GDPR cookie consent
Hold mapped optional tags until a choice allows them, and keep the cookie banner aligned with the preference center.
GDPR
When your counsel decides that consent is the right basis, Consent Guru helps you collect it, record it, and honor a withdrawal.
GDPR consent management is the work of asking for a specific, informed choice before processing that relies on consent, recording that choice, and making withdrawal available. The platform helps run that workflow. It does not decide whether consent is the right lawful basis.
Article 4(11) describes consent as freely given, specific, informed, and unambiguous. A pre-ticked box or a bundle of unrelated purposes fights that definition. Non-essential cookies are often handled under ePrivacy rules that expect a prior choice.
Consent Guru can present those purposes separately, store the consent record, and let the person withdraw from the preference center. That supports a GDPR workflow. It does not complete one.
Step 1
Define optional analytics or advertising apart from what the site needs to function.
Step 2
Publish the notice text and the vendor context you want shown before the choice.
Step 3
Keep the policy version with the decision so you can show what “informed” referred to.
Step 4
Treat withdrawal as a first-class update, then stop optional scripts that depended on the withdrawn purpose.
Hold mapped optional tags until a choice allows them, and keep the cookie banner aligned with the preference center.
Identifier, timestamp, locale, and notice snapshot for the decision you may need to demonstrate.
Do not mark a purpose as consent in the product if you are actually relying on another Article 6 basis.
Access and erasure requests are handled in the rights workflow, not as a cookie toggle.
Publish a consent experience for sites aimed at those visitors, and keep a record.
Map third-party advertising purposes separately from strictly necessary cookies.
When purposes change, publish a new version instead of reusing an old record.
This page is not legal advice and does not cover every GDPR duty. Security, transfers, processor terms, and DPIAs are outside a banner.
Consent Guru helps organizations implement and manage consent-related processes. It does not make a company GDPR compliant.
Under the GDPR, consent is a freely given, specific, informed, and unambiguous indication of agreement to processing for a stated purpose. It must be as easy to withdraw as to give.
A banner can be the interface for a consent choice. It satisfies a duty only if the underlying notice, granularity, record, and withdrawal also meet the standard your counsel applies.
At a minimum, keep who or what identifier you use, when the choice was made, which purposes were covered, and which notice version was shown.
This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.