How consent works
Consent is a person agreeing, in advance and on purpose, that you may do something specific with information about them. In marketing that usually means two related things: setting cookies or reading anything from their device beyond what the site strictly needs to work, and using contact details for something other than the reason they were given.
Where European or UK rules apply, the bar is set out clearly. Consent has to be freely given, so it cannot be the price of using the site. It has to be specific, so one tick cannot cover analytics, advertising and a newsletter at once. It has to be informed, so the person must know who is processing what and why. It has to be an active choice, which rules out pre-ticked boxes, silence and “by continuing to browse you agree”. Withdrawing it must be as easy as giving it. And you must be able to show it happened, which means keeping a record.
Consent is not the only lawful basis for using data — a contract or a legitimate interest can cover some processing — but for advertising cookies and marketing messages it is the one that usually applies.
Why consent matters
The obvious reason is legal risk, and it follows the customer rather than your office. A business in Kathmandu taking enquiries from the UK, Australia or the EU is dealing with those customers’ rules, not only with Nepal’s.
The less obvious reason is that consent now shapes your numbers. Tags that wait for permission collect nothing from people who decline, so reported traffic and conversions sit below reality and the gap moves when you change the banner. If you do not know your consent rate, you cannot interpret a drop in tracked conversions at all.
Where consent goes wrong
The commonest failure is a banner that decides nothing. Analytics and advertising tags fire as the page loads, the banner appears afterwards, and clicking “reject” changes nothing that already happened. Open the browser tools and look at what is set before any click — that single check catches most implementations.
Close behind it is the design that pushes one answer: a bright accept button beside a grey link, or a reject option buried a level deeper. Regulators have named this pattern specifically, and it undermines the consent you were relying on.
Then there is the paperwork nobody keeps. If you cannot show when someone agreed, to what, and what wording they saw, you have no evidence. And a privacy page that lists cookies you no longer set, or omits ones you do, quietly makes the consent uninformed.
Getting it right
Start with an honest inventory of what your site actually loads and what you do with the details people submit. Almost every site I audit is running at least one tag nobody remembers adding.
Then block everything non-essential until a choice is made, make accepting and rejecting equally easy, store the answer with a timestamp, and give people a way to change their mind. Keep the privacy and cookie pages matched to reality, and re-check after any change to your tag setup, because tags get added and pages do not get updated. Getting the mechanism right is ordinary tracking and analytics work, and it is far cheaper to do at the start than to unpick later.