Cookie Banner Requirements: EU Opt-In, US Opt-Out, and How to Test

Cookie banner requirements depend on where your visitors are. In the EU and UK, a banner must block every non-essential cookie until the visitor opts in, explain each purpose plainly, offer “Reject” as easily as “Accept” and let people change their mind later. In the US, most state privacy laws use an opt-out model: no pop-up is required, but you need a notice at collection, a way to opt out of the sale or sharing of personal data, and you must honor Global Privacy Control signals.
This guide covers both models, where the top results contradict each other, the technical side of “what counts as a cookie,” a 10-minute test you can run on your own banner, and what the banner will do to your conversion reports once it is live. It is a practical guide, not legal advice: if your situation is unusual, check with counsel.
Cookie Banner Requirements at a Glance
| Requirement | EU and UK (opt-in) | US states (opt-out) |
|---|---|---|
| Non-essential cookies before a choice | Blocked until the visitor accepts | Allowed, unless the visitor has opted out or sent GPC |
| Pop-up or banner | In practice yes, consent needs an affirmative action | Not required by the CCPA; a footer link can do the job |
| Reject option | Must be as easy as accepting | Opt-out link for sale or sharing of personal data |
| Pre-ticked boxes | Not valid consent | Not the model; opt-outs must be honored |
| Purpose explanation | Specific, plain-language purposes per category | Notice at collection: categories of data and purposes |
| Browser signals | No legal duty in most countries, good practice | Global Privacy Control must be honored in California |
| Withdrawal | As easy as giving consent, at any time | Opt-out available at any time |
| Proof | Be able to show consent was given | Keep records of opt-out requests |
What a Cookie Banner Is (and What It Is Not)
A cookie consent banner is the message a site shows on a first visit to explain which cookies and similar technologies it wants to use, and why, and to record the visitor’s choice. The text is the visible part. The part that decides compliance is the switch underneath: tags for analytics, ads, heatmaps or personalization should only load once the visitor accepts the matching category, and never after a rejection.
Three documents get mixed up here, and most sites need all three:
- Cookie banner: appears on the first visit, collects the choice and controls which scripts run.
- Cookie policy: the full list of cookies and similar technologies, with purpose, lifetime and vendor. Link it from the banner.
- Privacy policy: how you handle personal data in general, the legal bases you rely on and people’s rights. It covers far more than cookies.
A consent management platform (CMP) is the software behind the banner: it shows it, stores choices, blocks scripts and sends consent signals to tools such as Google tags.
Is a Cookie Banner Mandatory? A Decision Table
Two questions decide it: who visits, and what your pages load. A site with EU or UK visitors that sets analytics or advertising cookies needs a consent banner. A site that only sets strictly necessary cookies does not need one, though it still has to say what those cookies do.
| What your site loads | EU or UK visitors | US visitors only |
|---|---|---|
| Only strictly necessary cookies (cart, login, security, load balancing, storing the consent choice) | No consent banner; explain the cookies in your policy | No banner; privacy policy as usual |
| GA4 or another cookie-based analytics tool | Consent banner with an analytics category | Usually no banner; notice at collection, and honor opt-outs if the data is shared |
| Ad pixels, remarketing tags, social embeds that track | Consent banner with a marketing category | Do Not Sell or Share link, honor GPC, notice at collection |
| Cookieless analytics that stores nothing on the device and keeps no personal data | Often no consent needed, but check device-access and GDPR rules for your setup | Usually no banner |
| Visitors from many regions | Geo-targeted banner: opt-in for EU and UK, opt-out elsewhere | Same |
Ignoring the requirement carries regulatory risk (fines under the GDPR and national cookie laws, and penalties under US state laws), but the more common day-to-day cost is broken data: tags that fire before consent have to be cleaned up later, and platforms such as Google limit features for European traffic without valid consent signals.
