ConsentPixel – Privacy · Verified

GDPR & EU Compliance · Cookie Consent

GDPR Cookie Consent Requirements 2026: What Every Website Serving EU Visitors Must Know

In September 2025, France's CNIL fined Google €325 million and Shein €150 million for cookie violations — in a single day. In 2025 alone, European regulators issued €1.2 billion in GDPR penalties. The rules have not changed dramatically, but the enforcement has. Here is exactly what GDPR cookie consent requires in 2026, where most websites still get it wrong, and what a compliant implementation actually looks like.

By the ConsentPixel — Privacy · Verified team July 2026 14 min read For website owners and agencies serving EU and UK visitors
€1.2B
Total GDPR fines issued in 2025 alone — a 22% year-on-year increase
€325M
CNIL fine against Google in September 2025 — for cookie consent failures
Before
The one word that decides compliance: cookies and pixels must not fire before consent

GDPR cookie consent is one of the most actively enforced areas of European data protection law. The fundamental rules have been in place since 2018, but enforcement has accelerated sharply in 2025 and 2026, and the EDPB has expanded the scope of what counts as a "cookie" well beyond the traditional HTTP cookie. If you operate a website that receives visitors from any EU or EEA country — or the UK — this article gives you the current legal requirements, the enforcement reality, and the technical configuration that actually satisfies both. This is informational, not legal advice; consult qualified counsel for your specific situation.

GDPR cookie compliance is governed by two overlapping instruments, not one. Understanding which does what is essential for understanding why the requirements are what they are:

The ePrivacy Directive (2002/58/EC, amended 2009) — often called the EU Cookie Law — is the specific instrument that created the consent requirement for cookies. Article 5(3) states that any cookie not strictly necessary for a service the user explicitly requested requires prior consent. This applies to analytics cookies, advertising cookies, functional cookies, social media embeds, tracking pixels, device fingerprinting, and URL-based identifiers. Member states implement the Directive through national legislation, which is why enforcement and specific interpretations vary across the EU.

GDPR (General Data Protection Regulation, 2018) defines what valid consent looks like — it must be freely given, specific, informed, and unambiguous. When cookies process personal data (which analytics and advertising cookies always do, since they transmit IP addresses and device identifiers), GDPR's lawful basis requirements apply alongside the ePrivacy Directive's consent requirement. In practice this means every non-essential cookie has two compliance layers: ePrivacy requires consent before it's placed, and GDPR defines the quality of that consent.

The ePrivacy Regulation is dead — and that matters

After eight years of stalled negotiations, the European Commission formally withdrew the proposed ePrivacy Regulation in February 2025. The practical consequence: cookie rules in the EU will continue to be governed by the 2002 ePrivacy Directive, transposed differently by each member state. Harmonisation is not coming. The divergence between national implementations — and national enforcement intensity — will continue to grow. For businesses operating across multiple EU markets, the national differences in enforcement priority are as important as the baseline EU requirements.

The "strictly necessary" exemption is the only category that doesn't require consent. Its definition is narrow — the ICO, CNIL, and EDPB all agree that strictly necessary means the service literally cannot function without it from the user's perspective, not just that it makes the service work better for the business.

GDPR Article 4(11) defines consent as a "freely given, specific, informed and unambiguous indication of the data subject's wishes." All four elements must be present. If any one is missing, the consent is legally invalid. Courts and regulators have tested each element extensively, and the specific requirements are now well established:

Freely given

The visitor must have a genuine choice. Cookie walls — where users must accept cookies to access content — are generally non-compliant. The EDPB has also stated that "consent or pay" models (where users either pay a subscription or accept tracking) do not constitute freely given consent for large platforms in most cases (EDPB Opinion 08/2024). Reject must be as easy as accept — confirmed in the CNIL's €325M Google fine and now actively enforced across most EU member states.

