close

Do Not Track (DNT)

Consent & Rights
D

Do Not Track (DNT) is a browser signal — transmitted as an HTTP header (DNT: 1) — indicating a user's preference to opt out of behavioral tracking across websites. Proposed by the W3C and supported by major browsers from around 2011, DNT aimed to let users communicate a universal opt-out without interacting with individual consent banners. Unlike Global Privacy Control (GPC), DNT was never backed by legal requirement — no law obligated websites to honor it, and most ignored it. Major browsers including Safari, Firefox, and Edge deprecated DNT support by 2023. GPC supersedes DNT as the legally enforceable modern equivalent under CCPA.

Consent Record

Consent & Rights
C

A consent record — also called a consent log or consent receipt — is a timestamped entry documenting that a specific individual gave or withdrew consent for data processing, capturing when they acted, what information they were shown, and which consent interface version was displayed. Under GDPR Article 7(1), organizations relying on consent must demonstrate it was validly obtained; the burden of proof lies with the data controller. A consent record typically captures a unique visitor identifier, timestamp, cookie categories accepted or rejected, and banner version shown. During a regulatory investigation, consent records are the primary evidence that cookie-based tracking was lawfully conducted.

Purpose Limitation

Data Governance
P

Purpose limitation is one of GDPR's seven data processing principles, established in Article 5(1)(b). It requires personal data to be collected for specified, explicit, and legitimate purposes and not further processed in a way incompatible with those original purposes. Organizations must define the purpose before collection, communicate it to data subjects, and restrict subsequent use to that declared purpose. Compatible secondary purposes such as scientific research may be permissible under Article 89, but commercial repurposing requires a new lawful basis and typically new consent. For cookie consent, analytics consent cannot be extended to justify marketing targeting with the same data.

Privacy Notice

Privacy Laws
P

A privacy notice is a transparency disclosure provided at or before the point personal data is collected, explaining what is gathered, why, and how it will be used. Under GDPR Articles 13 and 14, data controllers must proactively provide this — not wait to be asked. A privacy notice differs from a privacy policy: a policy covers all processing activities across an organization; a notice is a targeted, in-context disclosure — a cookie banner tooltip, a checkout alert, or a form note. The ICO and EDPB recommend a layered approach: a concise notice at the point of collection, linking to the full policy for more detail.

Pseudonymization

Data Governance
P

Pseudonymization is a data processing technique that replaces directly identifying information — names, email addresses — with an artificial identifier (a pseudonym), so data can no longer be attributed to a specific individual without access to separately stored mapping information. GDPR Article 4(5) defines it as a recognized privacy-enhancing measure; Article 25 recommends it as a Privacy by Design implementation. Pseudonymized data remains personal data under GDPR if re-identification is possible — the key distinction from anonymization, which removes GDPR obligations entirely. It can reduce breach notification risk and helps controllers satisfy data minimization requirements under GDPR Article 5(1)(c).

Sensitive Personal Data

Data Governance
S

Sensitive personal data refers to specific categories warranting heightened protection under GDPR Article 9 due to the elevated risk their misuse poses to individuals. Processing these categories is prohibited by default unless one of ten narrow exceptions applies — explicit consent being one. The Article 9 special categories include racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health data, and data about sex life or sexual orientation. For website operators, this most commonly arises through health-related forms, political sites, or behavioral profiling that infers protected characteristics. Standard GDPR consent is insufficient — explicit consent is required.

Cookie Scanner

Cookies How-Tos
C

A cookie scanner is an automated tool that crawls a website and detects all cookies and tracking technologies active on its pages — including first-party cookies, embedded third-party scripts, and pixels. Scanners identify each cookie's name, domain, type, purpose, and lifespan, and categorize them into standard groups: strictly necessary, functional, analytics, performance, and marketing. GDPR and the ePrivacy Directive require full disclosure of all tracking technologies — a consent banner can only obtain valid consent for cookies the site owner knows about. Running undisclosed cookies is a compliance violation. ConsentBit's scanner detects new cookies within 24 hours and categorizes them automatically.

Privacy Sandbox

Tracking Tech
P

The Privacy Sandbox is Google's initiative to replace third-party cookies in Chrome with privacy-preserving web APIs that support advertising without cross-site user tracking. Announced in 2019, it aims to let advertisers target and measure campaigns while keeping behavioral data on-device. Key APIs include Topics API (assigns ad interest categories from local browsing history), Protected Audience API (enables remarketing without cross-site tracking), and Attribution Reporting API (measures conversions without exposing user-level data). Google's deprecation timeline has been delayed multiple times. As of 2026, Chrome is implementing cookie partitioning (CHIPS) alongside Privacy Sandbox APIs while phasing out unpartitioned third-party cookies.

Tracking Pixel

Tracking Tech
T

A tracking pixel — also called a web beacon or 1x1 pixel — is a tiny, invisible image embedded in a webpage or email that transmits data to a server when loaded. Unlike browser-stored cookies, it triggers an HTTP request sending the user's IP address, browser type, device, and page viewed. Tracking pixels are used by advertising platforms (Meta Pixel, Google Ads) and email tools to track opens and conversions. Under the ePrivacy Directive, pixels that process personal data require prior consent, the same standard as cookies. European regulators including the CNIL have fined sites that load pixels before consent is given.

Social Media Cookies

Tracking Tech
S

Social media cookies are tracking cookies set by platforms — including Meta, LinkedIn, X, and TikTok — when their scripts, share buttons, embedded videos, or advertising pixels load on a third-party website. They allow platforms to track user behavior across the web, build targeting profiles, and measure ad effectiveness. Common examples include the Meta Pixel, LinkedIn Insight Tag, and TikTok Pixel. Under GDPR and the ePrivacy Directive, social media cookies require explicit opt-in consent before activation. A consent management platform must block these scripts on page load and activate them only after a user accepts the relevant cookie category.

Performance Cookies

Tracking Tech
P

Performance cookies (also called measurement cookies) collect anonymized data about how visitors interact with a website — which pages they visit, how long they stay, which links they click, and where they encounter errors. Unlike marketing cookies, they are not used for behavioral targeting; their purpose is to help site owners improve website functionality. Common providers include Adobe Analytics, Hotjar, and Crazy Egg. Despite their non-targeting purpose, performance cookies require GDPR opt-in consent because they access the user's device and process personal data such as IP addresses. The strictly necessary cookie exemption does not apply to performance cookies.

CPRA (California Privacy Rights Act)

Privacy Laws
C

The California Privacy Rights Act (CPRA) is a California law passed in November 2020 that significantly expanded the CCPA. Its provisions took effect January 1, 2023, establishing the California Privacy Protection Agency (CPPA) — the first dedicated privacy enforcement agency in the US. Key additions include the right to correct personal information, the right to limit use of sensitive personal information, expanded opt-out rights covering data "sharing" (not just "selling"), and tripled fines for violations involving minors' data. For website operators using targeted advertising or behavioral analytics, CPRA compliance typically requires an updated cookie consent mechanism and a revised privacy policy.

Standard Contractual Clauses (SCCs)

Privacy Laws
S

Standard Contractual Clauses (SCCs) are pre-approved contract templates from the European Commission allowing personal data transfers from the EU/EEA to countries without an EU adequacy decision, including the United States. They are the most widely used transfer mechanism under GDPR Chapter V. Updated SCCs took effect December 2022, replacing versions invalidated by the Schrems II ruling. For website operators, SCCs apply whenever EU personal data flows to US-based tools — Google Analytics, Meta Pixel, email platforms, or cloud hosting providers. Running EU visitor data through US tools without a valid transfer mechanism in place is a GDPR violation.

DPIA (Data Protection Impact Assessment)

Privacy Laws
D

A Data Protection Impact Assessment (DPIA) is a structured process required by GDPR Article 35 for evaluating privacy risks before high-risk processing begins. A DPIA is required when using new technologies, processing sensitive personal data at scale, systematically monitoring publicly accessible areas, or profiling individuals for automated decision-making. The process documents the processing purpose, assesses necessity and proportionality, identifies risks to data subjects, and records the measures taken to address them. If risks cannot be adequately mitigated, the data protection authority must be consulted first. For website operators, deploying behavioral advertising systems or session-recording heatmap tools commonly triggers the DPIA requirement.

Data Breach

Data Governance
D

A data breach is a security incident in which personal data is accessed, disclosed, altered, or destroyed without authorization — through cyberattack, accidental exposure, or human error. Under GDPR Article 33, data controllers must notify their supervisory authority within 72 hours of a breach that risks individuals' rights. If high risk is likely, GDPR Article 34 requires direct notification to affected data subjects. Breaches are not limited to hacking — sharing a mailing list with the wrong recipient or losing an unencrypted device both qualify. Consent records maintained by a CMP can serve as audit evidence during breach investigations.