EU Cookie Banner Requirements (GDPR and ePrivacy)
Two laws work together. The ePrivacy Directive, implemented by each EU country’s national law, governs storing or reading information on a visitor’s device, which is where the consent requirement for cookies comes from. The GDPR then governs what you do with the personal data collected, and supplies the definition of valid consent: freely given, specific, informed and unambiguous, given by a clear affirmative action.
The most concrete guidance on what that means for a banner is the European Data Protection Board’s Cookie Banner Taskforce report, adopted in January 2023 after EU regulators coordinated their handling of a wave of complaints about banners. In practice, an EU banner has to meet these requirements:
1. Nothing non-essential runs before consent
Analytics, advertising, heatmap and personalization cookies stay blocked until the visitor accepts. Scrolling, closing the banner or continuing to browse is not consent. If a tag fires on page load and the banner appears a second later, the banner is decoration.
2. Reject is as easy as accept
A large majority of the regulators in the taskforce treated a banner with an “Accept” button but no reject option on any layer that has a consent button as an infringement. They also rejected designs where the only alternative is a small text link buried in a paragraph or placed outside the banner, and button contrast so low the reject text is unreadable. The safe pattern is “Accept all” and “Reject all” side by side on the first layer, same size and same weight, plus a “Settings” option.
3. No pre-ticked boxes
Category toggles on the settings layer start switched off. The taskforce confirmed that pre-ticked boxes do not produce valid consent under either the GDPR or the ePrivacy Directive.
4. Granular, specific purposes
Group cookies by purpose (for example analytics and marketing) and let visitors accept one and refuse the other. Describe each purpose in words a non-specialist understands. “To improve your experience” is the classic vague purpose that regulators and researchers flag, because it does not tell anyone what happens to their data.
5. No “legitimate interest” for cookies
Some banners move tracking purposes into a second layer labelled “legitimate interest,” switched on by default. The taskforce stated that legitimate interest cannot be the legal basis for placing or reading cookies that need consent, and that splitting choices this way can leave people thinking they must refuse twice.
6. Only truly essential cookies skip consent
The exemption covers cookies strictly necessary for the service the visitor asked for: a shopping cart, a login session, security, remembering the consent choice itself. Labelling analytics or ad cookies “essential” to dodge the banner is one of the practices the taskforce called out, and site owners are expected to be able to justify every cookie in that category.
7. Withdrawal at any time, as easy as giving consent
Keep a persistent way back to the settings, such as a small floating icon or a “Cookie settings” link in the footer of every page. Regulators do not impose one specific design, but withdrawing has to be as easy as consenting was.
8. No forced consent, and proof of consent
Do not design the banner so visitors believe they must accept to see the content. Store a record of each choice (timestamp, version of the banner, categories accepted) so you can show consent was obtained. A CMP does this for you; a home-made banner has to do it deliberately.
The UK version
The UK rules come from PECR plus the UK GDPR, and the ICO’s cookies guidance sums them up: tell people about the cookies, explain what they do and why, and get consent, with an exemption for cookies strictly necessary for a service the user requested. The UK changed its law in 2025 with the Data (Use and Access) Act, which widens the exemptions for some low-risk purposes. The ICO says its guidance on storage and access technologies is being revised, so check the current version before you rely on a new exemption.
US Cookie Banner Requirements (CCPA and State Laws)
US state privacy laws mostly follow notice and opt-out, not opt-in. California is the reference point. According to the California Attorney General’s CCPA page, a covered business must:
- give a notice at collection listing the categories of personal information it collects and what it uses them for;
- provide a clear “Do Not Sell or Share My Personal Information” link if it sells or shares personal information (sharing includes passing data to ad platforms for cross-context behavioral advertising, which is what many ad pixels do);
- treat a Global Privacy Control signal from the browser as a valid request to stop selling or sharing that visitor’s data.
The same page lists who is covered: for-profit businesses doing business in California with gross annual revenue over $25 million, or that buy, sell or share the personal information of 100,000 or more California residents or households, or that derive 50% or more of annual revenue from selling California residents’ personal information. The revenue figure is adjusted for inflation over time, so confirm the current number.
