Glossary

Prior consent

Consent obtained before the storage or access it authorises, rather than during or after that act; exemptions and the validity of consent still require their own analysis.

Source
ePrivacy Directive Art. 5(3)
Applies in
EEA and UK; purpose- and jurisdiction-specific elsewhere
Enforced by
The engine, not the banner

What it is

Prior consent is consent given before the act it authorises. In the cookie context the act is storing information on, or reading information from, the visitor’s device, so prior consent means nothing optional is stored or read until a choice has been made.

Implementation depends on ordering. A tag manager loaded in the document head or a self-initialising pixel may make requests before a banner renders unless denied defaults, tag-level conditions or loader gating were established first.

What it requires technically

  1. 1

    Do not create the loader

    The most robust pattern is to keep an executable third-party script out of the document until its condition is met. A correctly inert script placeholder can also work, but hiding an executable element, merely deferring it or setting a flag after execution does not undo an earlier request.

  2. 2

    Establish denied defaults where a vendor supports them

    For vendors with a consent signal (Google Consent Mode is one documented example), denied defaults must be set before the container loads, not after.

  3. 3

    Handle the late arrival

    A script that was requested before withdrawal can still finish loading afterwards. The adapter has to send the revoke signal to whatever turns up late.

  4. 4

    Verify in a browser

    Source inspection cannot tell you what executed. A scan that drives a real browser in each consent state can.

What is exempt

Article 5(3) exempts storage or access that is strictly necessary to provide a service the subscriber or user explicitly requested, and what is solely needed to transmit a communication. A narrowly used login session, an active shopping basket, load-balancer affinity and storage limited to remembering a requested consent choice are common candidates; the actual purpose and implementation still have to satisfy the narrow test. UK law now also has additional purpose-limited exceptions that are not identical to the EU position.

"We need it for our business" is not the test

The exemption is about what is strictly necessary to transmit a communication or provide the service the visitor requested, not merely what the site finds useful. A claimed analytics or audience-measurement exemption must satisfy the specific conditions published or recognised in the relevant jurisdiction.

Common questions

Does prior consent mean a blocking overlay?

No. It concerns the timing of non-exempt storage or access, not whether the notice blocks the whole screen. StrongPrivacy defaults to a bottom-right notice and withholds declared gated loaders until the mapped grant.

What happens if the visitor never answers?

Under StrongPrivacy’s opt-in model, no declared gated loader is granted by a timeout. A visitor who does not answer remains unconsented for those categories; independently installed or server-side technologies still need separate enforcement.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.