No, not every site. If the site writes only what the service itself needs, a policy is enough. A banner is a choice, not decoration.
You open your new website, which has the company story, a telephone number and a contact form, and the first thing you see is a bar asking for consent to cookies this page does not write at all, because the plugin was copied from another project that had Google Analytics, and now you are paying for theatre in which the “I agree” button hides an empty inventory. Next door, a shop on the same WordPress, but with Google Analytics 4 and a Meta pixel, shows only the content while the browser has already received an identifier before the buyer has read a single product name, and that difference is the whole subject of this article. The first case is a surplus notice. The second is storage without a lawful route, and the law does not ask whether a bar is visible; it asks what the site writes into terminal equipment and whether that was needed for the service the user themselves requested.
This article answers whether a website needs a cookie notice, and the answer is not “yes, for everyone”, even though almost every plugin behaves as if it were, and it is not “no, for no one”, even though that is a comfortable thing to tell a site that wants to stay clean. The answer is a boundary: if the site stores or reads only what the service the user asked for actually needs, a choice window is not a duty, but the information about those cookies still belongs in a policy that can be reached from every page. If the site measures visitors, shows advertising or loads a third-party tool before the user has asked for anything, there has to be a lawful route before the first write — consent, or a named PECR exception that is actually met — and then the bar is no longer decoration, but the only lawful way to obtain that consent where consent is the route.
We name this boundary because we have seen both ends in a single week: a site that buys a consent management platform (CMP) in order to hide a session cookie, and a site that launches analytics with no choice at all because “we have a privacy policy”, and neither of those states is compliance. Neither of them is a reason to rewrite the technical audit we have already written elsewhere, because that is where the question belongs of whether a bar that is needed actually stops the tags. What remains here is only the first question, which is too often answered with a plugin: whether you have anything to ask at all, before someone sells you a tool with which to ask.
Do I need a cookie notice on my website?
No, not every website, and that is the answer the Information Commissioner’s Office has written in its guidance on storage and access technologies: if the site uses only cookies that are strictly necessary for the service the user asked for, the controller can tell people about them in the privacy policy, and a pop-up with choice buttons is not mandatory. Statistical-purposes and appearance storage also skip consent, but only after clear information and a simple means of objecting, free of charge. That is not our opinion and it is not a “practical shortcut” agencies invent in order to sell less work; it is the edge of the controller’s duty, which the ICO itself has drawn, and it is worth reading before someone sells you a consent management platform for a site that has nothing to manage. If you still want to show a bar when there is no choice to make, it may be informative — “I understand” and a link to the policy — and “I agree” must not stand on it, because you are not asking for consent at that moment and a button that looks like consent is poor practice.
This boundary is also where the names start to mislead, because a cookie notice in everyday speech means any text that says the site stores something, while a cookie banner is the choice interface with which you obtain consent for what an exception does not cover, and a cookie policy is the document in which the ICO wants to see the purpose, the recipient and the retention period. The law does not, in any of those places, require a particular design of bar, and it also does not require every page that carries a form security token to ask first whether the user will allow the site to work at all. Mixing up these three words means either putting a choice where there is none, or imagining that a policy on its own authorises a measurement nobody requested.
The consequences of the wrong side are more expensive than they look, because a surplus “I agree” on a purely technical site teaches the visitor that consent is a formality, and teaches you that compliance is the installation of a plugin rather than a check of the inventory. A missing choice where advertising is already writing, or where analytics is writing without meeting a named exception, is not “a small risk, because we have a policy”; it is storage before a lawful route, which is still the first thing the ICO looks at when a banner and a site disagree. In both cases you have done work that does not match what happens on the site, and that is a worse state than a blank page, because it looks like order and therefore stays unchecked for longer.
Before you buy any tool, write down what the site writes into the browser in the first second of a clean profile, and for each row ask whether it is needed for the service the user has requested at that moment, not for the service you wish to measure. If the answer for every row is yes, you need a policy, not a banner, and this article sells you only that sentence from here on. If even one row is advertising, a cross-site tool, or a measurement that no exception covers, you need a lawful route before that row, and only then is it worth talking about the text of the bar, which we will also write here — but not sooner.
The law names storage and access, not a banner
The ICO’s chapter on the exceptions sits on Schedule A1 to the Privacy and Electronic Communications Regulations (PECR), inserted on 5 February 2026 when the Data (Use and Access) Act 2025 substituted regulation 6: storing information in a subscriber’s or user’s terminal equipment, or gaining access to information already stored there, is prohibited unless Schedule A1 applies — consent after clear and comprehensive information about the purpose, or a named exception, and the same sentence still stands in the European Union as Article 5(3) of the ePrivacy Directive, and in Germany as § 25 TDDDG. None of those texts contains the word “banner”, because the duty is about an action in terminal equipment, and the bar is only one way of collecting that consent, if consent is needed at all. A person who starts by buying a plugin starts from the wrong end, as if the law were about a frame at the bottom of the screen rather than about what happens before the frame.
The original exceptions are still two, and they are still narrow: consent is not needed if the storage or access is necessary for the transmission of a communication over an electronic communications network, or if it is strictly necessary to provide a service the subscriber or user has requested. In practice that second limb is a session identifier for a form or a basket, authentication, security against attacks, a player session, load balancing, a language or layout choice the user has made and which is not used for another purpose — and the list is not a menu into which you can drop whatever is convenient. “Necessary for us, so that we can see whether the site works” is not strictly necessary, however often it appears in a proposal, because the user who opens the home page has not requested a measurement. Since 5 February 2026 PECR also names statistical purposes, with clear information and a simple means of objecting free of charge; that is a different route, not a wider strictly-necessary limb, and advertising and anything that follows a person across sites are still outside every exception.
The scope is not tied to a file whose name contains “cookie”, because the European Data Protection Board’s 2023 guidelines on the technical scope of Article 5(3), adopted on 7 October 2024 in their second version, remind us that the article speaks of information, not of personal data, and of storage or access, not of one technology. Pixels, localStorage and a device fingerprint fall inside the same question, and the Court in Planet49 (C-673/17) says the same thing from the other side: the protection applies to any information in terminal equipment, even when it is not personal data. That is why a policy that promises “we do not use cookies” has not yet answered whether the site, by another method, accesses what already stands on the device. That answer matters more than whether the word “cookie” appears in a file name.
This is also the mistake we see in purchases, when someone buys a “cookie solution” as if the law were about the bar, and then wonders why an audit still finds requests the bar does not mention. A solution that starts with a plugin starts from the wrong end, because first you have to understand what is being stored and who needs it, and only then is it worth choosing whether a policy is enough or you need a choice interface that actually carries the choice out. We do not invent this order in order to slow a project down; we ask for it so that the project, after launch, still matches the inventory with which it was commissioned.
Two layers: terminal equipment and personal data
The first layer is PECR, which asks whether you may write or read anything at all, and the second layer is the UK GDPR, which asks, if personal data is then processed, on what legal basis and with what transparency. The ICO describes the same interaction, as the European Data Protection Board already set out in Opinion 5/2019, and the German supervisors draw the same picture as two dimensions that must not be melted into one “GDPR banner”. One layer does not cancel the other. One green tick does not answer both, however convenient it would be, in a purchase, to buy one tool against both questions.
This difference is why a privacy policy is not a cookie banner, because the policy fulfils the duty to inform — what is done, for what purpose, for how long, who receives the data — and that can be done even when no choice is needed. The banner obtains consent where an exception does not fit, and it has to meet Article 4(11) of the UK GDPR: a freely given, specific, informed and unambiguous indication by a clear affirmative action, which silence, a pre-ticked box and inactivity do not give. The Court said that in 2019 in Planet49, and the UK GDPR has written it into Recital 32 as well, so a button that hopes the person will not notice the tick is not consent even if the policy under it is long.
Older copies of PECR, and older ICO cookie pages written before 5 February 2026, still live in some people’s heads as if analytics always needed a banner and as if the 2003 regulations still decided the quality of consent, and they must not be read that way, because the Data (Use and Access) Act substituted regulation 6 and the ICO now reads the UK GDPR for what “consent” means. A reference in the old PECR text to Directive 95/46/EC is, after Article 94 of the UK GDPR, a reference to the UK GDPR itself, and “consent” means what Article 4(11) says, not what someone remembers from a page that has been replaced. We name this gap so that you do not start looking for the old regulation in a place where the commissioner already reads the substituted PECR and the UK GDPR.
In practice that means two questions that must not be asked in one breath: first, whether this action may happen at all before a choice, or whether it is an exception, and then, if the data is personal data, on what basis you process it further and where the user can read that. A site that answers only the second question with a long policy, and does not answer the first, has written an essay about what it does and has not asked whether it may do it. The other essay, which answers only the first and forgets the transparency of Article 13, is a bar without content, and we see both more often than an inventory that answers both.
