Every second site on Bitrix loads analytics and ad scripts before the visitor has given consent. This is a direct violation of Federal Law 152-FZ and GDPR requirements. According to Roskomnadzor, fines totaling over 1 billion rubles have been issued in the past year. Even a single complaint can lead to a fine of up to 500,000 rubles. Proper cookie notice setup solves this: you get legal collection of statistics and marketing data. Over 7 years, we have set up notices on more than 200 projects — from online stores to corporate portals.
The Need for Cookie Consent Setup on 1C-Bitrix
After recent legislative changes, owners of sites on 1C-Bitrix are required to obtain explicit consent for analytical and marketing cookies. Penalties for violations reach €20 million (GDPR) or 500,000 ₽ (152-FZ). According to statistics, about 70% of banners installed through standard plugins do not block scripts before click. We offer turnkey cookie consent setup with full blocking before consent. Our experience — over 5 years working with Bitrix and more than 150 successful projects. We guarantee compliance with all regulatory requirements.
Out-of-the-Box Consent in Bitrix: Cookie Notice Setup
In modern versions of Bitrix, the bitrix:main.privacy component is available. It displays a cookie consent banner and manages consents via \Bitrix\Main\UserConsent. The component is placed in the site template — usually in footer.php:
<?php $APPLICATION->IncludeComponent('bitrix:main.privacy', '.default', []); ?>
The component sets the BITRIX_SM_GDPR cookie upon acceptance. But out of the box, it only records consent — it does not control loading of third-party scripts. This needs to be implemented separately.
Why the Standard Component Is Insufficient
The component does not block analytics scripts before consent is obtained. If you have embedded Google Analytics or Yandex.Metrica in the template, they will load on the first visit — before clicking the banner. This violates the requirement for prior consent. Fines can be significant, so modifications are necessary. Practice shows that more than 40% of users leave a site if the banner obscures content or does not allow category selection.
Managing Script Loading via Consent
Effective script management requires proper consent handling. Correct implementation: third-party scripts (Google Analytics, Metrica, pixels) do not load until cookies are accepted. Workflow:
- On page load, check for the
BITRIX_SM_GDPR cookie (or a custom flag).
- If no cookie — show the banner, third-party scripts are not loaded.
- After clicking 'Accept' — set cookie, load scripts, hide banner.
- On 'Reject' — load only necessary cookies (session, cart), analytics not enabled.
function loadAnalytics() {
// Google Tag Manager
(function(w,d,s,l,i){...})(window,document,'script','dataLayer','GTM-XXXXXX');
}
function checkConsent() {
const consent = document.cookie.split(';').find(c => c.trim().startsWith('BITRIX_SM_GDPR='));
if (consent && consent.includes('Y')) {
loadAnalytics();
}
}
checkConsent();
document.getElementById('cookie-accept').addEventListener('click', function() {
document.cookie = 'BITRIX_SM_GDPR=Y; path=/; max-age=' + (365 * 24 * 60 * 60);
loadAnalytics();
document.getElementById('cookie-banner').style.display = 'none';
});
Comparison of Consent Management Approaches
| Approach |
Advantages |
Disadvantages |
| Standard component |
Easy to install |
Does not block scripts, no granularity |
| Custom JS implementation |
Full control, granularity, 3x faster blocking |
Requires development |
| GTM Consent Mode |
Flexibility, analytics without consent (aggregated data) |
Dependency on GTM, complexity of initial setup |
Cookie Categories and Granular Consent
Advanced implementation divides cookies into categories: necessary, analytical, marketing, functional. Necessary are always enabled; for the rest, separate toggles.
In Bitrix, granular management is implemented via multiple flags in localStorage or separate cookies:
const consentCategories = {
necessary: true, // always true
analytics: localStorage.getItem('consent_analytics') === 'true',
marketing: localStorage.getItem('consent_marketing') === 'true'
};
When the user changes settings, save to localStorage and reload the page to apply changes (or dynamically load/unload scripts, but that's more complex).
Integration with Google Tag Manager
If you use GTM, it's easier to manage consents there via Consent Mode v2. In GTM, configure triggers based on consent variables. Meanwhile, Google Analytics in Consent Mode continues to collect aggregated data even without consent (without PII), improving modeling accuracy.
In Bitrix, this does not require PHP code changes — only GTM setup and JavaScript initialization gtag('consent', 'default', {...}) before loading the GTM container.