Other states with comprehensive privacy laws follow a similar opt-out model, with their own thresholds and their own rules on universal opt-out signals. A practical US setup: footer links for privacy and opt-out, ad pixels that switch off when a visitor opts out or sends GPC, and a notice that names the categories you collect.
Where the Top Results Disagree: Does the CCPA Require a Banner?
Some vendor guides say GDPR and CCPA both require explicit consent before cookies. A law firm Q&A ranking for the same query says the opposite, quoting the California Attorney General’s response during rulemaking that a pop-up notice is not required and that a link to the relevant section of the privacy policy can serve as the notice at collection.
The second view matches the law. The CCPA is an opt-out law: it does not require opt-in consent before ordinary cookies are set. What it does require is the notice, the opt-out link when you sell or share, and honoring GPC. A banner is one way to deliver those, not a legal requirement in itself. The opt-in requirement that vendor guides describe comes from EU and UK law and applies to your EU and UK visitors.
Banner Types: Which Ones Still Work
| Banner type | How it works | EU and UK | US |
|---|---|---|---|
| Opt-in (explicit) | Nothing non-essential loads until the visitor clicks Accept | Required model | Allowed, stricter than needed |
| Granular opt-in | Accept or reject by category, toggles off by default | Best fit | Allowed |
| Opt-out | Tracking runs until the visitor opts out | Not valid for non-essential cookies | Standard model |
| Implied consent | “By continuing to browse you agree” | Not valid | Does not replace the opt-out link |
| Notice only | Informs, offers no choice | Not valid when consent is needed | Can serve as notice, not as an opt-out |
What Counts as a “Cookie” for These Rules
The EU and UK rules are about storing or reading information on the visitor’s device, not about the word cookie. Local storage, session storage, tracking pixels that read identifiers, SDKs in apps and scripts that read device characteristics to build a fingerprint can all fall under the same consent requirement. “We moved our tracker to local storage” does not remove the need for a banner.
The reverse is also true. A measurement setup that stores nothing on the device and processes no personal data sits outside the cookie consent rule, and most of the banner question goes away for it. The details matter, which is why we cover them separately in our guide to cookieless tracking.
Types of Cookies: The “6 Basic Types” Explained
Lists of cookie types disagree because cookies are classified in three separate ways. Only the first one decides whether you need consent.
| Classification | Types | Why it matters for the banner |
|---|---|---|
| By purpose | Strictly necessary, preferences (functional), statistics (analytics), marketing (advertising) | Banner categories follow these. Only strictly necessary is exempt from consent. |
| By lifetime | Session (deleted when the browser closes), persistent (kept until an expiry date) | List lifetimes in your cookie policy. A session cookie can still need consent. |
| By who sets it | First-party (your domain), third-party (another domain, such as an ad network) | Browsers already restrict many third-party cookies, but first-party analytics cookies still need consent in the EU and UK. |
The decline of third-party cookies did not end banners. First-party cookies, pixels and other storage still trigger the same rules, so the banner stays for as long as your site uses them.
What Are the Requirements for a Cookie? (The Technical Side)
Sometimes the question is about the cookie itself, not the banner. A cookie is a name and value your server or script sets, plus attributes that control where and how long it lives:
- Domain and Path: which hosts and URLs receive the cookie.
- Expires or Max-Age: without one it is a session cookie; with one it is persistent.
- Secure: only sent over HTTPS.
- HttpOnly: hidden from JavaScript, which protects session cookies from script-based theft.
- SameSite (Strict, Lax or None): controls whether the cookie is sent on cross-site requests. Browsers require Secure when SameSite is None.
For the banner, the attribute that matters most is the one you control in your cookie policy: an honest purpose and lifetime for every cookie you list.