Specific

Consent must be given separately for each purpose. You cannot bundle analytics, advertising, and functional cookies into a single checkbox. A visitor who consents to "analytics to improve site performance" has not consented to advertising tracking and has not consented to data flowing to Meta or Google Ads. Granular category controls are a GDPR requirement, not a design option.

Informed

The visitor must understand what they're consenting to before they consent. This means the consent banner itself — not the linked privacy policy — must identify the specific tools being used (Google Analytics, Meta Pixel, etc.) and explain what they do and who receives the data. Vague references to "third-party cookies" or "advertising partners" have been found insufficient by multiple DPAs including France's CNIL and the Dutch AP.

Unambiguous

Continuing to browse is not consent. Scrolling is not consent. Pre-ticked boxes are not consent (Planet49 ruling, CJEU 2019 — still binding). The visitor must take a positive action — clicking Accept or equivalent. Silence, inactivity, or dismissal of a banner without explicit acceptance does not constitute valid consent under GDPR.

The Five Requirements for Valid Cookie Consent

GDPR's consent definition contains five distinct requirements. All five must be met simultaneously. Meeting four out of five does not constitute valid consent — any single failure invalidates the entire consent.

1

Freely Given

Consent is not freely given if refusing is harder than accepting, if consent is bundled with service access (cookie walls are generally prohibited), if there is an imbalance of power between the organisation and the individual, or if declining results in any disadvantage. The key practical implication: Reject All must be available with the same prominence and the same number of clicks as Accept All.

Article 7 + Recital 42, 43
2

Specific

Consent must be specific to each purpose of processing. A single "accept all cookies" toggle that covers analytics, advertising, personalisation, and social media tracking in one click is not specific consent — each purpose category requires its own separate consent signal. This is what makes granular category toggles a requirement, not an optional nicety.

Article 6(1)(a) + Recital 32
3

Informed

The data subject must understand what they are consenting to before consenting. This means the first layer of your banner must describe — in plain, accessible language — what categories of cookies exist, what purposes they serve, and that third parties receive the data. Legal jargon, technical terms without explanation, and buried disclosures that require clicking through to a privacy policy before the visitor has seen the banner all fail the informed requirement.

Article 13 + Recital 60
4

Unambiguous

Consent requires a clear affirmative action. Pre-ticked boxes, implied consent from continued browsing ("By using this site you agree..."), scrolling as consent, and inactivity are all explicitly invalid under Recital 32. The visitor must take a deliberate, active step to indicate agreement. Clicking Accept counts. Not closing a banner does not.

Recital 32 + Article 7
5

Revocable

The data subject must be able to withdraw consent at any time, and withdrawal must be as easy as giving consent. Article 7(3) states this explicitly. In practice: a persistent "Cookie Settings" or "Manage Consent" link must appear on every page of the website — not buried in your privacy policy, not requiring a cookie clear, not requiring contact with your team. One click to open the preferences panel from anywhere on the site.

Article 7(3)
Prior consent — the same requirement as CIPA

GDPR and the ePrivacy Directive require consent to precede cookie placement — the cookie must not fire while the banner is still loading, not fire while the visitor is reading the banner, not fire if the visitor dismisses or ignores the banner. The standard is identical to what US courts require under CIPA for California visitors: prior, affirmative, technically enforced consent before any tracking fires. One compliant CMP configuration satisfies both.

EDPB's expanded scope: pixels, fingerprinting, URL tracking

The European Data Protection Board's Guidelines 2/2023 on technical scope of the ePrivacy Directive, finalised in October 2024, formally expanded the scope of Article 5(3) beyond traditional HTTP cookies. This is the most significant regulatory development for tracking pixel operators in 2025–2026.

