OneTrust Cookie Consent Configuration
VIDEO TRANSCRIPT | Recorded: 2025-10-30 | Verify against current system state
Abstract¶
Comprehensive overview of OneTrust cookie consent management system. Covers user-facing consent options (accept all, reject all, cookie settings, X button), GDPR vs non-GDPR behavior differences, cookie categorization (strictly necessary, functional, performance, social media, targeting), geolocation-based templates, cookie scanning procedures, and admin interface navigation.
Key Procedures¶
- Navigate to OneTrust admin as IT Support user
- Review consent analytics dashboard
- Scan website for new cookies (Cookie Compliance > Scan)
- Categorize uncategorized cookies after scan
- Configure GDPR vs Generic templates for different regions
- Set up geolocation rules for US, Global, and GDPR audiences
- Copy test/production scripts to CraftCMS
- Monitor opt-in/opt-out rates in dashboard
Notable Statements¶
- 0:00:54 "If you click accept all cookies, that's pretty self-explanatory"
- 0:01:09 "If you reject all, you are rejecting most cookies, but there's actually ones that we've categorized as strictly necessary"
- 0:01:21 "Strictly necessary cookies are things like our authentication cookie that is required for log on"
- 0:01:44 "Targeting cookies are things like feather, pixel... that are targeting you and sending your information to other sites"
- 0:02:02 "Performance cookies are more like Google Analytics... could include Sentry IO"
- 0:02:24 "Social media cookies are Twitter, Facebook pixels included here"
- 0:02:37 "Functional cookies are things that are required by third parties, like for example, SM Apply"
- 0:03:39 "In a GDPR legal requirements area like the EU, if you click the X... it defaults to rejecting all cookies"
- 0:03:53 "If you're anywhere else that doesn't have really strict GDPR like requirements... if you click the X, everything's accepted"
- 0:04:55 "We only have one website... we install a different script on the qa.com site"
- 0:05:77 "Most people are just accepting all cookies"
- 0:06:18 "It jumped when we went live with this to 8%. But then afterwards it kind of died off"
- 0:07:05 "If there are any cookies that aren't found, by default, they will be rejected"
- 0:08:28 "GDPR custom template will reject all cookies by default"
- 0:10:01 "This is a list of other countries that have some type of GDPR compliance requirement"
- 0:12:27 "We have really trimmed down our use of cookie consent down to the basics"
Systems & Configurations¶
Systems Mentioned¶
- OneTrust (cookie consent management)
- CraftCMS (website - receives consent scripts)
- Google Analytics (performance cookies)
- Sentry IO (performance cookies)
- SM Apply (functional cookies)
- Facebook Pixel (targeting/social media)
- Twitter (social media cookies)
Specific Configurations¶
| Item | Value/Setting | Timestamp | Notes |
|---|---|---|---|
| Managed domains | aanp.org only | 0:04:45 | QA uses different script |
| Templates | GDPR Custom, Generic | 0:08:28 | Different default behaviors |
| GDPR X behavior | Reject all | 0:03:47 | Except strictly necessary |
| Non-GDPR X behavior | Accept all | 0:03:54 | Default in US |
| Geolocation rules | US, Global, GDPR audiences | 0:09:32 | Three rule groups |
| US visitors | ~95% opt-in | 0:06:08 | Dashboard metric |
| EU visitors | Minuscule | 0:06:37 | Most traffic from US |
| Scripts | Test and Production | 0:10:68 | Different per environment |
Credentials/Access Mentioned¶
- IT Support user for OneTrust admin access
Vendor Contacts Mentioned¶
- Mighty Citizen (manages script deployment to CraftCMS)
Errors & Troubleshooting¶
- Issue: User reports functionality issues after cookie choice
- Cause: May have rejected functional or strictly necessary cookies
- Resolution: Have user check cookie settings and re-accept
-
Timestamp: 0:04:17
-
Issue: New cookies not categorized correctly
- Cause: Uncategorized cookies default to reject
- Resolution: Run scan and categorize new cookies
- Timestamp: 0:07:05
Transcript Gaps & Quality Notes¶
- Comprehensive admin overview (12 minutes)
- Training materials available in OneTrust
- Screen sharing not captured but well described
- Mentions consent section not currently used
- Cookie list embed script available but not deployed