Skip to main content

CCPA Compliance Implementation: No unapproved cookies fire on any page

A guide on how to maintain a compliant CCPA cookie inventory with ObservePoint.

Written by Luiza Gircoveanu

Overview

This check reconciles every cookie observed on the property against a documented, approved inventory that maps each cookie to a category (Strictly Necessary, Functional, Performance/Analytics, or Advertising/Sharing)and surfaces any cookie that is new, unapproved, or assigned to the wrong category.

Note: This guide is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel regarding your organization's specific CCPA/CPRA compliance obligations.

Why it is important

An "unknown" or uncategorized cookie is a compliance liability because regulators and consumers both assume the worst about undocumented data collection, and you cannot defend a cookie's presence, purpose, or retention period if it isn't in your inventory in the first place. This check can be partially, but not fully, automated. ObservePoint's crawl produces the observed inventory and flags drift against your approved list, but the initial categorization decision for any newly discovered cookie requires human review to determine its actual purpose and appropriate consent category.

Implementation

  1. Import your approved cookie categorization into ObservePoint's consent categories

  2. Configure a scheduled, full-property Audit with cookie inventory enabled, assign the consent categories to it (set_audit_consent_categories), and run it on a recurring cadence (weekly, or at minimum your quarterly full-site schedule).

  3. Check the pre-built ObservePoint report for Uncategorized or Unapproved Cookies, which reconciles the Audit's observed cookies against your approved mapping automatically.

  4. Detection is fully automated, but categorization isn't. The platform can tell you a cookie exists, not why a vendor sets it or which bucket it belongs in. Route any cookie the report surfaces to the vendor/tag owner for that determination, then add it back into your approved inventory and consent categories.

Remediation

For remediation, check the following steps:

  • For each newly discovered or miscategorized cookie, identify the owning vendor or script and determine its actual function and appropriate category. This step generally requires the tag/vendor owner rather than being resolvable from the cookie name alone.

  • Once categorized, update both your documented Cookie & Tag Inventory (see Documentation & Processes) and the corresponding consent category mapping in your CMP and in ObservePoint so future audits classify it correctly.

  • If the cookie was introduced by an unapproved vendor rather than an approved one operating outside spec, escalate through the Third-Party Vendors & Service Providers policy's unapproved-vendor remediation path rather than simply categorizing and moving on.

Conclusion

This check works best as a recurring reconciliation discipline rather than a one-time cleanup. Pair it with the quarterly full-site audit cadence so cookie drift is caught before it accumulates into a large, harder-to-triage backlog.

Did this answer your question?