Back to the blog
Guide

What is cookie consent? A guide for small businesses

Cookie consent is the permission your visitors give before your website stores cookies, or similar technologies, on their device. In the EU it is a legal requirement for everything that is not strictly necessary, and it applies to small businesses just as it does to large ones.

Which rules require cookie consent?

Two pieces of EU law work together:

  • The ePrivacy Directive:Article 5(3) only allows information to be stored on, or read from, a user's device once the user has consented, after being given clear and comprehensive information. The exceptions are storage needed to transmit a communication and storage that is strictly necessary for a service the user explicitly asked for. Each EU country has written this rule into its own law.
  • The GDPR: sets out what valid consent is and how you must handle it. The GDPR also names cookie identifiers and IP addresses as examples of online identifiers, so much of the data collected through cookies is personal data.

National data protection or telecoms authorities enforce the rules. If you also have visitors in the UK, their equivalent is the Privacy and Electronic Communications Regulations (PECR), enforced by the ICO. Since the Data (Use and Access) Act 2025, PECR has some extra exceptions, for example for certain statistical cookies, each with conditions set out in the ICO's guidance.

What makes consent valid?

The GDPR defines consent as a "freely given, specific, informed and unambiguous indication" of the person's wishes, given "by a statement or by a clear affirmative action" (Article 4(11)). For a cookie banner that means:

  • An active choice: the GDPR says silence, pre-ticked boxes or inactivity are not consent, and the EU data protection authorities add that scrolling or swiping through a page is not either.
  • No pre-ticked boxes: the Court of Justice of the EU confirmed this in Planet49 (C-673/17): a pre-ticked checkbox the visitor must untick to refuse does not give valid consent.
  • A real choice: access to your website should not depend on accepting cookies. The authorities consider consent obtained through such "cookie walls" not freely given.
  • Specific: visitors choose per purpose (analytics, marketing and so on), not one yes to everything.
  • Informed: visitors are told what the cookies are for before they choose. Planet49 adds that this includes how long the cookies last and whether third parties can access them.
  • Easy to withdraw: under Article 7(3) it must be as easy to withdraw consent as to give it.
  • Documented: under Article 7(1) you must be able to demonstrate that the visitor consented.

The four cookie categories

The law talks about purposes, not categories, but most cookie banners group cookies into four categories so visitors can choose per purpose:

Necessary

Needed for the website to work, such as login sessions, shopping baskets and security. These do not need consent.

Examples: Session cookie, CSRF token

Preferences

Remember choices such as language or layout. They make the site nicer to use but are not strictly necessary.

Examples: Language choice, display settings

Analytics

Measure how visitors use your website so you can improve it.

Examples: Google Analytics, Hotjar

Marketing

Follow visitors across websites to show them targeted ads, usually shared with third parties.

Examples: Meta Pixel, Google Ads remarketing

What a compliant cookie banner needs

Putting the rules and the EU data protection authorities' published positions together, your banner should have:

  • A reject option next to accept: most EU authorities consider a banner with an accept button but no reject option on the same layer an infringement
  • No tricks: no reject link hidden in the text, and no reject button that is barely readable
  • Blocking before consent: no cookie that needs consent is set until the visitor has given it
  • A way back: a link or icon that lets visitors change or withdraw their choice at any time
  • Records: a log of each decision, so you can show what was agreed and when

The EU cookie law guide goes through the legal texts in more detail.

How to get started

Setting up cookie consent does not have to be complicated. With a consent tool such as Consentaur it takes about five minutes:

  1. Scan your website: find out which cookies it actually sets. Consentaur does this automatically.
  2. Categorise the cookies: Consentaur recognises known cookies and sorts them into the four categories, and you can adjust the result.
  3. Set up the banner: adjust the look and text to fit your brand.
  4. Install the script: add one line of code to your website and tag your tracking scripts.
  5. Add a way back: a "Cookie settings" link in your footer with the data-cookiebar-settings attribute lets visitors change their choice at any time.
  6. Check it: make sure scripts wait for consent and that decisions are recorded.

Frequently asked questions

Does every website need a cookie banner?

You need to ask for consent if your website stores or reads anything on visitors' devices that is not strictly necessary for the service they asked for. That covers tools such as Google Analytics and the Meta Pixel. If your site only uses strictly necessary cookies, such as a login session or a shopping basket, you do not need consent, but you should still explain the cookies you use, for example in your privacy policy.

Does the rule only apply to cookies that collect personal data?

No. In Planet49 (C-673/17) the Court of Justice of the EU ruled that the consent requirement applies whether or not the information stored on the device is personal data.

Can I rely on legitimate interest instead of consent?

Not for setting or reading cookies that need consent. The EU data protection authorities' cookie banner taskforce confirmed in 2023 that legitimate interest cannot be the legal basis for placing or reading cookies under Article 5(3) of the ePrivacy Directive.

What happens if I do not ask for consent?

Cookie rules are enforced by national authorities under each country's ePrivacy law, and the penalties depend on that law. Where the GDPR applies to the data collected, breaching its consent conditions can lead to fines of up to 20 million euros or 4% of worldwide annual turnover, whichever is higher.

How long should I keep consent records?

The GDPR does not set a fixed period. It requires you to be able to demonstrate that a visitor consented (Article 7(1)), so keep records for as long as you rely on that consent. Consentaur keeps each consent record for 24 months.

Ready to sort out cookie consent?

Consentaur scans your site, shows a banner that meets these requirements and records every consent decision. Create a free account and set it up in about five minutes.

Start your free trial

14-day free trial. No credit card required.