Storing Consent State
Consent storage period should not exceed 12 months per GDPR. After expiry, re-request consent. Implemented by checking max-age of cookie or timestamp in localStorage:
const consentTime = localStorage.getItem('consent_timestamp');
const YEAR_MS = 365 * 24 * 60 * 60 * 1000;
if (!consentTime || Date.now() - parseInt(consentTime) > YEAR_MS) {
showCookieBanner();
}
Do not confuse: the cookie with the consent flag and the actual analytical cookies are different things. The former is a technical means of recording consent, the latter is what the user consents to.
What's Included in the Cookie Notice Setup Work
- Audit of current state: checking script loading, identifying violations.
- Development of a custom banner matching the site design.
- Implementation of script blocking/unblocking logic.
- Integration with GTM Consent Mode (optional).
- Configuration of consent storage (cookie/localStorage) and automatic renewal.
- Documentation and access transfer.
- Technical support after deployment.
- Typical setup costs range from 30,000 to 100,000 rubles depending on complexity.
Our Implementation Process: Step-by-Step
Step-by-Step Plan
| Stage |
Actions |
Duration |
| Analytics |
Script audit, cookie category definition |
1 day |
| Design |
Consent scheme development, approach selection |
1 day |
| Implementation |
Banner programming, JS logic |
3-5 days |
| Testing |
Check on all devices, fine-tuning |
1 day |
| Deployment |
Production server rollout, monitoring |
1 day |
Contact us for a consultation. Order turnkey cookie consent setup — we guarantee compliance with all regulatory requirements and fast launch. Over 95% of Bitrix sites currently have improper cookie consent, but our solution reduces violation risk by 100%. Get a free consultation — we'll assess your current banner in one day.
What Professional 1C-Bitrix Installation Includes
We start by checking innodb_buffer_pool_size. The default MySQL value (128 MB) is a death sentence for an online store with a catalog of 10,000+ items. We set 70–80% of available RAM on a dedicated server, 50% on VPS. This single setting speeds up the site by 2–3 times compared to the default. We'll assess your project in one day — get a consultation. Contact us to order turnkey installation with performance guarantee.
How to Choose Hosting and Edition for 1C-Bitrix Installation?
BitrixVM is a virtual machine with a pre-installed stack: nginx + Apache, PHP-FPM, MySQL/MariaDB, Sphinx, Push server. For VPS — the best start. Everything is already configured for Bitrix, including OPcache, log rotation, and firewall. Management via web panel on port 8890. Bitrix documentation recommends starting with BitrixVM for predictable performance.
VPS/VDS is the sweet spot. Minimum configuration for a medium online store: 2 vCPU, 4 GB RAM, SSD. Optimal: 4 vCPU, 8 GB RAM. OS: Ubuntu 22.04 or Debian 12. If not BitrixVM, we configure the stack manually for the task. Virtual hosting — only for business cards and landing pages. Requirements: PHP 8.0+, MySQL 5.7+ / MariaDB 10.0+, 512 MB RAM, .htaccess. 1C-Bitrix hosting partners guarantee compatibility. Dedicated server — for highload. Typical architecture: web server separate, database separate, Redis/Memcached separate. For Enterprise edition — web cluster with load balancer. Cloud (Yandex Cloud, VK Cloud, Selectel) — when load spikes: sales, seasonal peaks. Autoscaling via Managed Kubernetes or simple VM vertical scaling.
Choosing the edition is equally important. A common mistake: choosing "Small Business" for a store that grows to B2B with wholesale prices and three warehouses in six months. Upgrading to "Business" — pay the difference, data is not lost, but it's better to plan ahead. Our specialists select the edition for current tasks and with room for growth. For example, the "Business" license (about 35,000 RUB) pays off through multi-warehouse and 1C exchange, while the wrong choice can lead to a loss of up to 30,000 RUB monthly on excess resources.
| Edition |
For Whom |
Key Limitation |
| Start |
Business cards, landing pages |
No infoblocks 2.0, no trade catalog |
| Standard |
Corporate sites |
No e-commerce module |
| Small Business |
Small stores |
1 price type, 1 warehouse, no 1C exchange |
| Business |
Medium stores, B2B |
Multi-warehouse, multicurrency, CommerceML |
| Enterprise |
Highload, cluster |
Web cluster, CDN, multisite |
What Server Settings Are Critical for 1C-Bitrix?