Privacy by Design

Privacy Laws
P

Privacy by Design is a foundational principle under GDPR Article 25 requiring organizations to embed data protection into systems and processes from the outset, not as a compliance afterthought. The concept was developed by Ann Cavoukian and adopted into EU law as a binding GDPR obligation. Article 25 has two connected requirements: Privacy by Design (data protection built into systems before launch) and Privacy by Default (systems must apply the most privacy-protective settings by default — collecting minimum data, for the shortest necessary period). A consent management platform that blocks tracking scripts before consent is given directly implements Privacy by Default.

Right to Erasure (Right to Be Forgotten)

Consent & Rights
R

The right to erasure — also called the right to be forgotten — is a GDPR right under Article 17 allowing individuals to request deletion of their personal data. It applies when data is no longer needed for its original purpose, when the data subject withdraws consent and no other lawful basis exists, when they object to processing with no overriding grounds, or when data was unlawfully processed. Organizations must respond within one month. The right is not absolute — it does not cover processing needed for legal claims or public interest. Withdrawal of cookie consent is a common trigger for erasure requests.

Data Subject

Consent & Rights
D

A data subject is any living individual whose personal data is collected or processed by an organization. Under GDPR Article 4(1), this includes website visitors, customers, and app users — anyone a site tracks via cookie identifiers or IP addresses. GDPR grants data subjects eight enforceable rights: to be informed, access their data, correct it, request erasure, restrict processing, data portability, object to processing, and rights against automated decision-making. Data controllers must respond to requests exercising these rights within 30 days, and cookie consent systems must honor users' withdrawal choices in real time.

Personal Data

Data Governance
P

Personal data is any information relating to an identified or identifiable natural person. Under GDPR Article 4(1), a person is identifiable through names, ID numbers, location data, online identifiers, or physical, psychological, genetic, or social factors. For website operators, personal data includes far more than names and emails — IP addresses, cookie identifiers, device fingerprints, and behavioral profiles all qualify when they can be linked to an individual, even indirectly. This is why cookie consent is required: cookie identifiers constitute personal data from the moment they are set on a user's device. Only fully anonymized data falls outside GDPR's scope.

Cookie Policy

Cookies How-Tos
C

A cookie policy is a legal document disclosing the cookies and tracking technologies a website uses — their purpose, duration, and whether they are first-party or third-party. Under GDPR and the ePrivacy Directive, it is a mandatory disclosure that must be provided before or at the point of consent. A cookie policy is distinct from a privacy policy, which covers all personal data processing; the cookie policy focuses specifically on cookie-based tracking. A compliant cookie policy names each cookie, states its type, purpose, lifespan, and explains how visitors can withdraw consent. It must be updated whenever new tracking tools are added to the site.

Cookie Banner

Cookies How-Tos
C

A cookie banner is the on-page notice a website shows to inform visitors about cookies and request or record their consent. It's how websites satisfy ePrivacy Article 5(3)'s prior consent rule — the term itself isn't in the law. Core components: informational text, "Accept All" and "Reject All" at equal prominence, a preferences panel, and a link to the cookie or privacy policy. EDPB, CNIL, and ICO guidance ban dark patterns — buried "Reject All" buttons, pre-ticked toggles, and cookies firing before any interaction. California's model differs — a "Do Not Sell or Share" link plus GPC honoring replaces the EU-style banner.

Privacy Policy

Data Governance
P

A privacy policy is the public-facing document that tells users how a business collects, uses, shares, and protects their personal data. Under GDPR Articles 13 and 14, it must disclose the controller's identity, purposes, lawful basis, recipients, retention periods, and data subject rights. Under CCPA/CPRA §1798.130, it must also list categories of PI collected, sold/shared, and California residents' opt-out mechanisms. It should link from every page footer and the cookie banner, and be updated whenever processing materially changes. A privacy policy is distinct from a privacy notice (just-in-time at collection) and terms of service (a contract).

Data Processing Agreement

Data Governance
D

A Data Processing Agreement (DPA) — also called a Data Processing Addendum — is the GDPR Article 28 contract between a data controller and a data processor handling personal data on its behalf. Article 28(3) requires the processor to act only on documented instructions, apply Article 32 security measures, assist with data subject rights and breach notifications, delete or return data at the end of the contract, and use sub-processors only with permission. Where processing involves international transfers, the DPA typically includes Standard Contractual Clauses (SCCs). Note: "DPA" also stands for Data Protection Authority — different concept, same acronym.

