New · A dedicated AI SEO channel: see conversions from ChatGPT, Perplexity, Claude & Gemini →
← Blog
Part of: SEO Conversion Tracking: Measure Conversions and Value from Organic Search →

Cookie Banner Requirements: EU Opt-In, US Opt-Out, and How to Test

Portrait of Samy ThuillierBy ··14 min read
Cookie banner requirements shown as a consent banner with equal Accept all and Reject all buttons

Cookie banner requirements depend on where your visitors are. In the EU and UK, a banner must block every non-essential cookie until the visitor opts in, explain each purpose plainly, offer “Reject” as easily as “Accept” and let people change their mind later. In the US, most state privacy laws use an opt-out model: no pop-up is required, but you need a notice at collection, a way to opt out of the sale or sharing of personal data, and you must honor Global Privacy Control signals.

This guide covers both models, where the top results contradict each other, the technical side of “what counts as a cookie,” a 10-minute test you can run on your own banner, and what the banner will do to your conversion reports once it is live. It is a practical guide, not legal advice: if your situation is unusual, check with counsel.

Cookie Banner Requirements at a Glance

RequirementEU and UK (opt-in)US states (opt-out)
Non-essential cookies before a choiceBlocked until the visitor acceptsAllowed, unless the visitor has opted out or sent GPC
Pop-up or bannerIn practice yes, consent needs an affirmative actionNot required by the CCPA; a footer link can do the job
Reject optionMust be as easy as acceptingOpt-out link for sale or sharing of personal data
Pre-ticked boxesNot valid consentNot the model; opt-outs must be honored
Purpose explanationSpecific, plain-language purposes per categoryNotice at collection: categories of data and purposes
Browser signalsNo legal duty in most countries, good practiceGlobal Privacy Control must be honored in California
WithdrawalAs easy as giving consent, at any timeOpt-out available at any time
ProofBe able to show consent was givenKeep records of opt-out requests

What a Cookie Banner Is (and What It Is Not)

A cookie consent banner is the message a site shows on a first visit to explain which cookies and similar technologies it wants to use, and why, and to record the visitor’s choice. The text is the visible part. The part that decides compliance is the switch underneath: tags for analytics, ads, heatmaps or personalization should only load once the visitor accepts the matching category, and never after a rejection.

Three documents get mixed up here, and most sites need all three:

  • Cookie banner: appears on the first visit, collects the choice and controls which scripts run.
  • Cookie policy: the full list of cookies and similar technologies, with purpose, lifetime and vendor. Link it from the banner.
  • Privacy policy: how you handle personal data in general, the legal bases you rely on and people’s rights. It covers far more than cookies.

A consent management platform (CMP) is the software behind the banner: it shows it, stores choices, blocks scripts and sends consent signals to tools such as Google tags.

Is a Cookie Banner Mandatory? A Decision Table

Two questions decide it: who visits, and what your pages load. A site with EU or UK visitors that sets analytics or advertising cookies needs a consent banner. A site that only sets strictly necessary cookies does not need one, though it still has to say what those cookies do.

What your site loadsEU or UK visitorsUS visitors only
Only strictly necessary cookies (cart, login, security, load balancing, storing the consent choice)No consent banner; explain the cookies in your policyNo banner; privacy policy as usual
GA4 or another cookie-based analytics toolConsent banner with an analytics categoryUsually no banner; notice at collection, and honor opt-outs if the data is shared
Ad pixels, remarketing tags, social embeds that trackConsent banner with a marketing categoryDo Not Sell or Share link, honor GPC, notice at collection
Cookieless analytics that stores nothing on the device and keeps no personal dataOften no consent needed, but check device-access and GDPR rules for your setupUsually no banner
Visitors from many regionsGeo-targeted banner: opt-in for EU and UK, opt-out elsewhereSame

Ignoring the requirement carries regulatory risk (fines under the GDPR and national cookie laws, and penalties under US state laws), but the more common day-to-day cost is broken data: tags that fire before consent have to be cleaned up later, and platforms such as Google limit features for European traffic without valid consent signals.

