Who owns your cookie banner?
ost cookie banners have no owner. Four questions that expose the gap between communications, privacy, IT and procurement, and how to close it.
By Vincent de Winter9 min read
Who owns the cookie banner in your organisation?
Try asking it out loud in a meeting: how many of our visitors decline consent, and what do we still know about our own website when they do?
In most organisations, the room goes quiet. Not because the answer is complicated, but because nobody at the table feels responsible for the question. The cookie banner is the most viewed element of almost every website, and at the same time the only element without an owner.
That is not a technical problem. It is an organisational problem disguised as a technical one, and that is why it ends up with the wrong people.
In short
- The banner is bought as a compliance product and lands as an operational product. Reviewed once, then never again.
- Four roles make decisions about it. Nobody has a seat for what comes out the other end.
- You don't fix this with a better banner, but with four questions someone needs to be able to answer.
- And the same ownership question applies one layer deeper, to your analytics and your data. The banner is just the most visible example.
The banner is reviewed once and then never again
The pattern is remarkably consistent. Something triggers it: an audit, a new law, a news story or a new website. A consent management platform is selected, configured and assessed. Someone signs off: this is legally defensible. And then the topic is closed.
From that moment on, the banner does something every day that nobody looks at anymore. It determines which visitors you see again and which you don't, which pages are measurable, and whether the report you present to your leadership in six months means anything at all. So it is operational, daily and decisive, while it has been treated as a one-off project.
You can also tell by when a broken banner gets noticed. Almost always by accident, and almost always too late: someone notices the numbers look odd, starts digging, and ends up at a release from six weeks ago.
The misconception: "the banner is done once it's legally sound"
This is the misconception that keeps the whole pattern alive.
Legal sign-off is a minimum, not a goal. A banner that is compliant and gets dismissed by most of your visitors is entirely in order and leaves you with a website you know very little about. Both things are true at once, and organisations usually only hold themselves accountable for one of them.
Underneath lies a second misconception: the idea that you have to choose between being compliant and being able to measure. That is a false dilemma. Besides "ask for consent and measure everything" and "don't ask for consent and measure nothing", there is a third option: make sure part of your measurement no longer requires consent.
Whether that is allowed in your situation, and how far you can go, is a question for your own privacy officer and, for an organisation of any size, for a DPIA. That judgement is not ours to make, and you should be wary of any vendor who tells you it's fine regardless.
What we at Govanalytics can speak to is the supply side: we built the Govanalytics platform on the assumption that the third option should exist, so that the trade-off can at least be made. And what we see in practice is that in many organisations it isn't even on the table. Not weighed and rejected, but never raised, because there is nobody whose job it is to raise it. That is exactly the ownership problem.
Our position: give the banner one owner, and make it the outcome owner
Our position is simple: the banner should have one owner, and that is whoever is held accountable for what the website delivers. Not whoever carries the risk, and not whoever built it in.
There is an objection to this, and it's a serious one: the privacy officer carries the liability, so shouldn't they decide? Yes, but ownership and veto are two different things. The privacy officer keeps their veto, in full. What they shouldn't have is the responsibility for noticing that the banner stopped working after the last release, or for working out which question about the website actually needed answering. That is someone else's job, and as long as it isn't assigned anywhere, it doesn't happen.
Four roles, four decisions, and an empty seat
It helps to be clear about who decides what. Broadly, there are four roles at the table.
- Communications or marketing often chooses the vendor and is held accountable for reach and results. The decision that belongs here: which question about our website do we want to be able to answer, and what is the minimum we need for that.
- The privacy officer carries the risk and holds the veto. The decision that belongs here: which categories, which legal basis, and what counts as strictly necessary.
- IT or the web team builds it in and maintains it. The decision that belongs here: where in the chain consent lives, and which vendors that gives a foothold in your site.
- Procurement handles the contract. The decision that belongs here: where the data is stored, how you get out, and what you keep when you cancel.
And then the empty seat. For what comes out the other end, measurability itself, most organisations have no role defined. That isn't anyone's negligence in particular; it simply never became anyone's job. But the result is that the only person who could have seen something going wrong doesn't exist.
The four questions
You don't need a reorganisation to fix this. Four questions in one meeting are enough to see where the gap is.
- What share of our visitors declines, and since when have we known? If the answer is an estimate, or "probably somewhere around such-and-such percent", you're not measuring it. It can be measured.
- What do we still measure when someone declines? There are three honest answers: nothing, something aggregated, or cookieless measurement. All three are defensible. Not knowing which of the three it is, is not.
- Who notices when the banner breaks after a release? Keep asking until you hear a name. "We'll see it in the numbers" is not a name.
- If we switch vendors next year, what do we lose? This is where the question comes in that a security officer always asks and that "we are GDPR compliant" never answers: where is that data tonight, who can access it, and who owns it when the contract ends. That's not a certificate, that's an address.
The question that stays unanswered points to the role you're missing. That is the entire diagnosis.
The same question, one layer deeper
Everything above about the banner applies to every component that makes decisions on your behalf on your own website. The banner is just the most visible example, and therefore the easiest place to start.
Ask the same question about your analytics. Not "who manages the account", but: who owns that data when the contract ends, who can access it today, and what do you keep if your vendor changes its pricing or phases out a feature you had built on. That last one is not a hypothetical. It happens, and it usually happens to the organisations that had no answer to it beforehand.
We aren't neutral here, so we'll say so. Govanalytics is based on the open-source stack d8a.tech, so a customer can always carry on with it themselves, even without us. That isn't a favour and it isn't a sales pitch. It is the only way the answer to "who owns this" doesn't depend on our goodwill, and that's the kind of answer a security officer wants to hear.
You can apply that test to any vendor, including us and including your CMP. Don't ask whether they're compliant, because everyone says they are. Ask where the data is, who can access it and what you keep when you leave. Anyone who can't answer that in one sentence doesn't have the answer.
You can check what such an answer looks like on this very site. The Consent Studio subprocessor list shows, for each party, who it is, in which country, for what purpose and which data passes through, with a separate list for visitors and for customers. For visitors in the EU, two requirements apply at once: the data stays within EU member states, and the processing party is a European legal entity without a parent company outside the EU. That second requirement is where most "EU region" promises still fall apart.
What makes that list useful is not that everything looks perfect. It's that the uncomfortable lines are in there too: an American tool for internal project management, and a CDN that also uses nodes outside the EU for visitors from outside the EU. An answer to the address question that only looks good is usually not an answer but a brochure. This is the kind of document you should ask every vendor for, and it says a lot when it doesn't exist.
What you can do with this
Put these four questions on the agenda of the next meeting where communications, privacy and IT happen to be in the same room. That's usually the only moment in the quarter those three are together, so make use of it.
Then appoint one owner and give them two things: they may not change the banner legally on their own, and they are the one who answers the first two questions every quarter. That's a half-hour quarterly task, and the difference between knowing and guessing.
And if you find that question two can't be answered because nobody knows what is still measured in the declined state: that is exactly the moment to discover you have a choice there.
Also available in German, Dutch
Back to the blog