A cookie banner is only effective when the choices it presents control the actual storage, access and tracking behaviour. Review both the interface and the implementation, including tags loaded by embeds, scripts and navigation. An attractive consent screen cannot cure non-exempt tracking that already occurred.
This article breaks down what cookie banner compliance actually requires, which common patterns are illegal, and how to verify your implementation.
What Does the Law Actually Require?
Cookie banner compliance in Europe involves Article 5(3) of the ePrivacy Directive 2002/58/EC, as implemented nationally, and the consent standard in the General Data Protection Regulation (GDPR). Assess which operations require consent, then review the choice and information presented. Distinguish legal requirements from the national guidance and design recommendations below.
Prior consent for non-exempt operations. Article 5(3) requires consent before storing or accessing information on a device, except for its communication-transmission and strictly-necessary-service exemptions. Block non-exempt operations and the tags that initiate them until valid consent. A tag manager or analytics script is not automatically consent-requiring by its name: examine its actual behaviour and any applicable exemption, including the narrowly conditioned French audience-measurement exemption.
Freely given. A choice is not free merely because a button says “accept”. The EDPB consent guidelines reject access conditioned on consent where no genuine choice exists. Assess cookie-wall or paid-alternative arrangements against applicable national guidance and the actual alternative; neither a universal ban on every paid model nor automatic validity is a sound rule. See the consent guide.
Specific and granular by purpose. Where analytics and advertising both require consent, users must be able to choose between those purposes. A single mandatory bundled choice does not provide that granularity. An optional “accept all” control can coexist with genuine purpose-by-purpose choices under GDPR requirements.
Informed in plain language. The banner must state who sets cookies, what categories exist, what purposes they serve, and how long they persist. “We use cookies to improve your experience” does not meet the threshold.
A genuine, accessible refusal choice. In France, the CNIL requires acceptance and refusal with the same degree of simplicity. Its recommendation strongly favours making refusal accessible on the same screen with the same ease, and recommends equally readable, equally highlighted controls. Those design recommendations are not a uniform EU colour or contrast rule. Check applicable national guidance and the actual interaction; see the cookie consent compliance guide.
Which Patterns Can Undermine Valid Consent?
Supervisory authorities and courts have rejected practices such as pre-ticked consent and misleading choices. Other design details require assessment in context, including the national rules and the effect on the user’s ability to refuse.
Pre-Checked Boxes and Missing Reject Buttons
The CJEU settled pre-checked boxes in Planet49 (Case C-673/17, 2019): they do not constitute valid consent. Any CMP that loads with consent-requiring toggles on by default is non-compliant.
CNIL fined Google EUR 150 million and Facebook EUR 60 million in January 2022 because their banners offered “Accept” prominently but required multiple clicks to reject. Asymmetric effort vitiates consent. See our examples of GDPR consent.
Manipulative Design and Deceptive Scrolling
Confusing double negatives, a hidden refusal route or unreadable reject text can prevent a genuine choice. The EDPB Cookie Banner Taskforce declined to impose a general colour or contrast standard and calls for case-by-case assessment. As a conservative design recommendation, offer clearly readable accept and reject controls with comparable prominence; assess the complete banner rather than treating a colour difference alone as proof of illegality.
Treating continued scrolling as implied consent is also illegal. The EDPB rejected this in Guidelines 05/2020: scrolling does not constitute a clear affirmative act.
What Are the Cookie Categories?
Cookie banner compliance requires correct categorization, which starts with a cookie audit that maps every cookie your site actually sets. Miscategorizing a marketing cookie as “functional” is a compliance failure. The following categories help organise an inventory, but legal exemptions depend on the purpose and configuration, not the category label:
- Exempt operations – Article 5(3) covers storage/access solely for transmitting a communication, or strictly necessary to provide an information-society service explicitly requested by the user. Session authentication, shopping carts and security or load-balancing functions need to be assessed against the particular purpose and configuration.
- Preferences and functionality – assess individually. A language preference requested by the user can qualify for an exemption; unrelated tracking cannot be made exempt by calling it “functional”.
- Analytics – generally consent-based unless the exact implementation qualifies for a recognised national exemption. In France, the CNIL specifies narrow audience-measurement conditions. A product name, self-hosting or “cookieless” label alone does not establish exemption.
- Marketing and advertising – non-exempt advertising storage/access requires consent. Retargeting pixels, cross-site tracking identifiers, ad network cookies. Our GDPR compliance checklist covers the full set of obligations around these activities.
How Should the Technical Implementation Work?
The legal requirements translate into specific technical behaviors. A consent interface must control non-exempt storage/access and the scripts that perform it, while preserving operations covered by a documented applicable exemption.
Before consent, prevent storage or access that requires consent. Assess any claimed exemption against the applicable national rule and actual configuration. The CMP may set a cookie to record the banner was shown, but must not record a consent choice not yet made.
Scripts performing consent-requiring operations must respect purpose-specific checks before and after the choice. Consent to analytics does not authorize marketing tags. The choice must be remembered appropriately, and the user must be able to withdraw consent at any time per Article 7(3) GDPR, triggering suppression of the relevant tags. These recording, persistence, and withdrawal obligations are covered in depth in our GDPR consent management guide.
What Are the Enforcement Consequences?
Cookie enforcement must be linked to the actual legal basis and conduct. French cookie decisions apply national ePrivacy legislation as well as relevant GDPR standards; not every large privacy fine concerns a cookie banner. Do not describe the Irish TikTok children’s-data fine as a cookie-banner decision or attribute a French Amazon cookie fine to Luxembourg.
The CNIL sanction register identifies cookie refusal, information and consent findings. For design review, the EDPB Cookie Banner Taskforce report is more useful than an undifferentiated fine table: it covers absent reject choices, pre-ticked options and misleading presentation while recognising areas of national assessment. The GDPR fines guide gives the wider enforcement context.