EU Cookie Banner Requirements (GDPR and ePrivacy)

Two laws work together. The ePrivacy Directive, implemented by each EU country’s national law, governs storing or reading information on a visitor’s device, which is where the consent requirement for cookies comes from. The GDPR then governs what you do with the personal data collected, and supplies the definition of valid consent: freely given, specific, informed and unambiguous, given by a clear affirmative action.

The most concrete guidance on what that means for a banner is the European Data Protection Board’s Cookie Banner Taskforce report, adopted in January 2023 after EU regulators coordinated their handling of a wave of complaints about banners. In practice, an EU banner has to meet these requirements:

1. Nothing non-essential runs before consent

Analytics, advertising, heatmap and personalization cookies stay blocked until the visitor accepts. Scrolling, closing the banner or continuing to browse is not consent. If a tag fires on page load and the banner appears a second later, the banner is decoration.

2. Reject is as easy as accept

A large majority of the regulators in the taskforce treated a banner with an “Accept” button but no reject option on any layer that has a consent button as an infringement. They also rejected designs where the only alternative is a small text link buried in a paragraph or placed outside the banner, and button contrast so low the reject text is unreadable. The safe pattern is “Accept all” and “Reject all” side by side on the first layer, same size and same weight, plus a “Settings” option.

3. No pre-ticked boxes

Category toggles on the settings layer start switched off. The taskforce confirmed that pre-ticked boxes do not produce valid consent under either the GDPR or the ePrivacy Directive.

4. Granular, specific purposes

Group cookies by purpose (for example analytics and marketing) and let visitors accept one and refuse the other. Describe each purpose in words a non-specialist understands. “To improve your experience” is the classic vague purpose that regulators and researchers flag, because it does not tell anyone what happens to their data.

5. No “legitimate interest” for cookies

Some banners move tracking purposes into a second layer labelled “legitimate interest,” switched on by default. The taskforce stated that legitimate interest cannot be the legal basis for placing or reading cookies that need consent, and that splitting choices this way can leave people thinking they must refuse twice.

6. Only truly essential cookies skip consent

The exemption covers cookies strictly necessary for the service the visitor asked for: a shopping cart, a login session, security, remembering the consent choice itself. Labelling analytics or ad cookies “essential” to dodge the banner is one of the practices the taskforce called out, and site owners are expected to be able to justify every cookie in that category.

7. Withdrawal at any time, as easy as giving consent

Keep a persistent way back to the settings, such as a small floating icon or a “Cookie settings” link in the footer of every page. Regulators do not impose one specific design, but withdrawing has to be as easy as consenting was.

8. No forced consent, and proof of consent

Do not design the banner so visitors believe they must accept to see the content. Store a record of each choice (timestamp, version of the banner, categories accepted) so you can show consent was obtained. A CMP does this for you; a home-made banner has to do it deliberately.

The UK version

The UK rules come from PECR plus the UK GDPR, and the ICO’s cookies guidance sums them up: tell people about the cookies, explain what they do and why, and get consent, with an exemption for cookies strictly necessary for a service the user requested. The UK changed its law in 2025 with the Data (Use and Access) Act, which widens the exemptions for some low-risk purposes. The ICO says its guidance on storage and access technologies is being revised, so check the current version before you rely on a new exemption.

US Cookie Banner Requirements (CCPA and State Laws)

US state privacy laws mostly follow notice and opt-out, not opt-in. California is the reference point. According to the California Attorney General’s CCPA page, a covered business must:

  • give a notice at collection listing the categories of personal information it collects and what it uses them for;
  • provide a clear “Do Not Sell or Share My Personal Information” link if it sells or shares personal information (sharing includes passing data to ad platforms for cross-context behavioral advertising, which is what many ad pixels do);
  • treat a Global Privacy Control signal from the browser as a valid request to stop selling or sharing that visitor’s data.

