EU law firstGDPR · ePrivacy · EDPB

Consent that holds up, by default.

The ePrivacy Directive requires consent before non-essential cookies or similar technologies are used. The GDPR defines what valid consent is: freely given, specific, informed, unambiguous, provable and as easy to withdraw as to give. ZenoCookieConsent is built around those rules and the way European regulators apply them.

Six principles

What the law asks, and what the software does.

Reject as easy as accept

“Reject all” sits on the first layer next to “Accept all”, with the same size, colour and weight. They share one style rule in the code, so a configuration cannot make one of them less visible.

GDPR Art. 4(11), Art. 7EDPB cookie banner taskforce report (2023)

Prior blocking

Tags marked with data-zeno are inert until their category is granted: scripts do not run, iframes and pixels do not load. Consent comes first, then the cookies.

ePrivacy Directive Art. 5(3)CJEU C-673/17 Planet49

Granular, never pre-ticked

Visitors choose per purpose: functional, analytics, marketing. Every optional category starts switched off; strictly necessary storage is shown as always on and explained.

GDPR Art. 4(11), Recital 32EDPB Guidelines 05/2020

Proof of consent

Each decision is logged as a pseudonymous, append-only receipt with the exact banner revision, language and consent version, so you can show what a visitor saw and chose.

GDPR Art. 7(1)Art. 5(2) accountability

Withdrawal at any time

A persistent cookie button reopens the preferences after the first choice, and Zeno.show() powers your own “Cookie settings” link. Withdrawing takes as few clicks as consenting.

GDPR Art. 7(3)

Data stays on your servers

The banner script, its config and every receipt are served from and stored on infrastructure you control. No consent vendor as processor, no transfer to a third country on its behalf.

GDPR Art. 5(1)(c), 25, 28Chapter V transfers

Informed consent

In the visitor's own language.

Consent is only informed if it is understood. The banner and the admin dashboard are available in seven languages, chosen from the visitor's browser settings, and every text is yours to edit per domain.

enEnglish
deGerman
daDanish
esSpanish
frFrench
svSwedish
nbNorwegian

GDPR Art. 7(2) and Art. 12: clear and plain language.

Consent that stays current

Re-asked when things change.

Every published change becomes a numbered revision. When you start processing in a new way, publish with “require re-consent” and returning visitors see the banner again instead of carrying over a choice made for something else.

  • Configurable expiry. Stored choices lapse after 180 days by default, so consent is renewed regularly. We recommend never going beyond 13 months.
  • Cookie declaration. The published cookie list renders on your privacy page with data-zeno-declaration.
  • Google Consent Mode v2. Denied by default until the visitor chooses.

Data minimisation

Evidence without identities.

A receipt has to prove consent, not identify a person. ZenoCookieConsent records the least it can while still standing up as evidence.

The visitor's receipt id is also stored in their zeno_consent cookie, so their own history can be looked up on request.
RecordedNot recorded
Random receipt id (UUID)Names, emails or account ids
Choice per category and actionThe full IP address
Consent version, revision, languageQuery strings of the page URL
Page origin and path, user agentCross-site identifiers
Keyed hash of the truncated IPAnything sent to a third party

Shared responsibility

What stays with you.

Software can make the right thing the easy thing. It cannot know your site. As controller, you still need to:

Mark every non-essential tag

Only tags marked with data-zeno are blocked. There is no automatic cookie scanner, so keep the cookie list and markup in step with what your site loads.

Describe purposes honestly

Write category descriptions and a privacy policy that match your actual processing, and link the policy from the banner.

Operate it securely

Keep the installation updated, protect the server secret used for IP hashing, and back up the receipt database.

Check national rules

Member-state laws and regulators add detail, for example Germany's TDDDG §25 or guidance from the CNIL and the Danish Data Protection Agency.

Not legal advice. This page explains how the software is designed. Whether a specific website is compliant depends on its configuration and processing. Ask your data protection officer or counsel. See also the legal documentation.

Compliance without a compliance invoice.

All of this is in the free, self-hosted version. There is no other version.