Compliance

How Consentaur follows the law

This page describes exactly how Consentaur implements the requirements of the GDPR and the ePrivacy Directive. Use it as a reference, and as documentation you can share with your data protection officer, an auditor, a legal adviser or a regulator.

For a general introduction to the rules, read our guide to the cookie rules.

Cookie blocking before consent

The ePrivacy Directive requires that non-essential cookies are only set after active consent. Consentaur implements this by blocking third-party scripts until the visitor has made a choice.

When the Consentaur script loads on your website, this happens:

  1. Scripts assigned to a cookie category (analytics, marketing, preferences) are blocked automatically when the page loads.
  2. The visitor sees a consent banner and can accept all, reject all or choose specific categories.
  3. Only after active consent are the scripts in the chosen categories released.
  4. Necessary cookies (session, security, basic functionality) are never blocked, as they do not require consent.

"Reject all" is always shown on the first layer of the banner, next to "Accept all" and with the same size and look. It cannot be switched off. There are no pre-ticked boxes and no cookie walls.

Collecting consent

Under the GDPR, valid consent must be freely given, specific, informed and unambiguous, and it must be possible to withdraw it. Consentaur supports all five requirements:

Freely given
Visitors can reject all cookies without consequences. "Reject all" is always shown on the first layer of the banner.
Specific
Consent is given per cookie category (analytics, marketing, preferences). Visitors choose exactly what they accept.
Informed
The banner explains what each category covers. Your website can link to a cookie policy with details of every cookie.
Unambiguous
Consent requires an active step (a click). No pre-ticked boxes and no implied consent from continued browsing.
Withdrawable
Visitors can change or withdraw their consent at any time through a cookie settings link that you place on your website, for example in the footer.

Consent records

The GDPR requires you to be able to demonstrate that consent was given. Consentaur logs every consent action with the following data:

What we log:

  • Time of the consent action
  • Which categories were accepted or rejected
  • The action (accept all, reject all, custom choice)
  • Consent version (which vendors and categories the consent covered)
  • Language and device type
  • A random consent ID (see below)

What we do not log:

  • IP addresses
  • User agent strings
  • Cookies or browsing history
  • Referrer data
  • Any directly identifying personal data

Consent ID:The banner creates a random ID in the visitor's browser and keeps it with their choice in the consent cookie. The same ID is sent with every record, so a visitor's decisions can be found and documented. The ID is not derived from the IP address or the browser, and it differs on every website. It is still a pseudonymous ID, so we process the records as personal data under our data processing agreement.

New consent when things change: The banner asks again after 12 months, and when your website gets new vendors or categories of cookies.

Consent records are kept for 24 months and then deleted automatically. On the Growth and Business plans you can view the consent log in your dashboard.

Automatic cookie scanning

To keep the categories accurate, Consentaur scans your website regularly. A scan has three steps:

  1. HTTP scan: We fetch your pages and record cookies from Set-Cookie headers.
  2. Browser scan: We load your website in a headless browser to catch cookies set by JavaScript and third-party scripts.
  3. Categorisation: Cookies found are matched against a database of more than 2,000 known cookies. Cookies that are not recognised are categorised by pattern matching and can be reclassified manually.

Scans run automatically (daily or weekly depending on your plan), and we notify you when new cookies appear.

Google Consent Mode v2

Consentaur supports Google Consent Mode v2 and sends the correct consent signals to Google Analytics and Google Ads automatically. That means you meet Google's requirements for European traffic without configuring anything by hand.

For a technical walkthrough, read our guide to Google Consent Mode v2.

Data storage and processing

  • Consentaur is developed by Uneven Bits ApS, a Danish company based in Copenhagen.
  • Consent records are kept separately for each website, so the visitor ID cannot be used to track visitors across websites.
  • We do not sell consent data or share it with third parties.
  • Consent records are kept for 24 months. If you delete your account, the data is deleted within 30 days.

For a full description of how we process data, see our privacy policy.

What Consentaur does not cover

Consentaur handles the technical implementation of cookie consent. Some parts of GDPR compliance are outside our product:

  • Writing your privacy policy and cookie policy (legal advice)
  • Data processing agreements with your other suppliers
  • Processing of personal data in systems other than cookie consent
  • IAB TCF (not relevant for most small and medium-sized businesses)

We always recommend asking a legal adviser whether your overall data handling meets the law.

Frequently asked questions

Can Consentaur guarantee GDPR compliance?

Consentaur handles the technical side of cookie consent: blocking cookies before consent, consent per category, consent records and automatic scanning. Full GDPR compliance also depends on your privacy policy, your data processing agreements and the rest of your data handling. We always recommend asking a legal adviser about your specific situation.

How long are consent records kept?

Consent records are kept for 24 months and then deleted automatically. If you delete your account, your data is deleted within 30 days unless the law requires us to keep it longer.

Can I show a regulator that visitors consented?

Yes. Consentaur records every consent action on every plan, with the time, the categories chosen and the banner version. On the Growth and Business plans you can view the consent log in your dashboard and use it as evidence.

Does Consentaur support IAB TCF?

No. IAB TCF (Transparency & Consent Framework) is an advertising industry framework for programmatic ad networks, not a legal requirement. It mainly matters for large publishers and ad networks. Most small and medium-sized businesses do not need it: consent collected with Consentaur covers the consent requirements of the GDPR and the ePrivacy Directive.

What happens to consent records if I delete my account?

The data is deleted from our servers within 30 days of account deletion, unless the law requires us to keep it longer.

Ready to get compliant?

Up and running in 5 minutes. The free plan includes consent records and automatic scanning.

Create a free account