What it is
Prior consent is consent given before the act it authorises. In the cookie context the act is storing information on, or reading information from, the visitor’s device, so prior consent means nothing optional is stored or read until a choice has been made.
Implementation depends on ordering. A tag manager loaded in the document head or a self-initialising pixel may make requests before a banner renders unless denied defaults, tag-level conditions or loader gating were established first.
What it requires technically
- 1
Do not create the loader
The most robust pattern is to keep an executable third-party script out of the document until its condition is met. A correctly inert script placeholder can also work, but hiding an executable element, merely deferring it or setting a flag after execution does not undo an earlier request.
- 2
Establish denied defaults where a vendor supports them
For vendors with a consent signal (Google Consent Mode is one documented example), denied defaults must be set before the container loads, not after.
- 3
Handle the late arrival
A script that was requested before withdrawal can still finish loading afterwards. The adapter has to send the revoke signal to whatever turns up late.
- 4
Verify in a browser
Source inspection cannot tell you what executed. A scan that drives a real browser in each consent state can.
What is exempt
Article 5(3) exempts storage or access that is strictly necessary to provide a service the subscriber or user explicitly requested, and what is solely needed to transmit a communication. A narrowly used login session, an active shopping basket, load-balancer affinity and storage limited to remembering a requested consent choice are common candidates; the actual purpose and implementation still have to satisfy the narrow test. UK law now also has additional purpose-limited exceptions that are not identical to the EU position.
"We need it for our business" is not the test
The exemption is about what is strictly necessary to transmit a communication or provide the service the visitor requested, not merely what the site finds useful. A claimed analytics or audience-measurement exemption must satisfy the specific conditions published or recognised in the relevant jurisdiction.
Common questions
Does prior consent mean a blocking overlay?
No. It concerns the timing of non-exempt storage or access, not whether the notice blocks the whole screen. StrongPrivacy defaults to a bottom-right notice and withholds declared gated loaders until the mapped grant.
What happens if the visitor never answers?
Under StrongPrivacy’s opt-in model, no declared gated loader is granted by a timeout. A visitor who does not answer remains unconsented for those categories; independently installed or server-side technologies still need separate enforcement.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- ICO: guidance on storage and access technologies
Regulator guidance
Checked
- ICO: exceptions to the storage and access rules
Regulator guidance
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.