Skip to content
wiseguyxl

Quick answer: To use cookies legally on a website aimed at the EU or UK, you need prior, informed, freely given, specific consent for every non-essential cookie (analytics, advertising, personalisation). In practice that means a consent banner that (1) blocks non-essential cookies until the visitor acts, (2) offers a Reject button as prominent as Accept, (3) uses no pre-ticked boxes, (4) records proof of consent, and (5) lets people change their mind as easily as they opted in. Strictly necessary cookies (login, cart, security) do not need consent but should still be disclosed.

Why cookie consent is a legal requirement, not a nice-to-have

Two laws stack on top of each other in Europe. The ePrivacy Directive (the “cookie law”) governs storing or reading information on a user’s device — that is what actually requires consent before a cookie is set. The GDPR then defines what valid consent looks like: it must be a “freely given, specific, informed and unambiguous indication” of the person’s wishes. The Court of Justice of the EU settled the key question in the Planet49 ruling (C-673/17): a pre-ticked checkbox is not valid consent. Silence, inactivity, or continued scrolling never count either.

Because the rules apply to anyone processing data of people in the EU/UK, they reach far beyond European companies. If EU visitors can reach your site and you run Google Analytics, Meta Pixel, or any ad tag, you are in scope.

“Personal data is the new oil of the internet and the new currency of the digital world.”

— Meglena Kuneva, European Consumer Commissioner (2009)

The five requirements of a compliant cookie banner

Regulators across the EU have converged on the same expectations. A lawful banner must:

  1. Block first, ask second. No non-essential cookie or tracker may fire before the visitor gives consent. A banner that loads analytics on page view is already non-compliant.
  2. Be granular. Group cookies by purpose — strictly necessary, preferences, statistics, marketing — and let people accept or reject each purpose.
  3. Make rejecting as easy as accepting. “Accept all” with no equally visible “Reject all” is the single most fined pattern in Europe. Both choices must sit on the first layer, with equal prominence.
  4. Avoid dark patterns. No pre-ticked boxes, no confusing double negatives, no colour tricks that push people toward “Accept”. The French and other regulators treat these as invalidating consent.
  5. Be withdrawable and logged. Withdrawing consent must be as easy as giving it (a persistent “Cookie settings” link), and you must keep a record of who consented, to what, and when.

Strictly necessary vs. consent-required cookies

Cookie type Examples Consent needed?
Strictly necessary Session/login, shopping cart, load balancing, CSRF security No — but disclose in your policy
Preferences Language, region, saved layout Usually yes (unless user-requested)
Statistics / analytics Google Analytics 4, Matomo (unless anonymised & first-party in some countries) Yes
Marketing / advertising Meta Pixel, Google Ads, LinkedIn Insight, remarketing Yes — always

A frequent myth is that analytics is “harmless” and exempt. It is not exempt under the ePrivacy Directive. A handful of national authorities allow narrowly-scoped, first-party, anonymised measurement without consent, but the default assumption should be that analytics needs consent.

Google Consent Mode v2 — mandatory for EEA and UK traffic

Since March 2024, Google requires Consent Mode v2 for any site sending EEA or UK data to Google Ads, GA4 or remarketing. Consent Mode passes the visitor’s choices to Google through four signals — ad_storage, analytics_storage, ad_user_data and ad_personalization. In “basic” mode tags are blocked until consent; in “advanced” mode tags load in a cookieless, non-identifying state and send anonymous, modelled pings before consent. Without Consent Mode v2 properly wired to your consent banner, remarketing audiences and conversion measurement quietly stop working for European users. A certified Consent Management Platform (CMP) that integrates with the IAB Europe Transparency & Consent Framework (TCF v2.2) is the cleanest way to connect the two.

How the rules differ across Europe

The GDPR is EU-wide, but each country layers its own ePrivacy transposition and regulator guidance on top:

A practical 6-step implementation checklist

  1. Audit your cookies. Scan the site and list every cookie and tag, its purpose, provider, and lifespan.
  2. Pick a certified CMP (Cookiebot, Usercentrics, iubenda, CookieYes, Osano) that supports TCF v2.2 and Google Consent Mode v2.
  3. Block by default. Configure the CMP to hold all non-essential tags until consent, ideally via server-side or Google Tag Manager.
  4. Design an honest banner — equal Accept/Reject, granular categories, plain language, no dark patterns.
  5. Wire Consent Mode v2 so Google tags respect the choices, and test with the browser console.
  6. Log and refresh. Store consent records, re-ask when purposes change, and review at least every 6–12 months.

What non-compliance actually costs

Cookie and consent violations are not theoretical. The GDPR allows fines of up to €20 million or 4% of global annual turnover, and national ePrivacy laws add their own penalties. France’s CNIL fined Google €150 million and Facebook €60 million specifically because rejecting cookies took more clicks than accepting them. Regulators in Germany, Italy, Spain and the Netherlands have all issued cookie-banner decisions, and the noyb organisation has filed hundreds of complaints against non-compliant banners across the EU. Beyond fines, a banner that blocks nothing exposes you to consent-invalidity: if your consent is legally worthless, every downstream use of that data — analytics, ads, profiling — becomes unlawful too. Getting the banner right is therefore also risk management for the rest of your marketing stack.

Frequently asked questions

Do I need a cookie banner if I only use Google Analytics?

Yes. GA4 sets cookies and processes personal data (IP-derived), so under the ePrivacy Directive it requires consent in almost every EU country before it loads.

Is “Accept all” or nothing allowed?

No. A banner offering only “Accept” — or hiding “Reject” behind extra clicks — does not produce freely given consent and is the most commonly fined design in the EU.

Are cookie walls legal?

Generally no for tracking. Forcing acceptance to access content (“consent or pay” aside) is rejected by most EU regulators, including the AEPD and the Dutch AP.

How long is consent valid?

There is no single figure, but 6–12 months is the widely accepted maximum before you should re-ask.

Sources

Need a compliant, high-converting EU website?

WiseGuyXL builds and audits GDPR-ready, high-performing websites across Europe — web design & development services. We’ve delivered 341% organic growth across 30+ projects in 9+ markets.