cloud background image
services

Cookie Consent Setup
Made Easy

Cookie consent banners built for compliance, performance, and user trust, implemented directly into your Webflow site.

Make Your Website Compliant

What proper cookie consent setup looks like

A compliant Webflow cookie consent setup includes seven elements:

01
Cookie audit
A full cookie audit that catalogs every script, pixel, and cookie currently triggering on your site.
02
Consent categorization
Strictly necessary, functional, analytics, and marketing, with each cookie mapped to its category individually
03
Script blocking
A consent banner that blocks non-essential scripts until the user actively opts in (no pre-ticked boxes, no implied consent).
04
Granular controls
Granular preferences so users can accept some categories and reject others.
05
Consent log
A consent log that records what each visitor agreed to, when, and from which region.
06
Geographic logic
We refine CMS structures and internal logic to simplify content management, making it easier for your team to update the site without breaking the build.
07
Workflow optimization
We refine CMS structures and internal logic to simplify content management, making it easier for your team to update the site without breaking the build.
cloud background image

What's included in our cookie consent setup?

Every cookie consent setup we deliver includes:
Full cookie audit
Full cookie audit of your existing Webflow site, including third-party scripts, embeds, and CMS integrations.
Custom-designed banner
Built to match your brand system, typography, and color palette.
CMP integration
CMP integration with Cookiebot, configured for your site's specific cookie inventory and traffic profile.
Consent Mode setup
Google Consent Mode v2 and Microsoft UET Consent Mode setup so GA4, Google Ads, and Microsoft Ads continue to function compliantly.
Geographic detection
Geographic detection with region-specific consent logic across GDPR, CCPA/CPRA, VCDPA, LGPD, and POPIA.
Multi-language support
Multi-language banner with auto-translation across 47+ languages (when serving global markets).
Accessibility compliance
Accessibility compliance with WCAG 2.2 and WAI-ARIA standards.
Cookie policy page
Drafted to match your actual cookie inventory.
Consent log handoff
Full consent records delivered to your DPO or legal counsel in a usable format.
Recorded one-on-one training
A dedicated session covering how to manage consent settings, update the CMP, and handle cookie changes post-launch.
30 days of complimentary support
Direct access to our team after launch for questions, fixes, and adjustments.
cloud background image
how we work

How we implement cookie consent on Webflow?

Webflow has no native cookie consent feature, which is why most setups are fragile. Our approach uses Webflow's Before </body> tag custom code field for the consent script, Webflow's CMS for cookie descriptions, and server-side geographic detection where needed. The implementation:

Script Installation & Pre-Consent Control

We install the Cookiebot script in your site's global custom code, scoped to fire before any tracking script.

Consent Mode Configuration

We rewrite your existing GTM container to use Google Consent Mode v2 and Microsoft UET Consent Mode, so tags only fire after consent and your ad platform data stays accurate.

Cookie Classification & Mapping

We map every cookie on your site to the correct category in the Cookiebot dashboard.

Regional Compliance Testing

We test the banner across regions using VPN simulation to verify GDPR, CCPA, and LGPD logic all trigger correctly.

Handover & Documentation

We hand over the entire setup with documentation, a 30-day support window, and a recorded training session.

Timeline

Our process

Week 1
Week 2
Week 3
Week 1

Audit and planning

We scan your site, document every cookie, identify compliance gaps, and map out the Cookiebot configuration tailored to your stack and regional exposure.

Week 2

Implementation

We design and build the banner, integrate the CMP, configure Google Consent Mode v2, and set up geographic logic.

Week 3

Testing and handoff

We test across regions, deliver documentation, run a recorded training session with your team, and hand over all code and credentials.

Timeline
Typically 2 to 3 weeks.
Pricing
Pricing is project-based with a 50/50 split, half on signed proposal, half on launch.
cloud background image

Why we partnered with Cookiebot?

Google-certified, ad platform compliant

Cookiebot is a Google-certified CMP with full support for Google Consent Mode v2 and Microsoft UET Consent Mode. Google now requires Consent Mode v2 for ads personalization, remarketing, and analytics in the EU, EEA, and Switzerland, without it, your Google Ads and GA4 data degrade. Cookiebot also supports the IAB TCF v2.3 framework, required if you work with programmatic ad networks.

Google-certified, ad platform compliant

Patented cookie scanner

Cookiebot detects 63% more data processing services and trackers than any other CMP on the market, backed by a continuously updated repository of 13,000+ known cookies. Your site gets scanned automatically every month, so newly added scripts don't silently break compliance between your site updates.

Patented cookie scanner

Multi-jurisdiction by default

Pre-built banner templates for GDPR, CCPA/CPRA, VCDPA, LGPD, POPIA, and DMA, with geotargeting that applies the right rules per visitor automatically. Auto-translation across 47+ languages so your SaaS can serve global users without separate banner builds per market.

