06 · Checklist

Checklist: cookies and privacy on your website

Check cookies, consent, policy and tracking on your website, one item at a time.

18 items in 5 groups

Your ticks are only saved in this browser. Nothing is sent to us.

Practical advice, not legal advice. Supervision: PTS (cookies) and IMY (GDPR).

Map it out

3 items

  • Why: You cannot inform about something you do not know exists. Look under storage (Application or Storage) in the browser’s developer tools, both before and after you accept everything.

  • Why: What is needed for a service the visitor has asked for to work (login, shopping cart, security) does not need consent. Statistics, ads and social media do.

  • Why: Web hosts, statistics, newsletter, booking and chat often receive data about your visitors. The list is needed for the policy and for the data processing agreements.

Consent

5 items

  • Why: Open the page in a private window, decline and look in the developer tools under Network and Storage. Nothing from analytics or advertising services should show.

    We install a cookie banner that works
  • Why: According to PTS, you must be able to decline in the same view where you can accept, and the buttons must be designed in a similar way. A hidden option in settings is not enough.

  • Why: Consent must be an active choice. Pre-ticked boxes, “by continuing to browse you accept” and a button that only says “I understand” are not accepted.

  • Why: PTS allows no cookie walls: someone who does not consent should still be able to see the page.

  • Why: It should be as easy to withdraw consent as to give it. Show an icon or a link such as “Cookie settings” on every page.

Information

3 items

  • Why: It should describe every cookie: its purpose, whether it comes from a third party, how long it is kept and what information it collects. A policy that does not match reality misleads visitors.

    See our cookie policy as an example
  • Why: The visitor should be told who the controller is, why the data is collected, how long it is kept and how to ask for correction or erasure.

    See our privacy policy as an example
  • Why: Someone filling in details should be told what they are used for right there, before they send.

Tracking and third parties

4 items

  • Why: Web hosts, newsletter services, booking systems and analytics tools process personal data on your behalf, and then an agreement is required. Most providers have a ready one to accept.

  • Why: YouTube, Google Maps, Google Fonts and chat windows fetch content from a third party and may set cookies or send the visitor’s IP address there. Load them after consent or serve the fonts from your own server.

  • Why: Every extra field is a detail you have to protect, inform about and delete. Do not ask for a personal identity number or date of birth unless it is needed.

  • Why: Google Consent Mode tells Google’s tags what the visitor has accepted. It does not replace the banner itself.

    We install Google Analytics 4 with measurement after consent

Routines

3 items

  • Why: A new chat window, a pixel or an embedded service can set new cookies without the policy changing.

  • Why: Someone who asks for their data should as a rule get an answer within a month. Decide who receives the request, how you check who is asking and where the data is.

  • Why: If data leaks and there is a risk to the people concerned, the incident must be reported to IMY within 72 hours of you becoming aware of it. Decide who decides and how you document it.

  • No sign-up, no account
  • The ticks are only saved in your browser
  • Can be printed or copied as text

How to use the list

Three steps through the list

  1. Tick off what is already right

    Tap a row to tick it off, or use Tab and Space. Start with the mapping: it shows what needs to be fixed.

  2. Read why and follow the link

    Under each item it says why it is there. Where an example, a guide or a fixed package can help, there is a link.

  3. Carry on when you have time

    What you have ticked off is saved in your browser. Print the list or copy it as text if you want to share it with whoever looks after the site.

Good to know

  • Your ticks are only saved in this browser, on this device. Nothing is sent to us.
  • They are not synced between phone and computer, and disappear if you clear the browser’s data or browse in private mode.
  • The list is based on an ordinary company website. If you have sensitive personal data, an online shop or customers outside Sweden, more checks are needed.

What most often goes wrong with cookies on a company website?

A common mistake is a cookie banner that is just decoration: the visitor presses Decline, but the analytics tool and the ad pixel have already loaded. The banner and the scripts must be connected, and you can test it in a private window.

Another is that Decline is hidden behind an extra step while Accept is a big button. Check that both choices are equally easy to make and that the visitor can change their mind later.

The third is that the policy gets old. A new chat window, an embedded video or a new pixel sets new cookies without the cookie policy changing. Go through the list at every change.

This is how we describe our own in our cookie policy and privacy policy. If you want help, we install a cookie banner that works and set up measurement after consent.

Fixed packages

Do you want to avoid doing it yourself?

There are packages for most of what is on the list. Prices include VAT, and the scope is confirmed in writing before we start.

Frequently asked questions

Questions about cookies and privacy

Does a company website have to have a cookie banner?

Only if the site uses cookies or similar technologies that are not necessary, for example statistics, advertising or embedded services that set their own cookies. If the site only uses necessary cookies, no consent is needed, but you must still inform about them, for example in a cookie policy.

Which cookies require consent?

Consent is required for everything except what is necessary to deliver a service that the visitor has asked for. Login, shopping cart, security and your own cookie choice are necessary. Statistics, advertising and social media require consent.

Who checks that I follow the rules?

The Swedish Post and Telecom Authority (PTS) supervises the cookie rules in the Electronic Communications Act, and the Swedish Authority for Privacy Protection (IMY) supervises the General Data Protection Regulation (GDPR). If you are unsure about a concrete situation, you can ask them or a lawyer.

Not sure what applies to your website?

Tell us which tools the site uses, and we help you get cookies and tracking to follow consent. You get a written price before we start.

Chat with us