1 free tools on this site · Cookie audit

Start Pro

GDPR cookie banner: which rule actually governs the banner, what freely given consent means in practice, and the five things that invalidate it

By , Founder, Ellul SolutionsUpdated

The banner everyone calls a GDPR banner is mostly governed by a different instrument. The obligation to get permission before storing or reading something on a visitor's device comes from the ePrivacy Directive; the GDPR supplies the definition of consent that the ePrivacy rule then borrows. Knowing which is which stops a lot of pointless argument, because the storage rule applies whether or not the cookie holds personal data, and that is the question people usually start with.

Where each rule bites

ePrivacy says: do not store or read on the terminal equipment without consent, unless it is strictly necessary for the service requested. GDPR says: consent means a freely given, specific, informed and unambiguous indication, by a statement or a clear affirmative action. Put together, they mean a site needs a real decision before a non-essential cookie is written, and the quality of that decision is judged by the GDPR standard. The common mistake is to reason about whether a cookie identifies anyone; for the storage question, it does not matter.

What freely given rules out

A consent is not freely given if refusing costs the visitor something they are otherwise entitled to, if it is bundled with something else, or if the interface makes agreement obviously easier than refusal. That last point is why the colour and prominence of the two buttons has become a compliance question rather than a design preference. It is also why pre-ticked boxes and implied consent from continued browsing have been rejected: neither is a clear affirmative action.

What informed requires before the click

The visitor has to know what is being stored, by whom, and for what, before they decide, which means the essential information is in the box rather than behind a link. Naming the recipients matters more than naming the cookies. A visitor who cannot tell from the banner that an advertising network receives an identifier has not been informed, however complete the policy page is.

Withdrawal has to be as easy as giving

This is the one small sites most often miss entirely. There has to be a way back: a persistent control that reopens the choice, not a buried instruction to clear browser storage. It costs a floating link or a footer entry, and its absence is both a real defect and a very visible one, because anyone auditing the site will look for it in the first minute.

Questions people ask about gdpr cookie banner

Does the GDPR mention cookies?

Only in passing. The operative storage rule is in the ePrivacy Directive; the GDPR supplies the consent standard and covers what happens to the data afterwards.

Is legitimate interest available for analytics cookies?

Not for the storage itself. The ePrivacy rule asks for consent or strict necessity, and legitimate interest is not one of the options on that question.

Do I need a banner if I have no EU visitors?

Not on this basis. Check your own traffic rather than assuming, because a surprising share of small US sites have a real European audience.

Is a cookie wall allowed?

It is heavily constrained. Making access conditional on consent usually fails the freely given test unless a genuine equivalent alternative is offered.

Do I have to re-ask periodically?

No fixed interval is set. A material change to purposes or recipients is what triggers a fresh ask.

Who enforces this?

National data protection and communications authorities, which is why enforcement practice differs between member states even though the text does not.

Sources

Related answers

Open the free cookie auditCount what your site sets, free