Cookie banner requirements under GDPR: no tracking before consent
A GDPR cookie banner sets nothing optional before consent, puts Reject all beside Accept all, pre-ticks nothing and eases withdrawal. How to test it.
LLaunchScaler·Published ·9 min read
A cookie banner meets EU requirements when it sets no non-essential cookie or other tracker before the visitor chooses, offers Reject all on the same layer as Accept all, starts every optional category switched off, gives both choices the same visual weight, and lets people withdraw consent as easily as they gave it. Each of those can be tested in Chrome DevTools in a few minutes, before you rely on any consent tool's settings.
The rules come from two places. Article 5(3) of the ePrivacy Directive, applied through each country's national law, governs storing or reading anything on the visitor's device. The GDPR sets what valid consent is. Regulators have then said how they read both, and the list below marks which points are binding law and which are regulator positions. This is a working checklist, not legal advice.
What are the cookie banner requirements under GDPR?
Six requirements cover almost every banner: nothing optional runs before a choice, a reject option sits beside accept, no optional category is pre-ticked, accept and reject look equally prominent, the banner says how long cookies last and who can access them, and withdrawal is always one step away. The table gives each with its source and a pass or fail test.
Requirement
Source
Binding law or regulator position
Pass or fail test
No non-essential cookies or similar storage before consent
Fresh profile, load the page, touch nothing: no analytics or ad identifiers in cookies or local storage
Reject on the first layer when Accept all is there
Questions, answered
What people ask about this
01
Does a cookie banner need a Reject all button?
In practice, yes, when it has an Accept all button. The EDPB's Cookie Banner Taskforce reported that a vast majority of EU data protection authorities treat a layer with an accept button but no reject option as an infringement, and France's CNIL recommends Reject all at the same level and in the same format as Accept all.
Open the settings layer: every optional toggle is off
Accept and reject equally prominent
CNIL; EDPB Taskforce (case by case)
Regulator guidance
Same button style, size and readable contrast
Duration and third-party access disclosed
CJEU Planet49
Binding law
The banner or its cookie list gives each cookie's lifetime and the third parties that can read it
Withdrawal as easy as consent
GDPR Art. 7(3)
Binding law
A link or icon on every page reopens the choice, and withdrawing works
Two practices the Taskforce also rejected are worth checking at the same time. A banner cannot base cookie placement on "legitimate interest": the Taskforce confirmed that the legal basis for placing or reading cookies under Article 5(3) cannot be the controller's legitimate interests. And analytics or advertising cookies listed under "strictly necessary" are misclassified; site owners are expected to keep a cookie list and be able to demonstrate why each "essential" cookie is essential.
What can run before the visitor clicks anything?
Only what is strictly necessary. Article 5(3), as the EDPB quotes it, allows storing or accessing information on the visitor's device without consent only for the transmission of a communication, or where it is "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service." Everything else waits for consent.
The rule is not limited to cookies. The EDPB's Guidelines 2/2023 (version 2.0, adopted 7 October 2024) state that Article 5(3) also applies to "similar technologies", and analyse tracking pixels, URL tracking and unique identifiers among its use cases. Information in local storage falls under it too once it, or anything derived from it, leaves the device. A tag that writes an ID to localStorage and sends it to an analytics server needs consent just as a cookie does.
What usually counts as strictly necessary: session and login cookies, a load-balancing cookie, a shopping cart, security tokens, and the cookie that stores the visitor's consent choice itself. The Taskforce recalled the Article 29 Working Party's view that cookies retaining preferences the user expressed about a service should be deemed essential. What does not: analytics identifiers such as _ga, advertising cookies such as _fbp and _gcl_au, heatmap and session-replay tools.
One national exception is common. France's CNIL exempts audience measurement from consent when it serves only the site owner, produces only anonymous statistics and is not combined with other processing, with trackers limited to 13 months and the collected data kept for at most 25 months. Other countries set their own conditions, so check the regulator where your visitors are.
Does a Reject all button have to be on the first layer?
Where the first layer has an Accept all button, treat a same-layer reject as required. When the EDPB's Cookie Banner Taskforce asked authorities whether a layer with a consent button but no reject option infringes the ePrivacy Directive, "a vast majority of authorities" said it does. A few disagreed, because Article 5(3) does not explicitly mention a reject option.
The Taskforce also rejected the usual workarounds. A refusal offered only as a link inside a paragraph of banner text, or placed outside the banner, does not lead to valid consent when there is not enough visual support to draw an average user's attention to it. The same goes for a "Manage preferences" link that forces a visitor through a second screen to refuse while accepting takes one click.
The CNIL's 2020 recommendation gives the pattern it considers compliant: two buttons at the same level and in the same format, labelled "Tout accepter" and "Tout refuser" (accept all, refuse all) or an equivalent clear wording, with a "Personnaliser mes choix" (customise my choices) button on that same first layer for anyone who wants to choose by purpose.
Can cookie categories be pre-ticked?
No. In Planet49 (Case C-673/17, judgment of 1 October 2019), the Court of Justice of the EU ruled that consent to storing and accessing cookies is not validly given by a pre-checked checkbox the user must deselect to refuse. The Court added that this holds whether or not the stored information is personal data.
The Taskforce applied the same rule to the toggles on a banner's second layer, citing GDPR recital 32: "Silence, pre-ticked boxes or inactivity should not therefore constitute consent." Every optional category, such as Analytics, Marketing and Personalisation, must start switched off. Only Strictly necessary may be on and locked.
Planet49 also sets what the visitor must be told before consenting: the duration of the operation of cookies, and whether or not third parties may have access to them. A banner that says only "we use cookies to improve your experience" fails that on its face. Link a cookie table with each cookie's name, purpose, lifetime and the company behind it.
