Introduction
*Updated for 2026 compliance practices.*
If you run a Squarespace website that serves visitors from Belgium, cookie compliance is not just a box‑ticking exercise—it’s an ongoing obligation under the GDPR and the Belgian implementation of the ePrivacy Directive. A **Squarespace cookie compliance Belgium privacy evidence and monitoring checklist** helps you systematically confirm that consent is collected before non‑essential cookies fire, that your privacy disclosures are accurate, and that you can demonstrate compliance when asked. This guide gives you a practical, step‑by‑step approach to building that checklist, verifying your setup with GDPRChecker scans, and maintaining evidence over time.
Why Belgian Website Owners Need a Specific Checklist
Belgium is part of the EU, so the GDPR applies directly. However, the Belgian implementation of the ePrivacy Directive (the “cookie law”) adds national nuances. The APD has issued guidance that consent must be unambiguous, informed, and as easy to withdraw as it is to give. A generic “I use cookies” banner is not enough. Your checklist must cover:
- **Pre‑consent blocking**: No non‑essential cookies (analytics, marketing, social media embeds) may be set before the user clicks “Accept.”
- **Granular options**: Users must be able to reject all non‑essential cookies with one click, and ideally choose per‑category.
- **Proof of consent**: You need a record of when and how consent was given, including the banner text shown at that time.
- **Regular scans**: Because Squarespace sites often embed third‑party services (YouTube, Google Maps, Typeform, etc.), a one‑time check is insufficient.
A **Squarespace cookie compliance Belgium privacy evidence and monitoring checklist** turns these requirements into actionable verification steps.
Comparison: Manual Checks vs. Automated Scanning
Many Squarespace owners start by manually inspecting browser DevTools. While that gives a snapshot, it misses edge cases and does not scale. The table below compares manual methods with automated scanning using a tool like GDPRChecker.
| Aspect | Manual Check (DevTools) | GDPRChecker Automated Scan | |--------|--------------------------|----------------------------| | **Coverage** | One page at a time; easy to miss third‑party requests | Crawls multiple pages; detects all network requests, cookies, and local storage | | **Pre‑consent detection** | Requires careful timing and multiple browser profiles | Automatically captures requests before and after consent | | **Evidence** | Screenshots you take yourself; no timestamped audit trail | Dated, exportable scan reports with request details | | **Monitoring** | Must remember to re‑check after every change | Scheduled scans alert you to new trackers or consent gaps | | **Consent banner validation** | Manual inspection of banner behavior | Checks banner presence, reject flow, and whether tags respect consent signals |
For a Belgian site, the automated approach is the only practical way to maintain the **privacy evidence and monitoring** that regulators expect.
Step‑by‑Step Implementation of Your Checklist
1. Map Your Cookies and Trackers
Start by listing every cookie and tracker your Squarespace site uses. Squarespace itself sets essential cookies (e.g., `Crumb`, `SS_MATTR`, session cookies). You also need to account for:
- **Analytics**: Squarespace Analytics (if enabled), Google Analytics 4, or other tools.
- **Marketing pixels**: Facebook Pixel, LinkedIn Insight Tag, Google Ads conversion tracking.
- **Functional embeds**: YouTube videos, Google Maps, Twitter feeds, Calendly widgets.
- **Custom code**: Any scripts you added via Code Injection or Code Blocks.
Run a GDPRChecker scan on your site *without* accepting cookies. The report will show every network request that fires before consent. This is your baseline inventory.
2. Implement a Compliant Consent Banner
Squarespace has a built‑in cookie banner, but its default configuration may not meet Belgian requirements. You must:
- Enable the banner in **Settings > Cookies & Visitor Data**.
- Set the banner type to “Opt‑in” so that analytics and marketing cookies are blocked until consent.
- Customize the banner text to explain what cookies you use and link to your privacy policy.
- Ensure the “Reject All” button is as prominent as “Accept All.”