Data Controller

Data Governance
D

A data controller is the entity — person, company, or public authority — that determines the purposes and means of processing personal data. It's defined in GDPR Article 4(7), distinct from a data processor (Article 4(8)) who processes data on the controller's behalf. Controllers carry primary accountability under GDPR: choosing a lawful basis (Article 6), providing transparency notices (Articles 13-14), fulfilling data subject rights, notifying breaches within 72 hours, and appointing a DPO where required. Contract labels don't decide the role — regulators look at who actually decides the purposes and means. Two or more parties can be joint controllers under Article 26.

IAB TCF (Transparency and Consent Framework)

Data Governance
I

The IAB Europe Transparency and Consent Framework (TCF) is the technical standard for passing user consent across programmatic advertising. Current version: TCF v2.3, mandatory since November 2023. It uses a TC String — a Base64-encoded consent signal sent with every bid request — plus the Global Vendor List (GVL) registering vendors and their declared purposes. Publishers monetising EU/EEA traffic through IAB-integrated ad tech need a TCF-registered CMP. v2.3 tightened rules after the Belgian DPA's 2022 GDPR ruling — disclosed vendors are mandatory, and legitimate interest is no longer allowed for purposes 1-6. TCF signals consent — it doesn't create legal compliance by itself.

Consent Mode v2

Data Governance
C

Google Consent Mode v2 is Google's framework for adjusting how Google Ads, GA4, and other services behave based on user consent. Mandatory for EEA, UK, and Swiss traffic since March 2024 for anyone using remarketing or conversion measurement. It uses four parameters — ad_storage, analytics_storage, ad_user_data, ad_personalization — in Basic mode (tags don't fire until consent) or Advanced mode (tags fire but send cookieless pings when denied, enabling conversion modelling). Consent Mode v2 doesn't replace GDPR consent — it only adjusts what Google does with the consent signal you send. Setting parameters to "granted" by default is a common compliance failure.

Consent Management Platform (CMP)

Data Governance
C

A Consent Management Platform (CMP) is software — SaaS or self-hosted — that captures, records, and enforces user consent for cookies and tracking on a website. Core functions: displays the cookie banner, blocks non-essential scripts until consent is given, stores audit-ready consent logs for GDPR Article 7(1), and passes signals to Google Consent Mode v2 and IAB TCF. Well-configured CMPs also detect the visitor's region and adapt the banner — opt-in for GDPR, opt-out for CCPA. Enterprise players include OneTrust, Didomi, Usercentrics; SMB-focused include Cookiebot, Termly, ConsentBit. No law explicitly requires a CMP, but compliance at scale without one is effectively impossible.

Legitimate Interest

Consent & Rights
L

Legitimate interest is a GDPR Article 6(1)(f) lawful basis for processing personal data without consent. It requires a three-part test: the controller has a real business interest, the processing is necessary to achieve it, and that interest isn't overridden by the data subject's rights. It has to be documented in a Legitimate Interest Assessment (LIA), and data subjects retain the Article 21 right to object. Recital 47 explicitly recognises direct marketing as a possible legitimate interest. But there's a critical limit: for non-essential cookies, ePrivacy Article 5(3) is lex specialis — consent is required, and legitimate interest can't replace it.

Global Privacy Control (GPC)

Consent & Rights
G

Global Privacy Control (GPC) is a browser-level signal that automatically tells every website the visitor wants to opt out of data sale, sharing, and targeted advertising. Developed by an EFF-led consortium in 2020, it replaces clicking "Do Not Sell" on every site. Under CCPA/CPRA, businesses must honor GPC as a valid opt-out. Sephora's $1.2 million settlement (2022) was the first major enforcement for ignoring it. Colorado, Connecticut, and other states require the same. Brave and Firefox ship it by default; Chrome and Safari don't. The EU hasn't formally recognized GPC as consent.

Cookie Wall

Consent & Rights
C

A cookie wall is a design pattern that blocks access to a website unless the user "accepts" cookies — sometimes offered as a binary "accept or pay" choice. Under the GDPR's freely-given-consent standard (Article 4(11), Recital 32), most cookie walls fail: if the user has no genuine alternative, the consent isn't valid. EDPB Guidelines 5/2020 and Opinion 08/2024 make this explicit — including for large platforms running pay-or-consent models like Meta's Facebook/Instagram. Austria's DPA has ruled cookie walls unlawful outright. A "soft wall" offering an equivalent free alternative can be lawful, but pure blockers typically aren't.