Multi-jurisdiction by default

Accessibility built in

Native support for WCAG 2.2 and WAI-ARIA standards, plus the Global Privacy Control (GPC) signal — both increasingly important for enterprise procurement reviews and California compliance.

Accessibility built in

Auto-blocking that actually works

Cookiebot's auto-blocking prevents non-essential scripts from firing before consent without requiring you to manually wrap every tag. Combined with auto-categorization, this eliminates the most common compliance failure we audit: tracking scripts firing during the initial banner display.

Auto-blocking that actually works

Direct partner support

As an official partner, we get escalated support, early access to platform updates, and partner pricing we pass through to clients.

Direct partner support
cloud background image

GDPR, CCPA, and the regulations your cookie banner needs to cover

Different markets, different rules. A company selling globally needs a single banner that satisfies all of them.

GDPR (European Union and UK)

Applies to any company processing data from EU or UK residents, regardless of where the company is based. Requires explicit opt-in for non-essential cookies, clear language explaining what each cookie does, the ability to withdraw consent as easily as it was given, and a record of consent. Fines start at €10 million or 2% of global annual revenue, whichever is higher.

CCPA, CPRA, and VCDPA (California, Virginia, and other US states)

CCPA and CPRA apply to companies doing business in California with $25M+ revenue, 100K+ consumers, or 50%+ revenue from selling personal data. Requires a "Do Not Sell or Share My Personal Information" link and recognition of the Global Privacy Control signal. Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, Utah's UCPA, and Texas's DPSA layer similar opt-out and disclosure requirements. Civil penalties under CCPA run up to $7,500 per intentional violation.

LGPD (Brazil)

Mirrors GDPR's structure with Brazilian enforcement. Required for any company processing data from Brazilian residents.

POPIA (South Africa)

Comparable consent and accountability requirements to GDPR, with administrative fines up to R10 million.

DMA (EU Digital Markets Act)

Affects how "gatekeeper" platforms like Google and Meta handle user data. Your CMP needs to send proper consent signals so your ad accounts continue to operate compliantly in the EU.

cloud background image

Working with us

Tamara TeofanovicTamara Teofanovic
As the only B2B marketer on my team, I'm responsible for a lot of things — and not having to worry about the website has made my life so much easier.
Sean NolanSean Nolan
Instead of filling out a standard contact form, most clients now head straight to the calculator to get an instant estimate delivered to their inbox. From a commercial perspective, it's been absolutely invaluable.
Geoff McQueenGeoff McQueen
Some of the best operators I've ever worked with — and I've been building websites for almost thirty years.
Will SmithWill Smith
Hesitant to do this testimonial because I don't want anybody to fill up his calendar. But I can't recommend Hunor highly enough.
cloud background image

Frequently asked questions

Do I really need a cookie consent banner if I'm a US-only SaaS?

If you have any EU visitors at all, yes. GDPR applies based on the user's location, not your company's. If you're California-only and over the CCPA thresholds, you need at minimum a "Do Not Sell or Share" link and Global Privacy Control support.

Can't I just use a free Webflow cookie banner template?

Free templates almost always fire tracking scripts before consent, which is the exact behavior GDPR penalizes. They also rarely support granular consent or consent logging.

Will the banner slow down my site?

A properly implemented banner adds less than 50ms to page load. We host the consent script asynchronously and defer all non-essential scripts until consent is granted, which often improves overall page speed compared to firing all tracking on load.

What happens if regulations change?

We follow updates from the European Data Protection Board, the California Privacy Protection Agency, and other major regulators. For active clients, we flag material changes and quote the work needed to stay compliant. For past clients, we offer compliance refreshes as a separate engagement.

Will this affect my Google Ads or GA4 data?

The opposite, it protects it. Google now requires Consent Mode v2 for ads personalization, remarketing, and analytics in the EU, EEA, and Switzerland. Without it, your conversion tracking degrades and remarketing audiences shrink. Cookiebot is a Google-certified CMP with native Consent Mode v2 support, and we configure it during setup so your ad platforms keep receiving the modeled data they need.

Is the cookie banner accessible?

Yes. Cookiebot supports WCAG 2.2 and WAI-ARIA standards out of the box, which we verify during testing. This matters for enterprise procurement reviews and is increasingly a regulatory requirement in itself, the EU's European Accessibility Act took effect in June 2025.

Can you migrate an existing cookie consent setup to Cookiebot?

Yes. Migrations from Termly, OneTrust, Iubenda, and custom-built banners to Cookiebot are a common engagement, usually triggered by cost, compliance gaps, or a CMP that doesn't scale. We handle the full migration including consent log preservation where the source platform supports export.

Is cookie consent the same as a privacy policy?

No. A privacy policy is a written document explaining what data you collect and how you use it. Cookie consent is the technical mechanism that asks users to opt in to specific cookie categories before tracking begins. You need both.