The ePrivacy Directive requires consent before non-essential cookies or similar technologies are used. The GDPR defines what valid consent is: freely given, specific, informed, unambiguous, provable and as easy to withdraw as to give. ZenoCookieConsent is built around those rules and the way European regulators apply them.
Six principles
What the law asks, and what the software does.
Reject as easy as accept
“Reject all” sits on the first layer next to “Accept all”, with the same size, colour and weight. They share one style rule in the code, so a configuration cannot make one of them less visible.
Tags marked with data-zeno are inert until their category is granted: scripts do not run, iframes and pixels do not load. Consent comes first, then the cookies.
Visitors choose per purpose: functional, analytics, marketing. Every optional category starts switched off; strictly necessary storage is shown as always on and explained.
Each decision is logged as a pseudonymous, append-only receipt with the exact banner revision, language and consent version, so you can show what a visitor saw and chose.
GDPR Art. 7(1)Art. 5(2) accountability
Withdrawal at any time
A persistent cookie button reopens the preferences after the first choice, and Zeno.show() powers your own “Cookie settings” link. Withdrawing takes as few clicks as consenting.
GDPR Art. 7(3)
Data stays on your servers
The banner script, its config and every receipt are served from and stored on infrastructure you control. No consent vendor as processor, no transfer to a third country on its behalf.
GDPR Art. 5(1)(c), 25, 28Chapter V transfers
Informed consent
In the visitor's own language.
Consent is only informed if it is understood. The banner and the admin dashboard are available in seven languages, chosen from the visitor's browser settings, and every text is yours to edit per domain.
enEnglish
deGerman
daDanish
esSpanish
frFrench
svSwedish
nbNorwegian
GDPR Art. 7(2) and Art. 12: clear and plain language.
Consent that stays current
Re-asked when things change.
Every published change becomes a numbered revision. When you start processing in a new way, publish with “require re-consent” and returning visitors see the banner again instead of carrying over a choice made for something else.
Configurable expiry. Stored choices lapse after 180 days by default, so consent is renewed regularly. We recommend never going beyond 13 months.
Cookie declaration. The published cookie list renders on your privacy page with data-zeno-declaration.
Google Consent Mode v2. Denied by default until the visitor chooses.
Data minimisation
Evidence without identities.
A receipt has to prove consent, not identify a person. ZenoCookieConsent records the least it can while still standing up as evidence.
The visitor's receipt id is also stored in their zeno_consent cookie, so their own history can be looked up on request.
Recorded
Not recorded
Random receipt id (UUID)
Names, emails or account ids
Choice per category and action
The full IP address
Consent version, revision, language
Query strings of the page URL
Page origin and path, user agent
Cross-site identifiers
Keyed hash of the truncated IP
Anything sent to a third party
Shared responsibility
What stays with you.
Software can make the right thing the easy thing. It cannot know your site. As controller, you still need to:
Mark every non-essential tag
Only tags marked with data-zeno are blocked. There is no automatic cookie scanner, so keep the cookie list and markup in step with what your site loads.
Describe purposes honestly
Write category descriptions and a privacy policy that match your actual processing, and link the policy from the banner.
Operate it securely
Keep the installation updated, protect the server secret used for IP hashing, and back up the receipt database.
Check national rules
Member-state laws and regulators add detail, for example Germany's TDDDG §25 or guidance from the CNIL and the Danish Data Protection Agency.
Not legal advice. This page explains how the software is designed. Whether a specific website is compliant depends on its configuration and processing. Ask your data protection officer or counsel. See also the legal documentation.
Compliance without a compliance invoice.
All of this is in the free, self-hosted version. There is no other version.