Cookie Consent That Is Actually Compliant
GDPR cookie consent setup that audits every cookie your site loads, blocks non-essential scripts until a visitor agrees, records each consent, and implements Google Consent Mode v2 correctly. Built for law firms, healthcare, and financial services, where a banner alone is not compliance.
Full Cookie Audit
We scan and manually verify every cookie and tracking script your site loads, including third-party scripts you may not be aware of.
Correct Script Blocking
Analytics, marketing, and functional scripts are blocked until the visitor gives consent for that category. Not just a banner, actual technical enforcement.
Google Consent Mode v2
Proper Google Consent Mode v2 implementation preserves conversion tracking accuracy while fully respecting visitor consent choices.
Consent Records
We configure consent logging so you have a verifiable record of consent for each visitor, demonstrating compliance in any regulatory inquiry.
Easy Withdrawal of Consent
Visitors can change or withdraw consent at any time through an accessible preference centre, as required under UK GDPR.
Regulated Sector Experience
We understand the additional scrutiny that law firms, healthcare, and financial services businesses face and configure accordingly.
Some of our direct clients
Cookie Consent That Is Actually Compliant
Every tracking script identified, categorised, and blocked until consent is given. Google Consent Mode v2, consent records, and documentation you can put in front of a regulator.
- 7+
- Years of GDPR compliance delivery
- 100%
- Full audit before any work begins
- 0
- Scripts firing without proper consent
- 2 days
- Compliance setup response time

Why Regulated Businesses Choose Zestcode
We deliver cookie consent setups that are technically correct and genuinely compliant, not just visually compliant. Full audit, correct script blocking, Google Consent Mode v2, consent records, and clear documentation for your DPO or regulator.
- Full cookie and script audit
- Technical script blocking, not just banners
- Google Consent Mode v2
- Consent records and regulatory documentation
How a Cookie Consent Setup Works With Us
We look at what your site is doing
We start with a short call and an initial look at your site to see what cookies and scripts it currently loads, and whether anything is firing before consent. No jargon and no commitment, just a clear picture of where you stand and what compliant would look like for your sector.
We run the full audit and quote
We produce a complete inventory of every cookie and tracking script, categorise each one, and flag anything unexpected. You get a fixed-price proposal with a clear scope, so you know exactly what will be blocked, logged, and documented before we begin.
We implement blocking and Consent Mode
We configure genuine script blocking by category, wire in Google Consent Mode v2, and set up consent logging. Everything is tested by inspecting real network activity before and after each consent choice, so the site behaves exactly as the banner claims.
We hand over evidence and keep it current
You get the cookie inventory, the configuration documentation, and a working preference centre for withdrawing consent. We can review the setup periodically as your site changes, so it stays compliant rather than drifting out of date the moment a new tag is added.
Want to know if your site is genuinely compliant?
Send us your domain and we will audit what it loads before consent, then come back with a fixed quote and a realistic timeline, usually within 2 working days. NDA first, no obligation.
Here's What Our Partners Say
Agencies, direct clients and long-term retainers. Rated 5* on Google.
GDPR Cookie Consent FAQs
GDPR Cookie Consent Setup for Regulated UK Businesses
Most cookie banners look compliant and are not. If you work in a regulated sector, the questions worth asking are whether scripts are genuinely blocked before consent, whether your consent records would stand up to scrutiny, and whether analytics still works once you do it properly. Here is how we handle each.
Why a cookie banner on its own is not compliance
Under UK GDPR and PECR, consent has to be given before non-essential cookies and tracking scripts run. A banner that sits on top of a page while Google Analytics, Meta Pixel, and various marketing tags have already fired is decorative, not compliant. The consent it collects is meaningless because the tracking happened regardless.
This is the single most common problem we find. The banner is present, it looks professional, and behind it nothing is being blocked. Regulators and complainants can see this in seconds using browser developer tools, and increasingly they do.
Compliance means the technical behaviour of the site matches what the banner claims. That is the difference between visually compliant and genuinely compliant, and it is the whole point of what we do.
What a cookie audit actually involves
We start by loading your site the way a regulator would and recording every cookie, script, and network request it makes, category by category. Automated scanners catch some of this, but they miss cookies set only after interaction, cookies dropped by embedded content, and third-party tags loaded by other tags. We verify manually as well.
The output is a full inventory: what each cookie is, who sets it, what it is for, how long it persists, and which consent category it belongs in. That inventory is the foundation for everything else, because you cannot block or document what you have not found.
Many sites are running scripts nobody remembers adding, left behind by an old campaign or a plugin. The audit surfaces those too, so you know exactly what is on your site.
Blocking scripts before consent, not just after
This is the part that makes a setup real. Analytics, marketing, and functional scripts are prevented from loading at all until the visitor consents to that specific category. If someone accepts analytics but declines marketing, only analytics runs. If they decline everything, only strictly necessary cookies remain.
Doing this correctly means intercepting scripts before the browser executes them, handling tags injected through Google Tag Manager, and dealing with the awkward cases like embedded videos and maps that set cookies of their own. It is closer to development work than configuration.
We test the result the same way a regulator would, by inspecting network activity before and after each consent choice, so we can show the blocking works rather than assume it does.
Not sure your banner is actually blocking anything?
Most sites we look at load analytics and marketing tags before anyone clicks accept. Send us the URL and we will tell you honestly what is firing early and what it would take to fix.
Google Consent Mode v2 done properly
Google Consent Mode v2 is now required for advertisers using Google services in the UK and EEA, and it changes how consent and tracking interact. Instead of simply blocking Google tags, the tags load in a restricted state and respect the visitor's choices, sending pings without cookies when consent is declined.
Configured correctly, this preserves a usable level of conversion and analytics data through Google's modelling while fully honouring consent. Configured badly, it either leaks data it should not or destroys your reporting entirely.
We wire the consent signals from your platform into Consent Mode so the two agree, then verify the correct default and update states are firing. If your setup also involves tracking that feeds a CRM or ad platform, that often overlaps with our API integrations and business automation work.
Consent records and documentation for your DPO
Collecting consent is not enough on its own. UK GDPR expects you to be able to demonstrate that consent was given, freely and for a specific purpose. We configure consent logging so each visitor's choice, the categories they agreed to, the timestamp, and the version of the policy in force are recorded and retrievable.
We also give you plain documentation of what was built: the cookie inventory, the categorisation decisions, and how blocking and Consent Mode are configured. If a complaint or an ICO enquiry lands, your DPO has an answer ready rather than a scramble.
For law firms, healthcare providers, and financial services businesses, this evidence trail is often the point. It is the difference between saying you are compliant and being able to prove it.
Choosing a platform and keeping it maintained
We are not tied to one consent management platform, but we do have a recommendation for most regulated sites, and our CookieYes setup and configuration work covers that in detail. The platform matters less than how it is implemented; a good CMP configured carelessly is still non-compliant.
Cookies change. New plugins, new marketing tags, a new embedded tool, and your inventory drifts out of date. A setup that was compliant in January can quietly stop being so by summer, without anyone touching the banner.
We leave you with a setup that is correct on the day and documented so it stays maintainable. If you would rather not track it yourself, ongoing checks fit naturally alongside our WordPress support retainers, so your consent setup is reviewed as the site evolves.
Partner with Zestcode for Industry Leading Quality and Reliability
Tell what you're looking for and we'll see you how we can help. Quotes are typically provided within 2 working days of the initial call.