What is the OptanonConsent cookie?
This cookie is used by the OneTrust Consent Management Platform to store the visitor's cookie consent preferences and compliance configuration settings across the website.
Table of Contents
About OptanonConsent
| Vendor | OneTrust |
|---|---|
| Category Category The functional category of the technology, such as Web Analytics or Social Media. Learn more | Advertising & Paid Media |
| Consent Category Consent Category The consent category this cookie most commonly falls under across sites we scan, normalized into four standard categories. Learn more | Strictly Necessary |
| Prevalence | Very Common |
| Popularity Popularity Popularity is calculated from our dataset of 4.5B+ cookies analyzed across hundreds of millions of web pages. Learn more | Found on 28.2% of scanned pages |
| Expiration Type | Timestamp |
| Expiration Duration | 30 days |
| Party Type Party Type Whether the cookie is first-party or third-party. Learn more | Mixed |
| Risk Level Risk Level Rates how sensitive the data stored by this cookie is (High, Medium, or Low) based on data classification and distribution. Learn more | Low |
| Vendor Privacy Policy | https://www.onetrust.com/cookie-policy/ |
| Vendor Website | https://www.onetrust.com |
What is the purpose of OptanonConsent?
The OptanonConsent cookie is a persistent first-party cookie set by the OneTrust Consent Management Platform (CMP) to track, remember, and operationalize a user’s specific privacy preferences regarding the use of cookies and tracking technologies on a website. It acts as a client-side compliance ledger that ensures downstream scripts, pixels, and conditional marketing frames are either executed or blocked dynamically according to the user's explicit selections or the platform's geolocation compliance rules.
The cookie carries a rich, query-string formatted payload containing several structured technical fields. Key variables embedded within its value include "groups" (mapping alphanumeric purpose categories like C0001 for Strictly Necessary, C0002 for Performance, and C0004 for Targeting alongside their active binary states, e.g., ":1" for accepted and ":0" for rejected), "consentId" (a unique cryptographic transaction identifier linking the user's action to OneTrust's audit databases), and "datestamp" (recording the precise date and time of the user's preference interaction). It also carries operational metadata such as the platform's internal "version", "interactionCount", "geolocation" tracking flags, and "isGpcEnabled" markers to detect automated Global Privacy Control browser preference requests.
What are the Privacy Risks of OptanonConsent?
Risk Level: Low
The OptanonConsent cookie is classified as Low risk because its exclusive technical purpose is to maintain core site functionality regarding user-directed privacy settings, carrying no behavioral analytics markers or cross-site tracking IDs. Official technical specifications confirm that its payload - storing binary group choices and cryptographic consent IDs - serves strictly as a local compliance ledger to ensure the website dynamically executes or blocks downstream scripts according to the user's explicit preferences.
Because the technology operates solely to fulfill data privacy choices and explicitly avoids the profiling of user habits, it aligns perfectly with the Low risk tier. Furthermore, OneTrust’s standard compliance architecture ensures that no client-side Personally Identifiable Information (PII) is captured or shared with unauthorized third parties via this cookie, which firmly prevents it from escalating to a Medium or High risk classification.
How to Remove OptanonConsent from a Website
To remove the OptanonConsent cookie from a website, the website administrator must completely uninstall and remove the OneTrust Consent Management Platform (CMP) integration from the site's source code or Tag Management System. Because this cookie serves as the core foundational mechanism for storing consent states and executing compliance rules, it is mandatory for the operation of the OneTrust platform and cannot be disabled independently via configuration toggles or account-level settings while keeping the service active. Therefore, the site operator must remove the main OneTrust JavaScript SDK stub (otSDKStub.js), delete the associated banner script configurations (otBannerSdk.js), and purge any active OneTrust script tags or custom template containers deployed within their environment to eliminate the cookie entirely.