The EDPB confirmed that the consent requirement applies to any technology that stores or accesses information on a user's terminal device — not just cookies. Specifically named in the guidelines:

  • Tracking pixels embedded in web pages — any 1x1 pixel or transparent image that triggers a request to a third-party server on page load requires prior consent, because it accesses the user's terminal equipment (the browser initiates the request) and transmits identifying information (IP address, device headers, unique identifiers)
  • URL-based tracking — UTM parameters and link decorators that persist individual user identifiers across sessions fall within scope, particularly where they're used to track individual user journeys
  • Device fingerprinting — collecting combinations of browser characteristics (user agent, screen resolution, installed fonts, timezone) to identify individual users requires prior consent regardless of whether a cookie is set
  • HTML5 local storage and IndexedDB — any storage or access on a user's device for non-essential purposes requires consent, regardless of the technical mechanism used

The practical implication for Meta Pixel, TikTok Pixel, Google Analytics, Microsoft Clarity, and similar tools: they are all explicitly within EDPB's expanded Article 5(3) scope. None of them can fire before consent under EU law.

Recent enforcement: the cases every website owner should know

€325M
Google — CNIL (France) · September 2025
Two violations: displaying advertising inside Gmail without prior consent, and making the cookie rejection process significantly harder than acceptance during account creation. The CNIL found 74 million accounts affected by invalid consent. Reject was buried; accept was prominent. This asymmetry alone generated one of the largest cookie fines ever.
€150M
Shein — CNIL (France) · September 2025
Cookie violations including pre-enabled non-essential cookies and an inadequate rejection mechanism. Both Shein and Google fines were issued on the same day, demonstrating CNIL's capacity for coordinated high-value enforcement actions.
€15M
Swedish pharmacy chains — IMY (Sweden) · August 2025
Multiple pharmacy chains fined for deploying Meta Pixel on healthcare websites without proper user consent, transmitting sensitive health-related browsing data to Meta. The IMY held that liability rested with website operators, not Meta — you are responsible for what your pixels do.
€310M
LinkedIn — Irish DPC · October 2024
Behavioural advertising without valid legal basis. LinkedIn used contract as a legal basis for targeted advertising — the DPC found that consent was the only valid basis for behavioural advertising and that LinkedIn's approach failed to meet the GDPR standard. Microsoft set aside $425M before the decision, signalling that parent companies take these risks seriously.

What most websites still get wrong

Based on the enforcement record and DPA audit findings, the most common GDPR cookie consent failures in 2026 are:

FailureWhy it fails GDPRHow common
Pixels fire while the consent banner is loadingPrior consent requires zero tracking before the choice is made — even 50ms of pre-consent pixel activity is non-compliantExtremely common
Reject is harder to find than AcceptFreely given requires equal prominence — the Google €325M fine was partly for this exact asymmetryVery common
Pre-ticked optional cookie categoriesUnambiguous consent requires active action — pre-ticked boxes have been non-compliant since Planet49 (2019)Common
"By using this site you agree to cookies"Continued browsing is not consent — unambiguous requires a positive actionStill common
Cookie wall (must accept to access content)Freely given requires a genuine choice — access cannot be conditioned on tracking acceptanceModerately common
Single checkbox for all cookie purposesSpecific consent requires granular categories — analytics and advertising are separate purposesVery common
Privacy policy disclosure instead of banner disclosureInformed consent requires information before consent is obtained — a linked policy doesn't satisfy thisCommon on smaller sites
No consent records / timestampsGDPR accountability principle requires controllers to demonstrate consent was givenVery common

What a compliant configuration looks like

A GDPR-compliant cookie consent configuration has five non-negotiable technical properties:

