Modern slavery statement: publishing one that survives being read
A modern slavery statement is public, annual and signed by the board. What has to be in it, where it goes, and the sentences that make it worse than saying nothing.
A cookie policy lists what you set, why, and how long it lasts. What has to be in it, why the banner is the real compliance question, and the common mistakes.
A cookie policy is the page that tells visitors what your site stores on their device, what each thing is for, and how long it stays. It is separate from your privacy policy, though they are often merged, and it is the document regulators and prospective customers check first because it is public and takes ninety seconds to verify. That verifiability is the whole problem: a cookie policy that lists three cookies on a site that sets thirty is not a drafting error, it is evidence.
Almost every enforcement action in this area is about consent mechanics rather than the wording of the page.
Cookie banners are governed by ePrivacy rules in Europe rather than only by the GDPR, which is why the consent standard applies to storage on the device regardless of whether the data is personal. The practical consequence is that "it is anonymous analytics" does not remove the consent requirement, though several regulators now accept genuinely privacy-preserving measurement without it. The details differ by country and are actively changing.
Ettex Sites is where the page itself belongs — on your own domain, linked from every page, with the review date visible. The discipline that keeps it true is not writing: it is checking what the site actually sets whenever anything is added to it, which is a step in your release routine rather than a legal task. It sits beside the privacy policy, which covers what you do with personal data generally rather than what you store on the device. Ettex does not audit your site’s cookies, does not provide a consent banner, and this is not legal advice — the rules differ by jurisdiction and are being revised.
In most jurisdictions yes, provided the cookie information is complete and findable. A separate page is easier to keep current and easier for a reviewer to check, which is why most sites end up separating them again.
Usually not for consent, though a short notice is good practice. The trap is that "essential" is narrower than most people assume — it means essential to deliver the service the user asked for, not essential to your business.
Whenever the site changes, and at least annually regardless. Tie the check to deployment rather than to a calendar reminder and it will actually happen.
A modern slavery statement is public, annual and signed by the board. What has to be in it, where it goes, and the sentences that make it worse than saying nothing.
Most intranet projects fail on maintenance, not on features. Deciding who owns each page before launch matters more than which platform you pick.
An SPF record lists who may send mail as your domain. Two limits — one record and ten DNS lookups — cause most of the failures.