Skip to content

Configuration Checklist

Objectives

• Align cookie consent with Italian DPA (Garante) 10 June 2021 Guidelines.

• Ensure prior consent for non-essential cookies; granular choices; consent logs; easy withdrawal.

First Layer (Banner) — Required

• Language: Italian for Italy; clear, concise text.

• Buttons with equal prominence: “Accetta tutto” and “Rifiuta tutto”; plus “Gestisci preferenze”.

• No pre-ticked boxes; no ‘scroll = consent’. Persistent “Impostazioni cookie” link in footer.

Second Layer — Categories & Vendors

Define purposes and vendors. Default OFF except strictly necessary.

Categories (example):

1) Tecnici necessari (always on).

2) Analytics (GA4) — consent required unless fully anonymised per DPA criteria.

3) Marketing/Profilazione — keep OFF for Italy if not used.

4) Funzionalità — only if strictly necessary features exist.

Sample Italian Copy (Banner)

Usiamo cookie tecnici e, previo consenso, cookie di analisi per misurare l’audience. Puoi accettare tutti, rifiutare tutti o gestire le preferenze. In ogni momento puoi modificare la scelta dal link “Impostazioni cookie”.

Sample Italian Copy (Second Layer)

• Tecnici necessari: necessari al funzionamento del sito (non richiedono consenso).

• Analytics: ci aiutano a migliorare i contenuti; attivati solo con il tuo consenso.

• Marketing: cookie utilizzati per profilazione/pubblicità; non attivati in Italia.

• Funzionalità: migliorano alcune funzioni del sito.

GTM Implementation Steps

1) Configure CMP to send consent signals to GTM/Consent Mode.

2) Set GA4 config tag to fire only when analytics consent = granted.

3) Block/Consent-guard all other tags (Hotjar, advertising) behind user consent.

4) Store consent logs and provide a UI to change preferences later.

Testing & Audit Checklist

• Verify no analytics/marketing cookies before consent.

• Test ‘Reject all’ works on all pages/routes.

• Confirm GA4 hits only after consent; test across browsers/devices.

• Ensure “Impostazioni cookie” link is always visible and functional.

• Keep records: consent logs, CMP versioning, and periodic audits.