When consent is not needed — and when a notice still is
Consent is not needed where a cookie is needed for the requested service itself and is not used for another purpose, and that is a narrower condition than it sounds. A form that cannot tell your submission from a stranger’s without a session token, a basket that forgets the item without an identifier, authentication, or a security token — that is the core of the strictly necessary exception, not “everything we would find inconvenient to do without”. Load balancing that only routes the request sits in the communication exception. A language cookie that only remembers the preference is the ICO’s own appearance example: it does not need consent, but it does need clear information and a simple means of objecting, free of charge. An identifier that follows the person from visit to visit in order to show destinations cannot sit in any exception, because there the purpose is no longer the function the user asked for.
This is where excess most often hides, because analytics is enlisted as “necessary in order to improve the site”, a chat window as “necessary in order to answer the client”, an advertising pixel as “necessary in order to see whether the campaign works”, and none of those sentences is strictly necessary. The user who opens the home page has not requested a measurement, a chat or a campaign, and the strictly necessary exception belongs to the function they are using at that moment, not to the function you wish to measure. If you cannot write that link in one sentence without the word “us”, it is not a strictly necessary cookie. Analytics may have another PECR route, which we come to below; it does not become strictly necessary by being called statistics, and that is worth saying out loud while the tool is still only a wish, not once it is already writing.
The notice remains all the same, because the ICO says that a controller who uses only strictly necessary cookies can tell people about them in a privacy policy that is available on the site, and that a pop-up is then not mandatory. The German Federal Commissioner for Data Protection says the same thing in other words: people must be informed about technically necessary tools, and that can be done in a reachable privacy policy, but the controller must be able to justify why the particular tool is necessary. Article 13 of the UK GDPR requires that information even when personal data is collected without a banner, because transparency is not an appendix to consent and a policy is not a gift that can be postponed until someone complains.
On our own site we keep the session, the security token and the saving of the consent preference among the strictly necessary cookies and we do not ask for consent to them, because without them this page cannot accept a form and cannot remember what you have already chosen. That is our inventory decision, not an ICO quotation that the consent cookie is settled, and we do not hide it behind a general “everyone does that”, because a row of that kind is not a universal exemption. If your site has no such rows and no measurements either, a policy is enough; if you still want to show an informative bar, show “I understand” and a link, not “I agree”, because otherwise you are asking for what the law does not, at that moment, require.
When consent is needed before the first write
Advertising cookies, and any identifier that follows a person onto another site, still need consent, and the ICO has written that as a rule rather than a tip: no advertising purpose meets any PECR exception, and anything that builds a profile across services sits in the same bucket. Public bodies have no wider gate; marketing measurement is still marketing. Analytics is where the United Kingdom has moved. Since 5 February 2026 PECR has a statistical-purposes exception — the sole purpose of collecting aggregate statistics about how this service or this website is used, with a view to improving it, after clear and comprehensive information and a simple means of objecting free of charge. It is not a new name for “we only count pages”. If the same identifier feeds ads, is used to decide what to show this visitor, or is shared with a party that is not merely helping you improve this site, the exception does not apply and consent is still the route, before the first write.
Time is part of this rule, not a footnote under it, because if an identifier is written or read before the user has a route out of the prohibition — consent, or a named exception with its information and its opt-out — the later banner does not repair that second, however handsome the bar that appears half a second later. A faster animation does not fix the second either. That is why the question is not “do we have a banner”, but “what happens in the first second of a clean profile”, and that is the second we record in an audit with a log, not with the impression that the bar appeared early enough.
Third-party tools do not move this boundary; they only make it more visible, because an embedded YouTube video on a British company’s site sets third-party cookies and YouTube is their controller. That is not yet the same as saying that every embedded player automatically requires a choice bar before the first pixel, because if the video loads only after the user’s click, there may be nothing to store in the first second. The test remains the same — whether storage or access has already happened before the requested action — and if it has, a lawful route was needed earlier, but if it has not, you have left the choice where it belongs.
First or third party does not decide this test, and the German Federal Commissioner for Data Protection says so openly: a first-party cookie can be necessary and a third-party cookie can be necessary, and both can fail, so an identifier you write yourselves as the first party in order then to measure behaviour is not “safer” than a foreign pixel merely because the domain is yours. The law asks about the action and the purpose, not about which server the file lives on, and a policy that boasts “we do not use third-party cookies” has not yet answered what your own analytics does. This is also the place where we usually ask for the Network log to be opened, rather than arguing about the word “first-party”. The log ends that argument faster.
A cookie notice is not the same as a cookie banner
A notice is information, a banner is a choice, and a policy is the place the information remains when the bar has been closed, but these three words collapse in everyday English into one “cookie notice”, which is why searches put “cookie notice” and “cookie banner” next to each other as if they were one duty. They are not, because you can inform in a policy, without a bar, if an exception covers everything the site does, but a choice can be obtained only with an interface that also allows refusal, and that interface is the banner. Mixing them up means either asking for a signature where only text is needed, or imagining that text on its own authorises a measurement.