If you use Google services, integrate **Google Consent Mode v2**. This tells Google tags to adjust their behavior based on consent state. For example, Google Analytics 4 will send cookieless pings when consent is denied, rather than setting cookies. GDPRChecker can verify that Consent Mode signals are correctly implemented.
For more control, consider a third‑party Consent Management Platform (CMP) that integrates with Squarespace. GDPRChecker’s paid plans include a managed consent banner that supports Consent Mode v2 and provides consent records—critical evidence for Belgian compliance.
3. Block Tags Before Consent
Even with a banner, you must ensure that tags do not fire before the user makes a choice. On Squarespace, this means:
- **Google Analytics**: If you added the GA4 tag via Code Injection, wrap it in a consent check or use Google Tag Manager with Consent Mode. The built‑in Squarespace Analytics integration respects the opt‑in banner setting.
- **Facebook Pixel**: Use a CMP that blocks the pixel until consent, or implement a custom trigger in Google Tag Manager.
- **Embedded content**: Replace automatic embeds with click‑to‑load placeholders. For example, a YouTube video should not load any iframe until the user clicks and consents.
After making changes, run another GDPRChecker scan. The pre‑consent report should show only essential requests. Any marketing or analytics requests are a red flag.
4. Update Your Privacy Policy and Cookie Disclosure
Belgian law requires that your privacy policy clearly states:
- The identity and contact details of the data controller.
- The purposes of each cookie category.
- The legal basis (consent for non‑essential cookies).
- How users can withdraw consent.
- The retention period for each cookie.
Your cookie disclosure (often a separate page or a section in the privacy policy) must list every cookie by name, provider, purpose, and duration. This list must match what your scan reveals. GDPRChecker’s cookie inventory feature (available on paid plans) can generate this list automatically, saving hours of manual work.
5. Test the Reject Flow
A common mistake is to test only the “Accept” path. You must also verify what happens when a user clicks “Reject All” or simply closes the banner without making a choice.
- Open a fresh incognito window and visit your site.
- Click “Reject All” (or the equivalent).
- Check that no marketing or analytics cookies are set.
- Reload the page; the banner should not reappear, and the rejection should persist.
- Use GDPRChecker to confirm that Consent Mode signals are set to “denied” for the relevant categories.
6. Collect and Store Evidence
Evidence is what turns a compliant setup into a demonstrable one. For each major change or periodic review, save:
- **Scan reports**: Dated PDF exports from GDPRChecker showing pre‑consent and post‑consent states.
- **Banner screenshots**: Capture the banner as it appears on desktop and mobile, including the cookie policy link.
- **Consent logs**: If using a CMP, export records showing timestamps, consent choices, and banner version.
- **Policy snapshots**: Archive the version of your privacy policy that was live at the time of the scan.
Store these in a dedicated “compliance evidence” folder. Belgian regulators may ask for proof covering the entire period your site was active.
7. Monitor Continuously
Compliance is not a one‑time project. Every time you add a new Squarespace block, embed a video, or update a marketing pixel, you risk introducing unconsented trackers. Set up a monitoring routine:
- **Weekly automated scans**: GDPRChecker can scan your site on a schedule and alert you to new cookies or consent gaps.
- **Change‑triggered scans**: Run a manual scan after any site update.
- **Quarterly deep reviews**: Re‑read your privacy policy, check for expired cookies, and verify that all third‑party services still align with your disclosures.
Common Mistakes and How to Avoid Them
1. Relying on Implied Consent
“By continuing to browse, you accept cookies” is not valid under Belgian law. You must obtain affirmative, opt‑in consent before setting non‑essential cookies. Use an opt‑in banner and block tags until consent.
2. Ignoring Third‑Party Embeds
A Squarespace site often pulls in external content. A YouTube embed can set multiple cookies even if you never explicitly added a YouTube tag. Always use privacy‑enhanced embed options (e.g., `youtube‑nocookie.com`) or a click‑to‑load solution.