The same page lists who is covered: for-profit businesses doing business in California with gross annual revenue over $25 million, or that buy, sell or share the personal information of 100,000 or more California residents or households, or that derive 50% or more of annual revenue from selling California residents’ personal information. The revenue figure is adjusted for inflation over time, so confirm the current number.

Other states with comprehensive privacy laws follow a similar opt-out model, with their own thresholds and their own rules on universal opt-out signals. A practical US setup: footer links for privacy and opt-out, ad pixels that switch off when a visitor opts out or sends GPC, and a notice that names the categories you collect.

Where the Top Results Disagree: Does the CCPA Require a Banner?

Some vendor guides say GDPR and CCPA both require explicit consent before cookies. A law firm Q&A ranking for the same query says the opposite, quoting the California Attorney General’s response during rulemaking that a pop-up notice is not required and that a link to the relevant section of the privacy policy can serve as the notice at collection.

The second view matches the law. The CCPA is an opt-out law: it does not require opt-in consent before ordinary cookies are set. What it does require is the notice, the opt-out link when you sell or share, and honoring GPC. A banner is one way to deliver those, not a legal requirement in itself. The opt-in requirement that vendor guides describe comes from EU and UK law and applies to your EU and UK visitors.

Banner Types: Which Ones Still Work

Banner typeHow it worksEU and UKUS
Opt-in (explicit)Nothing non-essential loads until the visitor clicks AcceptRequired modelAllowed, stricter than needed
Granular opt-inAccept or reject by category, toggles off by defaultBest fitAllowed
Opt-outTracking runs until the visitor opts outNot valid for non-essential cookiesStandard model
Implied consent“By continuing to browse you agree”Not validDoes not replace the opt-out link
Notice onlyInforms, offers no choiceNot valid when consent is neededCan serve as notice, not as an opt-out

What Counts as a “Cookie” for These Rules

The EU and UK rules are about storing or reading information on the visitor’s device, not about the word cookie. Local storage, session storage, tracking pixels that read identifiers, SDKs in apps and scripts that read device characteristics to build a fingerprint can all fall under the same consent requirement. “We moved our tracker to local storage” does not remove the need for a banner.

The reverse is also true. A measurement setup that stores nothing on the device and processes no personal data sits outside the cookie consent rule, and most of the banner question goes away for it. The details matter, which is why we cover them separately in our guide to cookieless tracking.

Types of Cookies: The “6 Basic Types” Explained

Lists of cookie types disagree because cookies are classified in three separate ways. Only the first one decides whether you need consent.

ClassificationTypesWhy it matters for the banner
By purposeStrictly necessary, preferences (functional), statistics (analytics), marketing (advertising)Banner categories follow these. Only strictly necessary is exempt from consent.
By lifetimeSession (deleted when the browser closes), persistent (kept until an expiry date)List lifetimes in your cookie policy. A session cookie can still need consent.
By who sets itFirst-party (your domain), third-party (another domain, such as an ad network)Browsers already restrict many third-party cookies, but first-party analytics cookies still need consent in the EU and UK.

The decline of third-party cookies did not end banners. First-party cookies, pixels and other storage still trigger the same rules, so the banner stays for as long as your site uses them.

What Are the Requirements for a Cookie? (The Technical Side)

Sometimes the question is about the cookie itself, not the banner. A cookie is a name and value your server or script sets, plus attributes that control where and how long it lives:

  • Domain and Path: which hosts and URLs receive the cookie.
  • Expires or Max-Age: without one it is a session cookie; with one it is persistent.
  • Secure: only sent over HTTPS.
  • HttpOnly: hidden from JavaScript, which protects session cookies from script-based theft.
  • SameSite (Strict, Lax or None): controls whether the cookie is sent on cross-site requests. Browsers require Secure when SameSite is None.

For the banner, the attribute that matters most is the one you control in your cookie policy: an honest purpose and lifetime for every cookie you list.

What the Banner Must Say: A Copyable Template

Keep the first layer short and specific: who you are, each purpose in one plain sentence, equal buttons, and a link to the details. Adapt this to your actual tools. If you do not run ads, delete the marketing line instead of keeping it “just in case.”