  1. All non-essential scripts are blocked before consent. When a visitor lands on your page, zero requests to Google Analytics, Meta Pixel, TikTok, Hotjar, Clarity, or any other non-essential tracking tool should appear in the network tab. The CMP must enforce this blocking — displaying a banner while scripts load in the background is a violation.
  2. Accept and Reject are equally prominent on the first layer. Both options must be visible on the initial banner view without requiring the visitor to click through to a second layer to find Reject. A prominent Accept button with a small "Manage preferences" link that hides Reject is non-compliant.
  3. Granular category controls. At minimum, analytics and advertising must be separate consent categories. The visitor must be able to accept analytics but decline advertising, or decline both independently.
  4. Consent records with timestamps. Every consent event must be logged with: the timestamp when the choice was made, the version of the banner shown, the specific categories accepted or declined, and an identifier that ties the record to the session. These records must be producible within days if a DPA investigation asks for them.
  5. Withdrawal as easy as consent. GDPR Article 7(3) requires that withdrawal of consent must be as easy as giving it. A visible, accessible preference centre that lets visitors change or withdraw consent at any time is mandatory.
GDPR-compliant cookie consent: the required sequence Visitor arrives All scripts blocked Banner shown Accept + Reject equal prominence Visitor chooses Granular per purpose category Consent logged Timestamp + version + categories stored Scripts fire Only accepted categories only Non-compliant: any tracking request before Step 4 = ePrivacy Directive violation This applies to Google Analytics, Meta Pixel, Hotjar, Clarity, LinkedIn Tag — every non-essential script
The GDPR-compliant sequence. Any tracking request appearing before the consent log entry in Step 4 is a violation of the ePrivacy Directive.

What Your Banner Must Include — First Layer

The first layer is the initial banner that visitors see before interacting with your site. It must do a specific job: present the consent choice in a way that satisfies all five requirements above without requiring the visitor to navigate deeper to find the information they need to make an informed decision.

Non-negotiable first-layer elements

  • Clear description of cookie categories — at least the categories used (e.g. Strictly Necessary, Analytics, Marketing), written in plain language, not technical jargon. The visitor must understand what they are consenting to before clicking.
  • Accept All button — accepting all non-essential cookies in one click is the standard user expectation and must be available.
  • Reject All button — at the same level as Accept All — this is the most commonly violated requirement. If Accept All is on the first layer, Reject All must also be on the first layer with equivalent visual prominence. Multiple DPA enforcement actions since 2022 have been based solely on this requirement.
  • Link to preferences / manage cookies — access to granular category toggles for visitors who want to accept some but not all categories.
  • Link to your privacy policy or cookie policy — for visitors who want the full detail before deciding.
  • Statement that non-essential cookies are used and why — visitors must understand that their browsing data may be shared with third parties for analytics or advertising purposes.
⚠️
The "X" close button is not a valid Reject All. Some banners display a close (×) button as the implicit way to decline. The EDPB has stated clearly that closing a banner without making an affirmative choice is not unambiguous consent and is not a valid refusal. A close button can exist alongside Reject All, but cannot substitute for it.

The Second Layer — Preferences Panel Requirements

The preferences panel — the detailed view where visitors can accept or decline cookies by category — is the second layer. Visitors who click "Manage Preferences" or "Cookie Settings" on the first layer arrive here. It must meet its own set of requirements.

  • Granular toggles per purpose category — separate on/off switches for each consent category (Analytics, Marketing, Personalisation, etc.). A single toggle for "all non-essential cookies" is insufficient — it must be possible to accept analytics without accepting marketing, for example.
  • Strictly Necessary category clearly labelled and non-toggleable — essential cookies must be disclosed but cannot be declined. The UI should make clear why they cannot be turned off.
  • Default state of all non-essential toggles must be OFF — pre-ticked or pre-enabled toggles for non-essential categories are explicitly prohibited. Every non-essential category must default to disabled and only be enabled by an active visitor action.
  • Equal prominence for Accept All and Reject All — the same visual prominence requirement applies at the preferences panel level. If Accept All is a large coloured button, Reject All must also be a large coloured button of equivalent visual weight.
  • List of specific cookies or at least specific vendors — the EDPB recommends and several DPAs require that the second layer lists the specific cookies used in each category, or at minimum the categories of third-party vendors who receive data.
  • Save / Confirm selection button — visitors who configure granular choices must be able to save their specific selection, not just choose between all-or-nothing.

The Technical Requirements Beyond the UI

GDPR compliance is not just about how your banner looks — it is about what your website technically does in response to a visitor's consent decision. The UI requirements above are necessary but not sufficient. These are the technical requirements that the enforcement actions above make clear are being checked.

