Guide

Do I Need a Cookie Banner Under GDPR, or Is That a Myth?

Cookie banners have picked up a lot of folklore: some businesses think they're always required, others think they're theater nobody checks. Neither is quite right. Here's what's myth and what's real.

Published August 30, 2026·Last updated August 30, 2026

Cookie banners have accumulated a lot of folklore. Some businesses treat them as a mandatory, one-size-fits-all box to check on every website regardless of what it does. Others have decided the opposite, that banners are theater nobody actually enforces, and skip them entirely. Both are wrong in specific, identifiable ways. Here’s what’s actually myth versus what’s a real legal requirement.

Not quite. GDPR itself doesn’t mention cookies. The actual legal requirement for cookie consent comes from a separate law, the ePrivacy Directive (sometimes called the “Cookie Law”), which requires consent before storing or accessing information on a user’s device, cookies being the most common example. GDPR comes in because it sets the standard that consent has to meet (freely given, specific, informed, unambiguous) once ePrivacy says consent is required. The two laws work together, but the banner requirement technically originates in ePrivacy, not GDPR.

This isn’t just trivia, it matters because it means the requirement kicks in based on whether you’re storing/accessing device data, not based on GDPR’s separate personal-data-processing triggers. A site can trigger the cookie consent requirement through ePrivacy even in edge cases where GDPR’s broader processing rules might not obviously apply.

Also false. Both ePrivacy and GDPR carve out an exemption for cookies that are strictly necessary for a service the user explicitly requested, session cookies that keep someone logged in, a shopping cart cookie, load-balancing cookies. These don’t require a consent banner at all, though disclosing them in a privacy/cookie policy is still good practice. The consent requirement is about non-essential cookies: analytics, advertising, and personalization cookies that aren’t necessary to deliver the thing the user asked for.

Myth: “A banner that just says ‘we use cookies, OK?’ is compliant”

This is the most common real-world failure, and it’s not close. A compliant banner needs:

  • A genuine reject option, equally prominent to the accept option, not hidden behind extra clicks
  • No pre-checked boxes for non-essential categories
  • Granular choice, letting a visitor accept analytics but reject advertising, for example, not just an all-or-nothing toggle
  • No dark patterns, like making “reject” gray and small while “accept” is a bright, large button

We cover the full technical requirements in our compliant banner guide. “We have a banner” and “our banner is compliant” are very different claims.

Our recommendation

Enzuzo

A banner that technically exists but skips reject parity, granular categories, or pre-checked boxes doesn't actually satisfy the requirement, it just looks like it does until someone checks. Enzuzo's templates are built to the compliant version by default rather than the common shortcut version.

Try Enzuzo

Myth: “If I’m not EU-based, this doesn’t apply to me”

If EU visitors reach your site and you set non-essential cookies on their browsers, the requirement applies regardless of where your business is based, the ePrivacy/GDPR framework is triggered by where the visitor is, not where you are. See our guide on GDPR’s territorial scope for the broader version of this question.

What’s actually true: when you genuinely don’t need a banner

  • Your site sets no cookies at all beyond strictly necessary ones (rare, but genuinely possible for very simple static sites).
  • You have no EU/UK traffic whatsoever and no other law (like the CCPA/CPRA in California) applies to your visitor base either. For a full walkthrough of whether your specific setup needs one, see our decision-framework guide.

This guide is educational and not legal advice. Whether your specific site needs a cookie banner depends on your actual cookie usage and visitor locations; consult a privacy attorney for your specific situation.