What the Banner Must Say: A Copyable Template
Keep the first layer short and specific: who you are, each purpose in one plain sentence, equal buttons, and a link to the details. Adapt this to your actual tools. If you do not run ads, delete the marketing line instead of keeping it “just in case.”
We use cookies Necessary: keep the site working (your cart, your login, this choice). Always on. Analytics: count visits and see which pages lead to sign-ups, using [tool name]. Off unless you allow it. Marketing: measure and personalize our ads on [platforms]. Data is shared with those platforms. Off unless you allow it. [ Reject all ] [ Accept all ] [ Choose ] You can change this anytime from "Cookie settings" at the bottom of every page. Details: [Cookie policy]
Wording to avoid, because it is vague or pushes people toward accepting:
- “We use cookies to give you the best experience” (no actual purpose).
- “Some features may not work if you reject” when nothing you named depends on the cookie.
- “Our partners may use data for various purposes” (who, and which purposes?).
- Jargon such as “cross-device retargeting identifiers” without a plain explanation.
Test Your Own Banner in 10 Minutes
A banner can look perfect and still leak. This check uses only your browser’s developer tools (Chrome, Edge or Firefox):
- Start clean. Open a private window, open DevTools before loading the page, and turn on “Preserve log” in the Network tab. If you geo-target the banner, test from an EU or UK location (or your CMP’s preview mode for that region).
- Before clicking anything, look at Application (Chrome) or Storage (Firefox) > Cookies and Local Storage. Only necessary entries should be there. In the Network tab, filter for your analytics and ad domains (for example
collect,facebook,doubleclick,hotjar). Nothing should have fired. - Click Reject all, then reload and browse two pages. Still no analytics or marketing cookies, still no requests to those domains. If you use Google consent mode, requests may appear as cookieless pings with consent denied; that is a separate setup we cover in our consent mode v2 guide.
- Clear site data, accept only Analytics. Analytics should start; marketing should not.
- Withdraw. Open Cookie settings, switch Analytics off, reload. Collection must stop. Existing analytics cookies should be deleted or no longer read.
- US check: send GPC. Use a browser or extension that sends Global Privacy Control, load the page and confirm your ad pixels stay off for that visitor.
- Repeat on a second template (blog post, checkout, a subdomain), since tags are often added page by page.
Failure Modes and How to Fix Them
| Symptom | Usual cause | Fix |
|---|---|---|
| Analytics cookie present before any click | Tag hardcoded in the theme or added by a plugin, outside the CMP | Move it into the tag manager or CMP and gate it on consent |
| Tags fire after Reject | Tag manager trigger is “All pages” with no consent check | Add consent conditions or built-in consent checks to every non-essential tag |
| Banner reappears on every page | Consent cookie set on the wrong domain or path, or blocked by the CMP itself | Set the consent cookie on the root domain and classify it as necessary |
| Subdomain or shop shows no banner | CMP installed on the main site only | Install on every host; share consent across subdomains where your CMP supports it |
| New cookies not listed | Cookie scan is stale after adding a tool | Re-scan after every new tag; review the list on a fixed schedule |
| EU visitors see the US banner | Geo-detection by IP is wrong for VPNs or roaming users | When unsure, default to the stricter opt-in banner |
| Reject button exists but hidden in Settings | Theme based on an old template | Put Reject all on the first layer, same style as Accept all |
What a Compliant Banner Does to Your Conversion Data
Once rejection is real, a share of your EU and UK visitors disappears from cookie-based analytics, and their conversions disappear with them. That is expected. The problem is that the loss is not spread evenly, so reports by landing page and by channel start to mislead you. Here is the arithmetic, with illustrative numbers:
| True sessions | Visible sessions | Visible conversions | Visible value | Share visible | |
|---|---|---|---|---|---|
| Page A (EU-heavy) | 3,000 | 900 + 1,050 = 1,950 | 39 | $5,850 | 65% |
| Page B (US-heavy) | 3,000 | 2,700 + 150 = 2,850 | 57 | $8,550 | 95% |
Both pages produce 60 conversions and $9,000 a month. In the report, Page B looks 46% more valuable ($8,550 vs $5,850) purely because of who visits it. Two more effects to expect:
- A banner redesign looks like an SEO drop. Moving from an accept-only banner to equal Accept and Reject buttons lowers the acceptance rate. If acceptance falls from 80% to 50% in this example, Page A’s visible sessions fall from 2,580 to 1,950 overnight with no change in rankings. Annotate the date of every banner change in your analytics.
