Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Cookiebar is a lightweight open-source JavaScript library that displays a cookie consent banner and remembers a visitor consent choice. It itself sets only one strictly necessary cookie that stores the consent state. The banner helps a website obtain consent for other tracking technologies, but compliance depends on how the operator configures it.
Cookiebar is a small open-source JavaScript library that shows a cookie consent banner to website visitors and records whether they accepted or declined. It is delivered to the browser as a script and runs entirely on the client side, with no backend server collecting visitor data. Its purpose is to help a website operator obtain and remember the consent that other cookies and trackers require.
Cookiebar itself sets only one strictly necessary first-party cookie that stores the visitor consent state, typically for about one year, plus a functional flag remembering that the banner was dismissed. It does not profile visitors, build advertising identifiers, or send personal data to its developers. The personal data implications come from the third-party cookies that the operator decides to load once consent is given.
The consent-state cookie is strictly necessary and therefore exempt from consent under Article 5(3) of the ePrivacy Directive, while the controller relies on legitimate interest to keep a record of the choice. Cookiebar is a tool that supports compliance rather than a tracking technology in its own right. A banner alone does not make a website compliant; the operator must still ensure non essential cookies are actually blocked until consent is granted.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
To use Cookiebar lawfully the operator must configure it so that analytics, advertising, and other non essential scripts only run after the visitor has actively accepted them. Simple banner libraries like this one do not provide prior blocking, granular categories, audit logs, or IAB TCF signals out of the box, which dedicated consent management platforms offer. Where these capabilities are required, Cookiebar may need to be supplemented or replaced.
Cookiebar does not transfer personal data to third countries because it processes nothing on a server and the consent cookie stays first-party in the visitor browser. When the script is loaded from a public CDN, only the technical request to fetch the file reaches the CDN provider. Any international data transfers arise from the other services the operator chooses to enable after consent, not from Cookiebar itself.
Operators should self-host or pin the Cookiebar script, wire it so that tracking scripts are gated behind the recorded consent, and document the categories of cookies in a clear cookie policy. Test that declining consent genuinely prevents non essential cookies from being set. Review whether a fuller consent management platform is needed for granular control, proof of consent, and TCF support.
Websites using Cookiebar must obtain user consent under GDPR regulations.
DPIA considerations
A formal DPIA is rarely required for Cookiebar alone because it is a consent tool that sets only a strictly necessary cookie and performs no profiling. When assessing it, consider (1) that the consent-state cookie is exempt under ePrivacy Art. 5(3) and recorded on a legitimate interest basis; (2) that the real risk lies in the third-party trackers the banner is meant to gate, so the assessment should focus on those; (3) whether the implementation actually blocks non essential cookies before consent rather than merely displaying a notice; (4) whether the library lacks prior blocking, audit logging, or IAB TCF signals that the controller may need; and (5) the integrity of stored consent records as evidence of a valid choice.
Sample consent text
We use cookies to improve your experience. Strictly necessary cookies are always on. Click Accept to allow analytics and other optional cookies, or Decline to keep only essential ones.
Third-party domains contacted
cdn.jsdelivr.netcdnjs.cloudflare.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| cookiebar | Functional | About 1 year | Stores the visitor consent state so the website remembers which cookie categories were accepted or declined. |
| cookiebar_dismissed | Functional | About 1 year | Remembers that the consent banner has been dismissed so it is not shown again on every visit. |
| cookieconsent_status | Functional | About 1 year | Records the accept or decline decision used to gate non essential cookies on the site. |
| cookiebar_prefs | Functional | About 1 year | Stores granular category preferences where the operator enables per category consent. |
Cookiebar is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Cookiebar sets a single strictly necessary first-party cookie that stores the visitor consent state, usually for around one year, plus a functional flag to remember the banner was dismissed. It does not set any tracking or advertising cookies of its own. Any other cookies on the page come from the services the operator chooses to load after consent.
No, the consent-state cookie that Cookiebar sets is strictly necessary and exempt from consent under Article 5(3) of the ePrivacy Directive. However, the very purpose of the banner is to collect consent for the other non essential cookies on your site. You must therefore configure it so those trackers only fire after the visitor accepts.
The consent-state cookie is strictly necessary and exempt under ePrivacy Art. 5(3), and the controller relies on legitimate interest to keep a record of the choice. Cookiebar does not itself require a consent legal basis. The cookies it gates, such as analytics and advertising, generally require the visitor consent that the banner collects.
No, Cookiebar processes nothing on a server and the consent cookie stays first-party in the visitor browser, so there is no transfer of personal data to the US. If you load the script from a public CDN, only the technical file request reaches the CDN provider. Any US transfers come from the third-party services you enable after consent, not from Cookiebar.
A standalone DPIA is rarely needed for Cookiebar because it only sets a strictly necessary cookie and performs no profiling. The meaningful assessment concerns the third-party trackers the banner is meant to control, which can carry higher risk. Confirm that your implementation actually blocks non essential cookies before consent rather than merely showing a notice.
Self-host or pin the script, then wire your analytics and advertising tags so they only load after the visitor accepts the relevant category. Document the cookies you use in a clear cookie policy and test that declining truly prevents non essential cookies. Remember that a banner alone is not compliance; prior blocking of trackers is what makes the setup lawful.
Cookiebar is a simple banner library, so alternatives range from other open-source scripts to full consent management platforms such as Cookiebot, OneTrust, or Usercentrics. Dedicated platforms add prior blocking, granular categories, consent logging, and IAB TCF signals that simple libraries lack. Choose based on how much auditability and granularity your trackers and jurisdictions demand.
List the strictly necessary consent cookie that Cookiebar sets, including its purpose and roughly one-year duration, and explain that it stores the visitor choice. Most importantly, document every non essential cookie that the banner gates, with its provider, purpose, and retention. Keep the policy in step with the categories you actually present in the banner.