Website privacy & consent compliance
Your cookie banner probably is not blocking anything
Most consent banners collect a click and let every tracker fire anyway. That gap is what wiretap lawsuits are built on. We close it, prove it in writing, and hand the whole thing to your attorney to approve.
The problem
Installing the plugin is not the project
A consent banner out of the box does roughly one thing. It appears. The analytics, chat widget and advertising pixels underneath it have usually already loaded and already transmitted by the time a visitor sees it. The banner records a decision it never had the power to enforce.
That gap is what plaintiffs’ firms are filing on. California’s Invasion of Privacy Act and Florida’s Security of Communications Act both treat unconsented interception as the violation, and neither is satisfied by a notice that did not stop anything. E11 is not a law firm and will not tell you whether you are liable. Your counsel makes that call, and everything we build is designed to be handed to them.
Scope
What the work actually involves
Audit what is running
Every script, cookie and vendor on the site, what each does, and who it talks to. Most sites surface tags nobody remembers installing and vendors you stopped paying years ago. Removing those is the cheapest risk reduction in the project.
Build real pre-consent blocking
We configure the consent platform, usually CookieYes or Termly, to hold third-party cookies and scripts until a visitor consents. Every cookie gets classified. Statically loaded scripts get handled separately, because the platform cannot catch them alone.
Make consent work both ways
Accept means the analytics and advertising a visitor agreed to actually fire. Decline means they stay blocked without quietly breaking the site. The second half is the one most implementations get wrong.
Policies, forms and process
A rewritten privacy policy describing what the site genuinely does, a consumer request form with the identity-verification tiers the regulations require, confirmation email copy, and a runbook naming who answers a request and on what clock.
Prove it, in writing
A verification report documenting that the site makes zero third-party requests before consent, stays silent on reject, and fires correctly on accept. Evidence, not assurance.
Packaged for your attorney
The full set goes to your counsel to review and approve. We make the technical calls and document every one. They decide whether the calls were right.
Deliverables
Eleven deliverables, one price
$1,000 per site covers the audit, the consent build, the policy and request infrastructure, the verification report, and the handoff package for your counsel. Your attorney’s review time is billed by them. The annual re-audit is quoted separately. Every deliverable has a named approver, so nothing sits in limbo waiting for someone to decide it is theirs.
What’s included
- Tracking and vendor inventory, plus the cookie classification table
- Consent architecture spec, banner copy and preference centre wording
- Privacy policy rewrite, with a rights section for each regime that reaches you
- Footer notice links, and a call monitoring disclosure if you record calls
- Consumer request form, confirmation email copy and an internal response runbook
- Verification test report proving the site is silent before consent
Process
How it runs
01
Audit
You provision access and return the intake questionnaire. We audit the site and produce the tracking inventory: every script, cookie and vendor, and who each one talks to.
02
Your decisions
You annotate the inventory. Who owns each account, whether a signed agreement exists, and what gets removed. This is the critical path. We can tell you what is running on your site. We cannot tell you what you signed.
03
Build and block
We implement consent blocking and test to clean-state silence, drafting the policy and request infrastructure in parallel so the two tracks finish together.
04
Verify and hand off
We document that the site makes zero third-party requests before consent, package everything for your counsel, then publish and re-verify once their revisions land.
Questions
Common questions
Can we just install CookieYes ourselves?
You can, and the install is the easy part. What takes the time is classifying every cookie, catching the statically loaded scripts the platform cannot see, confirming the site is genuinely silent before consent, and producing evidence of it. The plugin is a tool, not an outcome.
Does geofencing to California and Florida work?
Not reliably. Someone on a VPN appears to be somewhere else. A California resident visiting family in Ohio is still a California resident. Location detection tells you where a request appears to come from, which is not the same as which state’s law protects the person behind it.
Will blocking trackers hurt our analytics?
Yes, and you should budget for it. Everyone who declines or ignores the banner drops out of your reporting. We have seen the loss run from 5 to 40 percent, and paid advertising feels it harder than organic search. We tell you what to expect before the switch rather than after.
What if we have already received a demand letter?
Call your attorney before you call us, and before you change anything on the site. Once a claim exists, remediation sequencing becomes a legal decision and notes made while investigating can become discoverable. We can help once counsel has scoped the response.
Find out what your site does before consent
Most organizations have never checked. It takes an afternoon, and the answer determines everything else.