The short answer

Most websites do need some form of cookie consent. If your site has visitors from the EU and you use Google Analytics, advertising pixels, embedded YouTube videos, or any third-party scripts — yes, GDPR requires a cookie consent banner. If you serve California residents at scale, CCPA requires a Do Not Sell / Do Not Share disclosure. If your site only uses strictly necessary cookies and no tracking, you can skip the banner entirely.

Key principle: Cookie consent requirements follow your visitors, not your business location. A US company with EU visitors is subject to GDPR. A Brazilian startup with California visitors must comply with CCPA.

Decision tree: do you need a cookie banner?

Work through these questions in order. Stop as soon as you have an answer.

1. Do any of your visitors come from the EU, EEA, or UK?

No → You're outside GDPR scope. Jump to question 4.

Yes → Continue to question 2.

2. Does your site use any non-essential cookies or tracking?

Non-essential includes: analytics (Google Analytics, Hotjar), advertising pixels (Meta, Google Ads), social share buttons, embedded YouTube/Vimeo, live chat (Intercom, Drift), A/B testing tools, affiliate tracking.

No (only login, session, or shopping cart cookies) → No GDPR banner required. Continue to question 4.

Yes → You need a GDPR-compliant cookie consent banner.

3. Is your GDPR banner compliant?

Compliant means: opt-in before cookies fire, equally easy to refuse as to accept, granular category controls, and a way to withdraw consent.

No or unsure → See our recommended tools.

Yes → You're covered for GDPR. Continue to question 4.

4. Do you have visitors from California, and does your business meet CCPA thresholds?

CCPA applies if you are for-profit and: (a) have $25M+ annual gross revenue, (b) buy/sell/receive/share personal data of 100,000+ California consumers annually, or (c) derive 50%+ of revenue from selling personal data.

No → You are not currently subject to CCPA. You may still wish to add a privacy policy.

Yes → You need a Do Not Sell / Do Not Share link in your site footer and a compliant privacy policy.

GDPR: what it actually requires

The EU's General Data Protection Regulation requires freely given, specific, informed, and unambiguous consent before setting non-essential cookies on devices belonging to EU/EEA residents. The UK GDPR (post-Brexit) has the same requirement.

Cookies that require consent under GDPR

Cookies that do NOT require consent under GDPR

What a valid GDPR cookie banner must do

  1. Block non-essential cookies before consent — cookies cannot fire until the visitor actively accepts
  2. Make refusal as easy as acceptance — a prominent "Accept All" button next to a buried "Manage Preferences" link does not pass
  3. Offer granular controls — visitors can accept analytics but decline advertising
  4. Allow withdrawal of consent — users must be able to change their mind at any time
  5. Record consent — you must be able to demonstrate when and what a user consented to
Common mistake: Running Google Analytics before the visitor clicks "Accept" is a GDPR violation, even if you have a banner. The banner must actually block scripts until consent is given.

CCPA: what it requires (and it's not a cookie banner)

California's Consumer Privacy Act and its 2023 amendment (CPRA) work differently from GDPR. Instead of opt-in consent before tracking, CCPA requires:

CCPA does not require a pop-up consent banner. But if you display one for GDPR visitors, your consent management platform should also handle the CCPA opt-out flow for US visitors.

Other privacy laws worth knowing

Law Jurisdiction Cookie requirement Applies if…
GDPR EU / EEA Opt-in consent before non-essential cookies You have EU/EEA visitors
UK GDPR United Kingdom Same as GDPR (PECR for cookie specifics) You have UK visitors
CCPA / CPRA California, USA Opt-out (Do Not Sell link), not opt-in banner For-profit, CA residents, meets thresholds
LGPD Brazil Opt-in consent similar to GDPR You process data of Brazilian residents
PIPEDA / Law 25 Canada / Quebec Disclosure + opt-out for non-essential cookies You have Canadian visitors
PDPA Thailand Opt-in consent You process data of Thai residents
Virginia CDPA Virginia, USA Opt-out for targeted advertising 100,000+ VA residents annually

How to avoid needing a cookie banner

The cleanest route is to eliminate non-essential cookies from your site. This is more achievable than it sounds:

Replace Google Analytics with a cookieless alternative

Plausible Analytics collects no personal data, sets no cookies, and is fully GDPR compliant without consent. You get page views, referrers, countries, and devices — without a banner. At $9/month it costs less than most cookie consent tools. Note: Plausible has no affiliate programme — we recommend them because we use them on our own websites, not for commission.