We use cookies

Necessary: keep the site working (your cart, your login, this choice). Always on.
Analytics: count visits and see which pages lead to sign-ups, using [tool name]. Off unless you allow it.
Marketing: measure and personalize our ads on [platforms]. Data is shared with those platforms. Off unless you allow it.

[ Reject all ]   [ Accept all ]   [ Choose ]

You can change this anytime from "Cookie settings" at the bottom of every page. Details: [Cookie policy]

Wording to avoid, because it is vague or pushes people toward accepting:

  • “We use cookies to give you the best experience” (no actual purpose).
  • “Some features may not work if you reject” when nothing you named depends on the cookie.
  • “Our partners may use data for various purposes” (who, and which purposes?).
  • Jargon such as “cross-device retargeting identifiers” without a plain explanation.

Test Your Own Banner in 10 Minutes

A banner can look perfect and still leak. This check uses only your browser’s developer tools (Chrome, Edge or Firefox):

  1. Start clean. Open a private window, open DevTools before loading the page, and turn on “Preserve log” in the Network tab. If you geo-target the banner, test from an EU or UK location (or your CMP’s preview mode for that region).
  2. Before clicking anything, look at Application (Chrome) or Storage (Firefox) > Cookies and Local Storage. Only necessary entries should be there. In the Network tab, filter for your analytics and ad domains (for example collect, facebook, doubleclick, hotjar). Nothing should have fired.
  3. Click Reject all, then reload and browse two pages. Still no analytics or marketing cookies, still no requests to those domains. If you use Google consent mode, requests may appear as cookieless pings with consent denied; that is a separate setup we cover in our consent mode v2 guide.
  4. Clear site data, accept only Analytics. Analytics should start; marketing should not.
  5. Withdraw. Open Cookie settings, switch Analytics off, reload. Collection must stop. Existing analytics cookies should be deleted or no longer read.
  6. US check: send GPC. Use a browser or extension that sends Global Privacy Control, load the page and confirm your ad pixels stay off for that visitor.
  7. Repeat on a second template (blog post, checkout, a subdomain), since tags are often added page by page.

Failure Modes and How to Fix Them

SymptomUsual causeFix
Analytics cookie present before any clickTag hardcoded in the theme or added by a plugin, outside the CMPMove it into the tag manager or CMP and gate it on consent
Tags fire after RejectTag manager trigger is “All pages” with no consent checkAdd consent conditions or built-in consent checks to every non-essential tag
Banner reappears on every pageConsent cookie set on the wrong domain or path, or blocked by the CMP itselfSet the consent cookie on the root domain and classify it as necessary
Subdomain or shop shows no bannerCMP installed on the main site onlyInstall on every host; share consent across subdomains where your CMP supports it
New cookies not listedCookie scan is stale after adding a toolRe-scan after every new tag; review the list on a fixed schedule
EU visitors see the US bannerGeo-detection by IP is wrong for VPNs or roaming usersWhen unsure, default to the stricter opt-in banner
Reject button exists but hidden in SettingsTheme based on an old templatePut Reject all on the first layer, same style as Accept all

What a Compliant Banner Does to Your Conversion Data

Once rejection is real, a share of your EU and UK visitors disappears from cookie-based analytics, and their conversions disappear with them. That is expected. The problem is that the loss is not spread evenly, so reports by landing page and by channel start to mislead you. Here is the arithmetic, with illustrative numbers:

Illustrative example: two landing pages, same true performance
Each page: 3,000 organic sessions a month, 2% conversion rate, $150 per conversion
Page A: 70% EU/UK visitors. Page B: 10% EU/UK visitors
Opt-in acceptance rate in EU/UK: 50%. US visitors all measured
Visible sessions = US sessions + (EU/UK sessions × acceptance rate)
True sessionsVisible sessionsVisible conversionsVisible valueShare visible
Page A (EU-heavy)3,000900 + 1,050 = 1,95039$5,85065%
Page B (US-heavy)3,0002,700 + 150 = 2,85057$8,55095%

