Glossary · Privacy & compliance
What is consent banner?
A consent banner, or cookie banner, is the notice a website shows to ask visitors for permission before storing or reading non-essential cookies and similar identifiers on their device, and to record their choice.
Banners are usually run by a consent management platform (CMP). They exist because of the EU's ePrivacy Directive and the consent standard set by GDPR.
Also called: Cookie banner, Cookie consent popup, CMP
Updated
When is a consent banner required?
In the EU and EEA, you generally need consent before storing or accessing information on a visitor's device unless it's strictly necessary for a service they asked for (login, cart, security). Analytics, advertising and most social embeds aren't strictly necessary. In the UK, PECR now has an exception for cookies used only for statistics, provided you inform users and offer a simple way to object. In the US, opt-in banners are generally not required, but laws like CCPA require opt-outs for selling or sharing data. This is general information, not legal advice.
What makes consent valid?
- Before any non-essential cookie or tag loads — not after.
- Freely given and specific — separate choices for analytics and ads are best practice.
- No pre-ticked boxes — the EU Court of Justice ruled them invalid in Planet49 (2019).
- Refusing as easy as accepting — French regulator CNIL fined Google €150 million and Facebook €60 million in 2022 because rejecting cookies took more clicks than accepting.
- Withdrawable at any time, as easily as given, and recorded.
The cost of a consent banner for analytics
Every visitor who refuses or ignores the banner disappears from consent-gated analytics. If 40% of visitors don't consent, your traffic, conversion and attribution reports describe only the other 60% — and not a random 60%, since consent rates differ by device, country and audience. That's the main reason teams move analytics to a cookieless setup that doesn't need consent.
Common consent banner mistakes
- Loading Google Analytics, pixels or session recorders before the visitor chooses.
- A big "Accept" button and a hidden "Reject" in a settings menu.
- Treating scrolling or continuing to browse as consent.
- No way to change the choice later.
Do you need a banner for VisitTrack?
It depends on the mode. Standard mode stores a first-party identifier, so in the EU and UK plan on a banner (or load the script only after consent). Cookieless mode stores and reads no identifier on the device, so it's designed to run without one; you should still mention VisitTrack in your privacy policy. Hybrid mode is cookieless for EU/EEA, UK and Swiss visitors and stores an id elsewhere. See do you need a consent banner? and check any site with the cookie banner checker.
Frequently asked questions
Do I need a cookie banner for analytics?
In the EU, generally yes if your analytics stores cookies or other identifiers on the device, because analytics usually isn't strictly necessary. Cookieless analytics that stores nothing on the device is designed to avoid that requirement, though GDPR still applies to the data processing.
Is a cookie banner required in the US?
There's no general US opt-in banner requirement, but state laws such as California's CCPA require a way to opt out of selling or sharing personal data, which many sites implement with a banner or a footer link.
Related terms
- Cookieless trackingCookieless tracking is web analytics that counts visitors without storing any identifier on the visitor's device — no cookies, localStorage or similar — typically by deriving a short-lived anonymous id on the server instead.
- ePrivacy DirectiveThe ePrivacy Directive (Directive 2002/58/EC, amended in 2009) is the EU law on privacy in electronic communications whose Article 5(3) requires consent before storing information on, or reading it from, a user's device — which is why it's called the "cookie law."
- GDPRGDPR, the General Data Protection Regulation (Regulation (EU) 2016/679), is the European Union law that governs how personal data about people in the EU is collected, used and stored, in force since May 25, 2018.
- PECRPECR, the Privacy and Electronic Communications Regulations 2003, is the UK law that implements the ePrivacy Directive's rules on cookies and similar technologies, electronic marketing and communications security, enforced by the Information Commissioner's Office (ICO).
- First-party vs third-party cookiesA first-party cookie is set by the website you are visiting, under its own domain; a third-party cookie is set by a different domain embedded in that page — such as an ad network or social widget — and can follow you across every site that embeds it.
Tools and guides
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.