Privacy Approximate reading time: 22 min ·

Do I Need a Cookie Notice on My Website?

No, not every site. If the site writes only what the service itself needs, a policy is enough. A banner is a choice, not decoration.

Illustration: a browser window with a document and a tick in the middle — the question of whether a cookie notice is needed at all.

No, not every site. If the site writes only what the service itself needs, a policy is enough. A banner is a choice, not decoration.

You open your new website, which has the company story, a telephone number and a contact form, and the first thing you see is a bar asking for consent to cookies this page does not write at all, because the plugin was copied from another project that had Google Analytics, and now you are paying for theatre in which the “I agree” button hides an empty inventory. Next door, a shop on the same WordPress, but with Google Analytics 4 and a Meta pixel, shows only the content while the browser has already received an identifier before the buyer has read a single product name, and that difference is the whole subject of this article. The first case is a surplus notice. The second is storage without a lawful route, and the law does not ask whether a bar is visible; it asks what the site writes into terminal equipment and whether that was needed for the service the user themselves requested.

This article answers whether a website needs a cookie notice, and the answer is not “yes, for everyone”, even though almost every plugin behaves as if it were, and it is not “no, for no one”, even though that is a comfortable thing to tell a site that wants to stay clean. The answer is a boundary: if the site stores or reads only what the service the user asked for actually needs, a choice window is not a duty, but the information about those cookies still belongs in a policy that can be reached from every page. If the site measures visitors, shows advertising or loads a third-party tool before the user has asked for anything, there has to be consent before the first write — Article 5(3) of Directive 2002/58/EC, as each market transposes it, and the GDPR where personal data is then processed — and then the bar is no longer decoration, but the only lawful way to obtain that consent.

We name this boundary because we have seen both ends in a single week: a site that buys a consent management platform (CMP) in order to hide a session cookie, and a site that launches analytics with no choice at all because “we have a privacy policy”, and neither of those states is compliance. Neither of them is a reason to rewrite the technical audit we have already written elsewhere, because that is where the question belongs of whether a bar that is needed actually stops the tags. What remains here is only the first question, which is too often answered with a plugin: whether you have anything to ask at all, before someone sells you a tool with which to ask.

No, not every website: if the site uses only cookies that are strictly necessary for the service the user asked for, the controller can tell people about them in the privacy policy, and a pop-up with choice buttons is not mandatory. That is not our opinion and it is not a “practical shortcut” agencies invent in order to sell less work; it is the edge of the controller’s duty under Article 5(3) of the ePrivacy Directive, and it is worth reading before someone sells you a consent management platform for a site that has nothing to manage. If you still want to show a bar when there is no choice to make, it may be informative — “I understand” and a link to the policy — and “I agree” must not stand on it, because you are not asking for consent at that moment and a button that looks like consent is poor practice.

This boundary is also where the names start to mislead, because a cookie notice in everyday speech means any text that says the site stores something, while a cookie banner is the choice interface with which you obtain consent for what an exception does not cover, and a cookie policy is the document in which the ICO wants to see the purpose, the recipient and the retention period. The law does not, in any of those places, require a particular design of bar, and it also does not require every page that carries a form security token to ask first whether the user will allow the site to work at all. Mixing up these three words means either putting a choice where there is none, or imagining that a policy on its own authorises a measurement nobody requested.

The consequences of the wrong side are more expensive than they look, because a surplus “I agree” on a purely technical site teaches the visitor that consent is a formality, and teaches you that compliance is the installation of a plugin rather than a check of the inventory. A missing choice where advertising is already writing, or where analytics is writing without meeting a named exception, is not “a small risk, because we have a policy”; it is storage before a lawful route, which is still the first thing the ICO looks at when a banner and a site disagree. In both cases you have done work that does not match what happens on the site, and that is a worse state than a blank page, because it looks like order and therefore stays unchecked for longer.

Before you buy any tool, write down what the site writes into the browser in the first second of a clean profile, and for each row ask whether it is needed for the service the user has requested at that moment, not for the service you wish to measure. If the answer for every row is yes, you need a policy, not a banner, and this article sells you only that sentence from here on. If even one row is advertising, a cross-site tool, or a measurement that no exception covers, you need a lawful route before that row, and only then is it worth talking about the text of the bar, which we will also write here — but not sooner.

