cmpgdprcookie bannerConsent Mode v2

GDPR Cookie Banner Guide for EU Websites

Marcin
1 July 2026
7 min read
GDPR Cookie Banner Guide for EU Websites

A GDPR cookie banner is more than a visual notice. It connects visitors’ choices to the analytics, advertising, ecommerce and embedded services used by a website. A well-configured banner explains the available options clearly and helps ensure that scripts respond correctly to those choices.

A consent management platform (CMP) can support this process, but no tool guarantees compliance on its own. Website owners remain responsible for assessing their technologies and vendors, maintaining accurate policies and reviewing applicable EU and national requirements.

If you are unsure whether your site needs consent controls, start with this practical guide to cookie banner requirements.

Many websites use analytics tools, advertising pixels, video embeds, A/B testing services and support widgets. These technologies may store information on a visitor’s device, access existing information or process personal data.

A cautious implementation separates essential technologies from optional categories and prevents optional scripts from operating before the visitor makes the relevant choice. The banner must therefore be connected correctly to tag managers, plugins and custom code.

AreaPractical consideration
InventoryIdentify the cookies, scripts and similar technologies used by the site.
ChoicePresent clear accept and reject options without misleading design.
CategoriesUse categories that reflect the site’s actual tools and purposes.
RecordsWhere appropriate, record the choice, category states and relevant policy version.
Script controlConfigure optional scripts to respect the visitor’s consent state.
WithdrawalProvide an accessible way to change or withdraw a choice.
IntegrationsPass the correct consent state to tags and connected services.
MaintenanceReview the setup after changes to plugins, campaigns, vendors or site code.

For European-level information, consult the European Data Protection Board and the European Commission’s data protection pages. National legislation and regulator guidance may impose additional requirements.

Category names and descriptions should match the technologies actually installed. A typical structure may include:

  • Necessary: Technologies required for security, core functions or a service requested by the visitor.
  • Analytics: Tools used to measure site use and performance.
  • Marketing: Advertising, conversion measurement, personalisation or remarketing tools.
  • Preferences: Optional features that remember settings or enhance the service.
  • Embedded media: Third-party videos, maps or other content that may use identifiers.

Do not copy generic descriptions without checking them against the site’s vendors and purposes. Explain what each category does in plain language rather than listing vendor names alone.

The interface should work on mobile devices, use consistent language and keep preference controls accessible after the initial visit. Visitors should not have to navigate confusing labels or an unnecessarily difficult process to reject optional technologies.

  1. Create a technology inventory. Test real browser sessions, including forms, checkout flows, videos and other interactive features.
  2. Separate essential and optional technologies. Document the reason for each classification.
  3. Write accurate descriptions. Match the banner and preference centre to the site’s actual tools and purposes.
  4. Configure default states. Do not treat optional categories as granted before the visitor has made a choice.
  5. Connect the CMP to the site. Ensure that tag-manager events, plugins and custom scripts handle consent states consistently.
  6. Test rejection. Check that optional vendors do not operate as if consent had been granted.
  7. Test partial choices. Verify accept all, reject all and individual category selections.
  8. Review records. Check what information is captured and how it relates to the applicable policy version.
  9. Provide persistent controls. Let visitors revisit and change their preferences.
  10. Retest after changes. Repeat the checks after adding vendors, plugins, campaigns or major site releases.

Teams evaluating implementation options can review CookiePilot’s CMP features and confirm that the selected configuration fits their technical and organisational needs.

Cookie and tracking requirements in the EU involve overlapping frameworks. The GDPR applies to the processing of personal data, while national rules implementing the ePrivacy framework address storing information on, or accessing information from, a user’s device. Requirements and exemptions can vary by jurisdiction and technology.

A generic statement that cookies improve the website may not give visitors enough information to make a meaningful choice about optional tracking. A cautious setup explains the relevant purposes, controls optional storage or access and retains appropriate evidence of the visitor’s decision.

A CMP can help collect, apply and document choices when configured correctly. It does not replace an accurate privacy policy, a current vendor inventory, appropriate data-protection assessments or a process for reviewing new scripts.

For websites using Google tags, Consent Mode v2 can communicate states including ad_storage, analytics_storage, ad_user_data and ad_personalization. The values sent should correspond to the visitor’s choices.

Consent Mode does not replace a consent interface or determine whether consent is legally required. It affects how supported Google tags behave in response to the signals they receive. See the official Google Consent Mode documentation for current technical details, or read the practical guide to Google Consent Mode v2.

Test at least these scenarios:

  • Reject optional categories and inspect the resulting tag behaviour.
  • Accept analytics only and verify that analytics and advertising states remain distinct.
  • Accept all categories and confirm that the intended granted states are sent.
  • Repeat the tests after changes to GTM, advertising platforms, ecommerce plugins or site code.
  • Loading optional analytics or marketing tools before the relevant choice.
  • Using descriptions that do not match the installed scripts.
  • Making rejection harder to find or use than acceptance.
  • Failing to test on mobile devices or with assistive technologies.
  • Omitting a persistent way to change preferences.
  • Adding pixels or plugins without reviewing the consent configuration.
  • Mixing languages within the interface.
  • Assuming that a CMP or plugin provides a legal guarantee.
  • Failing to retest after a release or tag-manager change.

Frequently asked questions

Not necessarily. The answer depends on the technologies used, their purposes and the applicable national rules. Technologies needed to provide a service requested by the user may be treated differently from optional analytics, advertising or embedded-media tools.

This depends on the technology, its configuration and applicable national guidance. A cautious approach is to keep optional analytics inactive until any required consent has been obtained. Assess what the technology stores, accesses and transmits rather than relying on its category label.

No. Consent Mode communicates states to supported Google tags. A CMP may provide the interface, preference controls and records used to collect and manage visitors’ choices.

What should a team document?

Maintain a technology inventory, category descriptions, consent configuration, policy versions, tag triggers, test results and a process for approving new vendors.

How often should the setup be reviewed?

Review it after relevant changes, including new plugins, vendors, advertising campaigns, analytics configurations, policy updates and major website releases. The appropriate routine schedule depends on how frequently the site changes.

Next step

Begin with an inventory of the site’s cookies, scripts and similar technologies. Then choose and configure a CMP around the site’s actual purposes, integrations, languages and maintenance process. If CookiePilot is under consideration, compare its plans and pricing with those requirements.

Written by

Marcin

Zespół CookiePilot dzieli się wiedzą o RODO, PKE i zarządzaniu cookies.

Share this article: