no longer granted are cleared.

What it does not cover

  • Consent for special categories of personal data (GDPR article 9) needs your own assessment; the banner has no separate flow for it.
  • Age checks and parental consent are not built in.
  • CookieForever does not implement the IAB Transparency & Consent Framework (TCF).

Questions about compliance?

Write to us — we answer questions about how the platform works before you commit to anything.

Contact us