- Conversion rates hold up better than counts. When a visitor who rejects is invisible for both the visit and the conversion, the rate stays roughly right while the totals shrink. Compare pages on rates and on regional segments, not raw totals.
To keep landing-page reporting honest, segment by region, keep a consistent banner, and look at your setup end to end as described in our SEO conversion tracking guide. SEOConversion is built as a cookieless, first-party tracker that reports conversions and value by organic and AI search landing page; it can run without a cookie banner in most of the US, UK, AU and CA, but EU sites should still check their own obligations.
Do You Need a Consent Management Platform?
A hand-built banner can work for a small site with one or two tools, but it has to do everything a CMP does: block scripts until consent, store proof of each choice, remember rejections, offer withdrawal and stay in sync with your cookie list. A CMP becomes the sensible choice when:
- you serve visitors in several jurisdictions and need different banners by region;
- you run Google Ads or GA4 for European traffic and need consent signals passed to Google tags;
- several teams add tags, so you need regular scans to catch new cookies;
- you need consent logs you can export if a regulator or partner asks.
If your site loads anything beyond strictly necessary cookies and has EU or UK visitors, you need a real opt-in banner, tested in the browser. If it only has US visitors, you need notice, an opt-out path for ad data, and GPC support, and the pop-up is optional.
FAQ
What are the legal requirements for a cookie banner?
In the EU and UK, the banner must block non-essential cookies until the visitor opts in, explain each purpose in plain words, offer reject as easily as accept, avoid pre-ticked boxes and let people withdraw consent later. In the US, most state laws use an opt-out model instead: you need a notice at collection, a way to opt out of the sale or sharing of personal data, and you must honor signals such as Global Privacy Control.
Is a cookie banner mandatory?
Only when the rules that apply to your visitors require consent or notice for what your site loads. A site with EU or UK visitors that sets analytics or advertising cookies needs a consent banner. A site that sets only strictly necessary cookies does not need a consent banner, although it still has to explain those cookies somewhere, usually in a cookie or privacy policy.
Is a cookie banner required under CCPA?
No pop-up is required by the CCPA itself. The law requires a notice at collection, a clear Do Not Sell or Share My Personal Information link if you sell or share personal data, and honoring Global Privacy Control as an opt-out. Many US sites use a banner because it is a convenient way to meet those duties, and because they also have EU or UK visitors.
What is a cookie consent banner?
It is the message a site shows on a first visit to explain which cookies and similar technologies it wants to use, and why, and to record the visitor’s choice. Technically it is also a switch: tags that need consent should only load after the visitor accepts the matching category.
What are 6 basic types of cookies?
Lists vary because cookies are grouped in three different ways. By purpose: strictly necessary, preferences, statistics (analytics) and marketing. By lifetime: session and persistent. By who sets them: first-party and third-party. Banners are organised by purpose, since that is what decides whether consent is needed.
How often should a cookie banner ask for consent again?
There is no single EU-wide expiry date written into the law. Ask again when you add new purposes or vendors, and follow your national regulator’s guidance on how long a choice can be stored. A rejection should be remembered too, so visitors are not asked on every page.
Measure organic conversions without the banner gap.
SEOConversion is a first-party, cookieless, PII-free tracker that shows which conversions and how much revenue come from Google, Bing and AI assistants, by landing page. It honors GPC and DNT and can run without a cookie banner in most of the US, UK, AU and CA.
Start free