Cookie Consent That Is Actually Compliant
GDPR cookie consent setup that audits every cookie your site loads, blocks non-essential scripts until a visitor agrees, records each consent, and implements Google Consent Mode v2 correctly. Built for law firms, healthcare, and financial services, where a banner alone is not compliance.
Some of our direct clients
Why Regulated Businesses Work With Us
Cookie consent that is technically correct and genuinely compliant, built by people who understand both the code and the regulatory scrutiny your sector faces.
Full Cookie Audit
We scan and manually verify every cookie and tracking script your site loads, including third-party scripts you may not be aware of.
Correct Script Blocking
Analytics, marketing, and functional scripts are blocked until the visitor gives consent for that category. Not just a banner, actual technical enforcement.
Google Consent Mode v2
Proper Google Consent Mode v2 implementation preserves conversion tracking accuracy while fully respecting visitor consent choices.
Consent Records
We configure consent logging so you have a verifiable record of consent for each visitor, demonstrating compliance in any regulatory inquiry.
Easy Withdrawal of Consent
Visitors can change or withdraw consent at any time through an accessible preference centre, as required under UK GDPR.
Regulated Sector Experience
We understand the additional scrutiny that law firms, healthcare, and financial services businesses face and configure accordingly.
The Platforms We Make Genuinely Compliant
WordPress, WooCommerce and custom sites, set up with real script blocking, consent records and Google Consent Mode v2. We work across every major consent management platform rather than defaulting to one.
Laravel & Bespoke Platforms
For systems and platforms that require bespoke processes, data handling complex integrations or internal business platforms with security at the forefront of the build.
WordPress & WooCommerce
For fast, reliable and easy to manage brochure based websites built following best practice with a bespoke theme powered by ACF Pro and supporting custom built plugins.
Shopify & Shopify Plus
For eCommerce and retail brands looking to grow revenue significantly online. Built using a bespoke theme specific to your brand and with a full seamless migration from legacy platforms.
Recently Completed Projects
Clintons Cards
A full migration from Magento 2 to Shopify Plus, with order, customer, product, stock and finance integrations kept live through the switch.
Ecommerce · Shopify Plus · IntegrationsQualityHive
A Laravel platform that web agencies use to capture, assign and close website bugs, taken from wireframe to launch, then handed over as clean, documented code.
SaaS platform · Laravel · API integrationsThe Sauce Foundry
A brand, a WooCommerce store and product photography for an artisan hot sauce startup, launched to a 3.8% conversion rate from day one.
Ecommerce · Branding · WooCommerceHave a project like these in mind?
Get in touchHere's What Our
Clients Say
Consistently rated 5* on Google by our full build clients and retainer clients.
GDPR Cookie Consent FAQs
GDPR Cookie Consent Setup for Regulated UK Businesses
Most cookie banners look compliant and are not. If you work in a regulated sector, the questions worth asking are whether scripts are genuinely blocked before consent, whether your consent records would stand up to scrutiny, and whether analytics still works once you do it properly. Here is how we handle each.
Why a cookie banner on its own is not compliance
Under UK GDPR and PECR, consent has to be given before non-essential cookies and tracking scripts run. A banner that sits on top of a page while Google Analytics, Meta Pixel, and various marketing tags have already fired is decorative, not compliant. The consent it collects is meaningless because the tracking happened regardless.
This is the single most common problem we find. The banner is present, it looks professional, and behind it nothing is being blocked. Regulators and complainants can see this in seconds using browser developer tools, and increasingly they do.
Compliance means the technical behaviour of the site matches what the banner claims. That is the difference between visually compliant and genuinely compliant, and it is the whole point of what we do.
What a cookie audit actually involves
We start by loading your site the way a regulator would and recording every cookie, script, and network request it makes, category by category. Automated scanners catch some of this, but they miss cookies set only after interaction, cookies dropped by embedded content, and third-party tags loaded by other tags. We verify manually as well.
The output is a full inventory: what each cookie is, who sets it, what it is for, how long it persists, and which consent category it belongs in. That inventory is the foundation for everything else, because you cannot block or document what you have not found.
Many sites are running scripts nobody remembers adding, left behind by an old campaign or a plugin. The audit surfaces those too, so you know exactly what is on your site.
Blocking scripts before consent, not just after
This is the part that makes a setup real. Analytics, marketing, and functional scripts are prevented from loading at all until the visitor consents to that specific category. If someone accepts analytics but declines marketing, only analytics runs. If they decline everything, only strictly necessary cookies remain.
Doing this correctly means intercepting scripts before the browser executes them, handling tags injected through Google Tag Manager, and dealing with the awkward cases like embedded videos and maps that set cookies of their own. It is closer to development work than configuration.
We test the result the same way a regulator would, by inspecting network activity before and after each consent choice, so we can show the blocking works rather than assume it does.
Not sure your banner is actually blocking anything?
Most sites we look at load analytics and marketing tags before anyone clicks accept. Send us the URL and we will tell you honestly what is firing early and what it would take to fix.
Google Consent Mode v2 done properly
Google Consent Mode v2 is now required for advertisers using Google services in the UK and EEA, and it changes how consent and tracking interact. Instead of simply blocking Google tags, the tags load in a restricted state and respect the visitor's choices, sending pings without cookies when consent is declined.
Configured correctly, this preserves a usable level of conversion and analytics data through Google's modelling while fully honouring consent. Configured badly, it either leaks data it should not or destroys your reporting entirely.
We wire the consent signals from your platform into Consent Mode so the two agree, then verify the correct default and update states are firing. If your setup also involves tracking that feeds a CRM or ad platform, that often overlaps with our API integrations and business automation work.
Consent records and documentation for your DPO
Collecting consent is not enough on its own. UK GDPR expects you to be able to demonstrate that consent was given, freely and for a specific purpose. We configure consent logging so each visitor's choice, the categories they agreed to, the timestamp, and the version of the policy in force are recorded and retrievable.
We also give you plain documentation of what was built: the cookie inventory, the categorisation decisions, and how blocking and Consent Mode are configured. If a complaint or an ICO enquiry lands, your DPO has an answer ready rather than a scramble.
For law firms, healthcare providers, and financial services businesses, this evidence trail is often the point. It is the difference between saying you are compliant and being able to prove it.
Choosing a platform and keeping it maintained
We are not tied to one consent management platform, but we do have a recommendation for most regulated sites, and our CookieYes setup and configuration work covers that in detail. The platform matters less than how it is implemented; a good CMP configured carelessly is still non-compliant.
Cookies change. New plugins, new marketing tags, a new embedded tool, and your inventory drifts out of date. A setup that was compliant in January can quietly stop being so by summer, without anyone touching the banner.
We leave you with a setup that is correct on the day and documented so it stays maintainable. If you would rather not track it yourself, ongoing checks fit naturally alongside our WordPress support retainers, so your consent setup is reviewed as the site evolves.
Partner with Zestcode for Industry Leading Quality and Reliability
Tell us what you're looking for and we'll see how we can help. Quotes are typically provided within 2 working days of the initial call.