The cheapest way to see the difference is a site that uses only strictly necessary cookies but shows an “I agree” button, because it asks for what is not needed and teaches that consent is the only button that closes anything. Good practice in the same place is an informative text, a link to the policy and “I understand”, which admits nothing and only removes the bar, and if you rename that “I understand” as consent you have returned to the poor example, only with a politer word. We do not retell this example in order to laugh at plugins; we retell it because it is the cheapest way to see that an object on the screen is not yet a duty.
Where consent is needed, the ICO wants it collected with a cookie banner, and refusal must be as easy as consent — on the first screen, not in a third menu — and that belongs to the case in which consent is needed, not the case in which it is not. A cookie wall — a wall that will not let the reader see the content until they have agreed — is, in the ICO’s words, a “take it or leave it” approach that in most cases is not freely given consent. A genuine free choice is required; “consent or pay” is a separate model with its own ICO guidance, not a get-out this article will bless in one clause, and the duty to inform remains even then. We are not importing a German page as UK law; PECR and the ICO already draw this line clearly enough that a notice and a choice should not be confused.
This difference is also why we no longer write a second technical document under another title, because the ICO talks about a cookie policy, and in the same document there is a place for the purpose, the recipient and the retention period. A second file with a different heading does not create a second compliance; it only gives a second place where the inventory can fall behind, and we have seen that often enough that we no longer promise a second file as a gift. If you have a policy in which those rows stand, you have a notice; if you have only a bar without those rows, you have decoration, and an audit does not treat decoration as evidence.
What to write in the cookie notice if consent is needed
If consent is needed, the information has to be such that a person understands what they are agreeing to before they agree, and the Court in Planet49 said that clear and comprehensive information includes the duration of the cookies and whether third parties access them. The ICO divides the same thing into categories, purposes and recipients, and says that this information must stand in the banner far enough for the choice to be informed, and in the policy, where it can be told more fully. A general text with quotations from the statute is not information, it is a cover, and a cover remains a cover even when it has been translated into twelve languages.
On the first screen, consent and refusal must be equally visible, because the same three kinds of deception still fail the test: “I agree” is coloured, refusal hides behind “more options”, or the only buttons are “I agree”, “close”, “I understand” and “continue”. Continuing to browse the site, and closing the banner, are not in themselves valid consent, and Planet49 adds that a pre-ticked box is not consent either, because consent requires an active act, not a silence in which you hoped the person would not notice the tick. These lines belong to this article because they are the form of the duty, not the DevTools steps we have left to the other text.
Withdrawal of consent must be as easy as giving it, because Article 7(3) of the UK GDPR says so directly, and the ICO translates that into a link that remains when the bar has gone, usually in the footer, from every page. A button that saves the new choice but does not tell the tags already loaded is the same fault we have written about in the technical audit, only from the other side: here it is the form of the duty, there the absence of proof. We do not end this article with the steps of the Network log, because those belong to the other text; here it is enough to say that a withdrawal that cannot be found is not a withdrawal, even if the policy has promised it.
The text we write for clients comes from the inventory, not from a template, because the ICO requires the technologies, the purposes, any third parties who store or access the information, and the duration, and that is what we also demand of ourselves: each row has to be one that can be checked against what happens on the site. A template left over from the previous project is worse than a blank page, because it names cookies that are no longer there and stays silent about those that are, and this is also the moment at which we stop writing a legal essay. The work from here is a check, not another signature under a text that nobody has compared with what happens in the first second.
What a banner the site does not need actually costs
A surplus banner is not caution. It steals the first screen, teaches the visitor to click without reading, and teaches you that compliance is a plugin’s default rather than a match between the inventory and what happens on the site. The poor-practice example of “I agree” on a technical site is exactly this bill: you have put a choice where there is none, and now you have to maintain a choice that changes nothing, because under it there is nothing to switch off.
That is a worse state than silence. An object on the screen creates an impression of order, and it is precisely this “order” that is why we treat a surplus bar as a fault.
We do not sell a consent management platform to a site that can make do with a policy, and that sounds like a lost deal, and it is. We would rather lose the work in which Cookiebot, OneTrust or a custom banner would have to be installed where the inventory is only a session and a security token, than gain a client who after six months asks why they are paying for a bar that manages nothing. This is the sentence a sales deck usually skips, and that is why we write it here. An article that always ends with “buy our audit” is not an answer to the question of whether a notice is mandatory at all.
