NormaKit Guide

Cookie Consent Banners: What EU Law Actually Requires

Practical guide · GDPR + ePrivacy Directive · applies to any site with EU visitors, not just EU-based businesses

Almost every freelancer or small-business site has a cookie banner. Very few are actually compliant. The rules don't come from GDPR alone — they come from the ePrivacy Directive (which governs storing or reading anything on a visitor's device, cookies included) layered together with GDPR's consent standard. Get the banner wrong and you're non-compliant even if your privacy policy is perfect.

What a compliant cookie banner must actually do

The most common mistake: a banner that only offers "Accept" (or makes "Accept" the only easy option, with "reject"/"manage preferences" hidden behind an extra click). Several EU data protection authorities — including Italy's Garante — have specifically flagged asymmetric accept/reject prominence as invalid consent, not a minor styling issue.

Which cookies actually need consent?

Not all of them. Strictly necessary cookies (session handling, security, load balancing, remembering the visitor's cookie choice) are exempt and can be set without asking. Everything else needs opt-in:

CategoryConsent required?Typical example
NecessaryNo — exemptSession ID, CSRF token
FunctionalYesLanguage/currency preference
AnalyticsYes (unless genuinely cookieless — see note below)Google Analytics, Plausible
MarketingYesAd retargeting pixels

Note: cookieless, non-tracking analytics tools that don't set a persistent identifier can sit outside the cookie banner requirement entirely (nothing is stored on the visitor's device) — but you still owe visitors a plain-language disclosure that the analytics exist, since that's a transparency question independent of the cookie/storage rule.

Do you also need a Privacy Policy or a DPA?

A cookie banner and cookie policy are one specific disclosure layered on top of your general GDPR obligations, not a replacement for them. See our GDPR Privacy Policy Checklist for Freelancers for the seven things a compliant privacy policy must state, and — if you process client data as a developer, marketer, or VA — our DPA guide for freelancers for when Article 28 requires a separate written agreement. If a cookie or any other security incident ever exposes data you shouldn't have exposed, see our guide to the first 72 hours after a data breach.

Quick self-audit

  1. Load your site in a private/incognito window — does anything other than a strictly-necessary cookie get set before you click anything?
  2. Is "Reject all" (or equivalent) exactly as easy to find and click as "Accept all"?
  3. Are non-necessary categories off by default, with no pre-ticked boxes?
  4. Is there a persistent way to change your choice later (footer link)?
  5. Do you have a record of what visitors actually consented to?

If you answered "no" or "not sure" to more than one, the banner likely needs a rebuild, not a copy tweak.

Don't want to draft all of this from scratch?

NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this situation: a ready-to-edit Cookie Policy (with banner copy and a cookie-category table you fill in), Privacy Policy, consent clauses, a full Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification checklist — €29 one-time, instant download, editable .docx and .pdf.

See what's included →

Not legal advice. This guide is general information, not a substitute for advice from a qualified lawyer or data protection professional about your specific situation. NormaKit's templates are likewise informational starting points, not legal advice, and should be reviewed and adapted before use.