GDPR cookie consent, without the dark patterns
Reject as easy as accept, region-aware banners, and the consent records regulators ask for.
Key takeaways
- In the EU, non-essential cookies and trackers need consent before they run, with a narrow exception for strictly necessary ones. Since February 2026 the UK also exempts some first-party analytics, if visitors are told and can object.
- Valid consent is freely given, specific, informed and unambiguous. Pre-ticked boxes and "by continuing to browse" banners do not count.
- Regulators fine banners that make rejecting harder than accepting. France's CNIL fined Google €150 million and Facebook €60 million over exactly that.
- You must be able to prove consent. Keep a record of what each visitor chose, when, and which version of your banner they saw.
When a website needs cookie consent
Two EU laws work together here. The ePrivacy Directive (opens in a new tab) says you may only store or read information on a visitor's device with their consent, unless it is strictly necessary for a service they asked for. The GDPR (opens in a new tab) defines what valid consent means and applies when the data identifies a person, which most tracking data does.
The UK started from the same structure through PECR and the UK GDPR, but since February 5, 2026 the Data (Use and Access) Act has added exemptions: first-party analytics used only to measure and improve a site, and some functionality cookies, can run without consent if you explain them clearly and give visitors a simple way to object. Advertising and cross-site tracking still need consent. The ICO's guidance on storage and access technologies (opens in a new tab) explains where the lines are.
| Usually needs consent | Usually does not |
|---|---|
| Analytics in the EU, such as Google Analytics | Session and login cookies |
| Advertising pixels (Meta, Google Ads, TikTok, LinkedIn) | Shopping cart contents |
| Session replay and heatmaps | Load balancing and security cookies |
| Embedded social and video players that set cookies | Remembering a visitor's consent choice |
The test is whether the cookie is strictly necessary for something the visitor explicitly requested. Useful is not the same as necessary. Analytics that help you improve the site are useful, and in the EU they still need consent. In the UK, check whether your analytics fit the new exemption; tools that share data with an ad platform generally do not.
What valid consent looks like
Article 4(11) of the GDPR (opens in a new tab) defines consent as a freely given, specific, informed and unambiguous indication of the person's wishes, given by a clear affirmative action. Each word rules something out.
- Freely given: access to the site cannot depend on accepting non-essential cookies.
- Specific: people can choose by purpose, such as analytics separately from advertising.
- Informed: the banner says who is collecting data and why, in plain language.
- Unambiguous, by affirmative action: a click on Accept. Scrolling, continuing to browse or a pre-ticked box is not consent.
The Court of Justice of the EU confirmed the last point in the Planet49 judgment (opens in a new tab) in 2019: a pre-checked checkbox does not produce valid consent.
Article 7 (opens in a new tab) adds two more rules. Withdrawing consent must be as easy as giving it, and the controller must be able to demonstrate that consent was given. The EDPB's Guidelines 05/2020 on consent (opens in a new tab) explain both in detail.
The dark patterns regulators fine
A dark pattern is a design that nudges people toward the choice the business prefers. Cookie banners are full of them, and regulators have been clear that they invalidate consent.
In January 2022 France's CNIL fined Google €150 million and Facebook €60 million (opens in a new tab) because accepting cookies took one click while refusing took several. The fix it demanded was simple: a refuse option as easy as the accept option.
The European Data Protection Board's cookie banner taskforce report (opens in a new tab) lists the practices most authorities agree are problems:
- No reject option on the first layer when there is an accept option.
- Pre-ticked purpose boxes on the second layer.
- Reject shown as a link while accept is a prominent button, or colors and contrast that hide the reject choice.
- Relying on legitimate interest for cookies that need consent.
- Labeling non-essential cookies as essential.
- No easy way to change your mind later.
One banner, many regions
Not every visitor is under the same law. Showing an EU-style opt-in banner to everyone is safe but costs analytics coverage in places that do not require it. Showing a U.S.-style notice to everyone breaks the law for European visitors.
| Region | Model | What the banner must do |
|---|---|---|
| EU and EEA | Opt-in | Block non-essential cookies until the visitor accepts; reject as easy as accept |
| UK | Opt-in, with exemptions | Same as the EU, except qualifying first-party analytics may run with clear notice and an easy way to object |
| California and other U.S. states with privacy laws | Opt-out | Offer a Do Not Sell or Share link and honor Global Privacy Control signals |
| Most other regions | Notice | Explain cookie use; follow local rules where they exist |
A region-aware banner detects where the visitor is and applies the right model automatically. In California, the regulations require businesses to treat a Global Privacy Control (opens in a new tab) browser signal as a valid opt-out; our CCPA page covers the U.S. side. The ComplyMo cookie manager applies these rules per visitor from a single install.
The consent records you need to keep
If an authority or a customer asks whether a person consented, "our banner is set up correctly" is not an answer. Article 7(1) puts the burden on you to demonstrate it. A useful consent record captures:
- A pseudonymous identifier for the visitor or browser, not their name.
- The date and time of the choice.
- What they accepted or rejected, by category.
- Which version of the banner and cookie policy they saw.
- The region or regime that applied.
- Later changes, including withdrawals.
Keep records for as long as you rely on the consent, plus a reasonable period for handling complaints, and make sure you can export them. ComplyMo keeps this consent log automatically and exports it to CSV.
Google Consent Mode v2
If you use Google Analytics or Google Ads with EEA traffic, Google expects your banner to pass consent signals to its tags. Since March 2024 that has meant Consent Mode v2 (opens in a new tab), which adds two signals, ad_user_data and ad_personalization, to the older analytics_storage and ad_storage.
Without those signals, Google limits features such as audience building and ad personalization for EEA users. With them, tags adjust their behavior to the visitor's choice. Consent Mode is not a substitute for blocking: it tells Google tags what they may do, while other trackers still need to be held back until consent. Our guide to why trackers fire before consent explains the difference.
A cookie consent checklist
- Inventory every cookie and tracker on the site, including those added by tag managers and plugins.
- Classify each one: necessary, preferences, analytics or marketing.
- Block everything non-necessary until consent in opt-in regions.
- Show Accept all and Reject all with equal prominence on the first layer.
- Offer per-category choices and a persistent way to change them.
- Send Consent Mode v2 signals if you use Google tags.
- Honor Global Privacy Control where the law requires it.
- Log every choice with a timestamp and banner version.
- Re-scan after every new tag, plugin or campaign.
If you want most of that list handled by one script, start a free trial and turn on the ComplyMo cookie banner with auto-blocking. For the accessibility side of the same install, read ADA website compliance in 2026.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your obligations with counsel.