3. Forgetting About Custom Code
Code Injection in Squarespace (Header or Footer) can add scripts that bypass the built‑in banner. Audit all custom code and ensure it respects consent signals.
4. Not Testing the Reject Flow
Many sites work perfectly when the user clicks “Accept” but fail silently on “Reject.” Always test the reject path with a fresh browser session and a scanner.
5. Assuming the Built‑In Banner Is Enough
Squarespace’s banner is a good start, but it may not support granular per‑category consent or integrate with Google Consent Mode v2 out of the box. Evaluate whether you need a more advanced CMP.
6. Neglecting Evidence Collection
Without dated scan reports and consent logs, you cannot prove compliance. Automate evidence collection with GDPRChecker so you are always audit‑ready.
How to Validate with GDPRChecker
GDPRChecker is built to turn the **Squarespace cookie compliance Belgium privacy evidence and monitoring checklist** into a verifiable, repeatable process. Here is how to use it at each stage:
- **Initial scan**: Run a full site scan without accepting cookies. The report flags every pre‑consent request, cookie, and tracker.
- **Banner check**: GDPRChecker verifies that a consent banner is present, that it blocks tags before consent, and that the reject option works.
- **Consent Mode diagnostics**: If you use Google services, the scanner checks that Consent Mode v2 signals are correctly sent.
- **Policy link validation**: The scan confirms that your banner links to a privacy policy and that the policy contains required disclosures.
- **Ongoing monitoring**: Schedule weekly scans. GDPRChecker alerts you if a new tracker appears or if the banner stops working.
- **Evidence export**: Download timestamped PDF reports for your records. Paid plans include consent logs and cookie inventories.
For Belgian site owners, this evidence is invaluable. It shows the APD that you have a systematic compliance program, not just a one‑time fix.
Implementation Checklist
Use this numbered checklist to build and maintain your Squarespace cookie compliance in Belgium.
- Run a pre‑consent GDPRChecker scan to inventory all cookies and trackers.
- Enable Squarespace’s opt‑in cookie banner and customize the text.
- Verify that the banner includes a clear “Reject All” button and a link to your privacy policy.
- Implement Google Consent Mode v2 if you use Google Analytics or Google Ads.
- Block all non‑essential tags (analytics, marketing, embeds) until consent is given.
- Replace automatic third‑party embeds with click‑to‑load placeholders.
- Update your privacy policy to list every cookie, its purpose, and retention period.
- Test the full reject flow in an incognito browser; confirm no non‑essential cookies are set.
- Run a post‑consent GDPRChecker scan to verify that tags fire only after consent.
- Export and save dated scan reports, banner screenshots, and consent logs.
- Schedule weekly automated scans and review alerts promptly.
- Repeat the full checklist after any site change or at least quarterly.
FAQ
What is Squarespace cookie compliance Belgium privacy evidence and monitoring checklist? It is a structured process for Squarespace site owners to ensure their cookie practices meet Belgian GDPR and ePrivacy requirements. The checklist covers consent collection, pre‑consent blocking, policy disclosures, evidence storage, and ongoing monitoring to prove compliance.
Do I need Squarespace cookie compliance Belgium privacy evidence and monitoring checklist for GDPR? Yes, if your Squarespace site is accessible from Belgium and uses non‑essential cookies. Belgian law requires demonstrable, informed consent and the ability to show evidence of compliance. A checklist helps you systematically meet these obligations.
How do I implement Squarespace cookie compliance Belgium privacy evidence and monitoring checklist? Start by scanning your site for cookies, then configure an opt‑in banner, block tags before consent, update your privacy policy, and test the reject flow. Use GDPRChecker to automate scans and collect evidence. Follow the step‑by‑step guide above.
