The short answer
Most websites do need some form of cookie consent. If your site has visitors from the EU and you use Google Analytics, advertising pixels, embedded YouTube videos, or any third-party scripts — yes, GDPR requires a cookie consent banner. If you serve California residents at scale, CCPA requires a Do Not Sell / Do Not Share disclosure. If your site only uses strictly necessary cookies and no tracking, you can skip the banner entirely.
Decision tree: do you need a cookie banner?
Work through these questions in order. Stop as soon as you have an answer.
1. Do any of your visitors come from the EU, EEA, or UK?
No → You're outside GDPR scope. Jump to question 4.
Yes → Continue to question 2.
2. Does your site use any non-essential cookies or tracking?
Non-essential includes: analytics (Google Analytics, Hotjar), advertising pixels (Meta, Google Ads), social share buttons, embedded YouTube/Vimeo, live chat (Intercom, Drift), A/B testing tools, affiliate tracking.
No (only login, session, or shopping cart cookies) → No GDPR banner required. Continue to question 4.
Yes → You need a GDPR-compliant cookie consent banner.
3. Is your GDPR banner compliant?
Compliant means: opt-in before cookies fire, equally easy to refuse as to accept, granular category controls, and a way to withdraw consent.
No or unsure → See our recommended tools.
Yes → You're covered for GDPR. Continue to question 4.
4. Do you have visitors from California, and does your business meet CCPA thresholds?
CCPA applies if you are for-profit and: (a) have $25M+ annual gross revenue, (b) buy/sell/receive/share personal data of 100,000+ California consumers annually, or (c) derive 50%+ of revenue from selling personal data.
No → You are not currently subject to CCPA. You may still wish to add a privacy policy.
Yes → You need a Do Not Sell / Do Not Share link in your site footer and a compliant privacy policy.
GDPR: what it actually requires
The EU's General Data Protection Regulation requires freely given, specific, informed, and unambiguous consent before setting non-essential cookies on devices belonging to EU/EEA residents. The UK GDPR (post-Brexit) has the same requirement.
Cookies that require consent under GDPR
- Analytics cookies — Google Analytics, Adobe Analytics, Hotjar, Microsoft Clarity
- Advertising cookies — Google Ads, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel
- Social media cookies — Facebook Like button, Twitter/X embeds, LinkedIn share buttons
- Video embeds — YouTube, Vimeo (both set tracking cookies on load)
- Live chat and support tools — Intercom, Drift, Crisp, Zendesk
- A/B testing and personalisation — Optimizely, VWO, Hotjar
- Affiliate and attribution tracking — Impact, ShareASale, PartnerStack
Cookies that do NOT require consent under GDPR
- Session cookies (keeping you logged in during a visit)
- Authentication cookies (remembering a login)
- Shopping cart cookies
- Security cookies (CSRF protection)
- Load-balancing cookies set by your hosting provider
- User preference cookies (language, currency) — strictly necessary to deliver a requested service
What a valid GDPR cookie banner must do
- Block non-essential cookies before consent — cookies cannot fire until the visitor actively accepts
- Make refusal as easy as acceptance — a prominent "Accept All" button next to a buried "Manage Preferences" link does not pass
- Offer granular controls — visitors can accept analytics but decline advertising
- Allow withdrawal of consent — users must be able to change their mind at any time
- Record consent — you must be able to demonstrate when and what a user consented to
CCPA: what it requires (and it's not a cookie banner)
California's Consumer Privacy Act and its 2023 amendment (CPRA) work differently from GDPR. Instead of opt-in consent before tracking, CCPA requires:
- A "Do Not Sell or Share My Personal Information" link in your site footer
- A privacy policy that discloses what data you collect, why, and who you share it with
- A way for California residents to request deletion of their data
- A way for California residents to opt out of the sale/sharing of their data
CCPA does not require a pop-up consent banner. But if you display one for GDPR visitors, your consent management platform should also handle the CCPA opt-out flow for US visitors.