The law names storage and access, not a banner

Article 5(3) of Directive 2002/58/EC says that storing information in a subscriber’s or user’s terminal equipment, or gaining access to information already stored there, is allowed only with consent after clear and comprehensive information about the purpose, and each market then has its own transposition of that sentence — in Germany, § 25 TDDDG. None of those texts contains the word “banner”, because the duty is about an action in terminal equipment, and the bar is only one way of collecting that consent, if consent is needed at all. A person who starts by buying a plugin starts from the wrong end, as if the law were about a frame at the bottom of the screen rather than about what happens before the frame.

The original exceptions are still two, and they are still narrow: consent is not needed if the storage or access is necessary for the transmission of a communication over an electronic communications network, or if it is strictly necessary to provide a service the subscriber or user has requested. In practice that second limb is a session identifier for a form or a basket, authentication, security against attacks, a player session, load balancing, a language or layout choice the user has made and which is not used for another purpose — and the list is not a menu into which you can drop whatever is convenient. “Necessary for us, so that we can see whether the site works” is not strictly necessary, however often it appears in a proposal, because the user who opens the home page has not requested a measurement. Advertising and anything that follows a person across sites are still outside every exception.

The scope is not tied to a file whose name contains “cookie”, because the European Data Protection Board’s 2023 guidelines on the technical scope of Article 5(3), adopted on 7 October 2024 in their second version, remind us that the article speaks of information, not of personal data, and of storage or access, not of one technology. Pixels, localStorage and a device fingerprint fall inside the same question, and the Court in Planet49 (C-673/17) says the same thing from the other side: the protection applies to any information in terminal equipment, even when it is not personal data. That is why a policy that promises “we do not use cookies” has not yet answered whether the site, by another method, accesses what already stands on the device. That answer matters more than whether the word “cookie” appears in a file name.

This is also the mistake we see in purchases, when someone buys a “cookie solution” as if the law were about the bar, and then wonders why an audit still finds requests the bar does not mention. A solution that starts with a plugin starts from the wrong end, because first you have to understand what is being stored and who needs it, and only then is it worth choosing whether a policy is enough or you need a choice interface that actually carries the choice out. We do not invent this order in order to slow a project down; we ask for it so that the project, after launch, still matches the inventory with which it was commissioned.

Two layers: terminal equipment and personal data

The first layer is Article 5(3) of the ePrivacy Directive, which each market transposes and which asks whether you may write or read anything at all, and the second layer is the GDPR, which asks, if personal data is then processed, on what legal basis and with what transparency. The European Data Protection Board already set out the same interaction in Opinion 5/2019, and the German supervisors draw the same picture as two dimensions that must not be melted into one “GDPR banner”. One layer does not cancel the other. One green tick does not answer both, however convenient it would be, in a purchase, to buy one tool against both questions.

This difference is why a privacy policy is not a cookie banner, because the policy fulfils the duty to inform — what is done, for what purpose, for how long, who receives the data — and that can be done even when no choice is needed. The banner obtains consent where an exception does not fit, and it has to meet Article 4(11) of the GDPR: a freely given, specific, informed and unambiguous indication by a clear affirmative action, which silence, a pre-ticked box and inactivity do not give. The Court said that in 2019 in Planet49, and the GDPR has written it into Recital 32 as well, so a button that hopes the person will not notice the tick is not consent even if the policy under it is long.

The ePrivacy Directive still contains a reference to Directive 95/46/EC, and it must not be read as if that 1995 directive still decided the quality of consent, because Article 94 of the GDPR carries the reference over to the GDPR itself. “Consent” means what Article 4(11) says, not what someone remembers from a repealed national act. We name this gap so that you do not start looking for the old article in a place where the supervisor already reads the Regulation.

In practice that means two questions that must not be asked in one breath: first, whether this action may happen at all before a choice, or whether it is an exception, and then, if the data is personal data, on what basis you process it further and where the user can read that. A site that answers only the second question with a long policy, and does not answer the first, has written an essay about what it does and has not asked whether it may do it. The other essay, which answers only the first and forgets the transparency of Article 13, is a bar without content, and we see both more often than an inventory that answers both.

Consent is not needed where a cookie is needed for the requested service itself and is not used for another purpose, and that is a narrower condition than it sounds. A form that cannot tell your submission from a stranger’s without a session token, a basket that forgets the item without an identifier, authentication, or a security token — that is the core of the strictly necessary exception, not “everything we would find inconvenient to do without”. Load balancing that only routes the request sits in the communication exception. A language cookie that only remembers the preference sits in the same strictly necessary list, provided it is not used for another purpose. An identifier that follows the person from visit to visit in order to show destinations cannot sit in any exception, because there the purpose is no longer the function the user asked for.

