Compliance

GDPR cookie compliance with GetCookies

Under the GDPR and the ePrivacy Directive, non-essential cookies may only be set after a visitor gives free, specific, informed and unambiguous consent, and you must be able to prove it. GetCookies handles the technical side of that on your website. It does not replace legal advice or the rest of your GDPR program.

What the rules require, and how GetCookies covers it

  • Prior consent

    Non-essential scripts are blocked until the visitor consents. GetCookies intercepts known trackers and adopts scripts you mark with type="text/plain" and a category attribute.

  • Granular choice

    Visitors can accept or reject by category (for example analytics and marketing), and reject as easily as accept.

  • Proof of consent

    Each decision is stored as a consent log with a timestamp and the categories chosen, which you can view and export from the dashboard. How long logs are kept depends on your plan.

  • Withdrawal

    A floating cookie-settings badge lets visitors reopen their choices and change them at any time.

  • Transparency

    Scans list every detected cookie with its purpose and expiry. On Pro and above you can embed a cookie declaration and publish hosted policy pages built from your scan results.

  • Regional rules

    Geo-targeting (Pro and above) shows GDPR-style opt-in to EU and UK visitors and CCPA-style notices to Californian visitors.

Tools for the rest of your privacy work

  • Data subject requests

    Track access and deletion requests and look up a visitor's consent history when you answer them.

  • Processor overview

    Document the third-party processors your site uses and audit them against your scans.

  • Google Consent Mode v2 and IAB TCF 2.3

    Pass consent signals to Google tags and to ad-tech vendors (Pro and above).

  • Scheduled scans

    Re-scan automatically so new cookies are caught when your site changes (Pro and above).

What GetCookies does not do

GetCookies does not write your records of processing, run DPIAs or assess your vendors. It does not cover consent inside native mobile apps. It generates IAB TCF 2.3 consent strings but is not yet registered with IAB Europe as a CMP. See the full list on the pricing page.

GetCookies as your data processor

When you use GetCookies, Getia AS processes consent records on your behalf. Our processor terms are in the Data Processing Addendum, the providers we use are on the subprocessors page, and our controls are on the security page. Data is hosted in the United States with Standard Contractual Clauses for transfers.

We notify customers before adding new subprocessors. Customers may object and terminate the agreement if an objection cannot be resolved.

Supervisory authority

Getia AS is established in Norway, so our supervisory authority is Datatilsynet, the Norwegian Data Protection Authority (Postboks 458 Sentrum, 0105 Oslo, datatilsynet.no). Data protection questions: [email protected].

Try GetCookies on your own site

Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.

Börja gratis