Free cookie consent checker

Do I need a cookie banner?
An answer per regime.

Four questions about who you serve and what your site loads. You get a verdict for the EU and UK, India's DPDP Act, California and Brazil, the rule behind each, and what to do next. Nothing you answer leaves your browser.

Who you serve

Tick every place you offer goods or services to, or where you track visitors. Where your servers sit does not decide this.

What runs on the page

Cookies, local storage, pixels and SDK identifiers all count. Not sure? Run the free cookie scanner first; it lists what fires before consent.

What else applies

Under 18 in India; under 16 in much of the EU (13 in some member states); under 13 in the US.
Annual revenue above the inflation-adjusted threshold (originally US$25 million), or buying, selling or sharing the personal information of 100,000 or more California consumers or households, or half your revenue from selling or sharing it.
Scan my site first
Worked example: an Indian SaaS site with EU visitors, analytics and ad pixels

Your result

An indication from your answers, not legal advice. What a regulator looks at is what actually fires in the browser, which this form cannot see; scan the site to confirm.
Yes, you need a consent bannerAnalytics and advertising are not strictly necessary, so they need prior opt-in for EU visitors and notice and consent for Indian users.
    02

    What counts as strictly necessary?

    Strictly necessary means the service the user explicitly asked for cannot work without it. A sign-in session, a shopping cart, a load-balancer cookie, fraud and bot protection, and the cookie that remembers a consent choice all qualify. Analytics, advertising, A/B testing and most personalisation do not, however useful they are to the business, because the user did not ask for them.

    The test comes from Article 5(3) of the ePrivacy Directive and is read narrowly by regulators; the ICO guidance gives the same list for the UK. Embedded content is the common trap: a YouTube video or a chat widget is wanted, but the cookies its provider sets for its own analytics or ads are not necessary for it to play.

    05

    Why does California need an opt-out instead?

    The CCPA, as amended by the CPRA, is an opt-out law. If you meet a threshold and your ad pixels pass personal information for cross-context behavioural advertising, that is “sharing”, and you must offer a “Do Not Sell or Share My Personal Information” link. You must also treat a Global Privacy Control signal from the browser as a valid opt-out (CCPA Regulations s.7025). No prior consent banner is required for adults.

    A single banner can serve every regime if it changes behaviour by location: opt-in for EU, UK, Indian and Brazilian visitors (ANPD cookie guidance), and an honoured opt-out for US ones.

    Questions

    The things people ask us

    Do I need a cookie banner if I only use Google Analytics?

    Yes, for visitors in the EU, UK, India or Brazil. Analytics is not strictly necessary, so it needs consent before it loads. The UK is adding narrow exemptions for some first-party analytics; Google Analytics sends data to a third party and is not the case those exemptions are built for.

    Do I need a cookie banner if my site has no cookies?

    Not if nothing non-essential is stored or read on the device. Local storage, pixels and SDK identifiers count the same as cookies, so check with a scan: third-party scripts often set cookies their owners never mention.

    Is a cookie banner required in India?

    The DPDP Act has no cookie-specific rule, but cookies and identifiers linked to a person are personal data. Analytics and advertising need notice and consent under sections 5 and 6, from 13 May 2027. Tracking and targeted advertising directed at children are prohibited outright.

    Is an implied-consent banner enough?

    Not in the EU, UK or India. Continuing to browse, scrolling or a notice that only says cookies are used is not a clear affirmative action. Consent has to be given before the tags fire, by a click on an accept button.

    Does California require a cookie banner?

    No opt-in banner is required for adults. If you meet a CCPA threshold and share data for behavioural advertising, you need a Do Not Sell or Share link and must honour the Global Privacy Control signal.

    Does this tool send my answers anywhere?

    No. It runs in your browser and nothing you tick is sent to TryTrustable.

    Do local storage and pixels need consent too?

    Yes, under the EU and UK rules. Article 5(3) covers any storing of or access to information on a device, whatever the technology. Under DPDP and CCPA the test is whether the data identifies a person.

    Is Google Consent Mode enough on its own?

    No. It passes a consent choice to Google's tags; you still need a banner that collects a valid choice and keeps a record of it.

    Do we need a banner for embedded YouTube videos?

    Usually yes for EU, UK and Indian visitors, because the player sets cookies for the provider's own purposes. Load the embed only after consent, or use the provider's reduced-cookie mode and check what it still sets.

    How often should we re-check what our site loads?

    After every change to tags or third-party scripts, and on a regular schedule, because tag managers add tags without a code change.

    Does a cookie wall that blocks the site until you accept count as consent?

    In the EU, regulators generally treat consent that is a condition of access as not freely given, though positions differ by country. Check current guidance for the markets you serve.

    Book a walkthrough

    A banner is the easy part. Proof is the work.

    The consent platform blocks tags until the visitor chooses, records which notice they saw, and shows a regulator what fired and when. We will set it up on your site on the call.