The other price is legal, not only aesthetic, because a bar that asks for consent to what does not need it, or that hides refusal, is the same deception the ICO acts against where consent is needed as well. You cannot defend “but we have a banner” if the banner was built for the wrong inventory, because compliance is not the presence of an object on the screen, but a match between what the site does and what you have said about it. A surplus object damages that match no less than a missing one, and that is also why we sometimes recommend taking a bar down, not putting one up, even though that sounds like the opposite of what an agency is expected to do.
If a banner is needed, the next question is not how it looks
If the inventory shows advertising, a cross-site tool, or analytics that the statistical-purposes exception does not cover, then yes, you need a choice before the first write, and then the scope of this article ends, because the next question is whether the bar that is now needed actually stops what it promises to stop. We have answered that in the article on whether Reject actually stops the tags: “Reject” that closes the frame but does not switch the tag off is not a refusal, and this text does not rewrite that, because it is already written. Repeating seven faults here would mean stealing the other article’s question, and we do not do that even if an internal link in this place looks like a sale.
Our audit of cookies and tracking starts at €800 and usually takes 1–4 weeks, depending on the templates, the languages, the CMP and the tag container, and this “starts at” is a published minimum, not an invoice. It belongs to the inventory, the configuration and the check, not to a promise that all of the organisation’s data protection will be put in order with one bar, and we choose basic or advanced consent mode after your legal assessment and your analytics needs. We do not promise modelled data where the Google property does not meet Google’s conditions, because these lines are the same ones that stand on the service page, and this article does not raise them or lower them.
Before you write to us, do the same check with which this text began: a clean profile, the first second, a list of what was written, and one line for each “why”, because that list is cheaper than any proposal. If the list is empty or contains only strictly necessary cookies, you need a policy, and we will say so, even if that means an audit is not this week’s deal. If the list has a row for which consent was needed yesterday, then a bar that looks polite today is not yet an answer, and then it is worth reading the other article, not this one again.
If you want us to read that list with you and say which side is yours, write to us, because sometimes the more honest answer is that a policy is enough and that the money is worth saving for the content, not the bar, and sometimes the answer is that consent is needed and that it is now time to check whether it works. Both are valid, and only one of them is fair on each site, and we would rather lose an audit in which a banner would have to be installed on an empty inventory than gain a project in which that banner becomes a reproach after launch.
Frequently asked questions.
Does every website need a cookie notice?
No, not every site. If the site uses only cookies that are strictly necessary for the service the user asked for, the ICO allows you to tell people about them in the privacy policy, and a pop-up with a choice is not mandatory. Statistical and appearance storage also skip consent, but only with clear information and a free opt-out. The notice in that case is the policy, not a banner. As soon as the site shows advertising, follows a person across sites, or measures visitors in a way no PECR exception covers, consent is needed before the first write, and then the choice interface is no longer decoration.
Is a privacy policy enough if I only use a session cookie?
Yes, if that cookie is genuinely needed for the requested service and is not used for another purpose. The ICO says that a policy which is reachable on the site is then enough, and that a choice window does not have to be put up. If you still show a bar, it may be informative with “I understand”, not “I agree”. Article 13 of the UK GDPR still requires information about personal data, even without a banner.
May I launch Google Analytics 4 before consent?
Not as a matter of course. Advertising, cross-site identifiers and any analytics that does not meet PECR’s statistical-purposes exception still need consent before the first write, and that is the first second in a clean profile, not the moment the bar finally appears. Advanced consent mode, in which tags may load with storage denied, is not an automatic permission and is not this article’s subject; the mode is determined by a legal assessment and then checked in an audit.
Does an embedded YouTube video or a map automatically require a banner?
No, not automatically — and yes, if the embed already writes or reads information in terminal equipment before the user clicks. YouTube cookies in an embed are third-party cookies and YouTube is their controller, but the test remains storage, not the presence of a player. If the video loads only on request, there may be nothing to ask in the first second; if an identifier leaves as the page opens, a lawful route was needed earlier.
What should I do if a banner is already there but I am not sure it works?
First ask whether this banner needed to be there at all. If the inventory is only storage that PECR excepts, the bar may be surplus and “I agree” on it is poor practice. If the inventory includes advertising or analytics that still need consent, the next job is to check whether “Reject” actually stops the tags, and we have described that in the article on the banner itself. A technical audit with us starts at €800 and usually takes 1–4 weeks.
A cookie audit that gets you to GDPR and ePrivacy compliance — a full analysis of your cookie configuration, a CMP banner, Consent Mode v2.
More posts.