Privacy
Cookie consent
Also called cookie banner choice.
Cookie consent is permission to store or read information on a person's device under ePrivacy-style rules. The rule covers cookies and similar tools such as local storage.
How it is measured
Under the EU rule, anything not strictly necessary for a service the user asked for needs consent first. Login and cart cookies are exempt. Analytics and advertising cookies usually are not. Regulators in several countries expect rejection to be as easy as acceptance.
Audit by listing every cookie and storage key on first load in a clean browser. Sort them into necessary and not. Anything in the second list that appears before a click is a gap.
Worked example
A bike-repair booking site sets 6 items on first load: a session cookie, a CSRF token, a language choice, a chat vendor cookie, an ad pixel cookie, and an analytics ID. The first three are necessary. The last three need consent.
After a fix, only the first three appear on a fresh visit, and the other three appear only after someone accepts.
How it differs
Cookie consent is about reading and writing on a device. Consent is the broader concept covering any processing based on a person's agreement. Cookie consent excludes processing after the data arrives; consent excludes nothing about the device rule.
Common errors
Relying on a banner that says "by continuing you accept". Setting non-essential cookies on first load. Treating localStorage as outside the rule. Hiding the reject button. Assuming a footer link equals consent.
In practice
Run a clean-browser audit of cookies and storage this week. Remove anything you cannot justify. Show accept and reject with the same weight.