1. Prior consent — scripts must not fire before consent is given

The most fundamental technical requirement. Non-essential cookies and tracking scripts — Google Analytics, Meta Pixel, advertising tags, session-replay tools — must not execute until a visitor has actively consented to the relevant category. This requires actual script blocking at the JavaScript level, not a banner overlay that loads after the scripts have already fired.

In practice: a visitor arriving at your page for the first time, in incognito, with no prior consent state, must not generate any non-essential cookie or third-party tracking request before they have interacted with the banner. Test this by opening DevTools → Network tab in incognito and loading your homepage. If Google Analytics or any other tracker appears in the network waterfall before the banner is dismissed, your implementation is non-compliant.

🚫
A banner that loads after trackers is a notice, not consent. The sequence matters: consent must be obtained before processing occurs, not alongside or after. A consent banner that appears while Google Analytics is simultaneously loading in the background is not prior consent. The Spanish AEPD's 2024 enforcement action was specifically based on this — the banner looked correct but analytics fired before any interaction.

2. Consent must be stored and honoured on subsequent visits

Consent is not a per-session event. When a visitor makes a choice — accept or decline — that choice must be stored and applied on all future visits until the consent naturally expires (12 months is the widely adopted standard), the cookie declaration materially changes, or the visitor actively changes their preference. Re-prompting a visitor who has already declined on every subsequent visit, or loading trackers on a visitor who previously declined, are both compliance failures confirmed in enforcement decisions.

3. Consent must be logged with a timestamp

GDPR's accountability principle (Article 5(2)) requires that you be able to demonstrate compliance. For consent, this means maintaining a record of when each visitor consented, what version of the consent notice they were shown, and what they agreed to. This log must be produceable in the event of a DPA investigation. The Irish DPC's 2024 fine was partly based on inability to demonstrate that valid consent had been obtained for third-party data transfers.

4. Withdrawal must be technically effective

When a visitor withdraws consent through the Manage Consent preferences panel, the processing must actually stop. This means the relevant third-party scripts must be blocked from firing on subsequent page loads, and any applicable opt-out signals (including GPC browser signals in US state law contexts) must be acted upon immediately. A withdrawal mechanism that records a preference in a database but does not actually suppress script execution is not a functioning withdrawal mechanism.

What compliant versus non-compliant looks like in practice

Non-compliant
Large teal "Accept All" button; grey small "Manage Preferences" text link
Google Analytics loads on page load before banner interaction
Declining requires three clicks through a preferences panel
Non-essential category toggles default to ON in preferences panel
No Reject All on first layer — must navigate to preferences to decline
No persistent "Cookie Settings" link on inner pages
Consent re-prompted on every visit after previous decline
No consent log — cannot prove consent was obtained
Compliant
Accept All and Reject All both visible at first layer with equal visual weight
All trackers blocked at page load — nothing fires before banner interaction
Declining requires exactly one click — same as accepting
All non-essential toggles default to OFF in preferences panel
Reject All available on first layer — no navigation required
Persistent "Cookie Settings" link in footer on all pages
Declined consent stored and respected — banner not re-shown until expiry
Timestamped consent log maintained — exportable for DPA audit

Dark Patterns GDPR Prohibits — With Specific Examples

In 2022, the EDPB published its Guidelines 03/2022 on dark patterns in social media platforms, which has since been extended as a general framework for consent interface design. Multiple DPAs have fined organisations specifically for dark patterns in cookie banners. Here are the prohibited patterns with concrete examples of how they manifest.

🎨

Interface interference — colour and size asymmetry

Accept All in a bright teal button; Reject All or Manage Preferences in grey text, smaller font, or lower visual hierarchy. Both options must have equivalent visual weight.

🖱️

Click asymmetry — more clicks to decline

Accept in one click from the first layer; decline requires Manage Preferences → toggle off each category → Save. Declining must require no more steps than accepting.