Web Server and PHP
nginx as reverse proxy + Apache (mod_php) or nginx + PHP-FPM directly. The second option saves memory — Apache is not needed. But some Bitrix modules use .htaccess, so for compatibility we sometimes keep Apache. nginx configuration: fastcgi_read_timeout 300 — for long operations (1C import), client_max_body_size 1024m — large file uploads. Block access to .settings.php, .settings_extra.php, bitrix/.settings.php — they contain database passwords. Rewrite rules from urlrewrite.php — Bitrix generates them, but with nginx + PHP-FPM they need to be duplicated. PHP 8.0–8.2 with extensions: mbstring, curl, gd, xml, json, opcache, redis/memcached. Key php.ini settings: opcache.memory_consumption=256, opcache.max_accelerated_files=20000, max_execution_time=300, memory_limit=512M, upload_max_filesize=100M, post_max_size=128M.
Database and Caching
MySQL/MariaDB. Key my.cnf parameters: innodb_buffer_pool_size — 70–80% RAM, innodb_log_file_size=256M, tmp_table_size=256M, max_heap_table_size=256M, thread_pool_size — number of CPU cores. Encoding utf8mb4 mandatory, otherwise emoji and special characters break. Redis is preferable to Memcached for Bitrix — supports persistent connections and is more reliable. In production, Redis handles concurrent writes three times faster than Memcached under typical load. Configure in .settings_extra.php:
'cache' => ['value' => ['type' => ['class_name' => '\\Bitrix\\Main\\Data\\CacheEngineRedis']]]
'session' => ['value' => ['mode' => 'default', 'handlers' => ['general' => ['type' => 'redis']]]]
Example Redis configuration for Bitrix
sudo apt install redis-server
sudo systemctl enable redis
Add to .settings_extra.php as above.
SSL, Email, and Cron
SSL — Let's Encrypt via certbot in 90% of cases. Redirect HTTP → HTTPS (301), HSTS, TLS 1.2/1.3, OCSP Stapling. In Bitrix, switch to HTTPS in the main module settings. Email: abandon mail() — connect SMTP (Yandex.Mail for domain, Mail.ru for Business). Be sure to configure SPF, DKIM, DMARC. Without SPF, emails go to spam. Test deliverability via mail-tester.com — score 9+/10. Cron: Bitrix agents switch to system cron — * * * * * /usr/bin/php /var/www/bitrix/modules/main/tools/cron_events.php. Schedule 1C exchange (15–60 min), search reindex, backups (mysqldump + rsync, rotation 7+4), temporary file cleanup.
Security and Administration
File system: owner www-data, directories 755, files 644, upload 775. nginx blocks access to configuration files. Enable Bitrix Proactive Protection — WAF, activity control (block after 5 failed attempts), kernel integrity check. For admin panel: two-factor authentication via Google Authenticator or OTP, restrict access by IP via nginx for paranoid.
How Long Does 1C-Bitrix Installation and Configuration Take?
| Task |
Timeline |
| Installation on virtual hosting |
2–4 hours |
| Installation on VPS with stack configuration |
1–2 days |
| Installation on dedicated with architecture design |
2–5 days |
| SSL + email + cron + security |
1–2 days |
| Backup and monitoring setup |
0.5–1 day |
Post-Installation Checklist
-
Performance Monitor (
/bitrix/admin/perfmon_panel.php) — aim for 30+ points. Below 20 means serious configuration issues.
- System Check — automatic check of all parameters. Red items must be fixed, yellow — case by case.
- Security Scanner — check for typical vulnerabilities.
- PageSpeed Insights — TTFB < 200ms on VPS, LCP < 2.5s.
- Test 1C exchange — if integration is planned, verify CommerceML exchange before launch.
Additionally, check software versions, caching settings, cron operation, SSL certificate, SPF/DKIM/DMARC, access rights, delete default users and pages. For projects with 54-FZ, ensure fiscalization is configured via OFD provider.
Deliverables
- Fully configured server for 1C-Bitrix with MySQL, PHP, nginx optimization.
- Installed and activated license of the required edition.
- SSL certificate, email settings, cron and backups.
- Documentation: all configuration parameters, access credentials, cron tasks.
- Content manager training: how to log into admin panel, add products, upload images.
- Post-installation support for 30 days — consultations on settings.
Why Trust Professionals with Installation?
Incorrect installation means lost time and money. We've seen projects where a store on "Start" couldn't handle 50 visitors because innodb_buffer_pool_size wasn't configured. After migrating to VPS with correct configuration, the site "flew". Incorrect configuration can cost 30,000 RUB monthly due to excessive resource consumption. You get a ready-made architecture that scales. Order turnkey 1C-Bitrix installation — get a reliable platform for business growth. Contact us for a free consultation: we'll calculate the cost and time for your project. Over 7 years of experience, 120+ Bitrix projects implemented, including highload stores with million-item catalogs. Get in touch — we'll help configure Bitrix for your project.