Both pages produce 60 conversions and $9,000 a month. In the report, Page B looks 46% more valuable ($8,550 vs $5,850) purely because of who visits it. Two more effects to expect:

  • A banner redesign looks like an SEO drop. Moving from an accept-only banner to equal Accept and Reject buttons lowers the acceptance rate. If acceptance falls from 80% to 50% in this example, Page A’s visible sessions fall from 2,580 to 1,950 overnight with no change in rankings. Annotate the date of every banner change in your analytics.
  • Conversion rates hold up better than counts. When a visitor who rejects is invisible for both the visit and the conversion, the rate stays roughly right while the totals shrink. Compare pages on rates and on regional segments, not raw totals.

To keep landing-page reporting honest, segment by region, keep a consistent banner, and look at your setup end to end as described in our SEO conversion tracking guide. SEOConversion is built as a cookieless, first-party tracker that reports conversions and value by organic and AI search landing page; it can run without a cookie banner in most of the US, UK, AU and CA, but EU sites should still check their own obligations.

Do You Need a Consent Management Platform?

A hand-built banner can work for a small site with one or two tools, but it has to do everything a CMP does: block scripts until consent, store proof of each choice, remember rejections, offer withdrawal and stay in sync with your cookie list. A CMP becomes the sensible choice when:

  • you serve visitors in several jurisdictions and need different banners by region;
  • you run Google Ads or GA4 for European traffic and need consent signals passed to Google tags;
  • several teams add tags, so you need regular scans to catch new cookies;
  • you need consent logs you can export if a regulator or partner asks.
Quick rule

If your site loads anything beyond strictly necessary cookies and has EU or UK visitors, you need a real opt-in banner, tested in the browser. If it only has US visitors, you need notice, an opt-out path for ad data, and GPC support, and the pop-up is optional.

FAQ

What are the legal requirements for a cookie banner?

In the EU and UK, the banner must block non-essential cookies until the visitor opts in, explain each purpose in plain words, offer reject as easily as accept, avoid pre-ticked boxes and let people withdraw consent later. In the US, most state laws use an opt-out model instead: you need a notice at collection, a way to opt out of the sale or sharing of personal data, and you must honor signals such as Global Privacy Control.

Is a cookie banner mandatory?

Only when the rules that apply to your visitors require consent or notice for what your site loads. A site with EU or UK visitors that sets analytics or advertising cookies needs a consent banner. A site that sets only strictly necessary cookies does not need a consent banner, although it still has to explain those cookies somewhere, usually in a cookie or privacy policy.

Is a cookie banner required under CCPA?

No pop-up is required by the CCPA itself. The law requires a notice at collection, a clear Do Not Sell or Share My Personal Information link if you sell or share personal data, and honoring Global Privacy Control as an opt-out. Many US sites use a banner because it is a convenient way to meet those duties, and because they also have EU or UK visitors.

What is a cookie consent banner?

It is the message a site shows on a first visit to explain which cookies and similar technologies it wants to use, and why, and to record the visitor’s choice. Technically it is also a switch: tags that need consent should only load after the visitor accepts the matching category.

What are 6 basic types of cookies?

Lists vary because cookies are grouped in three different ways. By purpose: strictly necessary, preferences, statistics (analytics) and marketing. By lifetime: session and persistent. By who sets them: first-party and third-party. Banners are organised by purpose, since that is what decides whether consent is needed.

How often should a cookie banner ask for consent again?

There is no single EU-wide expiry date written into the law. Ask again when you add new purposes or vendors, and follow your national regulator’s guidance on how long a choice can be stored. A rejection should be remembered too, so visitors are not asked on every page.

Measure organic conversions without the banner gap.

SEOConversion is a first-party, cookieless, PII-free tracker that shows which conversions and how much revenue come from Google, Bing and AI assistants, by landing page. It honors GPC and DNT and can run without a cookie banner in most of the US, UK, AU and CA.

Start free