📝

Misleading language and double negatives

"I do not want to be excluded from personalised advertising" as the label for a consent toggle. Language must unambiguously indicate what consenting or declining means.

🔒

Bundled consent

A single "accept all cookies to access the full site" gate where analytics, advertising, and personalisation are bundled together with no ability to consent selectively.

False urgency and countdown timers

Countdown timers ("Your choice expires in 10 seconds"), urgency language, or automatic acceptance if no action is taken within a time window. All invalid under the unambiguous requirement.

🔁

Consent fatigue — repeated re-prompting

Showing the consent banner again on the next visit after a visitor has already declined, or after any navigation event. Once a visitor has made a choice, honour it until consent naturally expires or the declaration materially changes.

😰

Implied benefit for accepting

Language that implies accepting provides a better experience — "Accept for a personalised experience" — when the alternative simply provides the standard experience. This creates implicit coercion.

🙈

Hiding the decline option

Placing Reject All only in the cookie policy document, or making it accessible only via a privacy settings page buried in the footer, while Accept All is on every page. Decline must be available wherever Accept is available.

Country-level differences that matter

Because the ePrivacy Regulation was withdrawn, the ePrivacy Directive continues to be implemented differently by each EU member state. For businesses operating across multiple EU markets, these differences affect which DPA is most likely to investigate you and what specific requirements apply:

CountryRegulatorKnown enforcement focusNotable requirement
FranceCNILHighest enforcement intensity in EU — cookie fines, email tracking, ad-techReject must be as easy as accept on first layer; formal guidance on email tracking pixels (April 2026)
NetherlandsAP (Autoriteit Persoonsgegevens)Third-party trackers, pre-ticked boxes — issued formal warnings to 200+ websites and fined Kruidvat €600KTechnical script blocking enforcement — Dutch AP reviews actual script behaviour, not just banner design
GermanyDSK (federal coordination) + 16 state DPAsTTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz) implements ePrivacy locally — stricter than many member statesLegitimate interest cannot be used for non-essential cookies; consent required for analytics
ItalyGaranteCookie walls, scroll consent, dark patternsEncourages use of documented CMPs; issued guidance on cookie classification
BelgiumAPDIAB TCF framework — APD's major ruling on TCF created years of litigationIAB TCF compliance is not a GDPR safe harbor; underlying consent obligations still apply
SpainAEPDHighest count of GDPR fines by number in Europe — active enforcement against SMEsGranular cookie categories required; cookie audit tools expected

The bottom line

GDPR cookie consent in 2026 is not a banner design question. It is a technical enforcement question. The CNIL's €325M fine against Google was not for having a bad privacy policy — it was for making reject harder than accept and displaying ads without prior consent. The Swedish pharmacy fines were not for having a confusing banner — they were for Meta Pixel firing before consent and transmitting health-related browsing data to Meta. The pattern is the same in every major enforcement action: the tools fired before consent was obtained, or the consent mechanism failed to be technically enforced. A compliant CMP that blocks all non-essential scripts before consent, presents Accept and Reject with equal prominence, logs every choice with a timestamp, and enables withdrawal as easily as consent is not optional in 2026. It is the minimum required by law and the minimum required to avoid joining the enforcement record above. This is informational, not legal advice; consult qualified counsel for specific situations.

Where DPAs Are Actively Enforcing in 2026

Cookie consent enforcement has increased significantly across Europe since 2023. These are the most relevant enforcement actions that directly inform what your banner must do in 2026.

