Tracker library

OneTrust: what it is, what it sets, and how to gate it.

A consent platform whose narrowly scoped preference cookies may be necessary to remember a choice. The exemption depends on the exact purpose and payload, not the vendor name.

Vendor
OneTrust
Scanner category
functional
Consent category
Usually necessary for the stored choice; verify payload
Control
Custom script or container tag

What it is

OneTrust is a consent and privacy management platform. Its cookies record the visitor’s decision so the banner does not reappear and so gated scripts know what they are allowed to do.

Storage limited to remembering and enforcing the visitor’s choice is commonly treated as necessary for the requested preference function. Review the actual fields and uses: analytics, identifiers or unrelated CMP features do not become exempt merely because the same vendor supplied them.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so OneTrust is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • onetrust.com
  • cookielaw.org
  • cookiepro.com
  • optanon.blob.core.windows.net

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
OptanonConsentThe visitor’s recorded consent state
OptanonAlertBoxClosedWhether the banner has been dismissed, and when
eupubconsent*IAB TCF consent string storage

Controlling it with consent

Do not gate storage that is genuinely limited to remembering the visitor’s choice. If an old OneTrust cookie is present, inspect a fresh profile and current network and script activity before deciding that OneTrust is still running; stale cookies can survive removal of the loader.

If you are migrating, the thing to check is that two consent systems are not running at once. Two banners produce contradictory states, unexplainable records, and scripts that consult whichever one answered first.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: the old platform’s behaviour, which is the intended outcome of a migration.

Verifying it

If a fresh profile receives OptanonConsent alongside another platform’s cookie, investigate a possible overlapping implementation. A cookie found only in an existing profile can be stale and is not proof that the old script still loads.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Do consent cookies themselves need consent?

Storage narrowly limited to remembering and enforcing a choice is commonly treated as necessary for that requested preference function. Verify the actual payload and purpose; unrelated analytics or identifiers are not exempt merely because a CMP sets them.

What should I check when replacing a consent platform?

That only one banner renders, that the old platform’s script is gone from the theme and from every container, and that scripts previously gated by it are now gated by the new one rather than ungated.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.