Skip to content

Worldwide regulations

Global privacy coverage without pretending one banner solves every law.

COKIQ now maps the major website consent regions teams ask about: GDPR, UK GDPR, India DPDP, CCPA/CPRA, US state privacy, GPC and GPP signal readiness, Brazil LGPD, Canada PIPEDA, South Africa POPIA, Singapore PDPA, Gulf privacy laws, China PIPL, APAC, LATAM, Google Consent Mode v2, and IAB TCF roadmap.

Available workflow2
Supported with legal review32
Roadmap / framework-specific1

This page is a product capability map, not legal advice or a compliance certificate. Legal wording, jurisdiction applicability, and regulator-specific decisions still need customer-side counsel review where required.

Claim discipline

What we can provide, and why some items stay in review.

The goal is to compete with bigger CMP platforms without copying claims we cannot prove. COKIQ separates product evidence, legal-review support, and external certification work.

Available product workflow

COKIQ can scan the site, detect cookies and scripts, show banner choices, block known non-essential trackers, update Google Consent Mode v2, record consent evidence, and export reports.

EU GDPR/ePrivacy workflowIndia DPDP workflowConsent Mode v2 mappingGPC/US opt-out signal evidenceEvidence Reports

Supported with legal review

COKIQ can provide the operational workflow and evidence pack, but local applicability, exact wording, threshold checks, data-transfer positions, and sector-specific requirements need customer-side counsel review.

UK PECRUS state privacy lawsIAB Tech Lab GPP implementation pathLGPDPIPEDAPOPIASingapore PDPAUAE/Saudi/Gulf lawsChina PIPLAPAC and LATAM laws

Roadmap or not claimed

Some items require external certification, formal audit, marketplace approval, verified self-attestation, or a separate technical standard. COKIQ labels these clearly instead of presenting future work as current compliance.

IAB Tech Lab GPP self-attestation after implementationGoogle CMP certificationIAB TCF production supportSOC 2 / ISO 27001Attorney compliance certificatePlatform marketplace apps

Legal applicability is customer-specific

Many laws depend on user location, company location, revenue, sector, processing purpose, sensitive data, employee/customer context, and whether data is sold, shared, transferred, or profiled.

Certifications are external approvals

Google CMP certification, IAB TCF participation, app-store approval, SOC 2, and ISO cannot be self-declared by COKIQ. They need program review, audits, or third-party certification.

Country wording needs counsel

COKIQ can produce evidence and workflow checklists, but final privacy notices, DPA terms, transfer language, Arabic/local-language clauses, and regulator-facing legal conclusions need qualified review.

Tracker coverage changes constantly

Pixels, tag managers, chat widgets, video embeds, affiliate scripts, and ecommerce apps change often. COKIQ supports known blocking patterns and scan evidence, then expands vendor recipes through QA.

What COKIQ provides

The actual deliverables we can stand behind.

This is the practical coverage customers can expect from COKIQ today. The product helps teams operate consent correctly; it does not replace a lawyer or claim certifications that are not granted.

