Blog

GDPR Cookie Consent Requirements: What the Law Actually Requires (2026)

Yes. If your website loads non-essential cookies, and almost every site does, from analytics to advertising to embedded video, and it can be seen by visitors in the EU or UK, the GDPR requires their consent before those cookies load. That part is settled. What trips people up is what "consent" has to look like to be valid, and the fact that the thing regulators actually enforce is not whether you show a banner. It is whether the tracking behind it really waits for the visitor to agree.

Key Takeaways

  • 01Yes. Under the GDPR, together with the ePrivacy Directive, you need a visitor's opt-in consent before any non-essential cookie or tracker loads. Strictly necessary cookies are exempt.
  • 02Consent has to be freely given, specific, informed, and unambiguous. Pre-ticked boxes, "by continuing you agree," and Accept-only banners do not count.
  • 03Rejecting has to be as easy as accepting. In 2022, France's CNIL fined Google €150 million and Facebook €60 million for banners where Accept was one click and Reject was several.
  • 04The enforcement risk is rarely a missing banner. It is a tracker that fires before consent. In our scan of 229 live sites, 78 to 83 percent fired a third-party request before anyone agreed.
  • 05ConsentStack holds non-essential trackers until the visitor opts in, ships Google Consent Mode v2 by default, and records each consent so you can prove it.

Yes, for non-essential cookies. Two laws work together here. The GDPR defines what valid consent is, and the ePrivacy Directive, often called the cookie law, applies that standard to anything stored on or read from a visitor's device. Together they require prior, opt-in consent before you set analytics, advertising, or other non-essential cookies and trackers. The exception is strictly necessary cookies, the ones your site genuinely cannot run without, like a login session or a shopping cart. Those do not need consent. Everything else does, and it has to wait until the visitor agrees.

The GDPR does not just want a click. It defines consent as freely given, specific, informed, and unambiguous, given through a clear affirmative action. In practice that becomes a short checklist your banner has to satisfy.

What the GDPR and ePrivacy rules require for cookie consent.
RequirementWhat it means in practice
Consent before loadingNon-essential cookies and trackers must not load until the visitor opts in. Loading them on the first page view and asking afterward is the single most common failure.
Freely givenNo pre-ticked boxes, no "by continuing to browse you accept," and no wall that blocks the site unless the visitor agrees. Saying no has to be a real option.
Specific and granularConsent is per purpose. A visitor can accept analytics while refusing advertising, so a single Accept All button is not enough on its own.
InformedBefore they choose, visitors need to know what each category of cookie does and who receives the data.
As easy to reject as to acceptIf Accept All is one click, Reject All has to be one click too, at the same level. Burying reject two menus deep is treated as invalid consent.
RevocablePeople change their mind, so you need a visible, always-available way to reopen preferences and withdraw consent.
DocumentedYou need a record of who consented, to what, and when, so you can show it if a regulator asks.

What regulators actually enforce

The largest cookie fines have not been about missing banners. They have been about banners that made saying no harder than saying yes. In January 2022, France's data protection regulator, the CNIL, fined Google €150 million and Facebook €60 million for exactly that. Both let a visitor accept every cookie with a single click, while refusing took several. The regulator treated that imbalance as invalid consent by itself, and gave the companies three months to add a one-click refuse option or face €100,000 a day.

A banner is not a checkbox to tick off

Notice what those fines had in common. Neither was about the absence of a banner. Each was about a banner that discouraged the choice it pretended to offer, or that let tracking run before the choice was made. A banner that does not actually hold the trackers back is not a lighter form of compliance. It is the violation.

The courts got there even earlier. In the 2019 Planet49 case, the EU's Court of Justice ruled that a pre-ticked consent box is not valid consent. Silence, a box the visitor has to untick, or the mere act of continuing to browse does not count. Consent has to be an active yes.

This is worth checking on your own site rather than assuming, because tracking before consent is the norm, not the exception. For our state of cookie compliance study we scanned 229 live websites and watched what loaded before the visitor touched anything. Between 78 and 83 percent of them fired a third-party request before any consent was given, which is the exact thing the GDPR forbids. And having a consent tool did not save them: of the sites running a recognized consent platform, 84 percent still failed a basic EU consent test. The banner was there. The blocking behind it was not. This is a plain-language summary rather than legal advice, so check anything load-bearing with your own counsel.

The GDPR and California are not the same job

If you have visitors on both sides of the Atlantic, you cannot run one banner design for both. The GDPR is an opt-in regime: nothing non-essential loads until the visitor agrees. California and the other US state laws are opt-out: tracking may load by default, but you have to disclose it and give people a working way to switch it off. A banner built for one is usually wrong for the other.

How the GDPR and the CCPA differ on cookies.
QuestionGDPR (EU and UK)CCPA and CPRA (California)
Can trackers load before the visitor chooses?NoYes
What does the visitor do?Opts inOpts out
Is a banner required?In practice, yesNo, but a notice and an opt-out are
Must browser signals be honored?Not requiredYes, GPC must be honored
Penalty ceilingUp to €20 million or 4% of global annual turnover$2,663 per violation, $7,988 if intentional

We cover the US side in our CCPA cookie consent requirements guide. The short version is that a banner tuned for Europe usually breaks the rules in California, and the reverse is true too.

How ConsentStack meets the GDPR standard

ConsentStack is built so the blocking behind the banner actually holds. Non-essential cookies and trackers are held before they load and stay held until the visitor opts in, so nothing fires ahead of consent. Choices are collected per purpose, so a visitor can accept analytics and decline advertising, and the right model is applied per region from a single install: opt-in for a visitor in Berlin, opt-out for one in Los Angeles, with no second setup to maintain. For Google's tools it ships Consent Mode v2 by default, keeping ad and analytics storage denied until the visitor agrees. Every decision is recorded, so if a regulator asks you can show who consented, to what, and when. And when someone clicks Reject, the scripts actually stay off, which is the part 84 percent of consent-tool sites were getting wrong. Plans start at $29 a month, and if you would rather not touch the configuration, we set it up for you.

Before you change anything, find out where you actually stand. Run your domain through our free compliance scanner and it will show you which trackers fire on page load, before any consent, and which keep going after someone clicks Reject, checked from both an EU and a US vantage point. It takes about a minute and does not ask for an email. If tracking is firing before your visitors agree, this is the fastest way to see it.

GDPR cookie consent FAQ

See what loads before your visitors consent

Run a free compliance scan and see exactly which trackers fire before anyone clicks accept, and which keep going after Reject. No signup.

Related Posts