Key takeaways
- The consent rule is about device access, not just cookies: ePrivacy Art. 5(3) also covers local storage, pixels and fingerprinting (EDPB Guidelines 2/2023).
- Exempt: what's strictly necessary for a service the user asked for — login sessions, carts, security, remembering the consent choice.
- Google Analytics, Meta Pixel, Google Ads tags, LinkedIn Insight, Hotjar and Clarity all need prior opt-in consent for EU visitors.
- The UK relaxed its rules: since 5 February 2026, first-party analytics used only to improve your own site can run without consent if you explain it and offer an opt-out.
- Cookieless analytics avoids the banner but not GDPR: you still need a privacy policy and a lawful basis for the processing.
When is a cookie banner legally required?
In the EU, the rule comes from Article 5(3) of the ePrivacy Directive (2002/58/EC), implemented in each member state's law: storing information on a user's device, or reading it, requires the user's consent unless it is strictly necessary to provide a service the user explicitly requested. GDPR then defines what valid consent is — freely given, specific, informed, unambiguous, and as easy to withdraw as to give. The Court of Justice confirmed in Planet49 (2019) that pre-ticked boxes don't count, and regulators such as France's CNIL have fined major sites for making "Reject" harder than "Accept". In the UK the equivalent is PECR regulation 6, as amended by the Data (Use and Access) Act 2025.
| What you use | EU | UK (after DUAA 2025) | Typical fix |
|---|---|---|---|
| Login, cart, security cookies | No consent | No consent | List them in your cookie notice |
| Google Analytics 4 | Consent required | Consent required (data goes to Google for its own use) | Load after consent, or switch to cookieless analytics |
| First-party analytics with cookies | Consent usually required (France's CNIL has a narrow exemption) | Exempt with clear notice + opt-out | Cookieless mode, or a UK-style notice |
| Cookieless analytics (stores nothing) | No banner; GDPR applies | No banner; GDPR applies | Privacy policy + DPA with the vendor |
| Meta, Google Ads, LinkedIn, TikTok pixels | Consent required | Consent required | Load only after opt-in |
| Session replay / heatmaps | Consent required | Consent required | Load after consent; mask inputs |
| YouTube, Maps, chat widgets | Usually consent (they set cookies on load) | Usually consent | Click-to-load placeholders |
| Google Fonts from Google's CDN | No cookie, but IP sent to Google (LG München I, 2022) | Same | Self-host the fonts |
How to use the checker
- 1.Tick where your visitors are. If you have any EU traffic, the EU rules apply to those visitors regardless of where your company is.
- 2.Tick every tool that runs on your site. Not sure? Open your site in a private window, then DevTools → Application → Cookies and Local Storage, and the Network tab: every third-party domain that loads before you click anything is a candidate.
- 3.Read the per-tool verdicts and fixes. Many "consent likely needed" items can be reconfigured — click-to-load embeds, chat that loads on click, self-hosted fonts — so they no longer need a banner.
- 4.If anything still needs consent, use a consent tool that blocks those scripts until opt-in and offers Reject as prominently as Accept.
Three example setups
- SaaS marketing site with GA4, Meta Pixel and an Intercom widget: banner required. GA4 and the pixel need opt-in; Intercom should load on click.
- Indie product with cookieless analytics, Stripe Checkout and self-hosted fonts: no banner likely needed for analytics. Keep a privacy policy naming the analytics vendor and Stripe.
- UK-only blog with first-party cookie analytics: under the 2026 UK exemption, a clear notice and an easy opt-out can replace the consent banner — but the moment you add ads or serve EU visitors, the stricter rules come back.
Common cookie-consent mistakes
- Loading tags before consent. A banner that appears while GA4 and the pixel have already fired doesn't make them compliant.
- No equal Reject button. Burying Reject in a second layer is the most-fined dark pattern in the EU.
- Treating Consent Mode as consent. Google Consent Mode adjusts tag behavior based on the user's choice; you still need the banner that collects it.
- Calling analytics "strictly necessary". Regulators have consistently said it isn't, outside narrow national exemptions.
- Assuming cookieless means no GDPR. The IP address and user-agent are personal data while they're processed; you still need a privacy policy and a DPA.
- Forgetting embeds. A single YouTube video on the homepage can be the only reason a site needs a banner.
Analytics without a cookie banner
If analytics is the only thing forcing a banner on your site, a cookieless tool removes it. VisitTrack's cookieless mode stores and reads nothing on the visitor's device: it derives a daily-rotating visitor ID from a one-way hash of the site, IP and user-agent with a salt that changes every day, and never stores the IP. The trade-off is that a visitor returning after 24 hours counts as new. A hybrid mode applies this only to EU, UK and Swiss visitors and uses a first-party ID elsewhere. VisitTrack's own docs are explicit that standard (cookie) mode should be loaded after consent in the EU. See also cookieless tracking in the glossary and how it compares with Google Analytics.
Frequently asked questions
Do I need a cookie banner if I only use Google Analytics?
Yes, for visitors in the EU and UK. GA4 sets cookies and sends data to Google, and analytics isn't strictly necessary, so you need opt-in consent before it loads. Google Consent Mode doesn't remove that requirement; it only changes how Google's tags behave depending on the answer.
Do strictly necessary cookies need consent?
No. Cookies that are strictly necessary for a service the user explicitly asked for — staying logged in, keeping a shopping cart, security and load balancing, remembering the consent choice — are exempt from consent under ePrivacy Article 5(3). You should still describe them in your cookie or privacy notice.
Does cookieless analytics need a cookie banner?
Generally no. If an analytics tool stores and reads nothing on the visitor's device, the ePrivacy consent rule doesn't apply. GDPR still governs the processing itself, so you need a privacy policy that names the tool and a data processing agreement with the vendor.
Is localStorage covered by cookie laws?
Yes. The ePrivacy rule covers any storing of or access to information on the user's device, and the EDPB's Guidelines 2/2023 confirm it includes local storage, tracking pixels and fingerprinting techniques, not only cookies.
Did the UK change its cookie rules in 2026?
Yes. The Data (Use and Access) Act 2025 added exemptions that took effect on 5 February 2026, including one for cookies used only to collect statistics that improve your own website, provided you give clear information and a simple, free way to object. Advertising cookies still need consent.
Do US websites need a cookie banner?
Usually not in the EU sense. Most US state privacy laws, such as California's CCPA/CPRA, are opt-out based: if you use ad pixels that share data for targeted advertising, you need a "Do Not Sell or Share" option and must honor Global Privacy Control signals. If you have EU or UK visitors, their rules apply to them.
Is this checker legal advice?
No. It's a simplified summary of the ePrivacy Directive, GDPR, EDPB guidance, CNIL and ICO positions as of October 2026, meant as a quick first check. National rules differ and change; for decisions about your site, consult a privacy lawyer or your data protection officer.
Related tools and guides
- Cookieless mode docsHow VisitTrack tracks without storing anything on the device.
- Cookieless trackingWhat it means and what you give up.
- VisitTrack vs Google AnalyticsPrivacy, consent and features compared.
- UTM builderCampaign tracking that works without cookies.
- Referrer channel checkerHow visits are attributed to channels.
- VisitTrack and GDPRHow VisitTrack handles personal data.