This is where excess most often hides, because analytics is enlisted as “necessary in order to improve the site”, a chat window as “necessary in order to answer the client”, an advertising pixel as “necessary in order to see whether the campaign works”, and none of those sentences is strictly necessary. The user who opens the home page has not requested a measurement, a chat or a campaign, and the strictly necessary exception belongs to the function they are using at that moment, not to the function you wish to measure. If you cannot write that link in one sentence without the word “us”, it is not a strictly necessary cookie. Analytics does not become strictly necessary by being called statistics, and that is worth saying out loud while the tool is still only a wish, not once it is already writing.

The notice remains all the same, because the ICO says that a controller who uses only strictly necessary cookies can tell people about them in a privacy policy that is available on the site, and that a pop-up is then not mandatory. The German Federal Commissioner for Data Protection says the same thing in other words: people must be informed about technically necessary tools, and that can be done in a reachable privacy policy, but the controller must be able to justify why the particular tool is necessary. Article 13 of the GDPR requires that information even when personal data is collected without a banner, because transparency is not an appendix to consent and a policy is not a gift that can be postponed until someone complains.

On our own site we keep the session, the security token and the saving of the consent preference among the strictly necessary cookies and we do not ask for consent to them, because without them this page cannot accept a form and cannot remember what you have already chosen. That is our inventory decision, not an ICO quotation that the consent cookie is settled, and we do not hide it behind a general “everyone does that”, because a row of that kind is not a universal exemption. If your site has no such rows and no measurements either, a policy is enough; if you still want to show an informative bar, show “I understand” and a link, not “I agree”, because otherwise you are asking for what the law does not, at that moment, require.

Advertising cookies, and any identifier that follows a person onto another site, still need consent: no advertising purpose meets the two exceptions in Article 5(3), and anything that builds a profile across services sits in the same bucket. Public bodies have no wider gate; marketing measurement is still marketing. Analytics is not a third Union exception. A usual measurement still needs prior consent unless the market you are in has written its own exemption, as the CNIL has for certain audience-measurement cookies in France and the Garante has for a narrow first-party class in Italy. The United Kingdom’s PECR statistical-purposes exception, from 5 February 2026, is that market’s, not a Union rule. It is not a new name for “we only count pages”. If the same identifier feeds ads, is used to decide what to show this visitor, or is shared with a party that is not merely helping you improve this site, consent is still the route, before the first write.

Time is part of this rule, not a footnote under it, because if an identifier is written or read before the user has consented, where consent is the route — the later banner does not repair that second, however handsome the bar that appears half a second later. A faster animation does not fix the second either. That is why the question is not “do we have a banner”, but “what happens in the first second of a clean profile”, and that is the second we record in an audit with a log, not with the impression that the bar appeared early enough.

Third-party tools do not move this boundary; they only make it more visible, because an embedded YouTube video on a British company’s site sets third-party cookies and YouTube is their controller. That is not yet the same as saying that every embedded player automatically requires a choice bar before the first pixel, because if the video loads only after the user’s click, there may be nothing to store in the first second. The test remains the same — whether storage or access has already happened before the requested action — and if it has, a lawful route was needed earlier, but if it has not, you have left the choice where it belongs.

First or third party does not decide this test, and the German Federal Commissioner for Data Protection says so openly: a first-party cookie can be necessary and a third-party cookie can be necessary, and both can fail, so an identifier you write yourselves as the first party in order then to measure behaviour is not “safer” than a foreign pixel merely because the domain is yours. The law asks about the action and the purpose, not about which server the file lives on, and a policy that boasts “we do not use third-party cookies” has not yet answered what your own analytics does. This is also the place where we usually ask for the Network log to be opened, rather than arguing about the word “first-party”. The log ends that argument faster.

A notice is information, a banner is a choice, and a policy is the place the information remains when the bar has been closed, but these three words collapse in everyday English into one “cookie notice”, which is why searches put “cookie notice” and “cookie banner” next to each other as if they were one duty. They are not, because you can inform in a policy, without a bar, if an exception covers everything the site does, but a choice can be obtained only with an interface that also allows refusal, and that interface is the banner. Mixing them up means either asking for a signature where only text is needed, or imagining that text on its own authorises a measurement.