Website cookie and script scanner
Cookie, pixel, analytics, chat, embed, and third-party tracker inventory
Cookie category review for necessary, analytics, marketing, preferences, and unknown scripts
Consent banner setup with accept, reject, and custom choices
Consent preferences revisit control
Runtime geo/regulation profiles for EU/UK, US, India, Brazil, Canada, South Africa, Singapore, Gulf, China, Hong Kong, Malaysia, Indonesia, Philippines, Australia, New Zealand, Switzerland, Japan, South Korea, Thailand, Turkey, LATAM, APAC, and global default handling
Global Privacy Control detection with marketing/sale-share opt-out enforcement
GPP and US privacy signal readiness path for IAB Tech Lab free Specification Adoption after production verification
US Do Not Sell or Share banner action for US profile visitors
Consent expiry and policy-version re-consent checks
Richer consent receipt evidence for profile, region, country, GPC/DNT state, banner version, policy version, and expiry
Known tracker auto-blocking for major analytics, marketing, chat, and support scripts
Iframe and embed consent placeholders for YouTube, Vimeo, Google Maps, social embeds, and Calendly
Blocked-script and blocked-embed evidence in runtime events and consent receipts
Google Consent Mode v2 default and update signal mapping
Consent and preference logs with timestamp, site, category state, region, and policy-version evidence
Cookie policy and privacy policy draft workflow
Scanner-synced cookie policy inventory with policy version and sync evidence
Admin evidence reports with scan baseline, policy inventory, consent receipts, GPC, banner version, and blocker evidence
JSON, PDF, and CSV evidence export path for authenticated dashboard users
Policy link checks and policy-version evidence
Monthly or change-based rescan reports
Dashboard compliance snapshot across connected domains
Agency/client portfolio reporting path
Installation support for custom HTML, Google Tag Manager, WordPress, Shopify, WooCommerce, WHMCS, Webflow, Wix, Next.js, React, Vue/Nuxt, and Laravel/PHP
Trust assets: privacy policy, cookie policy, DPA summary, subprocessors, data retention, support policy, security overview, and vendor questionnaire
Managed setup and review handoff for India, Gulf, SMB, agency, SaaS, ecommerce, and enterprise websites

Needs legal or customer review

  • Country-specific legal wording and final attorney sign-off
  • Whether a law applies to a specific customer, industry, revenue threshold, or user base
  • Data Processing Agreement negotiation and customer procurement review
  • Do Not Sell or Share / sensitive-data disclosures for US state privacy programs
  • Arabic, local-language, or sector-specific notices where local counsel requires them
  • Cross-border transfer analysis and regulator-facing legal positions

Not claimed yet

  • IAB Tech Lab GPP Specification Adoption submission
  • IAB TCF production support
  • Google CMP certification
  • SOC 2 or ISO 27001 certification
  • Attorney-issued compliance certificate
  • Automatic country-by-country legal advice
  • Fully localized legal notice library for every jurisdiction
  • WordPress, Shopify, or Wix marketplace app certification

How we add coverage

A proper rollout path for every new law.

COKIQ can keep adding regions, but each one must move through a source-backed product process before the website says it is available.

  1. 1Start from official regulator or legal-source reference, not competitor marketing copy.
  2. 2Map the website-level duties: notice, consent, opt-out, withdrawal, policy, rights route, transfer review, and evidence.
  3. 3Translate those duties into product controls: banner profile, categories, GPC/opt-out behavior, Consent Mode mapping, blocker rules, and report fields.
  4. 4Keep legal-review notes visible when the item depends on counsel, threshold analysis, localization, or external certification.
  5. 5Verify with scan results, policy inventory, consent receipts, script/iframe blocker events, and exportable Evidence Reports.
  6. 6Promote a region from roadmap/review to available only after implementation, testing, documentation, and public claim review are complete.

Coverage map

Major privacy laws and what COKIQ can operationalize.

European Union / EEA

GDPR and ePrivacy cookie consent

Available workflow

EU-facing websites usually need prior consent for non-essential cookies, granular choices, easy withdrawal, and evidence of the visitor choice.

Website focus

  • Prior consent before analytics and marketing tags
  • Granular categories and no pre-ticked choices
  • Cookie and privacy policy visibility
  • Consent logs and policy-version evidence

COKIQ support

  • Scanner-led cookie discovery
  • Category-based banner choices
  • Consent Mode v2 mapping
  • Consent logs and reports
Source: European Commission GDPR framework

United Kingdom

UK GDPR and PECR

Supported with legal review

UK cookie compliance combines UK GDPR personal-data duties with PECR rules for storing or accessing information on a user device.

Website focus

  • Clear cookie notice
  • Consent before non-essential cookies
  • Withdrawal path
  • Proof of preferences

COKIQ support

  • Cookie scanner
  • Banner controls
  • Policy links
  • Exportable consent records
Source: UK ICO cookie guidance

India

Digital Personal Data Protection Act, 2023

Available workflow

India DPDP work focuses on clear notice, consent, withdrawal, data principal rights, purpose limitation, and accountability for digital personal data.

