Skip to content
GDPR7 min readBy ComplyMo Team

GDPR cookie consent, without the dark patterns

Reject as easy as accept, region-aware banners, and the consent records regulators ask for.

Key takeaways

  • In the EU, non-essential cookies and trackers need consent before they run, with a narrow exception for strictly necessary ones. Since February 2026 the UK also exempts some first-party analytics, if visitors are told and can object.
  • Valid consent is freely given, specific, informed and unambiguous. Pre-ticked boxes and "by continuing to browse" banners do not count.
  • Regulators fine banners that make rejecting harder than accepting. France's CNIL fined Google €150 million and Facebook €60 million over exactly that.
  • You must be able to prove consent. Keep a record of what each visitor chose, when, and which version of your banner they saw.

Two EU laws work together here. The ePrivacy Directive (opens in a new tab) says you may only store or read information on a visitor's device with their consent, unless it is strictly necessary for a service they asked for. The GDPR (opens in a new tab) defines what valid consent means and applies when the data identifies a person, which most tracking data does.

The UK started from the same structure through PECR and the UK GDPR, but since February 5, 2026 the Data (Use and Access) Act has added exemptions: first-party analytics used only to measure and improve a site, and some functionality cookies, can run without consent if you explain them clearly and give visitors a simple way to object. Advertising and cross-site tracking still need consent. The ICO's guidance on storage and access technologies (opens in a new tab) explains where the lines are.

Usually needs consentUsually does not
Analytics in the EU, such as Google AnalyticsSession and login cookies
Advertising pixels (Meta, Google Ads, TikTok, LinkedIn)Shopping cart contents
Session replay and heatmapsLoad balancing and security cookies
Embedded social and video players that set cookiesRemembering a visitor's consent choice

The test is whether the cookie is strictly necessary for something the visitor explicitly requested. Useful is not the same as necessary. Analytics that help you improve the site are useful, and in the EU they still need consent. In the UK, check whether your analytics fit the new exemption; tools that share data with an ad platform generally do not.

Article 4(11) of the GDPR (opens in a new tab) defines consent as a freely given, specific, informed and unambiguous indication of the person's wishes, given by a clear affirmative action. Each word rules something out.

  • Freely given: access to the site cannot depend on accepting non-essential cookies.
  • Specific: people can choose by purpose, such as analytics separately from advertising.
  • Informed: the banner says who is collecting data and why, in plain language.
  • Unambiguous, by affirmative action: a click on Accept. Scrolling, continuing to browse or a pre-ticked box is not consent.

The Court of Justice of the EU confirmed the last point in the Planet49 judgment (opens in a new tab) in 2019: a pre-checked checkbox does not produce valid consent.

Article 7 (opens in a new tab) adds two more rules. Withdrawing consent must be as easy as giving it, and the controller must be able to demonstrate that consent was given. The EDPB's Guidelines 05/2020 on consent (opens in a new tab) explain both in detail.

The dark patterns regulators fine

A dark pattern is a design that nudges people toward the choice the business prefers. Cookie banners are full of them, and regulators have been clear that they invalidate consent.

In January 2022 France's CNIL fined Google €150 million and Facebook €60 million (opens in a new tab) because accepting cookies took one click while refusing took several. The fix it demanded was simple: a refuse option as easy as the accept option.

The European Data Protection Board's cookie banner taskforce report (opens in a new tab) lists the practices most authorities agree are problems:

  • No reject option on the first layer when there is an accept option.
  • Pre-ticked purpose boxes on the second layer.
  • Reject shown as a link while accept is a prominent button, or colors and contrast that hide the reject choice.
  • Relying on legitimate interest for cookies that need consent.
  • Labeling non-essential cookies as essential.
  • No easy way to change your mind later.

One banner, many regions

Not every visitor is under the same law. Showing an EU-style opt-in banner to everyone is safe but costs analytics coverage in places that do not require it. Showing a U.S.-style notice to everyone breaks the law for European visitors.

RegionModelWhat the banner must do
EU and EEAOpt-inBlock non-essential cookies until the visitor accepts; reject as easy as accept
UKOpt-in, with exemptionsSame as the EU, except qualifying first-party analytics may run with clear notice and an easy way to object
California and other U.S. states with privacy lawsOpt-outOffer a Do Not Sell or Share link and honor Global Privacy Control signals
Most other regionsNoticeExplain cookie use; follow local rules where they exist

A region-aware banner detects where the visitor is and applies the right model automatically. In California, the regulations require businesses to treat a Global Privacy Control (opens in a new tab) browser signal as a valid opt-out; our CCPA page covers the U.S. side. The ComplyMo cookie manager applies these rules per visitor from a single install.

