Website cookie consent is the practice of telling visitors which cookies you use and storing their choice before optional scripts run. A banner that only says “by continuing you agree” while analytics has already fired has not managed preferences. It has decorated the page.
This article is about implementation behaviour. It is not legal advice. Malaysia does not need a fictional “cookie act” invented for this page. Personal data in cookies can still fall under the Personal Data Protection Act 2010 when the data identifies a person. Application security topics such as sessions and injection are covered separately in web application security.
Categories that keep the banner honest
| Category | Examples | Typical treatment |
|---|---|---|
| Necessary | Load balancing, a cookie that remembers this consent choice, a security session the visitor asked for | Load without an optional opt-in, and say so |
| Functional | Language or region preference beyond the consent cookie | Optional, off until allowed if it is not essential |
| Analytics | Measurement of page visits | Off until the visitor opts in, if you are treating it as optional |
| Marketing | Ad networks, retargeting, embedded campaigns | Off until the visitor opts in |
Name the categories in plain language and list the cookies or tools inside them. “We value your privacy” with no list is not a preference centre.
The interface
- Offer accept, reject optional cookies, and a way to choose categories. A single “Accept” button with no reject path is not a preference.
- Do not pre-tick optional categories.
- Store the choice and its date. The consent cookie itself is necessary so you do not ask on every click and so you can prove what was stored.
- Let people reopen the preference centre from the footer and change their mind.
- When they withdraw analytics or marketing, stop those scripts on the next page and remove the cookies you set for them, as far as the browser allows.
- Keep the banner keyboard usable and readable. A dialog nobody can dismiss is an accessibility defect. See website accessibility.
Load tag managers in a mode that does not drop analytics cookies before the choice. Many sites fail here: the banner appears late, after the tags have already run.
A consent choice that scripts obey
- Page loads with only necessary cookies
- Visitor accepts, rejects, or sets categories
- The choice is stored
- Optional scripts run only for allowed categories
- A later change stops the scripts that were withdrawn
Forms and CRM handoff
An enquiry form is not a cookie banner. If the form also opts someone into newsletters, that tick must be separate and unchecked by default. How a CRM should store that flag is described in CRM email logging and consent.
A practical example
A marketing site wants visit statistics and a chat widget. Before consent, only the session and the consent cookie exist. “Reject optional” leaves analytics and chat unloaded. “Analytics only” loads the measurement tool and not the chat. The footer link “Cookie preferences” reopens the same panel six months later. A test in a private window confirms the analytics request is absent until accept.
Key takeaways
- Classify cookies and block optional ones until a choice is stored.
- Provide accept, reject, and a way to change the choice later.
- Do not claim a Malaysian cookie statute this page cannot cite.
- Test in a fresh browser: optional tags must be absent before consent.
FAQ
Do we need a banner if we only use a session cookie?
You still should say, in a short notice, which necessary cookies exist. A full marketing-style banner is for optional analytics and advertising cookies.
Is a consent tool a complete PDPA programme?
No. It records a cookie choice. Notices, access requests, and how long you keep form data are wider duties. Get advice for those.
Should the banner block the whole page?
Only if you can still reach the reject control. A wall that cannot be operated by keyboard, or that hides the only “no,” will be ignored or will trap people.