Skip to content
LET'S TALK
EN
Sales process

Cookie banner and GDPR: what you need

The law requires real consent to process a person's data, not a pretty banner. Check your site against three signs before the panel starts working against you.

By GrandMa Agency
Editorial and Growth
2026-08-20
Updated 2026-08-20
14 min read
EST. READING TIME  14 minutes·LAST UPDATED  August 2026·REVIEWED BY  GrandMa Editorial & Evidence

You open your own website before launching ads. A familiar panel appears at the bottom: “We use cookies.” The box next to “I agree to everything” is already checked. A large button invites you to accept everything, while refusal is hidden somewhere behind a “learn more” link. You see a banner and may think: good, that is already done.

But cookies - small pieces of data a website stores in a visitor’s browser - do not become acceptable just because there is a panel on screen. GDPR, the European rules for protecting personal data, does not prescribe a mandatory banner design. It asks a more important question: did the website have a lawful basis for processing data and, if you rely on consent, did the person actually give it themselves.

These are different things. A banner is a way to ask, not a magic stamp saying “everything is lawful.” If it has already chosen an answer for the visitor, makes refusal inconvenient, or does not explain what the choice concerns, its presence does not fix the situation. It only documents a broken process very diligently. And a broken process especially likes calling itself a “turnkey solution.”

You do not need to become a legal specialist to spot the main problem. Look at the banner as if you had just arrived on someone else’s website and had no reason to trust its owner. Do you understand what is being offered? Can you refuse easily? Has the website made the choice for you? You can answer these three questions directly on the screen.

1. A banner is not a basis by itself

Personal data is information that can identify a person directly or indirectly, while data processing is any action involving it: collection, storage, transfer, or other use. Article 6 of the GDPR lists six lawful bases for such processing. Consent is only one of them; others include, among other things, performing a contract and legitimate interest. For a small business, the point is not to unpack several hundred pages of the GDPR by yourself.

Do not call everything that happens on your website “consent to cookies” just because it is convenient to fit into one button. First find out exactly what the website does after a page opens and why you need it. Only then can you honestly explain to a person what you are asking them about.

A banner shows a choice, it does not replace one

Imagine a small online school. A visitor opens a course page, and the website immediately uses her behaviour for advertising messages. The owner added a banner, but the “Accept” button is large and prominent, while refusal is available only after several steps through settings. The question here is not whether the panel looks modern. The question is whether the visitor had a real choice before the website began relying on her consent.

Consent is a clear confirmation by a person of what they agree to. Article 7 of the GDPR requires it to be freely given, specific, informed, and unambiguous. These words sound like a legal cupboard with a false bottom, but the test behind them is human. A person must understand what they are being asked; see exactly what they can agree to; not feel pressured; and make a clear action themselves.

If the banner says only “for a better experience,” the visitor cannot see what the choice concerns. If it offers “agree to everything” without a clear separation, they cannot knowingly choose individual things. If refusal looks like a punishment and acceptance like the only normal route, the freedom of that choice is also questionable.

A banner is not there so that a visitor disappears from it faster. It is there so that their choice is clear.

2. Can you comfortably say "no"

Freely given consent means that a person gives it without pressure. On a page, you can check this not with theory but with your own finger. Open the website in a private browser window to see it as a new visitor, and find the route to refusal before clicking any button.

Compare the route to refusal with the route to consent. If consent takes one click, while refusal requires finding small text and opening settings, the choice is unequal.

Article 7 of the GDPR also speaks directly about the next point: withdrawing consent must be as easy as giving it. This concerns more than the first appearance of the panel: a person may change their mind later, once the banner is closed. That is why you need a clear route back to the settings - for example, a noticeable link at the bottom of the page or a clear item in the menu. A refusal button may formally exist but be so inconspicuous that a person does not notice it. Formal presence is not the same as an accessible choice.

Refusal should not be a mini quest

Imagine a gift workshop. Its banner lets you “Accept everything” with one click. Refusal is not next to it: you can find it only in the privacy policy text, where the visitor must also guess what to do next. This is not a choice between two actions. It is one action and a route for those ready to complete a mini quest with a poor prize.

The practical edit here does not require new legal language. Put a clear action for refusal next to the action for acceptance. Then close the banner, scroll to the bottom of the page, and find the way to return to your decision yourself. If you cannot see that way without searching, the visitor is not obliged to guess it either.

This is not about pixel-perfect symmetry between buttons. It is about symmetry of options. A person should see: I can agree, I can refuse, and I can come back and change my mind. If one of these options exists only in documentation for developers, it does not really exist on screen.