Other privacy laws worth knowing
| Law | Jurisdiction | Cookie requirement | Applies if… |
|---|---|---|---|
| GDPR | EU / EEA | Opt-in consent before non-essential cookies | You have EU/EEA visitors |
| UK GDPR | United Kingdom | Same as GDPR (PECR for cookie specifics) | You have UK visitors |
| CCPA / CPRA | California, USA | Opt-out (Do Not Sell link), not opt-in banner | For-profit, CA residents, meets thresholds |
| LGPD | Brazil | Opt-in consent similar to GDPR | You process data of Brazilian residents |
| PIPEDA / Law 25 | Canada / Quebec | Disclosure + opt-out for non-essential cookies | You have Canadian visitors |
| PDPA | Thailand | Opt-in consent | You process data of Thai residents |
| Virginia CDPA | Virginia, USA | Opt-out for targeted advertising | 100,000+ VA residents annually |
How to avoid needing a cookie banner
The cleanest route is to eliminate non-essential cookies from your site. This is more achievable than it sounds:
Replace Google Analytics with a cookieless alternative
Plausible Analytics collects no personal data, sets no cookies, and is fully GDPR compliant without consent. You get page views, referrers, countries, and devices — without a banner. At $9/month it costs less than most cookie consent tools. Note: Plausible has no affiliate programme — we recommend them because we use them on our own websites, not for commission.
Use privacy-preserving YouTube embeds
Replace youtube.com embeds with youtube-nocookie.com — YouTube's privacy-enhanced mode that doesn't set tracking cookies until the visitor plays the video.
Self-host fonts
Google Fonts loaded from Google's CDN transfers visitor IP addresses to Google. Self-host your fonts to eliminate this data transfer.
Audit your third-party scripts
Every script tag that loads from an external domain is a potential cookie source. Remove anything you don't actively use — many sites have orphaned tracking pixels from previous campaigns.
What happens if I don't have a cookie banner?
EU data protection authorities have the power to fine organisations up to €20 million or 4% of global annual turnover — whichever is higher. In practice, enforcement follows a rough priority order:
- Large enterprises and high-profile brands (fined first, fined most)
- Companies that received warnings and failed to comply
- Companies with many consumer complaints filed against them
- SMBs and individual website operators (less common, but increasing)
Notable enforcement examples include Google (€150M by France's CNIL for making cookie refusal difficult), Facebook (€60M), and numerous mid-size businesses in Germany, Italy, and Spain. The risk for small sites is real but lower — the bigger immediate risk is loss of user trust and ad platform account suspension.
Recommended cookie consent tools
CookieYes
The fastest setup for SMBs. Free up to 25,000 visits/month, Google Consent Mode v2, and automatic cookie scanning.
iubenda
Cookie banner plus lawyer-vetted privacy policy in one subscription. Best if you need both compliance documents and consent management.
See the full comparison of cookie consent tools →
Frequently asked questions
Do I need a cookie banner if I only use Google Analytics?
Yes, if you have visitors from the EU. Google Analytics 4 sets cookies and processes IP addresses. Under GDPR, analytics cookies require prior consent unless you use a cookieless analytics tool like Plausible. Under CCPA, GA4 may qualify as a "sale" of data, requiring a Do Not Sell link rather than a banner.
Do I need a cookie banner if my website is based in the US?
It depends on your visitors, not your location. If EU residents visit your site, GDPR applies to you regardless of where you are based. If you serve California residents and meet CCPA thresholds, a Do Not Sell / Do Not Share link is required. Most US websites serving a global audience need at least one form of consent mechanism.
Can I avoid a cookie banner entirely?
Yes — if you only use strictly necessary cookies (session cookies, login cookies, shopping cart cookies) and no analytics, advertising, or third-party tracking, you do not need a consent banner under GDPR. Switching to a cookieless analytics tool like Plausible also removes the need for a banner for analytics.
What happens if I don't have a cookie banner?
EU data protection authorities can fine companies up to €20 million or 4% of global annual turnover under GDPR. In practice, smaller sites are rarely targeted first, but enforcement is increasing. France's CNIL, Germany's DPAs, and Italy's Garante have all issued significant fines for missing or defective cookie consent, including to SMBs.
Does a Shopify store need a cookie banner?
Almost certainly yes. Shopify stores typically use marketing pixels (Meta, Google Ads), analytics, and remarketing cookies — all of which require GDPR consent from EU visitors and CCPA disclosure for California visitors. Shopify's built-in cookie banner is basic; dedicated tools like CookieYes or Enzuzo offer better compliance coverage.
Do I need a cookie banner for a WordPress site?
If your WordPress site uses any plugins that set non-essential cookies — including contact form plugins, analytics, social share buttons, or embedded media — yes, you need a cookie banner for EU visitors. WordPress-compatible tools include CookieYes, Termly, and Complianz.
Is a cookie policy the same as a cookie banner?
No. A cookie policy is a document that describes what cookies your site uses and why — it is required under GDPR but can be a separate page linked from your banner. A cookie banner (or CMP — consent management platform) is the interactive UI element that collects and records consent before setting cookies. You need both.