Opt-Out / Do Not Sell

Consent & Rights
O

Opt-out is the default-allowed model used under CCPA/CPRA and other US state privacy laws: businesses can collect and process personal information unless the user actively opts out. California requires the mandatory "Do Not Sell or Share My Personal Information" link on every regulated site, plus a "Limit the Use of My Sensitive Personal Information" option under CPRA. Businesses must also honor Global Privacy Control (GPC) as a valid universal opt-out signal. Similar frameworks apply in Colorado (CPA), Virginia (VCDPA), Connecticut (CTDPA), and others. Under GDPR, opt-out is not enough for non-essential cookies — Europe uses opt-in.

Opt-In Consent

Consent & Rights
O

Opt-in consent is the affirmative model where a user must actively agree — through a clear, deliberate action — before data collection or processing begins. Under GDPR Article 4(11) and Recital 32, consent must be freely given, specific, informed, and unambiguous, expressed by a positive act. Pre-ticked boxes, silence, inactivity, and continued scrolling don't count. It's the default model under GDPR and ePrivacy for all non-essential cookies, marketing tracking, and profiling. Contrast with opt-out (CCPA), where processing is allowed until the user says no. Opt-in also requires the option to withdraw consent as easily as it was given — Article 7(3).

Strictly Necessary Cookies

Tracking Tech
S

Strictly necessary cookies are the narrow category exempt from prior consent under ePrivacy Article 5(3) — cookies essential to deliver a service the user explicitly asked for. Typical examples: session IDs, authentication tokens, load-balancing cookies, CSRF tokens, shopping cart contents, and the cookie consent state itself. The ICO and EDPB apply the test narrowly: analytics, marketing, personalization, chatbot, embedded video, and social media cookies do not qualify — even if the site couldn't function "as well" without them. Convenience is not necessity. Under CCPA, strictly necessary cookies are still personal information but usually don't trigger sale-or-sharing opt-out unless the data is shared.

Marketing Cookies

Tracking Tech
M

Marketing cookies — also called advertising, targeting, or retargeting cookies — track visitors across sites to build ad profiles, retarget them, and measure campaign performance. Named examples: Meta's _fbp and fr, Google Ads' IDE and _gcl_au, LinkedIn's bcookie, plus TikTok, Twitter, and Pinterest tags. They always require opt-in consent under GDPR and ePrivacy Article 5(3) — never strictly necessary. Under CCPA and CPRA, sharing marketing cookie data with ad networks typically counts as "sale" or "sharing," triggering opt-out rights and GPC honoring. Marketing cookies are the number one target of CNIL, Garante, and ICO enforcement actions for pre-consent firing.

Functional Cookies

Tracking Tech
F

Functional cookies support non-essential website features beyond basic operation — remembering user preferences, chatbot state, embedded video settings, social sharing widgets. They cover a broader category that often includes customization cookies (user-chosen settings like language and theme) as a sub-type. Under GDPR and ePrivacy Article 5(3), functional cookies generally need opt-in consent — the ICO and EDPB take a narrow view of strictly necessary, and "improves user experience" isn't enough. A common misclassification is treating chatbot or personalization cookies as functional-and-therefore-necessary. Under CCPA, functional cookie data usually stays out of the sale/sharing definition unless shared with third parties.

Session Cookie

Tracking Tech
S

A session cookie is a temporary cookie stored only in browser memory and deleted when the browser closes. It has no Expires or Max-Age attribute — that's what distinguishes it from a persistent cookie. Typical uses: shopping cart contents, login state during a visit, CSRF tokens, and multi-step form data. Session cookies are usually strictly necessary under GDPR and ePrivacy Article 5(3), so they're exempt from consent — but only when used purely for the user-requested function. A session cookie used for analytics or profiling loses the exemption and needs consent. Security best practice: pair with HttpOnly, Secure, and SameSite attributes.

Third-Party Cookies

Tracking Tech
T

A third-party cookie is set by a domain different from the one in the browser's address bar — typically loaded via an embedded ad, iframe, script, or social widget. Common examples: IDE and _gcl_au from Google Ads, _fbp and fr from Meta, bcookie from LinkedIn. They're the backbone of cross-site retargeting, ad measurement, and social embeds. Under GDPR and ePrivacy Article 5(3), third-party cookies always require opt-in consent — they're never strictly necessary. Safari's ITP and Firefox's Total Cookie Protection block or partition them by default. Chrome's Privacy Sandbox is still phasing them out in 2026 — deprecation is partial, not complete.

ePrivacy Directive

Privacy Laws
E

The ePrivacy Directive (2002/58/EC) is the EU's sector-specific law on privacy and electronic communications — often called "the cookie law." Its Article 5(3) is the reason cookie banners exist: it requires prior consent before any information is stored on, or accessed from, a user's device — cookies, pixels, fingerprinting — unless strictly necessary to deliver the requested service. It predates the GDPR and works alongside it as lex specialis for device access. Legitimate interest under GDPR can't override the ePrivacy consent rule. The long-awaited ePrivacy Regulation was meant to replace it but remains unadopted in 2026 — Member States apply their national implementations.

