Cookie Consent: A Practical Guide for Website Owners
Cookie consent is one of the most visible — and most misunderstood — parts of GDPR compliance. Here's what you actually need to know and do.
What Cookies Need Consent?
Under GDPR + ePrivacy Directive: all non-essential cookies need prior, informed consent. The key word is "prior" — cookies must NOT be set until the user says yes.
Essential Cookies (No Consent Needed)
These are strictly necessary for the website to function: session cookies (login state), CSRF tokens, shopping cart cookies, load balancer cookies, and payment processing cookies.
Non-Essential Cookies (Consent Required)
Everything else: analytics (Google Analytics, Mixpanel), marketing/advertising (Facebook Pixel, Google Ads), functional (language preferences, A/B testing), social media (YouTube embeds), and session recording (Hotjar).
Cookie Banner Requirements
A compliant cookie banner must:
- Appear before any non-essential cookies are set
- List cookie categories with clear descriptions
- Allow granular consent — accept analytics, reject marketing
- Make rejecting as easy as accepting (no "accept all" with "settings" buried)
- Not use "cookie walls" — blocking access unless cookies are accepted (illegal under GDPR)
- Not use pre-ticked boxes (illegal under GDPR)
- Not imply that accepting cookies is required to use the site
- Store consent records (timestamp, what user consented to)
- Allow easy withdrawal of consent
Cookie Policy Page Requirements
Beyond the banner, you need a dedicated cookie policy page that lists: every cookie used (name, provider, purpose, duration, type), how to manage/delete cookies in each browser, what third-party services set cookies, and how to withdraw consent.
Generate Your Cookie Policy — Free
Get a complete GDPR-compliant cookie policy with detailed cookie table. Free, instant, no signup.
Generate Cookie Policy →