Cookie banners follow us around like a swarm of irritating flies. Some are unnecessary, others only give the impression of GDPR compliance, and most fail to meet the rules. Here are the key points to consider.
1. The GDPR is not to blame for everything!
The requirement to obtain visitors’ prior consent for certain website services comes not from the GDPR itself, but from Article 5(3) of the ePrivacy Directive:
Member States shall ensure that the storing of information or the gaining of access to information already stored in the terminal equipment of a subscriber or user is only allowed if the subscriber or user concerned has given their consent, having been provided with clear and comprehensive information, among other things, about the purposes of the processing. ...
Because the ePrivacy Directive takes precedence over the GDPR, these services cannot rely on “legitimate interests” under Article 6(1)(f) GDPR. Instead, consent under Article 6(1)(a) applies.
The GDPR, in turn, sets out how that consent must be obtained.
2. When do you need consent?
a. Consent is not required, for example, for:
- Device information, such as IP addresses, screen resolution and operating system, used to display or secure a website or app
- Strictly necessary cookies for language and font settings, login authentication, user preferences, shopping baskets or online forms (session cookies)
- Services that improve display, reduce loading times or optimise the website, such as content delivery networks (CDNs) and web fonts
As a general rule, no consent is required for cookies or services needed to run the website or provide a service the user has explicitly requested. If these are the only features you use, you do not need a cookie or consent banner; you simply need to update your privacy policy accordingly.
Those familiar “We use cookies, blah blah blah… OK” banners are unnecessary. They confuse visitors and make them less likely to pay attention.
Tools used purely for statistical web analysis, for example to improve a website, usually do not require consent either. Matomo falls into this category, particularly as it can be hosted on your own servers. These services can rely on legitimate interests under Article 6(1)(f) GDPR. In some cases, it makes sense to carry out and document a balancing-of-interests assessment. That is a data protection issue, however, rather than a question of banner design.
Google Analytics is an exception: supervisory authorities regard it as a tracking tool, even if the website owner only wants visitor statistics. Google Analytics therefore requires consent.
b. Consent is required for:
- Statistical analysis and audience measurement
- Behavioural or location-based advertising
- Social media plugins
One alternative to social media plugins is Heise’s two-click solution (the Shariff button). You can also use images or icons that simply link to the relevant platform. In that case, consent is not required; your privacy policy just needs to include the relevant information. You could add a notice that appears on hover, such as “You will be taken to Facebook”. That gives visitors an extra layer of clarity.
For any feature that requires consent, the key rule is to obtain it BEFORE collecting or transmitting data.
3. Maps, video and streaming services
At the time discussed here, there was still no consensus. Some data protection experts expected the planned ePrivacy Regulation, originally intended to take effect alongside the GDPR, to require prior consent for these services too. They also saw the Court of Justice of the EU’s autumn 2019 rulings and the German Federal Court of Justice’s May 2020 ruling as pointing in that direction.
The Bavarian State Office for Data Protection Supervision (BayLDA) stated on its website that videos could be embedded without prior consent if playback began only after an active click and no data was transferred beforehand, using a two-click solution or Embetty. It also advised embedding YouTube videos in privacy-enhanced mode (no-cookie).
BayLDA took a similar view of Google Maps: map content should only load when the visitor actively requests it, for example with an extra click in a two-click solution.
I asked BayLDA about this. At the time of my enquiry, the authority confirmed the interpretation described above, but said it still needed to examine the courts’ reasoning in detail. That review could lead to a change in its position.
If you want to plan ahead, consider obtaining consent for these services too. There is always room to take additional data protection precautions.
4. What valid consent requires
Consent must be obtained IN ADVANCE, be INFORMED and be FREELY GIVEN. In practice:
a. IN ADVANCE:
When someone first opens the website, scripts that could collect user data and pass it to third parties must remain disabled.
b. INFORMED:
Explain the services briefly, using clear, simple language and an easy-to-follow layout. The aim is to inform visitors, not overwhelm them.
c. FREELY GIVEN:
Do not pre-tick consent boxes. Visitors must actively agree, rather than have to opt out.