Do accept and reject need equal prominence?
They need to be comparable enough that neither choice is pushed. The CNIL recommends buttons and fonts of the same size, offering the same ease of reading and highlighted the same way. The EDPB Taskforce declined to impose one colour or contrast standard and said each banner is assessed case by case.
The Taskforce did name one practice it considers manifestly misleading: a reject button whose text contrast is so low that it is unreadable to virtually any user. The practical test is simple. Put the two buttons side by side at the size a phone shows them. If one is a filled brand-colour button and the other is grey text, the design steers the visitor, and a regulator will read it that way.
Positioning matters for the page itself too. A banner inserted into the page flow after load pushes the content below it down, and web.dev counts any visible element that changes its start position between frames as a layout shift. A banner that overlays the page with fixed positioning does not move other content. The guide to fixing Cumulative Layout Shift covers how those shifts are measured.
How long can you keep a visitor's cookie choice?
EU law sets no fixed period. The CNIL's recommendation asks you to store the choice, consent or refusal, so visitors are not asked again on every page, and to renew consent at appropriate intervals because people forget what they agreed to. It considers keeping the choice for 6 months, both consent and refusal, good practice.
The 13-month figure often quoted comes from a different rule: it is the CNIL's cap on the lifetime of audience-measurement trackers that are exempt from consent. Store refusal as carefully as consent. A banner that remembers acceptance for a year but forgets refusal after a session asks refusers again and again until they give in, which is the pressure the rules exist to prevent.
How easy must withdrawing consent be?
As easy as giving it. GDPR Article 7(3) states that the data subject can withdraw consent at any time, must be told so before consenting, and that "it shall be as easy to withdraw as to give consent." A visitor who accepted with one click must be able to withdraw without hunting for it.
The Taskforce recommends an easily accessible solution such as a small, permanently visible icon or a link in a visible, standard place. The CNIL suggests a link named something like "Gérer mes cookies" (manage my cookies), or a cookie icon at the bottom left of every page. A footer link labelled "Cookie settings" that reopens the banner meets the idea on most sites. After withdrawal, the tags must stop and their non-essential cookies should be deleted.
How do you test a cookie banner in DevTools?
Load the site in a clean browser with DevTools open before the page loads, touch nothing, and read what was stored and sent. Then repeat after rejecting, after accepting and after withdrawing. Each pass takes a couple of minutes in Chrome.
Open an incognito window or a new Chrome profile, open DevTools, and in the Network panel tick Preserve log.
Load your homepage. Do not click the banner.
Open Application > Storage > Cookies and select your origin, then check Local storage. Any analytics or advertising identifier here (for example _ga, _fbp, _gcl_au) is a fail.
In the Network panel, filter by the domains of your analytics, ad and pixel vendors. A request that carries an identifier before any choice is a fail.
Check the banner itself: Reject all on the first layer, no pre-ticked toggles in the settings layer, both buttons equally readable, and a link to the cookie list with lifetimes and third parties.
Click Reject all. Reload, visit two more pages, and repeat steps 3 and 4. Nothing new may be set or sent.
Clear site data from the Application panel's Storage section, reload, and click Accept all. Confirm your tags now fire, which proves the consent state really controls them.
Use the footer link or icon to withdraw. Reload and repeat steps 3 and 4: the tags must stop and their cookies should be gone.
If Google tags are on the page, check their consent signals at the same time; the guide to Google Consent Mode v2 shows the default and update calls and how to read them in Tag Assistant. And list every vendor that fired in step 7, because each is a recipient your privacy policy must disclose, as covered in what a SaaS privacy policy must include.
Check your banner the way a first visit sees it
A DevTools pass shows what happened in your browser on one visit. To have a real browser record what your live pages set before and after a choice, run the free scan first, then open the full audit. The free LaunchScaler scan needs only your URL and no account, and its compliance category includes "Non-essential trackers fire before any consent action", "No 'Reject all' control on the banner's first layer", "Non-essential cookie categories pre-enabled by default", "Accept and reject controls are visually asymmetric (nudging)", "Trackers still fire after the user rejects", "No easy, persistent way to withdraw consent" and "Banner omits cookie duration and third-party recipients".
The free run shows each verdict. The full audit, $19 one time for your domain, opens every check to its evidence and exact fix, such as which trackers fired before consent and which cookies came back after a reject. These checks detect signals, not legal compliance, so a site that passes every one can still need a lawyer's review for its own countries.
02
Can analytics cookies be set before consent?
Not under Article 5(3) of the ePrivacy Directive, which allows storing or reading information on a visitor's device without consent only when it is strictly necessary for a service the visitor asked for. Analytics and advertising identifiers do not meet that test, though some countries, including France, exempt narrowly configured audience measurement.
03
Are pre-ticked cookie boxes allowed?
No. The EU Court of Justice ruled in Planet49 (1 October 2019) that consent given through a pre-checked checkbox the user must deselect is not valid, whether or not the stored information is personal data.
04
How long can I keep a visitor's cookie choice?
EU law sets no fixed period. France's CNIL considers keeping the choice, consent or refusal, for 6 months good practice, and asks you to renew consent at appropriate intervals.
05
Does withdrawing consent have to be easy?
Yes. GDPR Article 7(3) says it must be as easy to withdraw consent as to give it. Regulators suggest a permanent link or small icon on every page that reopens the cookie settings.
The assessment fails when LCP, INP or CLS misses Good at the 75th percentile of 28 days of real Chrome data. How to read it and which metric to fix first.