Plugin screenshot thumbnail 1/6
Plugin screenshot thumbnail 2/6
Plugin screenshot thumbnail 3/6
Plugin screenshot thumbnail 4/6
Plugin screenshot thumbnail 5/6
Plugin screenshot thumbnail 6/6

Cookie consent for Craft CMS, built for Quebec's Law 25 and usable under the GDPR.

Nothing third-party is set before the visitor agrees. An inline bootstrap in <head> reads the consent cookie and primes Matomo and Google Consent Mode in a refused state, before any tracker runs. The banner itself is a custom element appended to the body.

The HTML is the same for every visitor, and JavaScript applies the decision — so pages stay cacheable, whatever the consent state. Without JavaScript, nothing is activated.

What you get

  • A consent banner with categories you define in the control panel, each with its own cookie inventory.
  • A cookie table for your privacy policy, rendered whole or one category at a time, from a Twig call or a [cookie-table] marker inside a rich text field.
  • YouTube videos behind a local placeholder that loads on click, with the thumbnail served by your own site.
  • Global Privacy Control honoured: a browser that sends it has refused, and the banner can be skipped for those visitors.
  • Wording in English and French; any language is added with a single file, and every string is overridable per project.
  • Per-site settings across a multisite install.
  • A documented CSS contract — custom properties, a dark scheme, stable class names — so the banner takes your design without a fork.
  • A JavaScript API, window.qsmConsentKit, for conditional tags and scripts.

No template change is required, and the only dependency beyond Craft CMS is the plugin's own core package.

The consent register — Pro

The cookie on the visitor's device is a trace: it can be edited, deleted, and it cannot be produced on demand. The register is what you show when someone asks you to demonstrate that consent was given, and what it was given to.

  • Every decision recorded server-side with the server's clock, the site, the categories granted, and a fingerprint of the exact wording that was on screen — computed by the server, never taken from the browser.
  • Read it in the control panel, filtered by date, answer and site, each decision showing the screen as it was worded then, not as you word it today.
  • Export to CSV, Excel or JSON. The JSON carries the wording of every screen and describes how the fingerprint is computed, so a third party can recompute it without the plugin.
  • Retention runs with Craft CMS's own housekeeping, and three permissions separate reading, exporting and purging — producing a proof is not the same trust as destroying one.

Records already kept stay readable, exportable and purgeable whatever the edition says.

What it does not do

Consent is one piece of a privacy programme, not the whole of it. This plugin does not produce the privacy impact assessment Law 25 requires for communication outside Quebec, does not designate your privacy officer, and does not write your privacy policy.

Lite

Pro

Plus $25/year after one year.

Installation Instructions

To install this plugin, copy the command above to your terminal.

Reviews

This plugin doesn't have any reviews.

Active Installs
0
Version
5.0.8
License
Craft
Compatibility
Craft 5
Last release
September 25, 2026