Website focus

  • Simple notice and purpose clarity
  • Consent and withdrawal records
  • Grievance/contact route
  • Periodic review of pixels, analytics, forms, and chat widgets

COKIQ support

  • DPDPA page and guide
  • Consent logs tied to policy versions
  • Website scan reports
  • Operational checklist for Indian SMB and agency sites
Source: India Code DPDP Act, 2023

United States

CCPA/CPRA and US state privacy laws

Supported with legal review

US privacy work often centers on notice, opt-out choices, sale/share disclosures, sensitive-data handling, and recurring tracker review.

Website focus

  • Do Not Sell or Share review where applicable
  • Advertising and analytics tracker discovery
  • Privacy policy disclosures
  • Consumer request workflow

COKIQ support

  • CCPA page
  • Tracker and pixel scans
  • Preference evidence
  • Recurring campaign-page reports
Source: California DOJ CCPA overview

United States - Virginia

Virginia Consumer Data Protection Act

Supported with legal review

Virginia CDPA programs need privacy notices, consumer rights routing, opt-out controls for targeted advertising or sale where applicable, and records for operational review.

Website focus

  • Consumer rights request route
  • Targeted advertising opt-out review
  • Cookie and tracker disclosure
  • Preference and evidence records

COKIQ support

  • US opt-out workflow foundation
  • Tracker scans
  • Consent evidence
  • Legal-review handoff
Source: Virginia Attorney General CDPA overview

United States - Colorado

Colorado Privacy Act

Supported with legal review

Colorado privacy work includes consumer rights, targeted advertising and sale opt-outs, sensitive-data review, and recognition of universal opt-out signals.

Website focus

  • Universal opt-out signal handling
  • Do Not Sell or targeted advertising review
  • Sensitive-data notice review
  • Consumer rights routing

COKIQ support

  • GPC-ready roadmap
  • US opt-out workflow foundation
  • Tracker discovery
  • Consent and preference exports
Source: Colorado Attorney General CPA resources

United States - Utah

Utah Consumer Privacy Act

Supported with legal review

Utah privacy readiness focuses on clear notices, consumer rights routing, opt-out review for sale or targeted advertising, and practical tracker documentation.

Website focus

  • Privacy notice review
  • Targeted advertising opt-out review
  • Cookie and pixel inventory
  • Consumer request workflow

COKIQ support

  • US privacy workflow foundation
  • Tracker reports
  • Preference evidence
  • Legal-review notes
Source: Utah Consumer Privacy Act text

United States - Connecticut

Connecticut Data Privacy Act

Supported with legal review

Connecticut privacy programs require notices, consumer rights handling, targeted advertising and sale opt-outs, sensitive-data review, and evidence of choices.

Website focus

  • Opt-out workflow review
  • Consumer rights request route
  • Cookie and tracker disclosure
  • Sensitive-data review

COKIQ support

  • US opt-out workflow foundation
  • Tracker inventory
  • Consent logs
  • Reports for counsel review
Source: Connecticut Attorney General privacy law

United States - Texas

Texas Data Privacy and Security Act

Supported with legal review

Texas privacy readiness includes notices, consumer rights, opt-out controls, sensitive-data review, and operational evidence for qualifying businesses.

Website focus

  • Consumer rights route
  • Targeted advertising and sale opt-out review
  • Sensitive-data review
  • Website tracker documentation

COKIQ support

  • US opt-out workflow foundation
  • Tracker scans
  • Preference records
  • Legal-review handoff
Source: Texas TDPSA overview

United States - newer state laws

Florida, Montana, Iowa, Indiana, Tennessee, Delaware, New Jersey, Nebraska, New Hampshire, Maryland, Minnesota and similar state privacy programs

Supported with legal review

Newer US privacy laws expand the need for notices, opt-out review, sensitive-data handling, universal opt-out signal review, and recurring tracker documentation across more state audiences.

