What a cookie banner has to do
Cookie banner requirements depend on where your visitors live, not where your business is registered. Two rulebooks cover most of the web: the EU and UK ask for consent before non-essential cookies load, and most US states ask instead for clear notice and a working way to opt out. A site with visitors in both places has to satisfy both.
EU and UK: consent before anything loads
The GDPR and national ePrivacy rules set the same five conditions. Four of them are about the banner. The first one is not, which is why a banner can look correct and still leave the site non-compliant.
| Requirement | What it means on a real site |
|---|---|
| Ask before anything loads | Analytics, advertising and personalization scripts must not run until the visitor agrees. A banner that appears while the tags are already firing does not meet this, however the banner itself is worded. |
| Make it an active choice | No pre-ticked boxes. Scrolling, continuing to browse, or dismissing the banner is not agreement, so a close button cannot be treated as an accept. |
| Give reject the same weight as accept | Both options belong on the first layer, at the same size and prominence. Reject buried behind a preferences link is the pattern regulators cite most often. |
| Let people choose by purpose | Analytics, advertising and personalization are separate decisions, not one switch. Strictly necessary cookies are the only group that may be on by default. |
| Make withdrawing as easy as agreeing | Visitors need a way back into the choice from any page, and withdrawing has to take no more effort than granting did. |
The first row is the one that fails silently. On the 229 sites that ran our scanner, 78% to 83% sent a third-party request that needs consent before the visitor answered anything. Full detail on the rules themselves is on the GDPR page.
United States: notice, opt-out, and one big exception
There is no federal US privacy law, so the rules that reach your site depend on which states your visitors are in. The counts below are read from our regulation records when this page builds, so they move when the law moves.
The US is usually summarized as opt-out, and for ordinary analytics it is: 25 of these laws let tracking start before the visitor chooses, as long as you offer a clear way to decline and you honor it. The summary breaks down on sensitive data. 24 of the 27 laws require opt-in consent before you handle categories like health, precise location, biometrics, or racial and ethnic origin, which puts a consent step back in front of exactly the data most likely to be audited.
The obligation sites miss most often is invisible from the banner. 12 laws in force require you to respect a preference the browser sends automatically, usually Global Privacy Control. That signal arrives before anyone clicks anything, so no amount of banner design will catch it.
Last reviewed August 9, 2026. Compare every US state law side by side for effective dates, cure periods, and whether consumers can sue directly.
Cookie banner examples
Every design below satisfies the layout side of the rules above: accept and reject carry the same weight, and nothing is pre-ticked. Filter by style to find a look that fits your site.
28 designs
We use cookies to improve your experience.
This site uses cookies. Learn more
Cookies help us serve you better.
Your privacy
We use cookies to personalize content and analyze traffic.
We value your privacy. Manage your cookie preferences any time.
Cookies
Choose what we can store on your device.
We use cookies
To keep things running smoothly and understand what people love.
Cookie preferences
We use cookies for analytics and a better experience.
Mind if we use cookies?
They help us remember your preferences.
We respect your privacy
We use cookies to enhance your browsing. You choose what to allow.
Manage cookies
Toggle the categories you are comfortable with.
Welcome 👋
Before you dive in, choose how we use cookies.
We use cookies to make this site work.
Cookies keep you signed in and help us improve.
We use cookies to analyze traffic and improve your experience.
We use cookies for a better experience.
Cookie time!
We bake these to make your visit sweeter.
Can we use cookies?
Hey there, quick thing
We use a few cookies. Totally your call.
Cookies.
We use them. You decide.
We use cookies
No tricks. Choose below.
Heads up
Cookies make this site run.
Privacy first
We use cookies to keep this site fast and relevant.
Cookie settings
Pick what we store while you browse.
Cookie disclaimer, cookie popup, cookie notice: the same thing
These names all describe one artifact, and no law uses any of them. The wording usually says more about who wrote it than about what it does.
- Cookie banner, cookie notice, cookie notification. The neutral names, and the ones most vendors and regulators use.
- Cookie disclaimer, cookie warning. Borrowed from legal notices. They suggest the point is to disclose rather than to ask, which fits a US opt-out notice better than an EU consent request.
- Cookie popup, cookie modal. Describe placement rather than purpose. A modal blocks the page until answered; a popup or corner card does not.
- Consent banner, consent management platform. The banner is the visible part. The platform is the part that decides which scripts may run, stores the answer, and proves later what was chosen.
What you call it changes nothing about the obligations above. What it does when someone clicks Reject changes everything.
Cookie banner questions, answered
What are the legal requirements for a cookie banner?
They depend on where your visitors live, not where your business is. Under EU and UK rules, a banner must ask before non-essential cookies load, take an active choice rather than a pre-ticked box, offer reject as prominently as accept, let people decide purpose by purpose, and make withdrawing as easy as agreeing. Most US state laws instead run on an opt-out model, where tracking may start first as long as you give a clear way to decline and honor it.
Does the CCPA require a cookie banner?
No. The CCPA and CPRA require notice at collection, a way to opt out of the sale or sharing of personal information, and respect for browser opt-out signals such as Global Privacy Control. A banner is a common way to deliver all three, but the law asks for the outcome rather than the banner. 12 state laws in force today require honoring that browser signal, and it arrives before the visitor touches your page, so no banner click will catch it.
Do US state laws ever require opt-in consent?
Yes, and this is the part the opt-out summary hides. 24 of the 27 state privacy laws tracked here require opt-in consent before you handle sensitive categories of data, such as health, precise location, biometrics or racial and ethnic origin. Ordinary analytics stays opt-out in those states; the sensitive slice does not.
What is a cookie banner?
What should my cookie banner say?
Is it illegal to not have a cookie banner?
What are the different types of cookie banners?
How do you design a cookie banner?
What are the most common cookie banner mistakes?
- Tracking that starts before anyone chooses. The most common mistake has nothing to do with how the banner looks. Across the 229 sites that ran our scanner, 78% to 83% sent a third-party request that needs consent before the visitor answered. On a control group of the web's most-visited sites, it was 75%.
- Recording the choice, then ignoring it. The banner saves a reject and the analytics and advertising tags load anyway. Across 949 sites with a working reject button, 43.4% of tracking cookies were still in the browser afterwards, and 97.5% of those had been set before the visitor answered. An independent study of 200 sites (arXiv 2411.15414) found 57.5% did not delete cookies after consent was withdrawn.
- Making accept easier than reject. A large “Accept all” next to a small “Manage preferences” link, or reject buried two clicks deep. This is the dark pattern regulators cite most often, because an unequal choice is not a real choice.
- Pre-ticked boxes. Analytics or marketing already switched on when the banner appears. Consent has to be something a visitor gives, not something they forget to take away.
- Calling everything essential. Only the cookies your site cannot work without belong in that group, such as login sessions and cart state. Analytics, advertising and personalization do not.
- Vague copy. “We value your privacy” tells nobody anything. Name the categories you use, say what each one is for, and say what changes when someone declines.
- No way to change the answer later. People should be able to reopen the choice and withdraw consent without hunting through a policy page for it.
- Treating a close, a scroll, or an X as agreement. Dismissing a banner is not consenting to anything, and the effect of every button should be obvious before it is clicked.
- A banner that only really works on a desktop. Full-screen takeovers on phones, buttons too small to hit, and controls a keyboard or screen reader cannot reach all turn a consent choice into a trap.
The first two are the ones you cannot catch by looking at the banner. Scan your site to see which trackers fire before consent and which survive a reject.
100+ happy customers
Like one of these? Build it.
Design your banner to match your brand, then drop it in with one install. Full control over the look, no code required.