Note:
Broad statements such as “This site uses cookies for analytics and advertising” or “…to improve your browsing experience” are not enough on their own. They do not explain clearly what happens to the data.
A genuine choice also means visitors can use the website even if they refuse optional services.
Try Trackboxx free for 30 days now
No payment information required! No automatic renewal! Your Trackboxx ready to go in 1 minute.
5. Recording and proving consent
You must document consent and be able to demonstrate it. Many data protection experts consider technical records sufficient: for example, the dated consent text, the banner’s code and version, timestamps and the user’s cookie ID. Collecting additional personal data just to prove consent is unnecessary and conflicts with data minimisation.
6. Withdrawing consent: the opt-out option
Users can withdraw consent at any time. Every service you use must therefore offer a working opt-out option that visitors can easily access whenever they need it.
7. What should a consent banner look like?
The following content must be included in the banner:
- The data controller, if this is not already clear on the website
- Name of the tool
- Purpose of processing
- Recipients of the data
- A statement that consent is optional and can be withdrawn, with an opt-out option
- Link to the privacy policy
- Position the banner carefully: it must not block access to your legal notice or privacy policy.
The required information is specified, but you can choose the design. Use submenus to keep the banner from becoming cluttered. Here is one way to design the first layer while covering the minimum requirements:

This is just one possible design for the first information layer, not a template you have to follow.
There are many consent management platform (CMP) tools. You can compare their features online. Well-known examples include Cookiebot, Borlabs Cookie, Usercentrics and Consentmanager.
A consent tool should meet these basic requirements:
- Show the banner as soon as someone visits the website or app
- Keep legally required information accessible, including the legal notice, terms and conditions, and privacy policy
- Set cookies or process mobile advertising IDs only after the user actively agrees. Browsing the site, dismissing the banner or letting it close automatically after a set time does not count as consent.
- Allow people to use the website or app even if they reject cookies or advertising IDs
- Opt-out function
- Provide logs and reports to help demonstrate consent
Further guidance is available in the German Data Protection Conference’s guidance for telemedia providers and the Baden-Württemberg data protection authority’s FAQ on cookies and tracking.
You need to choose the right solution for your website, with advice from your web agency if helpful. If you do not want to build your own, compare the relevant providers and their features.
From a data protection perspective, check whether the provider can substantiate its GDPR compliance claims and where its servers are located.
8. And what about marketing?
Many visitors do not want to be tracked and will click “Reject all”. That may be frustrating for marketing and analytics, but they are exercising their legal right to control the use of their information.
At an information event I attended, an employee of the Swedish Consentmanager provider Jaohawi AB shared some interesting figures:
Their analysis found that, on average, 40–50% of visitors chose “Accept all services”. That means 50–60% declined consent.
According to the speaker, improving the banner could raise the acceptance rate to around 65%, or about 70% among loyal returning customers.
He estimated that introducing a consent banner leaves roughly half of the marketing data missing from reports. He suggested accounting for these gaps statistically when preparing forecasts.
You can respect privacy while improving your banner’s positioning, colours and wording to encourage more visitors to agree to optional services.
But do not take it too far.
Oversized “Accept” buttons, almost invisible “Reject” buttons and manipulative design do not meet the legal requirements.
Consent obtained unlawfully is not valid consent, and the breach can lead to a fine.
Consumer protection organisations, as well as data protection authorities, are increasingly monitoring this area.
9. Conclusion
Be fair and use common sense. Decide which consent-based features your customers actually need. Follow the consent and documentation requirements, use a balanced design and make it easy to opt out.
10. Further reading and resources
You can find more guidance in the DSK’s information resources and on the websites of the relevant supervisory authorities. Bavaria has separate authorities for the public and non-public sectors.
Practical, accessible publications are also available. If in doubt, ask a qualified data protection professional.
Try Trackboxx free for 30 days now
No payment information required! No automatic renewal! Your Trackboxx ready to go in 1 minute.