Website focus

  • State-by-state applicability review
  • Targeted advertising and sale opt-out review
  • Universal opt-out signal review where required
  • Cookie and pixel evidence for legal teams

COKIQ support

  • US privacy workflow foundation
  • GPC signal evidence where observed
  • Tracker and pixel inventory
  • Reports for counsel review
Source: FTC privacy and security business guidance

United States - Oregon

Oregon Consumer Privacy Act

Supported with legal review

Oregon privacy programs need notice, consumer rights routing, opt-out support, and attention to sensitive-data handling and tracker disclosures.

Website focus

  • Consumer rights route
  • Opt-out workflow review
  • Cookie and tracker disclosure
  • Sensitive-data review

COKIQ support

  • US privacy workflow foundation
  • Tracker reports
  • Preference logs
  • Reports for counsel review
Source: Oregon Department of Justice OCPA

Brazil

LGPD

Supported with legal review

Brazil LGPD applies personal-data principles to cookies and tracking where they identify or can relate to a person.

Website focus

  • Specific purpose disclosure
  • Non-essential cookie controls
  • Cookie-policy detail
  • Easy reject and preference management

COKIQ support

  • Cookie inventory
  • Banner category workflow
  • Policy-review evidence
  • Reports for counsel review
Source: Brazil ANPD cookie guidance

Canada

PIPEDA and provincial privacy laws

Supported with legal review

Canadian website privacy work usually requires meaningful consent, purpose clarity, safeguards, access rights, and accountable data handling.

Website focus

  • Meaningful consent language
  • Purpose and third-party disclosure
  • Retention and access request route
  • Cookie and analytics transparency

COKIQ support

  • Policy link checks
  • Cookie category review
  • Consent records
  • Monthly reports
Source: Office of the Privacy Commissioner of Canada

South Africa

POPIA

Supported with legal review

POPIA regulates processing of personal information and requires accountable, purpose-limited handling of personal data collected through digital channels.

Website focus

  • Collection notice
  • Purpose limitation
  • Security safeguards
  • Direct marketing and profiling review

COKIQ support

  • Tracker discovery
  • Consent and preference logging
  • Policy evidence
  • Report exports
Source: South African Government POPIA page

Singapore

PDPA

Supported with legal review

Singapore PDPA sets baseline personal-data protection duties including consent, purpose notification, protection, retention, transfer, and accountability.

Website focus

  • Consent and purpose notice
  • Personal-data cookies and identifiers
  • Withdrawal request path
  • Transfer and retention controls

COKIQ support

  • Banner and policy workflow
  • Cookie scan history
  • Consent logs
  • Operational reports
Source: Singapore PDPC PDPA overview

United Arab Emirates

UAE Personal Data Protection Law

Supported with legal review

UAE privacy readiness needs clear notice, consent or lawful-basis review, data subject request routing, security controls, and transfer review for websites serving UAE users.

Website focus

  • Arabic/English notice review where needed
  • Consent and purpose records
  • Cross-border transfer review
  • Marketing pixel and WhatsApp/contact-form audit

COKIQ support

  • Cookie and script scans
  • Consent records
  • Policy-readiness reports
  • Managed setup path for UAE SMBs
Source: UAE data protection laws overview

Saudi Arabia

Personal Data Protection Law

Supported with legal review

Saudi PDPL readiness focuses on notice, lawful processing, consent where required, rights handling, transfer review, security, and local regulatory alignment.

Website focus

  • Arabic/English privacy notice review
  • Consent and purpose evidence
  • Cross-border transfer review
  • Marketing and analytics tracker review

COKIQ support

  • Cookie and script scans
  • Consent and preference records
  • Policy-readiness reports
  • Managed setup path for Saudi-facing websites
Source: SDAIA Saudi PDPL guide

Qatar / Bahrain / wider Gulf

Gulf privacy and personal-data protection laws

Supported with legal review

Wider Gulf privacy work varies by jurisdiction, but websites commonly need clear notice, consent or lawful-basis review, contact-form discipline, tracker transparency, and local counsel review.

Website focus

  • Country-specific notice review
  • Marketing and analytics tracker inventory
  • Consent or opt-out control review
  • Local-language and transfer review where needed

COKIQ support

  • Scan baseline
  • Banner configuration
  • Consent evidence
  • Reports for local counsel review
Source: Qatar National Data Privacy Office

APAC broader coverage

Australia, New Zealand, Japan, Korea, Thailand, Indonesia, Philippines

Supported with legal review

APAC privacy rules vary by country, but website operations commonly need notice, consent or lawful-basis review, purpose clarity, retention discipline, and user-rights routing.