3. Has the website decided for the person

Article 7 of the GDPR states directly: silence, inactivity, and pre-ticked boxes do not constitute consent. So a checkbox next to “allow everything,” which the visitor must untick themselves, is not a minor inaccuracy in the settings. The website has already supplied the answer instead of the person.

Check this as a new visitor. Open a private window or clear the website data, load the page, and look at every toggle. If you rely on consent for a particular item, it must wait for the person’s clear affirmative action. Not for closing it with a cross. Not for scrolling the page. Not for a phrase that declares any continued browsing automatic agreement.

An important detail: a ready-made plugin or service does not make this decision for you. It may provide buttons, toggles, and space for explanations, but it does not know what exactly is connected to your website or how you decided to configure it. The same tool can be used for an honest choice or for options that are enabled in advance. Look not at the name on the invoice, but at the first screen the visitor sees.

Wording such as “By continuing, you agree” tries to turn an ordinary action into supposed permission. Consent must be expressed through a clear affirmative action.

Do not confuse an empty checkbox with a decision the visitor cannot see. Check every screen: the initial panel, the detailed settings, and the screen after reopening it. Only then will you see whether an earlier choice returns where it should not have been.

4. Is it clear what exactly you are asking consent for

Specific and informed consent means that a person understands what their choice concerns. This does not mean you need to force them to read a long document before every click. But the word “cookies” by itself does not explain what the website does or why you are asking for permission.

Start not by editing the banner text, but with an ordinary list of integrations. Look at the enquiry form, cart, visitor measurement, advertising integrations, embedded videos, and other external elements. Next to each item, write three answers in plain language: what it does, which data it may concern, and why you need it. Do not invent official wording. The note should be something you could explain to a person over the phone.

Read the banner text aloud. A visitor should be able to distinguish a function needed for an action on the website from additional tracking, and understand every toggle.

Proper consent work is not a separate legal mini quest to hide at the end of a launch. It is part of the technical work on the page, form, and cart. When planning a website or online store, add a consent check to the list of things that must be clear before launch. Then it will not get lost between design, payment, and the phrase “there is only one small edit left.”

At the same time, this check is not a complete answer to every legal question. GDPR contains broader requirements, and the specific situation depends on what data your website uses and for what purpose. If you have a complex data setup or do not understand the basis on which a particular integration operates, pass your list to a lawyer. But you can see the three basic signs of a banner yourself before that conversation.

5. What to check on your website now

Do not begin by looking for a new service with GDPR in its name. First look at the current banner as a visitor, because its actual behaviour matters. Open a clean or private window, visit the home page, then a page with a form or cart. Some elements may not appear on the first screen, so do not stop after one click. Do not try to redo everything you do not yet understand in one evening, and do not remove the banner at random: that does not answer what exactly happens to the data.

Make a short check for yourself:

  • Is at least one consent item enabled before the visitor acts?
  • Is refusal next to acceptance, rather than behind several extra steps?
  • Can you find where to change the decision after closing the banner?
  • Does the text explain exactly what you are asking consent for, without general phrases?
  • Do you have a list of integrations on the website and understand the purpose of each one?

Your first step is one thing: open the website in a private window and take a screenshot of the banner’s first screen. Mark where a person agrees, where they refuse, and what was already selected before they acted. This screenshot will usually show clearly whether you are giving the visitor a choice or only the scenery of a choice.

6. FAQ

The GDPR provisions described here do not require a banner of a particular appearance. They require a lawful basis for processing personal data and, when you rely on consent, that it is freely given, specific, informed, and unambiguous. A banner is often a convenient way to show and obtain that choice, but the mere presence of a panel proves nothing. First find out which actions take place on your website, then set up a clear way to ask a person about them.

7. Glossary

cookies
Small pieces of data that a website stores in a visitor's browser to remember certain information or run connected functions.
GDPR
European rules for protecting personal data. They determine when and on what grounds people's data may be processed.
персональних даних
Information by which a person can be identified directly or indirectly; a lawful basis is needed to use it.
Обробка даних
Any action involving a person's data: collecting, storing, transferring, or otherwise using information on a website.
Згода
A person's clear confirmation of their decision about data processing; under GDPR, it must be freely given, specific, informed, and unambiguous.

8. Sources

  1. Regulation (EU) 2016/679 (GDPR) — Article 6, lawfulness of processing
  2. Regulation (EU) 2016/679 (GDPR) — Article 7, conditions for consent

TURN FOLLOW-UPINTO A PROCESS.

We help turn scattered next steps into a clear, measurable workflow.