Almost every freelancer or small-business site has a cookie banner. Very few are actually compliant. The rules don't come from GDPR alone — they come from the ePrivacy Directive (which governs storing or reading anything on a visitor's device, cookies included) layered together with GDPR's consent standard. Get the banner wrong and you're non-compliant even if your privacy policy is perfect.
Not all of them. Strictly necessary cookies (session handling, security, load balancing, remembering the visitor's cookie choice) are exempt and can be set without asking. Everything else needs opt-in:
| Category | Consent required? | Typical example |
|---|---|---|
| Necessary | No — exempt | Session ID, CSRF token |
| Functional | Yes | Language/currency preference |
| Analytics | Yes (unless genuinely cookieless — see note below) | Google Analytics, Plausible |
| Marketing | Yes | Ad retargeting pixels |
Note: cookieless, non-tracking analytics tools that don't set a persistent identifier can sit outside the cookie banner requirement entirely (nothing is stored on the visitor's device) — but you still owe visitors a plain-language disclosure that the analytics exist, since that's a transparency question independent of the cookie/storage rule.
A cookie banner and cookie policy are one specific disclosure layered on top of your general GDPR obligations, not a replacement for them. See our GDPR Privacy Policy Checklist for Freelancers for the seven things a compliant privacy policy must state, and — if you process client data as a developer, marketer, or VA — our DPA guide for freelancers for when Article 28 requires a separate written agreement. If a cookie or any other security incident ever exposes data you shouldn't have exposed, see our guide to the first 72 hours after a data breach.
If you answered "no" or "not sure" to more than one, the banner likely needs a rebuild, not a copy tweak.
NormaKit is a bilingual (EN/IT) GDPR document pack built for exactly this situation: a ready-to-edit Cookie Policy (with banner copy and a cookie-category table you fill in), Privacy Policy, consent clauses, a full Art. 28 DPA, a mini Records-of-Processing (ROPA) template, and a breach-notification checklist — €29 one-time, instant download, editable .docx and .pdf.
See what's included →Not legal advice. This guide is general information, not a substitute for advice from a qualified lawyer or data protection professional about your specific situation. NormaKit's templates are likewise informational starting points, not legal advice, and should be reviewed and adapted before use.