DPA / CaseViolationFinePractical implication
French CNIL — Multiple actions 2024–25No Reject All at first layer; accepting required fewer clicks than declining€125,000–€3M per actionReject All must be on the first layer with equal visual prominence to Accept All
Spanish AEPD — 2024Analytics cookies firing before consent interaction; pre-ticked marketing categories€200,000Technical script blocking required — banners without blocking are non-compliant regardless of UI design
German DSK / LfDI — 2025Consent obtained through dark patterns — colour asymmetry between Accept and Decline€400,000Visual design of consent interface is now actively reviewed — not just legal text
Italian Garante — 2024–25Cookie wall with no genuine alternative; continued tracking after opt-out€1M–€5M rangeOpt-out must technically stop tracking — not just record a preference without effect
Irish DPC — 2024No consent log — could not demonstrate consent was obtained for data transferred to third parties€310,000GDPR accountability principle requires proof of consent — logging is mandatory, not optional
Belgian APD — 2025Consent re-prompted on every visit to users who had already declined€250,000Declined consent must be stored and respected — banner must not re-appear on subsequent visits

See whether your site meets GDPR cookie consent requirements

ConsentPixel — Privacy · Verified scans any website and shows exactly which scripts fire before consent — the same test DPA audit tools run. Free, no card required.

Scan my site free

Complete GDPR Cookie Consent Checklist 2026

✅ GDPR Cookie Consent Compliance Checklist — 2026 16 items
No non-essential scripts fire before consent is givenTest in DevTools Network tab (incognito) — GA4, Meta Pixel, analytics must not appear before banner interaction
Accept All and Reject All both present on the first layerReject All must not require navigating to a preferences panel — it must be on the banner itself
Accept All and Reject All have equal visual prominenceSame button size, same visual weight — no colour or size asymmetry that favours one option
Declining requires no more clicks than acceptingReject All is one click. Accept All is one click. These must be equivalent.
First layer describes cookie categories in plain languageVisitor must understand what they're consenting to before making a choice — no jargon, no "learn more" barriers
Third-party data sharing is disclosed on the first layerVisitor must know their data may be shared with advertisers / analytics platforms before consenting
Preferences panel has granular toggles per categoryAnalytics, Marketing, Personalisation — separate, independently configurable
All non-essential toggles default to OFF in preferences panelPre-enabled toggles for non-essential cookies are explicitly prohibited under GDPR
Preferences panel has a Save Selection buttonVisitors must be able to save granular choices — not just choose all-or-nothing
No dark patterns in the consent interfaceNo colour asymmetry, click asymmetry, misleading language, false urgency, or implied benefits for accepting
Persistent Cookie Settings link on every pageVisitors must be able to change or withdraw consent from any page — not just the homepage
Withdrawal actually stops processingChanging to Reject in the preferences panel must suppress scripts — not just record a preference
Consent is stored and honoured on subsequent visitsBanner must not re-appear on return visits until consent expires (typically 12 months)
Consent log maintained with timestamp and versionRecord what the visitor was shown, when they consented, and what they agreed to — GDPR accountability principle
Cookie declaration lists all cookies or vendors per categoryAvailable from the preferences panel — specific cookie names or at minimum categories of third-party vendors
Cookie declaration updated when new trackers are addedConsent obtained under an outdated declaration does not cover new cookies added after the consent event

Frequently asked questions

Does GDPR require a cookie banner?

GDPR itself does not mandate a specific banner format. However, the ePrivacy Directive requires prior consent before any non-essential cookie or tracking technology is placed on a visitor's device — and in practice, a consent management platform displaying a consent banner is the standard and legally accepted mechanism for collecting, recording, and managing this consent. The banner must offer both Accept and Reject with equal visual prominence and must not pre-tick any optional categories. Not legal advice.

Does Google Analytics need consent under GDPR?

Yes. Google Analytics is not strictly necessary for website operation, so it requires prior consent under the ePrivacy Directive and GDPR before placing cookies or transmitting user data. Multiple DPAs — including the Austrian DSB, French CNIL, Italian Garante, and Dutch AP — have ruled that GA transfers user data to the US without adequate safeguards. Even within the EU, GA4 must be blocked until consent is obtained. Not legal advice.

What is the maximum GDPR fine for cookie violations?

