Cookies, consent and compliance – how we handle it


Updated June 2026

What do website cookies really do?

Cookie compliance. Sorted — before your site goes live.

Cookie consent is one of those things that’s easy to get wrong because it’s generally considered as an afterthought to a new website, or a necessary annoyance, but embarrassing to get wrong publicly. A badly implemented cookie banner, or none at all, puts your organisation in breach of UK GDPR and the Privacy and Electronic Communications Regulations (PECR).

At Rubber Duckiee we take care of it. On every site we build.

Cookie banners, they’re so commonplace now it’s rare what they’re saying is really taken in. Instead it’s a matter of how quickly you can get past them to the content you’re searching for. And if you’re managing a website, you’ve almost certainly wondered: do we really need to make a fuss about this?

When used well, cookies are not just a compliance, tick box exercise though. They’re a really useful tool that can support your business’ online growth.

So, here’s what cookies actually do, as well as how our website development team help our clients use them not only responsibly but effectively, and with confidence.

Cookies – more than just tracking

Basic version: A cookie is a file sent from a website to your browser (e.g. Firefox) and is stored on your computer, this file is sent back to the website every time you visit.

Technical version: A cookie is a text file that works as an identifier which is a string of letters and numbers, this file is sent by a web server to a web browser and then stored by the browser. The identifier is then sent back to the server each time the browser requests a web page from the server.

Cookies are used by web servers to identity, and track users as they navigate a website, they also identify returning users. There are two types of cookie, persistent cookies and session cookies.

Persistent cookie; will be stored by the browser and remain valid until its set expiry date (unless deleted by the user before the expiry date).

Session cookie; will expire at the end of the user session, or when the web browser is closed.

Essentially, cookies help websites remember things. Without them, every page you visit would forget who you are and what you were doing.

That means:

  • No staying logged in.
  • No language or region preferences.
  • No shopping basket between visits.
  • No saved form progress or personalised views.

Without cookies, trying to do anything online would be incredibly time consuming and repetitive.

In themselves therefore they weren’t problematic. Where things became an issue is how they started being used behind the scenes to track people across multiple sites without their knowledge.

EU Cookie Law and GDPR

The Cookie Law is an attempt at protecting privacy, and as a result requires websites to notify visitors that information is being stored and retrieved from their computer or mobile device.

The belief was that by making consumers aware of how information about them is being collected, and then enabling them to choose whether they want to allow that exchange of information they would be better able to protect their privacy online.

Following their introduction and signing into law if your website uses any kind of non-essential cookie (like analytics or marketing tools), you now need clear explanations and proper consent.

Who has to comply?

Any website that uses cookies, and is based in the EU, or targeted towards EU citizens, is expected to comply. Meaning they must get consent from their visitors.

Why it matters for your organisation

For an organisation leader, the risk isn’t just regulatory. A badly thought through cookie implementation signals to your visitors that compliance isn’t something you take seriously. For organisations that publish research, advise clients, or operate in regulated sectors, such an impression matters.

A properly implemented consent mechanism meanwhile may in the grand scheme of things only be a small detail, but it’s one that says something larger: that your organisation does things properly.

Web development beyond compliance

At Rubber Duckiee, we don’t treat cookie banners as a tick-box exercise. Understanding what cookies do and the value they bring, coupled with a healthy respect for people’s privacy, means they’re a consideration from the start of any web project we take on.

What this means in practice: 

In line with our commitment to custom coding our client’s websites tailored to them we begin every project by working with our client to establish their goals and work back from that to plan exactly how to achieve those goals. This forces us to question precisely what’s needed as part of the website build to deliver success. Not every third-party tool needs to be there.

So we start by asking:

  • Which cookies are really needed to deliver on our agreed goals?
  • What value do they add?
  • Are there lighter, more privacy-friendly alternatives?

This helps prevent clutter, which in turn helps maintain speedy load times which in turn keeps your visitors happy.

And when it comes to keeping your visitors happy we always keep in mind their experience.

Cookie consent needs to be informed, it doesn’t need to be irritating.

We design cookie banners and settings that:

  • Use plain English
  • Match the tone of your site
  • Respect the visitor’s journey

Our broader approach to compliance

Cookie consent is one part of a wider set of legal and technical standards we apply to every project. From privacy policies and SSL certificates to accessibility and data handling, we treat compliance as part of the build, not an afterthought.

Our responsibility — and yours

We will design, build and configure a compliant cookie consent solution on every site we develop. That includes the technical implementation, the consent mechanism, and the correct blocking of non-essential scripts until consent is given.

However, this needs to be done in partnership. Cookie compliance depends on accurate information about the tools, trackers and third-party services running on a site. If you add a new analytics platform, a marketing pixel, or an embedded third-party service after we’ve built your site, it’s your responsibility to let us know so we can update the implementation accordingly.

Want a responsible approach to your next website project? 

Have a chat with an expert today.