Küpsised ja nõusolek Lätis: mida oma lehel kontrollida

See artikkel on praegu saadaval ainult inglise keeles.

Praktiline nimekiri saidi omanikule: mis laaditakse enne nõusolekut, kus bännerid eksivad, mida teeb Google Fonts ja mida skaneering näidata suudab ja ei suuda.

The cookie banner has become the part of a website everybody adds and nobody checks. Install a plugin, pick a colour that fits the design, question closed. The trouble is that a banner is not compliance — it is only the surface. Underneath it there may still be a site that sets an analytics cookie in the first second, before the visitor has pressed anything at all.

What follows is a practical checklist for a site owner. It is not a legal opinion. It is what you can verify yourself in an afternoon, and what a check cannot establish for you.

The rule, very briefly

The requirement comes from two directions. The General Data Protection Regulation defines what valid consent looks like: freely given, specific, informed and unambiguous — meaning an active choice, not a pre-ticked box. The ePrivacy rules, transposed in Latvia through the Electronic Communications Law, define when consent is needed at all: essentially whenever a site writes to or reads from a visitor’s device, except for what is strictly necessary to provide the service they asked for.

Three practical consequences follow. Analytics is not strictly necessary. A shopping cart, a session identifier and a language preference are. And refusing has to be as easy as accepting.

Check one: what happens before consent

This is the single check that answers the important question. Open the site in a fresh private window, open the developer tools and look at cookies and network requests before touching the banner at all.

  • Is there a _ga, _gid or similar analytics cookie? If so, the banner is blocking nothing.
  • Are there requests to ad networks, a Meta pixel or a heatmap tool?
  • Has an embedded video already loaded its player and its cookies? Embeds are the most common case of a correct banner on an incorrect page.
  • Has a chat widget or a booking form started up on its own?

If the answer to any of those is yes, the problem is not the banner. The problem is that the scripts load regardless of it — and that is precisely what a scan tends to surface.

Check two: where banners go wrong

On the banner side we keep seeing the same five things.

  • No reject button. A coloured “Accept” next to a grey “Settings” link is not an equivalent choice.
  • Pre-ticked boxes. If the marketing category is already on, consent was not given, it was assumed.
  • “By continuing to use the site you agree.” Scrolling is not consent.
  • No way to change your mind. Consent has to be withdrawable later; the simplest answer is a permanent link in the footer.
  • Consent is not recorded anywhere. With no record of who agreed and when, there is nothing to show afterwards.

Check three: third-party requests nobody calls cookies

Data does not leave through cookies alone. Every request to somebody else’s domain hands that party the visitor’s IP address and the page they were on, whether or not a cookie is set.

The classic example is fonts loaded straight from a third party. It is also the easiest to fix: put the font files on your own server and the request never leaves. We did exactly that for this site, for that reason — and as a side effect the page loads faster. The same logic applies to maps, which can be a static image with a link, and to embedded video, where most platforms offer a no-tracking mode, or where a preview image that only loads the player on click does the job.

Check four: the cookie policy

The cookie policy has to match what the site actually does. The most common mismatch is a stale list: the policy names a tool removed two years ago and omits two added last month. Review the policy at the same time as the scan rather than separately — the discrepancy is then obvious.

What a scan can and cannot tell you

It is worth being precise here, because automated checking is often sold as more than it is.

It can: open the site in a real browser, record every cookie and third-party request that happens before any consent, identify which consent platform is in use, and show which requests went to which domain. That is an objective fact you can put in front of a client without an argument.

It cannot: tell you whether your legal basis is right. Whether you keep a record of processing activities. Whether you have contracts with your processors. Whether the data a form collects is kept for a defensible period. And a scan only sees the page it was pointed at — a contact form or a checkout step may behave differently.

In other words, a scan answers “what does this site do”. The question “is that allowed” is answered by a person who knows why the data is being collected.

What to do this week

Three steps, usually faster than they sound. Scan the site and write down what loads before consent. Move everything that is not strictly necessary behind consent — for most consent platforms that is a single setting, provided the scripts are added through it. Then check the cookie policy against the new list.

Check your own site now

Our free cookie test opens the site in a real browser and shows what gets set before consent. No account needed. If you need the same thing monthly across every client site, it is one of the 14 services in the Bugzio panel.

Kõik artiklid Alusta tasuta

Loe ka

Teised artiklid

Proovi Bugziot oma projektil

14-päevane prooviaeg, piiramatu arv teatajaid ja 14 seireteenust ühes paneelis. Paigaldamine võtab viis minutit.

14-päevane prooviaeg · piiramatu arv teatajaid · kuus keelt