Under GDPR, the maximum fine for violations is €20 million or 4% of global annual turnover, whichever is higher. Cookie violations that breach the ePrivacy Directive alone may carry lower national-level fines in some member states, but where GDPR's data protection principles are also violated (which most tracking cookie deployments will trigger), the higher GDPR fine ceiling applies. France's CNIL imposed €325M on Google and €150M on Shein in September 2025 for cookie violations.

Does GDPR cookie consent apply to B2B websites?

Yes. GDPR applies to the processing of personal data of natural persons — B2B website visitors are natural persons whose IP addresses and device identifiers are collected by tracking cookies. There is no B2B exemption from cookie consent requirements. Even if your website targets business clients, if it tracks individual visitors using non-essential cookies, prior consent is required for EU visitors. Not legal advice.

Can legitimate interest be used for analytics cookies instead of consent?

No, not for the ePrivacy Directive layer. The ePrivacy Directive requires consent before placing non-essential cookies — it does not permit legitimate interest as an alternative legal basis. GDPR's legitimate interest provision (Article 6(1)(f)) applies to data processing, but it cannot substitute for the prior consent requirement under ePrivacy Article 5(3). Multiple DPAs and the CJEU have confirmed this: analytics cookies require consent, not legitimate interest. Not legal advice.

Does GDPR require a "Reject All" button on the first layer?

GDPR does not explicitly use the words "Reject All," but the requirement follows from the principle that consent must be freely given and has been confirmed by multiple Data Protection Authority (DPA) decisions. If an "Accept All" option is presented on the first layer, an equivalent "Reject All" option should also be available with equal visual prominence. The French CNIL, German DSK, and several other DPAs have issued enforcement actions where accepting cookies was made easier than declining them. Requiring users to open a preferences panel to reject cookies while allowing one-click acceptance is generally considered a dark pattern that can invalidate consent. Not legal advice.

Can you use cookie walls under GDPR?

Generally, no. Cookie walls that block access to a website unless visitors accept non-essential cookies are widely considered incompatible with GDPR's requirement that consent be freely given. The European Data Protection Board (EDPB) has stated that consent is not freely given when access to a service depends on agreeing to unnecessary processing. Some regulators have accepted limited "pay or consent" models where a genuine paid alternative exists, but a traditional cookie wall with no meaningful alternative is unlikely to be compliant in most EU jurisdictions. Not legal advice.

How long is GDPR cookie consent valid?

GDPR does not define a specific validity period for cookie consent. However, France's CNIL recommends a maximum duration of 13 months, and many organizations renew consent every 12 months as a best practice. Consent should also be refreshed whenever there is a material change to your cookie practices, such as adding new trackers, introducing new processing purposes, or using additional third-party vendors. Consent obtained before those changes generally does not cover the new processing activities. Not legal advice.

Does GDPR require consent for strictly necessary cookies?

No. Strictly necessary cookies—such as session cookies, shopping cart cookies, login authentication tokens, and load-balancing cookies—do not require prior consent under the ePrivacy Directive or GDPR because they are essential for providing the requested service. They should still be disclosed in your cookie policy. Analytics, advertising, personalization, and social media tracking cookies are not considered strictly necessary and generally require prior consent before being placed on a visitor's device. Not legal advice.

What is a dark pattern in a cookie banner?

A dark pattern is a user interface design that influences or pressures visitors into accepting cookies when they might otherwise refuse. Common examples include making the "Accept All" button larger or more prominent than "Reject All," requiring more clicks to decline than to accept, using confusing or misleading wording, pre-selecting optional cookie categories, repeatedly requesting consent after rejection, or implying users receive better functionality only if they accept unnecessary tracking. The EDPB published guidance on dark patterns in 2022, and multiple European regulators have taken enforcement action against websites using these practices. Not legal advice.

ConsentPixel — Privacy · Verified
We build GDPR and CIPA-first consent enforcement for websites and the agencies that manage them. This article is informational and not legal advice. GDPR enforcement evolves rapidly — verify current DPA guidance for your jurisdiction. Consult qualified counsel for specific situations.
Scroll to Top