CCPA (California Consumer Privacy Act)

Privacy Laws
C

The California Consumer Privacy Act (CCPA) is California's baseline privacy law, in force since January 2020 and expanded by the CPRA from January 2023. It applies to for-profit businesses in California that meet one threshold: $25M+ revenue, PI from 100,000+ California consumers, or 50%+ revenue from selling or sharing PI. Consumers have rights to know, delete, correct, opt out of sale and sharing, and limit use of sensitive personal information. The California Privacy Protection Agency (CPPA) and Attorney General enforce it — up to $2,500 per violation, $7,500 for intentional or minors' cases, plus $100–$750 per consumer for breaches.

GDPR (General Data Protection Regulation)

Privacy Laws
G

The General Data Protection Regulation (GDPR) is EU Regulation 2016/679, in force since May 2018. It governs how organisations process the personal data of individuals in the EU and EEA — including non-EU businesses that target or monitor EU residents. GDPR sets out six lawful bases for processing and grants a set of enforceable data subject rights including access, erasure, portability, and objection. Fines run in two tiers: up to €10 million or 2% of global turnover, and €20 million or 4% for breaches of core principles or rights. National data protection authorities enforce it, coordinated by the EDPB.

Default Cookie Settings

Consent & Rights
D

Default cookie settings can mean two things. Browser-level: what Chrome, Safari, and Brave allow out of the box — Chrome still permits third-party cookies in 2026, while Safari and Brave block them. Site-level: what a consent banner pre-selects before the user chooses. Under GDPR Recital 32, pre-ticked boxes don't count as consent — the EDPB requires non-essential cookies off by default until the user actively opts in. CNIL and the ICO have fined sites where "Reject All" is buried or analytics tags fire before consent. CCPA flips this: the default is allowed unless the user opts out, including via Global Privacy Control.

Third-Party Data

Data Governance
T

Third-party data is personal or behavioural data collected by an entity with no direct relationship to the individual, then sold or licensed for targeting, lookalikes, or B2B enrichment. Common sources include data brokers like Acxiom, Experian, and LiveRamp. It contrasts with first-party data (collected directly from your visitors) and zero-party data (explicitly shared by the user). The category has collapsed in 2024-2026 — Chrome's cookie deprecation, Apple ATT, and GDPR consent pushed brands toward first-party strategies and data clean rooms like Snowflake and InfoSum. Under GDPR, third-party data still needs a lawful basis; under CCPA, sharing it usually triggers opt-out rights.

Personalization Cookies

Tracking Tech
P

Personalization cookies store behaviour, history, and inferred preferences to tailor the content, recommendations, or experience a visitor sees — recommended products, "people who watched this also liked," personalised homepage layouts. They're distinct from customization cookies: customization stores settings the user explicitly chose (language, theme), while personalization is derived from behaviour. Under GDPR and ePrivacy, personalization cookies are not strictly necessary and require opt-in consent before firing. The EDPB is clear: "improves UX" doesn't make behavioural profiling exempt. Under CCPA and CPRA, when personalization uses cross-context data, it can count as targeted advertising — meaning opt-out rights and honoring GPC signals.

First-Party Cookie

Tracking Tech
F

A first-party cookie is set by the same domain shown in the browser's address bar — used for session management, authentication, preferences, shopping carts, and first-party analytics. Google Analytics' _ga is first-party — even though Google processes the data, the cookie itself is scoped to your domain. Third-party cookies are set by a different domain — an ad network or embed. First-party doesn't mean exempt from consent. Under GDPR and ePrivacy, a first-party analytics or marketing cookie still needs opt-in consent before firing — only "strictly necessary" cookies are exempt. Safari's ITP caps JavaScript-set first-party cookies at around 7 days, whatever the expiry.

Customization Cookies

Tracking Tech
C

Customization cookies store user-chosen preferences like language, region, currency, theme, font size, or accessibility settings, so the site remembers them across pages and visits. Common examples include lang, _locale, theme, and currency. Vocabulary varies: most CMPs treat customization as a sub-type of "functionality cookies," alongside "personalization cookies" (which involve broader behavioural data). Under GDPR and ePrivacy Article 5(3), customization cookies are exempt from consent if the preference was actively chosen by the user and the cookie only delivers that choice. If the preference is inferred or used for profiling, opt-in consent is required. CCPA treats them as opt-out, lower risk.

