5 min read
Cookies and consent banners
What the banner is really asking, why 'legitimate interest' is doing so much work, and what happens when you close it.
Not all cookies are the same
A first-party cookie is set by the site you are on. It keeps you signed in and remembers your basket. A third-party cookie is set by someone else whose code the site loaded, and its purpose is usually to recognise you on other sites too.
Consent rules exist because of the second kind. Most modern browsers now block third-party cookies outright, which is why the industry has moved on to fingerprinting and to first-party identifiers passed to partners behind the scenes.
Reading the banner properly
A compliant banner has to make refusing as easy as accepting. If the reject button is hidden behind a second screen, the banner is already outside the rules in most of Europe.
- ✦Accept all: turns on every purpose, usually including hundreds of partners
- ✦Reject all: should leave only what is strictly necessary to run the site
- ✦Manage preferences: where the real list lives, often with pre-ticked 'legitimate interest' toggles
- ✦Closing with the X: legally should count as refusal, and often does not
The legitimate interest loophole
Many banners present a second set of switches labelled legitimate interest, already on. The argument is that certain processing does not need consent. Regulators have repeatedly rejected that argument for advertising, and enforcement is slowly catching up, but the switches remain widespread.
If you only do one thing, open the preferences screen and turn off the legitimate interest column as well.
Making it stop being a chore
Deciding once, at the browser level, beats deciding on every site.
- ✦Enable Global Privacy Control, which sites in several jurisdictions must honour
- ✦Use a blocker that auto-refuses banners rather than auto-accepting them
- ✦Clear site data on close for sites you do not sign in to
See these techniques run against your own browser, live.
Take the reading