Compliance
The signals, sent for you
Google's tags and a growing number of browsers have their own language for consent. CookieForever translates the visitor's choice into both.
What is sent, and when
Consent Mode v2
All seven signals — analytics_storage, ad_storage, ad_user_data, ad_personalization, functionality_storage, personalization_storage and security_storage — are set from the categories the visitor granted.
Denied by default
Before any tag loads, the signals are set to denied, except security storage, which strictly necessary functions rely on. If the page already sets its own defaults, they are left alone.
Updated on every answer
Each choice sends an update, followed by a cookie_consent_updated event to the dataLayer, so your tag manager can react to it.
Global Privacy Control
Browsers can send a GPC signal asking not to have personal data sold or shared. It is honoured by default for visitors under Californian, Connecticut and Colorado rules, and can be switched on for everyone.
What GPC changes
When the signal is honoured, tags that sell or share data — advertising pixels from Google Ads, Meta, LinkedIn, TikTok and Pinterest — stay held even if their category is granted, and the advertising signals are sent as denied.
What it does not cover
- Which rules apply to a visitor is worked out from the country and region your hosting passes along; without them, the GDPR rules apply.
- CookieForever does not implement the IAB Transparency & Consent Framework (TCF).
Questions about compliance?
Write to us — we answer questions about how the platform works before you commit to anything.