BlueOcean Privacy AI
Guides

Privacy for websites — explained simply.

Cookie banners, tracking, consent mode, warning-letter risks: the key topics, clear and jargon-free.

GDPR-compliant cookie banners: how to avoid complaints and penalties

What a cookie banner must look like in 2026 to be legally sound across the EU: "Reject all" on the first level, no dark patterns, trackers only after consent.

Read →

Google Consent Mode v2: What you need to know

What is Google Consent Mode v2, is it mandatory and how do you set it up in compliance with the GDPR? Clearly explained for agencies and website operators.

Read →

Tracking without consent — how high is the legal risk?

Why trackers that fire before consent are the biggest legal risk under the ePrivacy Directive and the GDPR — and how you as an agency can protect yourself and your clients.

Read →

Cookiebot alternative: when it's worth switching

Cookiebot, Usercentrics & Co. become more expensive with every customer. When an alternative is worthwhile for agencies - and what you should look out for.

Read →

Data protection for Shopify and WordPress sites

What's important when it comes to data protection for Shopify and WordPress websites: trackers, plugins, cookie banners and the typical pitfalls.

Read →

Usercentrics alternative: cheaper, with multi-client & privacy policy

Are you looking for an alternative to Usercentrics/Cookiebot? Comparison of options for web agencies - incl. multi-client cockpit, tracker scanner and automatic privacy policy from €49/month.

Read →

Cookie banner for Webflow: GDPR-compliant & warning-proof

Webflow's native consent solution does not reliably block trackers before consent is given. How to make a Webflow page GDPR-compliant - with pre-consent blocking, privacy policy and tracker scan.

Read →

OneTrust alternative: leaner, cheaper, GDPR-focussed

OneTrust is powerful, but often oversized and expensive for agencies and SMEs. The lean alternative with cookie banner, automatic privacy policy, tracker scanner and multi-client cockpit - from €49/month.

Read →

CookieFirst alternative: banner + privacy text + scanner in one

CookieFirst provides a good cookie banner - but no privacy policy and only a basic scan. The alternative bundles banner, growing privacy text, tracker scanner and multi-client cockpit from €49/month.

Read →

Borlabs cookie alternative: for all CMS, with data protection text

Borlabs Cookie is a good WordPress plugin - but WordPress-only and without a privacy policy. The alternative runs on any CMS, blocks trackers before consent and automatically creates the privacy policy text. From €49/month.

Read →

Google Analytics 4 & GDPR: What agencies need to know in 2026

GA4 is not automatically GDPR-compliant. The essentials: consent BEFORE loading, Consent Mode v2, a data processing agreement with Google. The checklist for agencies across the EU.

Read →

Google Fonts & GDPR: Why the integration is warned

Dynamically loaded Google Fonts transmit the IP address to Google - without consent, a warning can be issued. How to embed fonts locally in a legally compliant way.

Read →

Google reCAPTCHA & GDPR: Consent or alternative?

reCAPTCHA transfers data to Google, often as soon as it is loaded. When consent is required and what data protection-friendly alternatives are available.

Read →

Meta pixel & GDPR: Tracking only with clear consent

The meta pixel shares visitor data with Facebook - without consent, a clear warning can be issued. What agencies need for legally compliant conversion tracking.

Read →

ChatGPT & GDPR: How to use AI in your company in a legally compliant manner

ChatGPT in business: when it is GDPR-compliant, what you need to look out for when making entries and why the free version can be risky

Read →

Google Maps & GDPR: Load map only after consent

An embedded Google Maps map loads data from Google and sets cookies - problematic without consent. How to embed maps in a legally compliant way.

Read →

YouTube embeds & GDPR: nocookie + consent instead of tracking

A normal YouTube embed sets tracking cookies before the video runs. How to embed videos in a legally compliant way: nocookie domain plus consent/two-click.

Read →

Calendly & GDPR: Appointment booking with consent & AV contract

Calendly is a US service that transfers data and sets cookies. What you need for legally compliant integration - and EU alternatives.

Read →

Mailchimp & GDPR: Use US newsletters legally compliant

Mailchimp is based in the USA. Can be used with an AV contract, double opt-in and transparency - or as an EU alternative. The points for agencies.

Read →

HubSpot & GDPR: CRM, tracking cookies & US transfer

HubSpot sets tracking cookies and transfers data to the USA. Can be used with an AV contract, consent for tracking and correct configuration.

Read →

Microsoft 365 & Copilot: Data protection in the company

M365 and Copilot can be operated in compliance with data protection regulations - with an AV contract (DPA), EU Data Boundary and clear Copilot rules. What counts.

Read →

Hotjar & GDPR: Session recording only with clear consent

Hotjar records user behaviour (heatmaps, recordings) - particularly sensitive. Mandatory: consent before loading, masking, AV contract.

Read →

Canva & GDPR: Using the design tool in a legally compliant way

Canva can be used as a business tool - with an AV contract and caution with personal data in uploads. The most important points for teams.

Read →

Free GDPR check: Does your website load trackers before consent?

Check your website for GDPR risks free of charge: Which trackers fire before consent? Cookie banner, privacy policy, SSL - in 5 minutes, without registration.

Read →

CCM19 alternative for web agencies: when it's worth switching

CCM19 is a strong German consent tool. For agencies, however, it lacks a privacy policy that grows with the company and an ongoing consent scan. The 2026 comparison.

Read →

consentmanager alternative for agencies: Why BlueOcean Privacy AI scales more favourably

consentmanager is a powerful CMP with IAB TCF and Crawler. It is expensive for agencies with many customer sites. BlueOcean: Banner, AI privacy policy and scanner from €49.

Read →

Compliance alternative: not just reporting trackers, but solving them

Complianty monitors customer websites closely. But monitoring alone doesn't fix a breach. Why BlueOcean Privacy AI solves the problem in the same stack.

Read →

Is a cookie banner mandatory?

Is a cookie banner mandatory? Yes, as soon as non-essential cookies or trackers run (ePrivacy Directive Art. 5(3), GDPR). When it is not required across the EU - and what a legally compliant banner must be able to do.

Read →

What does a cookie warning really cost?

Warning costs, damages and the risk of fines for cookie and data protection violations - realistically categorised, plus how to avoid warnings from the outset.

Read →