Cookie Control itself remembers user choices via its own cookie named CookieControl.
Internal cookies are automatically acknowledged and protected. By default, these cookies are set as SameSite=Strict and Secure=false on the site's top level domain (TLD) and kept for a period of 90 days.
It is possible to customise these settings with the following properties:
| consentCookieExpiry | Expects a number to determine how many days the consent of the user will be remembered for. |
| encodeCookie | Expects a boolean value to determine whether or not the value of Cookie Control's own cookie should be encoded as a Uniform Resource Identifier (URI) component. |
| sameSiteCookie | Expects a boolean value to determine whether or not Cookie Control's own cookie will be marked as SameSite. |
| sameSiteValue | Used in conjuction with the property sameSiteCookie to control the value of the SameSite cookie flag. Can be either "Strict", "Lax" or "None". This property is only acknowledged if either sameSiteCookie: true , or if the site is served without data encryption (http:// only). |
| secureCookie | Expects a boolean value to determine whether or not Cookie Control's own cookie will be marked as Secure. |
| subDomains | Expects a boolean value to determine whether Cookie Control's own cookie is set to the top level domain (tld) and therefore accessible on all sub domains, or disabled and saved only to the request host. |
For convenience, you can extend your configuration with these properties and their default values as follows:
const config = {
// apiKey and other settings...
consentCookieExpiry: 90,
encodeCookie: false,
sameSiteCookie: true, // if false, cookie set as SameSite=None;secure;
sameSiteValue: 'Strict', // either 'Strict', 'Lax', or 'None'
secureCookie: false,
subDomains: true,
}To alter the name of the cookie that Cookie Control uses to store user preferences, the ccCookie property can be updated with a string containing your chosen name.
This allows preferences to be shared across selected sub-domains, while remaining isolated from others, on a site- or configuration-specific basis.
const config = {
// apiKey and other settings..
ccCookie: 'CookieControl'
}Please note, any value can be entered into the configuration, even if it is not a valid cookie name. Cookie Control will automatically sanitise invalid names. Sanitisation includes the replacement of capital letters to lower case and the removal of whitespace. If you rely on the cookie name elsewhere, or would like to protect it within the necessary cookies array, please ensure you use the final cookie name after validation.
For users that wish to differentiate their consent signal across various subdomains and ensure all are protected across the entire estate, we would suggest using a consistent prefix for the cookie name, such as cookiecontrol-example, to conveniently protect all cookies following this pattern with the wildcard character (*). For example:
necessaryCookies:["cookiecontrol-*"]
It is also possible to log all consent records received (and revoked) via Cookie Control for up to a year.
This functionality is offered solely for the purposes of satisfying the Conditions for consent within Article 7 of the European Union's General Data Protection Regulation (GDPR):
"
Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.
"
To enable consent records, please ensure you have agreed with CIVIC's data processing agreement (DPA) by logging into your account profile and extend your configuration with the logConsent property:
const config = {
// apiKey and other settings..
logConsent: true, // also requires acceptance of CIVIC's DPA
}A privacy statement discloses ways in which one party gathers, uses and manages data. For websites, this type of document typically outlines the broader, more generalized treatment of its user's personal data and may include details such as the types of software being used and their use of cookies.
Cookie Control allows you to make your users aware of your main privacy statement through use of the statementproperty. It is entirely optional, though if configured offers two main benefits:
To extend your configuration with a valid privacy policy, the statement property must be given the value of a JavaScript Object containing the following properties:
| description | The text description that introduces your privacy policy. |
| name | The text label that best describes your privacy policy and is included within the HTML link element. |
| url | The URL where your privacy policy may be publicly accessed. The HTML link element will try to open in a new tab, so it may point to a PDF document if you wish without closing the user's access to your site. |
| updated | The date that your privacy policy was last issued, in the format of dd/mm/yyyy. |
For convenience, you can extend your configuration with the following snippet - though please be aware that there are no default values forURL and updated and the property will be dismissed if not supplied.
const config = {
// apiKey and other settings...
statement: {
description: 'For more detailed information, please check our',
name: 'Cookie and Privacy Statement',
url: 'https://www.civicuk.com/',
updated: '25/05/2018',
},
}Site specific behaviour and functionality may be defined in two different ways:
These two forms of consent management are incompatible due to policies set out by the TCF v2 specification, so you first need to decide which is more appropriate for your website.
If you have not heard of the Internet Advertising Bureau (IAB Europe), or are running only analytics software on your website then chances are Optional Categories will be sufficient for your needs.
Optional Cookie Categories is the form of consent management the majority of our customers opt for due to its flexibility, though please note it does require some manual upfront effort to configure accurately.