GDPR合规咨询:存储用户同意决策的布尔值Cookie是否合规?
Great question—this is a common pain point when building GDPR-aligned consent flows. The short answer is yes, storing a simple boolean cookie to track a user's opt-in/opt-out choice is generally GDPR-compliant, but you need to stick to several key rules to stay on the right side of the regulation:
The cookie must be strictly necessary for consent management
GDPR explicitly permits "strictly necessary" cookies without prior consent, and a cookie that remembers a user's consent call falls squarely into this category. Critical rule: this cookie should only store the booleantrue/falsevalue—no extra user identifiers, browsing data, or unrelated metadata. Its sole purpose should be to avoid re-prompting users unnecessarily.Full transparency is non-negotiable
You must disclose this cookie to users, either in your consent banner or privacy policy. Be clear about:- That the cookie exists
- Exactly what it does (stores their consent decision for analytics)
- Its lifespan (30 days in your implementation)
- That it’s strictly necessary to manage their consent preferences
Respect the user’s decision completely
- If they opt out: You must not activate Google Analytics (or any other non-essential tracking), and the cookie should store
falseto skip future prompts. - If they opt in: You can enable GA, but ensure GA’s own data handling complies with GDPR (e.g., anonymizing IP addresses, avoiding unauthorized data sharing with third parties).
- Always give users an easy way to change their mind later—like a "Manage Consent" link in your footer that lets them toggle their choice and updates the cookie accordingly.
- If they opt out: You must not activate Google Analytics (or any other non-essential tracking), and the cookie should store
Limit the cookie’s lifespan to what’s needed
Your 30-day expiration window is reasonable. GDPR doesn’t set a hard maximum duration, but you should only keep the cookie for as long as necessary to avoid re-prompting. Extending it beyond a logical timeframe could raise compliance red flags.
A common mistake to avoid: Don’t mix this consent-tracking cookie with Google Analytics’ own cookies (like
_gaor_gid). Those should only be set after the user opts in—never before.
As long as you follow these guidelines, storing a simple boolean cookie for consent decisions is a solid, GDPR-compliant practice.
内容的提问来源于stack exchange,提问作者TechyDude

