Compliance
GDPR cookie compliance with GetCookies
Under the GDPR and the ePrivacy Directive, non-essential cookies may only be set after a visitor gives free, specific, informed and unambiguous consent, and you must be able to prove it. GetCookies handles the technical side of that on your website. It does not replace legal advice or the rest of your GDPR program.
What the rules require, and how GetCookies covers it
Prior consent
Non-essential scripts are blocked until the visitor consents. GetCookies intercepts known trackers and adopts scripts you mark with
type="text/plain"and a category attribute.Granular choice
Visitors can accept or reject by category (for example analytics and marketing), and reject as easily as accept.
Proof of consent
Each decision is stored as a consent log with a timestamp and the categories chosen, which you can view and export from the dashboard. How long logs are kept depends on your plan.
Withdrawal
A floating cookie-settings badge lets visitors reopen their choices and change them at any time.
Transparency
Scans list every detected cookie with its purpose and expiry. On Pro and above you can embed a cookie declaration and publish hosted policy pages built from your scan results.
Regional rules
Geo-targeting (Pro and above) shows GDPR-style opt-in to EU and UK visitors and CCPA-style notices to Californian visitors.
Tools for the rest of your privacy work
Data subject requests
Track access and deletion requests and look up a visitor's consent history when you answer them.
Processor overview
Document the third-party processors your site uses and audit them against your scans.
Google Consent Mode v2 and IAB TCF 2.3
Pass consent signals to Google tags and to ad-tech vendors (Pro and above).
Scheduled scans
Re-scan automatically so new cookies are caught when your site changes (Pro and above).
What GetCookies does not do
GetCookies does not write your records of processing, run DPIAs or assess your vendors. It does not cover consent inside native mobile apps. It generates IAB TCF 2.3 consent strings but is not yet registered with IAB Europe as a CMP. See the full list on the pricing page.
GetCookies as your data processor
When you use GetCookies, Getia AS processes consent records on your behalf. Our processor terms are in the Data Processing Addendum, the providers we use are on the subprocessors page, and our controls are on the security page. Data is hosted in the United States with Standard Contractual Clauses for transfers.
We notify customers before adding new subprocessors. Customers may object and terminate the agreement if an objection cannot be resolved.
Supervisory authority
Getia AS is established in Norway, so our supervisory authority is Datatilsynet, the Norwegian Data Protection Authority (Postboks 458 Sentrum, 0105 Oslo, datatilsynet.no). Data protection questions: [email protected].
Try GetCookies on your own site
Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.
Aloita ilmaiseksi