Website focus

  • Country-specific notice review
  • Tracker and analytics transparency
  • Consent or opt-out controls where relevant
  • Exportable evidence for local counsel

COKIQ support

  • Scan baseline
  • Banner configuration
  • Consent evidence
  • Recurring reports
Source: Singapore PDPC regional baseline reference

Australia

Privacy Act and Australian Privacy Principles

Supported with legal review

Australian privacy readiness focuses on transparent collection notices, cookie and tracking disclosure, direct marketing review, security, and access/correction request handling.

Website focus

  • Collection notice
  • Cookie and analytics transparency
  • Direct marketing review
  • Access and correction route

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Consent and preference records
  • Reports for counsel review
Source: OAIC Privacy Act overview

Thailand

Personal Data Protection Act

Supported with legal review

Thailand PDPA website work usually needs notice, consent or lawful-basis review, withdrawal handling, rights request routing, and data-transfer review.

Website focus

  • Notice and consent review
  • Withdrawal route
  • Cookie and tracker transparency
  • Rights request handoff

COKIQ support

  • APAC scan baseline
  • Banner configuration
  • Consent evidence
  • Legal-review reports
Source: Thailand PDPC

China

Personal Information Protection Law

Supported with legal review

China PIPL readiness for websites needs purpose disclosure, consent or separate-consent review, rights request routing, cross-border transfer review, and local legal validation.

Website focus

  • Purpose and processor disclosure
  • Consent and separate-consent review
  • Cross-border transfer review
  • Rights request route

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Consent or preference records
  • Legal-review handoff
Source: China PIPL English text reference

Hong Kong

Personal Data (Privacy) Ordinance

Supported with legal review

Hong Kong PDPO website readiness focuses on collection notices, purpose clarity, data-user accountability, direct marketing review, security, and rights request handling.

Website focus

  • Personal information collection statement review
  • Purpose and use disclosure
  • Direct marketing review
  • Access and correction route

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Preference records
  • Legal-review reports
Source: Hong Kong PCPD PDPO overview

Malaysia

Personal Data Protection Act

Supported with legal review

Malaysia PDPA readiness needs notice, consent review, disclosure purpose, security safeguards, retention discipline, and review of transfer or processor arrangements.

Website focus

  • Privacy notice and consent review
  • Cookie and tracker transparency
  • Retention and security review
  • Transfer and processor review

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Consent and preference records
  • Reports for legal review
Source: Malaysia Personal Data Protection Department

Indonesia

Personal Data Protection Law

Supported with legal review

Indonesia PDP readiness for websites needs clear notice, lawful processing review, consent or rights handling, security safeguards, and local regulatory review for electronic systems.

Website focus

  • Notice and lawful-basis review
  • Consent and withdrawal route
  • Cookie and tracker transparency
  • Rights request and security review

COKIQ support

  • APAC scan baseline
  • Banner configuration
  • Consent evidence
  • Legal-review reports
Source: Indonesia PDP law reference

Philippines

Data Privacy Act

Supported with legal review

Philippines privacy readiness focuses on transparency, legitimate purpose, proportionality, consent or lawful processing review, security, and data-subject rights routing.

Website focus

  • Transparency and purpose notice
  • Consent or lawful-basis review
  • Cookie and tracker inventory
  • Rights request and security route

COKIQ support

  • APAC scan baseline
  • Policy evidence
  • Consent records
  • Reports for legal review
Source: Philippines National Privacy Commission DPA

Canada - Quebec

Quebec Law 25

Supported with legal review

Quebec Law 25 adds privacy governance, transparency, consent, and confidentiality-by-default expectations that can affect website cookies and trackers.

