Cookie banners and consent: what the rules require

In the EU and the UK, you need clear, opt-in consent before setting any cookie or similar tracker that isn’t strictly necessary for the service the user asked for. That catches analytics, advertising and most social media pixels. The US has no general cookie consent law, but state privacy laws require you to let people opt out of tracking for targeted advertising, and several require you to honor browser privacy signals. A compliant European banner offers “Reject all” as easily as “Accept all,” and nothing non-essential loads until the visitor chooses.

It isn’t really about cookies

The European rule comes from the ePrivacy Directive (in the UK, the Privacy and Electronic Communications Regulations, usually called PECR). It covers storing or reading any information on a user’s device. Cookies are the famous example, but the same rule applies to pixels, local storage, SDKs in mobile apps and device fingerprinting.

Take a ceramics shop in Lisbon selling online. Its site runs an analytics tool, a Meta pixel, a chat widget and an embedded video player. It doesn’t matter that none of these are labelled cookies in the site settings. Each one reads or stores something on the visitor’s device, so each one needs checking.

Which trackers need consent

The European exemption is narrow. You don’t need consent for something strictly necessary to provide a service the user explicitly asked for, or used only to carry a communication over a network.

Grid comparing cookie rules: strictly necessary cookies need no consent in the EU, UK or most US states; analytics need consent first in the EU and UK, with limited exemptions, and are usually allowed with disclosure in the US; advertising and cross-site tracking need consent first in the EU and UK and an opt-out plus Global Privacy Control in the US
How the three main cookie categories are treated in Europe and in most US states with privacy laws.

Analytics is where things are loosening a little. France’s regulator allows a narrow exemption for tightly configured audience measurement. The UK’s Data (Use and Access) Act 2025 goes further, allowing some low-risk cookies, including certain analytics, without consent as its provisions come into force, provided users are told and can object. Check the current position before relying on either.

What valid consent looks like in the EU and UK

Consent has to meet the GDPR standard: freely given, specific, informed and unambiguous. For a cookie banner, that turns into some very practical rules.

  1. Nothing non-essential fires before the choice. The analytics script and ad pixels stay blocked until the visitor clicks accept.
  2. Consent takes a clear action. Scrolling or carrying on browsing doesn’t count, and pre-ticked boxes aren’t consent.
  3. Rejecting is as easy as accepting. European regulators expect a “Reject all” option on the first screen, with similar prominence to “Accept all.”
  4. Choices are granular. Someone should be able to accept analytics and refuse advertising.
  5. People know who’s tracking them. Name the categories and main third parties, and say how long cookies last.
  6. Changing your mind is easy. A footer link or small floating button that reopens the settings does the job.
  7. You can prove it. Keep a record of what each visitor agreed to and when.
Two cookie banners side by side: a risky one with a large Accept all button, a small settings link and pre-ticked boxes, and a better one with equal Accept all and Reject all buttons, a Choose link and unticked boxes
The difference regulators look for is usually visible at a glance.

Mistakes regulators keep finding

Honestly, most of these come from installing a consent tool and never testing it. Spend twenty minutes in a private browser window with the network tab open and you’ll know where you stand.

The US: opt-outs, privacy signals and pixel lawsuits

US law mostly doesn’t require consent before cookies load. Instead, state privacy laws treat tracking for targeted advertising as a sale or sharing of personal data (or simply as targeted advertising, depending on the state) and give people the right to opt out. Covered businesses usually need a “Do Not Sell or Share My Personal Information” link or similar, and California, Colorado and a growing list of other states require you to treat browser signals like Global Privacy Control as a valid opt-out.

There’s litigation risk as well. Over the past few years plaintiffs’ firms have filed a wave of lawsuits, many in California under older wiretapping and privacy laws, arguing that tracking pixels, session replay tools and chat widgets let third parties listen in on visitors without consent. Results have been mixed, but the suits keep coming. That’s one reason many US businesses now show a banner even where no statute strictly requires one.

Some sectors carry extra risk. Pixels on health-related pages have drawn attention from federal regulators, and tracking what people watch can raise issues under the federal Video Privacy Protection Act.

Canada, Australia and the UAE

Canada’s federal privacy law requires meaningful consent, which can sometimes be implied for less sensitive uses. Quebec is stricter: its privacy law requires technologies that identify, locate or profile people to be switched off by default. Australia has no specific cookie rule, but the Privacy Act applies when tracking involves personal information, and the law is being reformed. In the UAE, the federal data protection law is built largely around consent, the DIFC and ADGM free zones have their own regimes, and many businesses targeting UAE users simply use a European-style banner.

Setting up a banner that holds up

  1. Scan your site to list every cookie, pixel and script, including the ones plugins added quietly.
  2. Sort them into necessary, functional, analytics and advertising.
  3. Choose a consent management tool and configure it to actually block each category until consent. A notice on its own isn’t enough.
  4. Show the right banner by region: opt-in for EU and UK visitors, opt-out links and signal handling for the US states that require them.
  5. Test in a private window. Reject everything, then check that nothing non-essential loaded.
  6. Update your cookie policy so it matches what the site actually does.
  7. Set a sensible renewal period for consent, and remember refusals for months rather than asking again on every visit.

Next steps

You can check agency and vendor contracts for missing data protection terms with LegalWolf.

This article is general information, not legal or tax advice. Laws differ between countries and states and change over time, so check the rules that apply to you or speak to a qualified professional.