Unauthorised Disclosure

Data Governance
U

Unauthorised disclosure is when personal data is shared or made available to someone who has no lawful basis to receive it. Under GDPR Article 4(12), it's one form of personal data breach — alongside accidental loss, destruction, or unauthorised access. The most common cause isn't hackers; it's a misaddressed email, a reply-all to a mailing list, or an S3 bucket left on "anyone with the link." If the disclosure risks people's rights, Article 33 requires notifying the supervisory authority within 72 hours of becoming aware — not of when it happened — and Article 34 adds notification to affected individuals where the risk is high.

Data Protection Authority (DPA)

Privacy Laws
D

A Data Protection Authority (DPA) is an independent public body that enforces data protection law in a given jurisdiction — what GDPR Article 51 formally calls a "supervisory authority." Each EU member state has at least one: France's CNIL, Italy's Garante, Spain's AEPD, Ireland's DPC. Germany has 17. Major non-EU regulators include the UK's ICO, California's CPPA, Australia's OAIC, and Brazil's ANPD. DPAs investigate complaints, audit organisations, issue binding decisions, and fine up to €20 million or 4% of global turnover. One catch: "DPA" also stands for Data Processing Agreement — the Article 28 contract between controller and processor.

Disclaimer

Privacy Laws
D

A disclaimer is a statement that limits a publisher's liability or warns visitors about how to rely on a website's content, products, or services. Common types include no-guarantee, professional advice (medical, legal, financial), affiliate, copyright and fair use, and — increasingly — AI-generated content disclaimers. Placement matters: clickwrap acceptance is strongest, a dedicated page or terms of service is solid, a footer link is weakest. Disclaimers can shield against ordinary negligence, but they can't disclaim fraud, gross negligence, or statutory consumer protections under the UK Consumer Rights Act or US FTC rules. A copy-paste boilerplate from a similar site rarely holds up.

Subject Access Request (SAR)

Consent & Rights
S

A subject access request (SAR) is a request to see what personal data an organisation holds about you under UK GDPR Article 15. The response must include a copy of the data plus information on purposes, recipients, retention, and automated decisions. The ICO requires a reply within one calendar month, extendable by two for complex requests. The first copy is free; refusal or a fee is only allowed for manifestly unfounded or excessive requests — and the ICO sets that bar high. SARs are common in UK employment disputes. Failures can attract ICO fines up to £17.5 million or 4% of global turnover.

Data Retention Policy

Data Governance
D

A data retention policy is the documented set of rules that defines how long an organisation keeps each category of personal data and what happens at the end — deletion, anonymisation, or archival. It's how organisations meet the GDPR Article 5(1)(e) storage limitation principle: personal data can't be kept longer than necessary for the purpose. A working policy covers categories separately: customer records, employee data, financial records tied to tax law, marketing data, and consent logs (CNIL benchmarks ~5–6 years for proof of consent). The common failure isn't writing the policy — it's enforcing it across legacy systems, backups, and third-party processors.

Cookie Consent

Consent & Rights
C

Cookie consent is the explicit permission a website visitor gives before cookies andsimilar tracking technologies — pixels, fingerprinting scripts, tracking links — canstore or access information on their device. Under the GDPR, the ePrivacy Directive,and laws like the CPRA, that consent must be freely given, specific, informed, andunambiguous through a clear affirmative action.Pre-ticked boxes, scrolling, and "Accept All" walls don't count. A working cookieconsent setup does three things at once: blocks non-essential trackers until the visitorchooses, logs each decision as proof of compliance, and lets people withdraw consentas easily as they gave it.‍

Google Analytics Cookies GDPR

Tracking Tech
G

Google Analytics cookies like _ga, _gid, and _gat aren't GDPR-compliant by default.They count as personal data because the identifiers can single out users, and sincethey're not strictly necessary, GA needs opt-in consent before the script fires. A propersetup has three pieces: a consent tool that blocks GA until the visitor accepts, a DataProcessing Amendment signed with Google, and reliance on the EU-US Data PrivacyFramework for transfers to US servers. Google Consent Mode v2 helps by adjustingGA's behaviour when consent is denied, but it doesn't replace any of those threepieces.‍