Website focus

  • Consent and notice review
  • Privacy-by-default checks
  • Cookie and tracker transparency
  • Rights request route

COKIQ support

  • Tracker discovery
  • Policy link checks
  • Consent evidence
  • Reports for legal review
Source: Quebec privacy commission Law 25

Switzerland

Federal Act on Data Protection

Supported with legal review

Swiss FADP readiness includes transparent processing notices, purpose clarity, data subject rights routing, and transfer/vendor review where tracking identifies people.

Website focus

  • Transparent notice
  • Cookie and tracker disclosure
  • Rights request route
  • Cross-border transfer review

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Preference records
  • Legal-review reports
Source: Swiss FDPIC data protection law

Japan

Act on the Protection of Personal Information

Supported with legal review

Japan APPI website readiness focuses on purpose disclosure, personal-data handling transparency, third-party transfer review, and user request routing.

Website focus

  • Purpose disclosure
  • Cookie and tracker review
  • Third-party transfer review
  • User rights request route

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Consent or opt-out records
  • Legal-review handoff
Source: Japan PPC APPI

South Korea

Personal Information Protection Act

Supported with legal review

South Korean privacy readiness often requires detailed notice, consent review, third-party disclosure, retention controls, and rights request handling.

Website focus

  • Detailed notice review
  • Consent and third-party disclosure
  • Retention review
  • Rights request route

COKIQ support

  • APAC scan baseline
  • Consent evidence
  • Policy reports
  • Legal-review handoff
Source: Korea PIPC

New Zealand

Privacy Act 2020

Supported with legal review

New Zealand website privacy readiness requires clear collection notices, purpose and disclosure transparency, security, retention discipline, and access/correction request handling.

Website focus

  • Collection notice
  • Cookie and analytics transparency
  • Disclosure and transfer review
  • Access and correction route

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Preference records
  • Reports for counsel review
Source: New Zealand Privacy Commissioner

Turkey

Personal Data Protection Law

Supported with legal review

Turkey KVKK readiness needs information notice review, explicit-consent review where required, transfer review, data security, and request handling.

Website focus

  • Information notice review
  • Explicit consent review
  • Cookie and tracker transparency
  • Transfer and rights request route

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Consent records
  • Reports for legal review
Source: Turkey KVKK law

Mexico

Federal Law on Protection of Personal Data Held by Private Parties

Supported with legal review

Mexico privacy readiness for websites focuses on privacy notice quality, consent or exception review, ARCO rights routing, transfer disclosure, and security controls.

Website focus

  • Privacy notice review
  • Consent and transfer disclosure
  • Cookie and tracker transparency
  • ARCO rights request route

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Consent or preference records
  • Legal-review reports
Source: Mexico INAI personal data section

Argentina

Personal Data Protection Law 25.326

Supported with legal review

Argentina privacy readiness includes notice, data-subject rights, database/controller accountability, purpose limitation, security, and transfer review where website tracking identifies people.

Website focus

  • Privacy notice and purpose review
  • Cookie and tracker disclosure
  • Rights request route
  • Transfer and security review

COKIQ support

  • Tracker inventory
  • Policy evidence
  • Preference records
  • Reports for legal review
Source: Argentina AAIP personal data rights

Ads and publisher frameworks

Google Consent Mode v2 and IAB TCF

TCF roadmap, Consent Mode available

Advertising and publisher ecosystems add operational requirements on top of legal duties, especially for Google tags, remarketing, conversion tracking, and EU ad serving.

Website focus

  • Google consent defaults and updates
  • ad_user_data and ad_personalization mapping
  • GTM/GA4 verification
  • IAB TCF evaluation for publishers

COKIQ support

  • Consent Mode v2 compatible signals
  • Google-tag readiness checks
  • Install verification
  • IAB TCF on roadmap
Source: Google CMP / Consent Mode policy docs

Implementation discipline

What must be proper everywhere.

COKIQ should keep the same product promise across every market: scan first, control scripts, show clear choices, keep evidence, review changes, and avoid unsupported legal-certification claims.

Regional banner behavior
Country-aware policy wording
Consent Mode v2 defaults
Accept, reject, and custom logs
Policy version evidence
Monthly rescan reports
Customer legal-review notes
Roadmap labels for TCF/certification