How Do You Test Your Cookie Banner?
Compliance is verifiable. Run through this checklist before and after deployment.
Pre-consent state:
- Open the site in a fresh browser session (no existing cookies).
- Before interacting with the banner, check device storage against the inventory. Every operation occurring without consent must have a documented applicable exemption.
- Inspect network requests and device storage. Identify whether any non-exempt information is stored or accessed, even if no traditional cookie appears.
- Verify that the interface offers a genuine choice and assess any access condition against applicable guidance.
Banner design:
- Check refusal against applicable national guidance. As a conservative design recommendation, provide a clear first-layer reject choice with comparable prominence; assess readability and the actual effort required rather than applying a universal colour rule.
- Verify that a “Manage Preferences” or “Customize” option allows granular choice by category.
- Check that no toggles or checkboxes are pre-checked for consent-requiring purposes.
- Read the text: does it clearly state who sets cookies, what categories exist, and what purposes they serve?
Post-consent behavior:
- Where analytics requires consent, accept that purpose alone. Verify that non-exempt advertising operations remain blocked.
- Refuse all consent-requiring purposes. Verify that non-exempt storage/access remains blocked, including cookieless tracking; documented exempt operations may continue.
- Navigate to a second page. Verify that your consent choice persists and the banner does not reappear.
- Find the mechanism to withdraw consent. Verify that using it suppresses the relevant tags.
For a comprehensive walkthrough of the broader compliance landscape, see our guide on how to comply with GDPR and the hidden productivity drain of cookie banners for the operational cost of getting this wrong.
Keep a State-by-State Verification Record
Use a fresh browser profile and record the page, date, CMP/configuration version and expected state. Test no action, reject, accept one purpose, accept all, change preferences and withdraw. Repeat on a second page and after returning to the site. A choice that works only on the landing page leaves the rest of the journey unverified.
For each state, capture the visible choice, storage entries and relevant requests. Trace an unexpected request to its initiator: the tag manager, embedded video, direct script or server-side integration may each need a different fix. Distinguish an allowed service request from non-exempt tracking by examining the purpose and data, not only the destination’s hostname.
Test withdrawal after trackers have already run. Confirm that future non-exempt access stops and that first-party identifiers are handled consistently with the withdrawal design. Record third-party limitations and the mechanism used to propagate the choice; simply closing the banner does not remove a previously granted purpose.
Finally, reconcile the cookie inventory and notice with what was observed. Keep consent evidence sufficient to show the information and choice presented without collecting unnecessary identifiers. The CNIL’s consolidated cookie recommendation includes current French guidance, including cross-device choices; do not silently extend a choice to every device without assessing the conditions.
Frequently Asked Questions
Do I need a cookie banner if I only use strictly necessary cookies?
A consent banner is unnecessary where all storage or access falls within applicable exemptions, but information duties still need assessment. Check every purpose, including embeds and preference functions. The words “functional” or “analytics” do not alone determine whether consent is required.
Is Google Analytics exempt from consent requirements?
Do not assume an analytics product is exempt. Verify the actual purposes, configuration, recipients and applicable national exemption conditions. Separate that consent question from GDPR lawful-basis and international-transfer questions; a decision about transfers is not itself a universal ruling about cookie consent.
Can I use a cookie wall that blocks content until users consent?
An access condition that leaves no genuine choice is incompatible with freely given consent. Evaluate the actual alternatives and applicable national and EDPB guidance. Offering a paid option does not automatically establish valid consent, and the answer cannot be reduced to one universal price or design rule.
How often should I re-obtain consent?
There is no universal GDPR 13-month consent-renewal rule. The CNIL implementation guidance generally regards six months as appropriate for remembering both acceptance and refusal. Do not confuse that recommendation with audience-measurement tracker lifetimes. Reassess consent when purposes or other material information change.
Does the ePrivacy Directive apply to mobile apps?
Yes. Article 5(3) covers any storage on “terminal equipment” – smartphones, tablets, any connected device. Mobile SDKs that set device identifiers or local storage are subject to the same consent requirements. Note also that controllers cannot delegate compliance to a CMP vendor. If your CMP is misconfigured, the fine falls on you. Always audit actual behavior, not vendor claims.
FAQ
What makes a cookie banner legally compliant?
Where consent is required, obtain it before non-exempt storage/access, provide informed purpose-specific choices without pre-ticked consent, and make withdrawal as easy as giving consent. Assess refusal and design under applicable national guidance and the complete interface. Comparable prominence is a conservative design recommendation; it is not a universal EU colour/contrast validity test.
Is “reject all” mandatory on cookie banners?
Check the applicable national rules and guidance. The CNIL requires refusal with the same degree of simplicity as acceptance and strongly recommends same-screen access with the same ease. Its recommendation gives “accept all”/“reject all” buttons as one clear implementation and also recognises other clearly explained refusal mechanisms. A particular label is not prescribed across the EU. A first-layer reject choice remains a conservative design recommendation.
Can implied consent (scrolling, continued browsing) satisfy cookie consent?
No. The CJEU’s Planet49 ruling (2019) and the EDPB’s Guidelines 05/2020 are clear: only an active, affirmative action constitutes valid consent. Scrolling, continued browsing, and “by using this site you consent” notices are non-compliant.
What are the most common cookie banner violations?
Examples authorities have identified include pre-ticked consent for non-exempt tracking, storage/access before consent, misleading refusal choices, inability to demonstrate consent and withdrawal that is harder than acceptance. Assess access conditions under the freely-given-consent analysis above rather than treating every overlay or paid alternative as automatically unlawful.