How can I verify Squarespace cookie compliance Belgium privacy evidence and monitoring checklist with a scanner? Use GDPRChecker to run pre‑consent and post‑consent scans. The tool detects network requests, cookies, and consent banner behavior. It flags any tags that fire before consent and verifies that Consent Mode signals are correct.
What are common Squarespace cookie compliance Belgium privacy evidence and monitoring checklist mistakes? Common mistakes include relying on implied consent, ignoring third‑party embeds, forgetting custom code, not testing the reject flow, assuming the built‑in banner is sufficient, and failing to collect dated evidence. Regular scanning prevents these issues.
Which cookies and trackers should I check for Squarespace cookie compliance Belgium privacy evidence and monitoring checklist? Check all cookies and trackers: Squarespace essentials, analytics (GA4, Squarespace Analytics), marketing pixels (Facebook, LinkedIn), functional embeds (YouTube, Google Maps), and any custom scripts. A GDPRChecker scan provides a complete inventory.
How often should I review Squarespace cookie compliance Belgium privacy evidence and monitoring checklist? Review the full checklist at least quarterly, and after every site change (new plugin, embed, or script). Set up weekly automated scans to catch new trackers immediately. Evidence should be updated with each review.
What evidence should I keep for Squarespace cookie compliance Belgium privacy evidence and monitoring checklist? Keep dated GDPRChecker scan reports (pre‑ and post‑consent), screenshots of your consent banner, consent logs from your CMP, and archived versions of your privacy policy. Store them securely for at least the duration required by Belgian law.
Next Steps for Belgian Squarespace Owners
A **Squarespace cookie compliance Belgium privacy evidence and monitoring checklist** is your blueprint for staying on the right side of Belgian privacy law. By combining the practical steps in this guide with automated scanning from GDPRChecker, you can move from guesswork to verified compliance.
Start with a free scan of your Squarespace site today. Identify your pre‑consent gaps, fix them using the checklist, and set up ongoing monitoring. For deeper coverage, explore our related guides on cookie banner requirements, Google Analytics GDPR compliance, and Consent Mode v2 vs. Google Certified CMP. If you are unsure whether you need a full CMP, read do I need a CMP if I do not run Google Ads. For a broader compliance framework, see our GDPR checklist for small businesses. Finally, make sure your disclosures are solid with our privacy policy requirements guide.
Ready to build your evidence file? Run your first GDPRChecker scan now and take control of your Belgian cookie compliance.
Practical examples
Example 1: A small ecommerce site
A shop changes its cookie banner wording before a seasonal campaign. The operator records the previous and new banner version, tests Reject all and Accept all, and stores screenshots plus the resulting network checks. That creates a clear before-and-after record without relying on memory.
Example 2: A B2B lead-generation site
A marketing team adds a form analytics tag through its tag manager. Before publishing, it documents the consent category, the tag trigger, the privacy notice update, and a test showing that the request does not fire after a visitor rejects optional cookies.
Example 3: A multi-page content site
An editor notices that a new embedded video adds a third-party request. The team scans the affected pages, compares the result with the last scan, updates the cookie disclosure if necessary, and keeps the scan report with the deployment reference.
> This guide is technical implementation guidance for website owners. It is not legal advice.
Article schema
```json { "@context": "https://schema.org", "@type": "Article", "headline": "Squarespace Cookie Compliance in Belgium: Privacy Evidence and Monitoring Checklist", "description": "Practical guide to Squarespace cookie compliance in Belgium. Step-by-step checklist for consent, evidence, and monitoring. Verify with GDPRChecker scans.", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.gdprchecker.online/guides/squarespace-cookie-compliance-in-belgium-privacy-evidence-and-monitoring-checkli" }, "publisher": { "@type": "Organization", "name": "GDPRChecker", "url": "https://www.gdprchecker.online" } } ```
Copyright and editorial notice
© GDPRChecker
This original AI-assisted editorial draft was selected, reviewed, and published by GDPRChecker. All rights are reserved where protected by applicable law. Do not reproduce the article without permission.