The cheapest way to see the difference is a site that uses only strictly necessary cookies but shows an “I agree” button, because it asks for what is not needed and teaches that consent is the only button that closes anything. Good practice in the same place is an informative text, a link to the policy and “I understand”, which admits nothing and only removes the bar, and if you rename that “I understand” as consent you have returned to the poor example, only with a politer word. We do not retell this example in order to laugh at plugins; we retell it because it is the cheapest way to see that an object on the screen is not yet a duty.

Where consent is needed, the ICO wants it collected with a cookie banner, and refusal must be as easy as consent — on the first screen, not in a third menu — and that belongs to the case in which consent is needed, not the case in which it is not. A cookie wall — a wall that will not let the reader see the content until they have agreed — is, in the ICO’s words, a “take it or leave it” approach that in most cases is not freely given consent. A genuine free choice is required; “consent or pay” is a separate model with its own ICO guidance, not a get-out this article will bless in one clause, and the duty to inform remains even then. We are not importing a German page as the reader’s law; Article 5(3) and the GDPR already draw this line clearly enough that a notice and a choice should not be confused.

This difference is also why we no longer write a second technical document under another title, because the ICO talks about a cookie policy, and in the same document there is a place for the purpose, the recipient and the retention period. A second file with a different heading does not create a second compliance; it only gives a second place where the inventory can fall behind, and we have seen that often enough that we no longer promise a second file as a gift. If you have a policy in which those rows stand, you have a notice; if you have only a bar without those rows, you have decoration, and an audit does not treat decoration as evidence.

If consent is needed, the information has to be such that a person understands what they are agreeing to before they agree, and the Court in Planet49 said that clear and comprehensive information includes the duration of the cookies and whether third parties access them. The ICO divides the same thing into categories, purposes and recipients, and says that this information must stand in the banner far enough for the choice to be informed, and in the policy, where it can be told more fully. A general text with quotations from the statute is not information, it is a cover, and a cover remains a cover even when it has been translated into twelve languages.

On the first screen, consent and refusal must be equally visible, because the same three kinds of deception still fail the test: “I agree” is coloured, refusal hides behind “more options”, or the only buttons are “I agree”, “close”, “I understand” and “continue”. Continuing to browse the site, and closing the banner, are not in themselves valid consent, and Planet49 adds that a pre-ticked box is not consent either, because consent requires an active act, not a silence in which you hoped the person would not notice the tick. These lines belong to this article because they are the form of the duty, not the DevTools steps we have left to the other text.

Withdrawal of consent must be as easy as giving it, because Article 7(3) of the GDPR says so directly, and the ICO translates that into a link that remains when the bar has gone, usually in the footer, from every page. A button that saves the new choice but does not tell the tags already loaded is the same fault we have written about in the technical audit, only from the other side: here it is the form of the duty, there the absence of proof. We do not end this article with the steps of the Network log, because those belong to the other text; here it is enough to say that a withdrawal that cannot be found is not a withdrawal, even if the policy has promised it.

The text we write for clients comes from the inventory, not from a template, because the ICO requires the technologies, the purposes, any third parties who store or access the information, and the duration, and that is what we also demand of ourselves: each row has to be one that can be checked against what happens on the site. A template left over from the previous project is worse than a blank page, because it names cookies that are no longer there and stays silent about those that are, and this is also the moment at which we stop writing a legal essay. The work from here is a check, not another signature under a text that nobody has compared with what happens in the first second.

What a banner the site does not need actually costs

A surplus banner is not caution. It steals the first screen, teaches the visitor to click without reading, and teaches you that compliance is a plugin’s default rather than a match between the inventory and what happens on the site. The poor-practice example of “I agree” on a technical site is exactly this bill: you have put a choice where there is none, and now you have to maintain a choice that changes nothing, because under it there is nothing to switch off.

That is a worse state than silence. An object on the screen creates an impression of order, and it is precisely this “order” that is why we treat a surplus bar as a fault.

We do not sell a consent management platform to a site that can make do with a policy, and that sounds like a lost deal, and it is. We would rather lose the work in which Cookiebot, OneTrust or a custom banner would have to be installed where the inventory is only a session and a security token, than gain a client who after six months asks why they are paying for a bar that manages nothing. This is the sentence a sales deck usually skips, and that is why we write it here. An article that always ends with “buy our audit” is not an answer to the question of whether a notice is mandatory at all.