Use privacy-preserving YouTube embeds

Replace youtube.com embeds with youtube-nocookie.com — YouTube's privacy-enhanced mode that doesn't set tracking cookies until the visitor plays the video.

Self-host fonts

Google Fonts loaded from Google's CDN transfers visitor IP addresses to Google. Self-host your fonts to eliminate this data transfer.

Audit your third-party scripts

Every script tag that loads from an external domain is a potential cookie source. Remove anything you don't actively use — many sites have orphaned tracking pixels from previous campaigns.

What happens if I don't have a cookie banner?

EU data protection authorities have the power to fine organisations up to €20 million or 4% of global annual turnover — whichever is higher. In practice, enforcement follows a rough priority order:

  1. Large enterprises and high-profile brands (fined first, fined most)
  2. Companies that received warnings and failed to comply
  3. Companies with many consumer complaints filed against them
  4. SMBs and individual website operators (less common, but increasing)

Notable enforcement examples include Google (€150M by France's CNIL for making cookie refusal difficult), Facebook (€60M), and numerous mid-size businesses in Germany, Italy, and Spain. The risk for small sites is real but lower — the bigger immediate risk is loss of user trust and ad platform account suspension.

Recommended cookie consent tools

Editor's Pick

CookieYes

The fastest setup for SMBs. Free up to 25,000 visits/month, Google Consent Mode v2, and automatic cookie scanning.

From: FreeScore: 4.8 / 5
Best All-in-One

iubenda

Cookie banner plus lawyer-vetted privacy policy in one subscription. Best if you need both compliance documents and consent management.

From: €4.99/moScore: 4.6 / 5

See the full comparison of cookie consent tools →

Frequently asked questions

Do I need a cookie banner if I only use Google Analytics?

Yes, if you have visitors from the EU. Google Analytics 4 sets cookies and processes IP addresses. Under GDPR, analytics cookies require prior consent unless you use a cookieless analytics tool like Plausible. Under CCPA, GA4 may qualify as a "sale" of data, requiring a Do Not Sell link rather than a banner.

Do I need a cookie banner if my website is based in the US?

It depends on your visitors, not your location. If EU residents visit your site, GDPR applies to you regardless of where you are based. If you serve California residents and meet CCPA thresholds, a Do Not Sell / Do Not Share link is required. Most US websites serving a global audience need at least one form of consent mechanism.

Can I avoid a cookie banner entirely?

Yes — if you only use strictly necessary cookies (session cookies, login cookies, shopping cart cookies) and no analytics, advertising, or third-party tracking, you do not need a consent banner under GDPR. Switching to a cookieless analytics tool like Plausible also removes the need for a banner for analytics.

What happens if I don't have a cookie banner?

EU data protection authorities can fine companies up to €20 million or 4% of global annual turnover under GDPR. In practice, smaller sites are rarely targeted first, but enforcement is increasing. France's CNIL, Germany's DPAs, and Italy's Garante have all issued significant fines for missing or defective cookie consent, including to SMBs.

Does a Shopify store need a cookie banner?

Almost certainly yes. Shopify stores typically use marketing pixels (Meta, Google Ads), analytics, and remarketing cookies — all of which require GDPR consent from EU visitors and CCPA disclosure for California visitors. Shopify's built-in cookie banner is basic; dedicated tools like CookieYes or Enzuzo offer better compliance coverage.

Do I need a cookie banner for a WordPress site?

If your WordPress site uses any plugins that set non-essential cookies — including contact form plugins, analytics, social share buttons, or embedded media — yes, you need a cookie banner for EU visitors. WordPress-compatible tools include CookieYes, Termly, and Complianz.

Is a cookie policy the same as a cookie banner?

No. A cookie policy is a document that describes what cookies your site uses and why — it is required under GDPR but can be a separate page linked from your banner. A cookie banner (or CMP — consent management platform) is the interactive UI element that collects and records consent before setting cookies. You need both.