Use when requests involve cookie banners, consent flows, analytics or marketing tracker gating, consent records, or basic privacy-by-design decisions around user tracking and preferences. Design privacy-conscious consent and cookie handling basics for websites and applications: tracker classification, consent-required versus essential processing, consent UX, preference storage, withdrawal, and policy alignment.
Consent handling should be deliberate, minimal, and easy to understand. Prefer clear classification of trackers and processing purposes so teams only ask for consent when needed, respect user choices consistently, and keep policy text aligned with actual behavior.
| Situation | Action |
|---|---|
| Storage or tracking is strictly necessary for a requested core function | Handle it separately from optional consent categories and explain it clearly. |
| Script supports analytics, advertising, personalization, or third-party profiling | Default to consent-gated treatment unless strong policy guidance says otherwise. |
| One vendor serves multiple purposes | Split enforcement by purpose where possible rather than bundling everything together. |
| Consent experience makes refusal materially harder than acceptance | Rework the UX to avoid manipulative choice architecture. |
| A new tag or embed is added without documented purpose and controls | Treat rollout as incomplete until classification and enforcement are defined. |
references/consent-playbook.mdreferences/consent-checklist.md