The other price is legal, not only aesthetic, because a bar that asks for consent to what does not need it, or that hides refusal, is the same deception the ICO acts against where consent is needed as well. You cannot defend “but we have a banner” if the banner was built for the wrong inventory, because compliance is not the presence of an object on the screen, but a match between what the site does and what you have said about it. A surplus object damages that match no less than a missing one, and that is also why we sometimes recommend taking a bar down, not putting one up, even though that sounds like the opposite of what an agency is expected to do.

If a banner is needed, the next question is not how it looks

If the inventory shows advertising, a cross-site tool, or analytics that is not strictly necessary, then yes, you need a choice before the first write, and then the scope of this article ends, because the next question is whether the bar that is now needed actually stops what it promises to stop. We have answered that in the article on whether Reject actually stops the tags: “Reject” that closes the frame but does not switch the tag off is not a refusal, and this text does not rewrite that, because it is already written. Repeating seven faults here would mean stealing the other article’s question, and we do not do that even if an internal link in this place looks like a sale.

Our audit of cookies and tracking starts at €800 and usually takes 1–4 weeks, depending on the templates, the languages, the CMP and the tag container, and this “starts at” is a published minimum, not an invoice. It belongs to the inventory, the configuration and the check, not to a promise that all of the organisation’s data protection will be put in order with one bar, and we choose basic or advanced consent mode after your legal assessment and your analytics needs. We do not promise modelled data where the Google property does not meet Google’s conditions, because these lines are the same ones that stand on the service page, and this article does not raise them or lower them.

Before you write to us, do the same check with which this text began: a clean profile, the first second, a list of what was written, and one line for each “why”, because that list is cheaper than any proposal. If the list is empty or contains only strictly necessary cookies, you need a policy, and we will say so, even if that means an audit is not this week’s deal. If the list has a row for which consent was needed yesterday, then a bar that looks polite today is not yet an answer, and then it is worth reading the other article, not this one again.

If you want us to read that list with you and say which side is yours, write to us, because sometimes the more honest answer is that a policy is enough and that the money is worth saving for the content, not the bar, and sometimes the answer is that consent is needed and that it is now time to check whether it works. Both are valid, and only one of them is fair on each site, and we would rather lose an audit in which a banner would have to be installed on an empty inventory than gain a project in which that banner becomes a reproach after launch.

FAQ

Frequently asked questions.

Does every website need a cookie notice?

No, not every site. If the site uses only cookies that are strictly necessary for the service the user asked for, the information can live in the privacy policy, and a pop-up with a choice is not mandatory. The notice in that case is the policy, not a banner. As soon as the site shows advertising, follows a person across sites, or measures visitors, consent is needed before the first write under Article 5(3) as each market transposes it, and then the choice interface is no longer decoration.

Is a privacy policy enough if I only use a session cookie?

Yes, if that cookie is genuinely needed for the requested service and is not used for another purpose. A policy which is reachable on the site is then enough, and a choice window does not have to be put up. If you still show a bar, it may be informative with “I understand”, not “I agree”. Article 13 of the GDPR still requires information about personal data, even without a banner.

May I launch Google Analytics 4 before consent?

No. Advertising, cross-site identifiers and a usual Google Analytics 4 configuration still need consent before the first write, and that is the first second in a clean profile, not the moment the bar finally appears. The United Kingdom’s PECR statistical-purposes exception is not that test. Advanced consent mode, in which tags may load with storage denied, is not an automatic permission and is not this article’s subject; the mode is determined by a legal assessment and then checked in an audit.

Does an embedded YouTube video or a map automatically require a banner?

No, not automatically — and yes, if the embed already writes or reads information in terminal equipment before the user clicks. YouTube cookies in an embed are third-party cookies and YouTube is their controller, but the test remains storage, not the presence of a player. If the video loads only on request, there may be nothing to ask in the first second; if an identifier leaves as the page opens, a lawful route was needed earlier.

What should I do if a banner is already there but I am not sure it works?

First ask whether this banner needed to be there at all. If the inventory is only strictly necessary storage, the bar may be surplus and “I agree” on it is poor practice. If the inventory includes advertising or analytics that still need consent, the next job is to check whether “Reject” actually stops the tags, and we have described that in the article on the banner itself. A technical audit with us starts at €800 and usually takes 1–4 weeks.

RELATED SERVICE
Cookie audit

A cookie audit that gets you to GDPR and ePrivacy compliance — a full analysis of your cookie configuration, a CMP banner, Consent Mode v2.

Learn more →