How do the Shopblocks cookie warnings work? Is it compliant with GDPR?

If using Shopblocks’ built-in GDPR/CCPA-compliant privacy settings, your website will show a cookie warning as new users enter your website for the first time. Users can then choose to accept or opt-out of unessential cookies such as marketing/analytics tools that don’t affect your website’s operations.

Native integrations with analytics tools such as Google Analytics and Facebook Advertising will be automatically disabled should a user opt-out.

For custom integrations, you can use the “cookie_notice_agreed” cookie that will be set in your users’ browser after interacting with your cookie warning. This essential cookie (which is exempt from government privacy rules) will be set to a value of “consent” or “optout” as appropriate and this may be used for you to decide whether to load other third-party analytics, tracking and marketing tools. This cookie is set to expire after one year. In addition, if a user clears their cookies manually they will be see the cookie warning again the next time they visit your website. Speak to your Shopblocks Customer Success Manager for technical help in this area if required.

In terms of data storage, no personal data is stored on Shopblocks’ servers regarding your users’ consent status. Instead, the information is stored on the users’ browser only and that information alone determines how their website experience is tailored for their individual privacy preferences. Neither GDPR or CCPA mandate server-side recording of user opt-out preferences and the Shopblocks approach ensures users are in full control. In addition, both sets of regulations suggest a good practice is to collect and store only the necessary data related to consent and opt-out preferences to align with data minimisation principles. As consent information is stored only in users’ browsers, this aligns with privacy regulation principles and minimises data collection.

In summary, the built-in Shopblocks cookie warning system is designed to be a simple and straightforward approach to compliance with both the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).

It is important to remember that compliance is not just about technical features but also about how these features are implemented, documented, and maintained. Additionally, it’s advisable to seek legal advice or a GDPR/CCPA compliance expert to ensure full compliance with the regulations.