Cookies, consent, and the pages you need
The rule most commonly enforced, and the simplest way to avoid it entirely.
Consent comes before the cookie
Under GDPR, non-essential cookies require consent BEFORE they are set. A banner that appears while the analytics cookie is already stored does not satisfy that, and it is the most commonly enforced rule in this area.
It applies to you if you have European visitors, regardless of where you are based.
The way to make this problem disappear
Switch to cookieless analytics — Plausible, Fathom, or Umami. They set no identifying cookies, so they need no consent banner at all. You remove the compliance question rather than managing it, and you get a faster page.
If you keep a cookie-based tool: do not load its script on first visit, offer a reject option as easy to click as accept, store the choice, and allow withdrawal.
Session replay deserves its own decision
Session replay captures mouse movement, clicks, and — unless explicitly configured otherwise — what visitors type. A default configuration can record passwords and card numbers and send them to a third party.
Mask all inputs by default and opt harmless ones in, never the reverse. Exclude every page with a password field or payment form. Set the shortest retention the tool allows, and name the tool in your privacy policy.
The pages
A privacy policy is required almost everywhere once you process personal data, and analytics counts. It is also required by Google, Meta and Apple in their own terms, so this can cost you an ad account as well as a fine.
Say what you collect, why, who you share it with by name, how long you keep it, and how someone gets their data deleted. Do not paste a template with the wrong company details in it — that is worse than nothing, because it is demonstrably untrue.
Not sure whether this applies to you?
Give us the address and we will tell you. No code, no access, no install — and every finding we have is shown in full, including on the free trial.
Check a site