If an authority or a customer asks whether a person consented, "our banner is set up correctly" is not an answer. Article 7(1) puts the burden on you to demonstrate it. A useful consent record captures:

  • A pseudonymous identifier for the visitor or browser, not their name.
  • The date and time of the choice.
  • What they accepted or rejected, by category.
  • Which version of the banner and cookie policy they saw.
  • The region or regime that applied.
  • Later changes, including withdrawals.

Keep records for as long as you rely on the consent, plus a reasonable period for handling complaints, and make sure you can export them. ComplyMo keeps this consent log automatically and exports it to CSV.

If you use Google Analytics or Google Ads with EEA traffic, Google expects your banner to pass consent signals to its tags. Since March 2024 that has meant Consent Mode v2 (opens in a new tab), which adds two signals, ad_user_data and ad_personalization, to the older analytics_storage and ad_storage.

Without those signals, Google limits features such as audience building and ad personalization for EEA users. With them, tags adjust their behavior to the visitor's choice. Consent Mode is not a substitute for blocking: it tells Google tags what they may do, while other trackers still need to be held back until consent. Our guide to why trackers fire before consent explains the difference.

  1. Inventory every cookie and tracker on the site, including those added by tag managers and plugins.
  2. Classify each one: necessary, preferences, analytics or marketing.
  3. Block everything non-necessary until consent in opt-in regions.
  4. Show Accept all and Reject all with equal prominence on the first layer.
  5. Offer per-category choices and a persistent way to change them.
  6. Send Consent Mode v2 signals if you use Google tags.
  7. Honor Global Privacy Control where the law requires it.
  8. Log every choice with a timestamp and banner version.
  9. Re-scan after every new tag, plugin or campaign.

If you want most of that list handled by one script, start a free trial and turn on the ComplyMo cookie banner with auto-blocking. For the accessibility side of the same install, read ADA website compliance in 2026.

This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your obligations with counsel.

Frequently asked questions

Do I need a cookie banner if I only use Google Analytics?

For visitors in the EU and EEA, yes: analytics cookies are not strictly necessary, so they need consent first, and Google expects Consent Mode signals for that traffic. In the UK, first-party analytics used only for statistics can run without consent if you explain them and offer an easy opt-out, but Google Analytics shares data with Google, so get advice before relying on that.

Does a cookie banner need a Reject all button?

In practice, yes, for EU and UK visitors. Regulators have fined companies when refusing took more effort than accepting, and most European authorities expect a reject option on the first layer.

Is "by continuing to browse you accept cookies" valid consent?

No. The GDPR requires a clear affirmative action, and continuing to browse or scrolling does not qualify. Pre-ticked boxes are also invalid, as the EU Court of Justice confirmed in Planet49.

How long should I keep cookie consent records?

Keep them for as long as you rely on the consent, plus a reasonable period to handle complaints or audits. Many businesses keep records for the life of the consent and then a further year or more.

Is Google Consent Mode enough to comply with GDPR?

No. Consent Mode tells Google tags how to behave based on the visitor's choice. You still need a valid consent banner, and non-Google trackers must be blocked until the visitor agrees.

Sources

  1. EUR-Lex: General Data Protection Regulation (EU) 2016/679 (opens in a new tab)
  2. EUR-Lex: ePrivacy Directive 2002/58/EC (opens in a new tab)
  3. EDPB: Guidelines 05/2020 on consent under Regulation 2016/679 (opens in a new tab)
  4. EDPB: Report of the work undertaken by the Cookie Banner Taskforce (opens in a new tab)
  5. Court of Justice of the EU: Planet49 judgment (C-673/17) (opens in a new tab)
  6. CNIL: Cookie sanctions against Google and Facebook (French) (opens in a new tab)
  7. ICO: Guidance on the use of storage and access technologies (opens in a new tab)
  8. Google: Consent mode overview (opens in a new tab)
ComplyMo

Compliance, handled
in five minutes.

Accessibility, GDPR, and cookies. One script. One price. 14 days free.