Knowledge centre

Data protection · high risk

Cookie basics for a first business website

Identify the technologies in use and apply consent and information requirements proportionately.

Reviewed 04/08/2026Version 2

It is about more than visible cookies

The rules can cover technologies that store information on or access information from a person's device, including some pixels, local storage and fingerprinting. Begin with an inventory, not a banner design.

Do this now

  1. Scan and manually review the website before and after making each available choice.
  2. List each technology, provider, purpose, duration and whether it is essential to the service requested.
  3. Prevent non-essential technologies from operating before the required choice has been made.
  4. Offer a clear way to accept, reject and later change non-essential choices.
  5. Explain the technologies in accessible language and keep the cookie information aligned with the privacy notice.
  6. Re-test after adding analytics, video, chat, advertising, booking or social-media tools.

What good looks like

Rejecting is as understandable as accepting, the site still performs essential functions, and observed network or storage behaviour matches the wording. Choices are not manipulated through colour, button size or confusing labels.

Common mistakes

  • Installing a banner while trackers still load immediately.
  • Treating analytics or embedded media as automatically essential.
  • Forgetting technologies added through tag managers or plugins.
  • Publishing a generic list that does not match the site.

When to get help

Get data-protection or technical help for advertising, profiling, extensive analytics, sensitive information or technology you cannot identify or control.

Keep in your roadmap

Save the technology inventory, scan date, consent configuration, notice version and next re-test date.