Коротко
- For non-essential cookies (analytics, marketing, personalisation) in the EU, prior opt-in consent is usually required.
- Consent: freely given, specific, informed, unambiguous; withdrawal — as easy as giving it.
- Pre-ticked boxes, «continuing browsing = consent», Accept without an equivalent Reject — are invalid.
- On a ClikBy redirect: pixel_notification + Reject → pixels do not fire; align with the CMP on the site.
Not legal advice
Cookie consent practice for sites and smart links. The ePrivacy Directive / PECR and national acts clarify details — check with the DPA of your audience.
A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → GDPR. Not legal advice and not a verbatim translation.
Conditions for valid consent (Art. 4/7)
- Freely given — without coercion; you cannot do «consent or the service is unavailable» if the data is not strictly needed for the service.
- Specific — separately by purpose (analytics ≠ marketing); not one «bag».
- Informed — who collects, why, how long they keep it, rights, how to withdraw.
- Unambiguous — a clear affirmative action (Accept click / category choice).
The controller must be able to prove consent (consent log: who/when/what/policy version). Withdrawal — at any time, without worse UX than giving consent.
Pre-ticked boxes and silence
CJEU Planet49 and DPA guidance: pre-ticked checkboxes do not give valid consent. Silence, page scrolling, «by continuing to use the site…» — is also not consent.
- No pre-checked analytics/marketing;
- No wall where Reject is hidden on step 3 and Accept is one button;
- No bundled consent «all or nothing» without granular choice if purposes differ.
Which cookies are strictly necessary
Strictly necessary / essential — needed for the requested service: login session, cart, load balancing, security, remembering the consent choice. They can usually be set without prior consent (but with information in the cookie policy).
Antifraud/security on infrastructure is sometimes justified by legitimate interest or necessity — that is not a blank check for ad pixels. Do not call a marketing cookie «essential».
Non-essential: analytics, ads, personalisation
Everything that is not strictly necessary for basic operation: Google Analytics, Meta/TikTok/Yandex pixels, retargeting, A/B marketing tags, social plugins with tracking — do not activate before consent.
| Category | Примеры | Before consent |
|---|---|---|
| Essential | session, consent cookie, CSRF | Allowed (with notice) |
| Analytics | GA4, Metrica (if not essential) | Block until Accept |
| Marketing | Meta Pixel, Google Ads tags | Block until Accept |
| Preferences | language/theme, if not critical | Assess; often consent |
In the CookieYes KB: «Which cookies are non-essential / strictly necessary under GDPR?» — GDPR list.
GDPR + ePrivacy / «cookie law»
GDPR regulates personal data; access to terminal equipment (cookies on the device) is additionally covered by the ePrivacy Directive and national laws (PECR in the UK and equivalents). In practice for sites this means: non-essential cookies → prior consent, even if you would like to rely only on LI.
Therefore «we have legitimate interest for analytics» does not cancel the banner if the DPA requires consent for cookies.
Google Analytics, Consent Mode and pixels
- GA4 / ad tags in the EU — after consent or in a limited Consent Mode (if configured correctly);
- «Is Google Analytics GDPR compliant?» — the tool can be used in a compliant way, but responsibility is on the controller (settings, transfers, consent);
- Meta/Google/VK pixels on smart links = third-party processing; describe in the policy and wait for consent;
- Server-side tagging does not automatically remove the transparency/consent duty.
In the ClikBy product there is a gtag Consent Mode link in the /cookies module — check that tags on the site actually read the signal and are not loaded around it.
ClikBy in practice
- Сайт — CMP or the «Cookie notice window» module (/cookies): Accept / Reject / Manage, categories, Consent Mode.
- Link redirect — pixel_notification: Reject → cookie consent{link_id}=0 → pixels do not fire on check.
- Consistency — an EU user refused on the site, but on the short link the pixel fired without a window — a controller conflict.
- Visit data — even without marketing cookies, IP/UA may be personal data; the legal basis and retention — in your policy + instructions to the processor.
In ClikBy for clicks on the client's links: Customer = controller, ClikBy = processor (privacy-policy §1.9). The EU representative in the Policy is Barcelona. Levers: Cookie Consent, pixel_notification on the redirect, a DPA if needed.
FAQ
Is granular consent like in GDPR needed for CCPA?
For CCPA — generally no (opt-out model). For GDPR — yes, for different purposes. Comparison: CCPA vs GDPR.
Is one Accept button enough?
No, if there is no equivalent refuse and non-essential blocking before the choice.
Where else in the KB?
Cards on conditions for consent, essential/non-essential cookies, pre-ticked boxes, GA consent — in CookieYes → GDPR.