Cookie Consent Done Right
Most cookie banners on the web are quietly non-compliant. They load trackers before anyone clicks, hide the reject button, or treat “continuing to browse” as agreement. Getting consent right is not complicated once you understand the handful of rules behind it — and doing it properly also builds trust with visitors.
The short version
Ask for consent before loading any non-essential cookie or tracker. Make rejecting as easy as accepting, use no pre-ticked boxes, explain what each category does, and keep a record of what people chose. Strictly necessary cookies don’t need consent. This is general information, not legal advice.
Consent must come first
Under EU rules (the ePrivacy framework, read together with the GDPR), non-essential cookies may only be set after the user agrees. That means your analytics, advertising and social-embed scripts should not run on page load — they wait until the visitor opts in. A banner that already dropped a tracking cookie by the time it appears has failed the most basic test.
What counts as “essential”
Strictly necessary cookies keep the site working: a login session, a shopping cart, a security token, or remembering the consent choice itself. These do not require consent. Everything aimed at measurement, profiling or marketing is non-essential and does require it. When in doubt, ask.
| Cookie type | Example | Consent needed? |
|---|---|---|
| Strictly necessary | Login session, cart, CSRF token | No |
| Preferences | Language or theme choice | Often yes |
| Analytics | Visitor measurement | Yes |
| Marketing | Ad targeting, retargeting pixels | Yes |
The rules of valid consent
For consent to count, it has to be freely given, specific, informed and unambiguous. In practice:
- No pre-ticked boxes. Silence or inactivity is not consent. Every non-essential category starts off.
- Reject as easy as accept. If “Accept all” is one click, “Reject all” must be one click too — and equally prominent.
- Granular choice. Let people accept some categories and refuse others, with a plain description of each.
- Easy to withdraw. Changing your mind later should be as simple as giving consent in the first place.
- Keep records. Store what each visitor consented to and when, so you can demonstrate compliance.
Common mistakes to avoid
- Loading trackers before the banner is answered.
- A big “Accept” button with reject buried in a submenu — a classic dark pattern.
- Treating scrolling or continued browsing as agreement.
- Cookie walls that block all access unless you accept marketing cookies.
- Vague labels like “we use cookies to improve your experience” with no categories.
- No way to withdraw consent once given.
Records and transparency
Keeping a consent log — who chose what, and when — is what lets you show a regulator you did things properly. Pair the banner with a clear cookie section in your privacy policy that lists the cookies you set, their purpose and their lifespan. Together, the banner and the policy tell a consistent story.
This guide is general information, not legal advice. Requirements vary by country and situation; consult a qualified professional for your specific case. Our compliance overview puts cookie rules in wider context.
Frequently asked questions
Do I need consent for Google Analytics?
Yes. Analytics cookies are non-essential, so they should only load after the visitor opts in, and the visitor must be able to refuse without penalty.
Is “by using this site you accept cookies” enough?
No. Implied consent from continued browsing is not valid. Consent must be an affirmative action, such as clicking accept on a specific category.
Can I make people accept cookies to use my site?
Cookie walls that force acceptance of non-essential cookies are generally not considered freely given consent. Offer a genuine reject option.
Related guides
GDPR Website Checklist for Small Businesses
A practical, jargon-free checklist to bring a small website in line with GDPR, from cookies to data requests.
Read →Privacy & ComplianceThe NIS2 Directive Explained for Website Owners
What the EU NIS2 directive is, who it applies to, and the baseline security it expects.
Read →Privacy & ComplianceWhat Every Privacy Policy Needs
The core sections a website privacy policy should contain and the plain-language way to write them.
Read →Check your site against this guide
Run a free ScanOpsPro scan and see how your site handles the fundamentals.
Run a free scan