Cookie consent banners are everywhere — but the vast majority of them don't actually comply with EU GDPR or the ePrivacy Directive. A banner that says "We use cookies. By continuing to use our site, you consent" is not valid consent. Neither is a pre-ticked checkbox, a banner with no "reject" option, or one that buries the opt-out behind multiple clicks.
This guide explains what valid cookie consent looks like, what the law actually requires, and how to implement it correctly for both EU and US visitors.
What is cookie consent and why is it required?
Cookies are small text files placed on a visitor's device when they visit a website. Some are essential — login sessions, shopping cart contents — and don't require consent. Others track behaviour for analytics or advertising purposes, and these require prior informed consent under EU law.
The legal requirement comes from two sources:
- The ePrivacy Directive (2002/58/EC) — requires informed consent before placing non-essential cookies
- EU GDPR (Regulation 2016/679) — sets the standard for what valid consent looks like: freely given, specific, informed, and unambiguous
Together, these mean you need a consent mechanism — a cookie banner — that allows users to actively opt in to non-essential cookies before those cookies are placed.
What counts as valid consent under GDPR?
Under Article 7 of the EU GDPR and Recital 32, valid consent must be:
Freely given
Consent must be a genuine choice. You cannot make access to your website conditional on accepting cookies (known as a "cookie wall") — unless you offer an equivalent alternative without cookies. Consent is not freely given if refusing cookies means the website doesn't work or becomes significantly harder to use.
Specific
Consent must be given separately for each purpose. A single "accept all" checkbox that covers analytics, advertising, personalisation, and social media cookies together is not specific consent. Users must be able to consent to analytics cookies without consenting to advertising cookies.
Informed
Before giving consent, users must know: which cookies will be placed, who places them (first party or named third parties), what they're used for, and how long they last. Generic statements like "third-party cookies for advertising" are not sufficient.
Unambiguous
Consent requires an active, affirmative act — a deliberate click on an "Accept" button. Passive actions like scrolling, continuing to browse, or closing a banner do not constitute consent. Consent is not unambiguous if the "accept" button is much larger or more prominent than the "reject" button.
⚠ Pre-ticked checkboxes are explicitly prohibited as a consent mechanism under EU GDPR. Even if a user doesn't untick a box, this does not constitute valid consent.
Common cookie consent mistakes
"By continuing to browse, you accept cookies"
This is not consent. Browsing is not an active affirmative act. Numerous EU supervisory authorities — including the CNIL, the ICO (when UK GDPR applied pre-Brexit), and the Belgian DPA — have confirmed that implied consent through continued use is invalid.
No "reject all" button
If accepting cookies takes one click but rejecting them requires navigating to a settings panel and unchecking multiple boxes, that fails the "freely given" and "as easy to withdraw as to give" requirements. The CNIL fined Google €150 million and Facebook €60 million specifically for this issue.
Consent recorded for all cookies together
Bundling consent for analytics, advertising, and personalisation into a single toggle fails the "specific" requirement. Each purpose category needs its own consent.
No record of consent
Under Article 7(1) of EU GDPR, the data controller must be able to demonstrate that consent was given. This means you need to record when consent was given, what version of the consent banner was shown, and what the user consented to.
Cookies placed before consent
Non-essential cookies must not be placed until consent is given. Many implementations fire analytics scripts on page load before the consent banner is interacted with. This is a violation of the ePrivacy Directive.
What categories of cookies require consent?
Cookies fall into four main categories:
- Strictly necessary cookies — essential for the website to function (login sessions, CSRF tokens, shopping cart). No consent required.
- Analytics/performance cookies — measure how visitors use the site (Google Analytics, Hotjar). Consent required in EU.
- Functional cookies — remember user preferences like language or region. Consent typically required if non-essential.
- Marketing/targeting cookies — track users for advertising (Meta Pixel, Google Ads, LinkedIn Insight Tag). Consent required.
What about US visitors — does CCPA require cookie consent?
CCPA takes a different approach from EU GDPR. Instead of an opt-in requirement, CCPA requires an opt-out mechanism for the "sale" or "sharing" of personal data — which includes sharing data with advertising networks through cookies.
Under CCPA, you must:
- Disclose in your Privacy Policy that you use tracking cookies and share data with advertising networks
- Provide a "Do Not Sell or Share My Personal Information" link or a Global Privacy Control (GPC) signal
- Honour opt-out requests within 15 business days
You don't need an opt-in banner for US visitors — but you do need a visible opt-out mechanism and a compliant Privacy Policy that discloses your use of advertising cookies.
What must a Cookie Policy include?
A compliant Cookie Policy should include:
- What cookies are and why you use them
- A table of the cookies you set — name, provider, purpose, and duration
- Categories of cookies (strictly necessary, analytics, marketing)
- Named third parties who place cookies on your site
- How users can manage or withdraw consent
- Links to third-party opt-out tools (Google opt-out, Your Online Choices)
- Date the policy was last updated
DataShark generates a personalised Cookie Policy that names your specific third-party cookies, explains each purpose, and includes the correct opt-out information for EU, UK, and US visitors — from $14.
Ready to generate your GDPR policy?
Answer a few questions about your business and get a personalised, legally-structured document in minutes.
Start free — from £29 →