GDPR Cookie Consent: What a Compliant Banner Actually Requires
Most cookie banners disclose tracking without actually blocking it. Here's what GDPR consent actually requires, technically and legally, for a banner to be compliant.
A cookie banner is easy to add and easy to get wrong. Plenty of sites have one, feel covered, and are still running non-compliant tracking underneath it. GDPR’s requirements for cookie consent are specific enough that “we have a banner” and “we’re compliant” aren’t the same claim.
The legal basis: GDPR plus the ePrivacy Directive
Cookie consent specifically is governed by the ePrivacy Directive (sometimes called the “cookie law”), working alongside GDPR’s general consent standard. Together they require that consent for non-essential cookies be:
- Freely given, no forcing a choice by blocking site access entirely, and no cost or disadvantage for declining.
- Specific and informed, the visitor needs to actually understand what they’re consenting to, not a vague “we use cookies” statement.
- Unambiguous, via a clear affirmative action, no pre-ticked boxes, no implied consent from continued browsing.
- As easy to withdraw as to give, a “reject” or equivalent option must be presented with equal prominence to “accept,” not buried in a secondary settings menu while “accept” is a single prominent button.
Where implementations actually fail
The most common gap isn’t the visible banner design, it’s what happens underneath it. A banner that discloses tracking and records a choice, without technically preventing non-essential scripts from firing before that choice is made, doesn’t meet the “freely given” and “prior consent” standard. If Google Analytics or an ad pixel initializes the moment the page loads, the banner’s presence doesn’t change that the tracking already happened without consent.
Usercentrics
Usercentrics is built to actually block scripts at the network level pre-consent, not just display a banner over the top of trackers that are still running, which is the specific gap that undermines most DIY implementations.
What to check on your own site
- Equal prominence. Is “reject” (or “decline”) as visually easy to find and click as “accept”? A single-click accept next to a multi-step reject flow doesn’t meet the standard.
- Pre-consent blocking. Open developer tools, check the Network tab, and reload before touching the banner. If third-party requests are already firing, consent isn’t actually gating anything.
- Granularity. Where required, visitors should be able to consent to some categories (analytics) and not others (advertising), not just an all-or-nothing toggle.
- A working withdrawal mechanism. Visitors need an ongoing way to change their choice after the fact, not just at first visit.
Why this matters beyond avoiding fines
Beyond the risk covered in our piece on how GDPR fines actually work, a genuinely compliant banner is also the foundation for the technical fixes covered elsewhere on this site, see our guide on whether you need one at all if you’re starting from scratch, or our free cookie banner quiz for a fast read on your specific setup.
This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.