GDPR + ePrivacy · UK GDPR + PECR

In Europe, consent comes first.

The ePrivacy Directive requires consent before any non-essential cookie is set; the GDPR defines what real consent looks like. UserGuard is designed to run that model properly: prior gating, honest choices, and records that prove it.

What the EU requires

Consent that would survive an audit.

European regulators have made the standard concrete: nothing non-essential fires before consent; “Reject” sits beside “Accept” with equal prominence; consent is granular by purpose; withdrawing is as easy as agreeing; and you can demonstrate every consent you rely on — Article 7(1). Get any of those wrong and a beautifully-designed banner is still non-compliant.

UserGuard holds non-essential tags until consent through Consent Mode v2 signals and script gating, and logs every choice against banner version, and is designed to meet GDPR and ePrivacy consent requirements when properly configured.

Prior tag gating

Non-essential tags held until consent, via Consent Mode v2 default-denied signals plus script gating. One documented exception: if our config is unreachable, scripts you marked by hand stay held and auto-detected ones are released, so an outage of ours can never take your site down with it.

An honest first layer

Accept all and reject optional are the same button, in the same accent color at the same size and weight, and neither is pre-selected. Preferences opens the preference center, which has its own one-click reject all. No dark patterns, no buried reject.

Records for Article 7(1)

Every consent event tied to site, banner version, region, and timestamp. When someone asks you to demonstrate consent, you export a CSV.

United Kingdom

The UK is not a footnote to the EU.

Post-Brexit, the UK runs UK GDPR plus PECR. It is the same prior-consent model, enforced by the ICO, which has actively swept major UK sites for missing equal-prominence reject buttons. And the rules are diverging: the Data (Use and Access) Act 2025 adds UK-specific consent exemptions and raises PECR fines from £500K to UK GDPR levels.

UserGuard treats the UK as its own region configuration, tracked as the law shifts, not a copy of the EU settings.

Google Consent Mode v2

Built for the Google reality.

Since March 2024, Consent Mode v2 has been required for Google advertising and measurement features covering EEA and UK users. UserGuard is designed to set default-denied signals for all four consent types before any Google tag loads, then update them the moment a visitor chooses, so your analytics and ads degrade gracefully instead of firing without consent.

IAB TCF support is on our roadmap; we intend to complete IAB Europe’s CMP validation, and we won’t claim the badge before it’s real.

Honest answers

GDPR questions, answered

Do I need prior consent for cookies in the EU?

Yes. The ePrivacy Directive requires prior consent for any non-essential storage or access on a visitor’s device (cookies, pixels, localStorage), and the GDPR and regulator guidance set the consent standard: freely given, specific, informed, and unambiguous, with rejection as easy as acceptance and withdrawal as easy as giving it. Nothing non-essential should fire before the visitor says yes.

What are records of consent?

GDPR Article 7(1) requires you to be able to demonstrate that consent was given. UserGuard logs every consent event against site, banner version, region, and timestamp, exportable as CSV. Records built to answer that exact question.

Does UserGuard support Google Consent Mode v2?

UserGuard is designed for full Consent Mode v2 integration: default-denied signals for all four consent types (ad_storage, analytics_storage, ad_user_data, ad_personalization) before any Google tag loads, updated the moment a visitor chooses. Consent Mode v2 has been required for Google advertising features covering EEA and UK users since March 2024.

Is UserGuard an IAB TCF certified CMP?

Not yet. TCF participation requires completing IAB Europe’s validation process, and we won’t claim it before it exists. TCF support is on our roadmap, and we intend to complete IAB Europe’s CMP validation.

Does the UK follow the same rules?

The UK has its own parallel framework (UK GDPR plus PECR, enforced by the ICO) with the same prior-consent model but growing differences, including the Data (Use and Access) Act 2025’s new exemptions and dramatically higher PECR fines. UserGuard treats the UK as its own configuration, not a footnote to the EU.

This page is general information about privacy laws, not legal advice. UserGuard helps you operate consent and opt-out management as part of your compliance program. Configuration decisions and legal outcomes remain yours. Consult qualified counsel for your situation.

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started 30-day money-back guarantee · cancel anytime