Cookies and Pixels

Tracking Tech
C

Cookies and pixels are the two most common website tracking technologies, oftentreated as interchangeable. A cookie is a small text file stored in the visitor's browser,like Google Analytics' _ga. A pixel is a 1x1 invisible image or HTML snippet that firesa server request on page load and often plants a cookie via the Set-Cookie header —like the Meta Pixel. Under ePrivacy Article 5(3) and EDPB 2023/2024 guidelines, bothrequire prior consent — pixels aren't exempt just because they don't store data on thedevice. Most cookie banners disclose cookies but ignore pixels — a gap CNIL hasstarted fining for.‍

Persistent Cookies

Tracking Tech
P

Persistent cookies stay on a visitor's device after the browser closes, with an explicitexpiry set through the Expires or Max-Age attribute. Lifespans range from days totwo years — Google Analytics' _ga defaults to two years; a "remember me" tokenmight last 30. Persistent doesn't mean tracking: a first-party cookie storing a languagepreference is fine; a third-party ad cookie following you across sites isn't. Under GDPRand ePrivacy, persistent cookies need opt-in consent unless strictly necessary, andCNIL caps consent validity at 13 months. Safari's ITP further caps first-party persistentcookies at 7 days, whatever expiry you set.‍

Data Minimisation

Data Governance
D

Data minimisation is the GDPR Article 5(1)(c) principle that personal data must beadequate, relevant, and limited to what is necessary for the stated purpose. Everyfield a business collects has to pass that three-part test. Verifying a user is over 18?Ask for age confirmation, not a date of birth. Newsletter signup? Email is enough — aphone number is excess. Data minimisation pairs with purpose limitation and storagelimitation: collect for a defined reason, keep only what you need, delete when done.The 2026 EDPB AI guidelines apply the same logic to model training.‍

What is DPO

Privacy Laws
D

A Data Protection Officer (DPO) is the independent expert who oversees anorganisation's GDPR compliance — advising on data practices, running DPIAs, andacting as the contact point for data subjects and regulators. Under GDPR Article 37, aDPO is mandatory only when an organisation is a public authority, conducts large-scale systematic monitoring, or processes special category or criminal data at scale.The DPO can be internal or outsourced but must report to top management; a CTO ormarketing head can't double up without a conflict of interest. Non-appointment risksfines up to €10 million or 2% of global turnover. CCPA and CPRA don't require one.‍

What is DSAR

Consent & Rights
D

A Data Subject Access Request (DSAR) is a formal request from an individual askingan organisation to confirm whether it's processing their personal data and, if so,provide a copy plus supplementary information — purposes, recipients, retention,source, and any automated decision-making. Under GDPR Article 15, organisationsmust verify identity and respond within one calendar month — free of charge unlessthe request is manifestly unfounded or excessive — with up to two months' extensionfor complex requests. Under CCPA, the parallel "right to know" has 45 days, twiceyearly. DSARs are distinct from deletion (Article 17) or portability (Article 20)requests.‍

No Guarantee Disclaimer

Privacy Laws
N

A No Guarantee Disclaimer is a notice on a website telling visitors that the publisherdoesn't promise the content is accurate, complete, or reliable, and that they use it attheir own risk. It usually appears in the footer, inside the terms of service, or at thetop of high-risk articles — things like health, finance, legal advice, or AI-generatedcontent. The disclaimer can protect against ordinary negligence claims, but it can'tshield against fraud, gross negligence, or statutory consumer protections. It worksbest when accepted through a clickwrap step; a quiet footer notice is the weakestversion.‍

Consent Withdrawal

Consent & Rights
C

Consent withdrawal is the right to revoke previously given consent at any time, withno need to give a reason. It's set out in GDPR Article 7(3). The mechanism to withdrawhas to be as easy as the original opt-in — a one-click preference centre or a persistent"change preferences" button, not a buried link, email request, or login wall.Withdrawal only stops future processing; it doesn't cancel anything done lawfullybefore, and it doesn't automatically delete data — that's a separate right under Article17. Organisations also have to inform users of this right before collecting consent inthe first place.‍

Analytics Cookies

Tracking Tech
A

Analytics cookies record how visitors use a website — pages viewed, session length,click paths, traffic sources, device type — so site owners can measure performanceand improve UX.

Common examples include Google Analytics (_ga, _gid), Matomo, Hotjar, andMixpanel, with lifespans from a single session up to two years. Under the GDPR andePrivacy Directive, analytics cookies aren't strictly necessary, so they need opt-inconsent before firing — even first-party ones — unless they fall under the narrowCNIL/ICO exemption for fully anonymised, non-shared analytics. CCPA uses an opt-outmodel, and Google Consent Mode v2 keeps analytics_storage denied until thevisitor approves.‍

Image

Ready to Make Your Webflow Website Privacy-Compliant? Get Started Now!

Get compliant