Do I need a cookie banner?
An answer per regime.
Four questions about who you serve and what your site loads. You get a verdict for the EU and UK, India's DPDP Act, California and Brazil, the rule behind each, and what to do next. Nothing you answer leaves your browser.
Your result
Do I need a cookie banner?
You need a cookie consent banner if your site sets anything that is not strictly necessary (analytics, advertising pixels, session replay or embedded third-party content) and serves people in the EU, the UK, India or Brazil. A site that uses only strictly necessary cookies, such as a sign-in session or a cart, needs no banner, but must still say what it sets in a cookie policy.
The answer differs by regime because the rules differ in kind. The EU and UK ask for prior opt-in for the storage itself. India asks for notice and consent for personal data, and an identifier tied to a person is personal data. California asks for an opt-out of selling and sharing, not an opt-in. The checker above applies each in turn.
What counts as strictly necessary?
Strictly necessary means the service the user explicitly asked for cannot work without it. A sign-in session, a shopping cart, a load-balancer cookie, fraud and bot protection, and the cookie that remembers a consent choice all qualify. Analytics, advertising, A/B testing and most personalisation do not, however useful they are to the business, because the user did not ask for them.
The test comes from Article 5(3) of the ePrivacy Directive and is read narrowly by regulators; the ICO guidance gives the same list for the UK. Embedded content is the common trap: a YouTube video or a chat widget is wanted, but the cookies its provider sets for its own analytics or ads are not necessary for it to play.
What makes a cookie banner valid?
A valid banner blocks non-essential cookies until the visitor agrees, offers a reject option as prominent as accept, lets the visitor choose by category, and keeps a record of each choice. A banner that only informs, or that loads trackers first and asks later, is not consent under the EU, UK or Indian rules.
- No pre-ticked boxes. The CJEU held in Planet49 that a pre-ticked box is not valid consent
- Reject as easy as accept. The EDPB cookie banner taskforce found a missing first-layer reject button to be the most common violation
- Nothing fires before the click. Consent given after a tag has already run cannot cover it (EDPB consent guidelines)
- Withdrawal as easy as giving. A permanent link or icon to reopen the choice; DPDP section 6(4) says the same
- A record. Which notice version the visitor saw, what they chose and when. Without it you cannot prove consent was given
Does India's DPDP Act require a cookie banner?
The DPDP Act does not mention cookies. It applies to digital personal data, and a cookie or device identifier linked to an identifiable person is personal data. Analytics and advertising do not fit the Act's narrow legitimate uses, so in practice they need an itemised notice and consent: a clear affirmative action, specific to the purpose, and as easy to withdraw as to give.
The notice and consent duties in sections 5 and 6 apply from 13 May 2027 under the DPDP Rules. For children the position is stricter: section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children, which consent does not cure. Our guide to DPDP Consent Managers explains how a consent management platform differs from a registered Consent Manager.
Why does California need an opt-out instead?
The CCPA, as amended by the CPRA, is an opt-out law. If you meet a threshold and your ad pixels pass personal information for cross-context behavioural advertising, that is “sharing”, and you must offer a “Do Not Sell or Share My Personal Information” link. You must also treat a Global Privacy Control signal from the browser as a valid opt-out (CCPA Regulations s.7025). No prior consent banner is required for adults.
A single banner can serve every regime if it changes behaviour by location: opt-in for EU, UK, Indian and Brazilian visitors (ANPD cookie guidance), and an honoured opt-out for US ones.
What counts as a cookie under these laws?
Under the EU and UK rules, a cookie is any technology that stores information on a device or reads information from it, not only an HTTP cookie. Local storage, session storage, IndexedDB, tracking pixels, device fingerprinting and identifiers set by mobile SDKs are all covered by Article 5(3) of the ePrivacy Directive and regulation 6 of the UK's PECR. Changing the technology does not avoid the rule.
Under India's DPDP Act the question is different: whether the data is personal data, meaning data about an identifiable individual. An advertising ID, a hashed email sent to an ad platform or an analytics user ID tied to an account all are. California's CCPA treats unique identifiers, cookies and pixels as personal information in the same way.
What does Google Consent Mode v2 do, and what does it not do?
Google Consent Mode v2 passes the visitor's consent choice to Google tags so they adjust their behaviour; it is not itself a consent banner. When consent is denied, Google tags can still send cookieless pings, which Google uses for modelled conversions. Whether those pings are acceptable before consent depends on the regime and the regulator, so check current guidance for the countries you serve.
Since March 2024, Google requires Consent Mode v2 signals for advertisers who use its measurement and ad personalisation features with users in the EEA. You still need a banner that collects a valid choice and records it; Consent Mode only carries that choice to Google's tags. Our consent platform sets the signals to denied by default and updates them when the visitor chooses.
How do you check what fires before consent?
Check what fires before consent by loading the site in a clean browser, making no choice in the banner, and recording every cookie set and every request sent to a third party. Then accept, reload, and compare. Anything non-essential in the first list is a problem under the EU, UK and Indian rules, whatever the banner says.
Do it on more than the home page: landing pages, the checkout and pages with embedded video often load extra tags. Tag managers add tags without code review, so repeat the check after marketing changes. The free cookie scanner runs both passes in a real browser and lists what fired before consent by provider; its results can feed the cookie policy generator.
What should a cookie banner do in each regime?
A single banner can meet every regime if it changes behaviour by the visitor's location. The table below sets out what each regime expects before non-essential tags load and what the banner must offer.
| Regime | Model | Before non-essential tags load | Must offer |
|---|---|---|---|
| EU and EEA | Opt-in | Prior consent by a clear click | Reject as easy as accept, choice by category, withdraw at any time |
| United Kingdom | Opt-in | Prior consent, with narrow exemptions being added | Same as the EU; check the ICO's current guidance on new exemptions |
| India (DPDP) | Notice and consent | Itemised notice and affirmative consent, from 13 May 2027 | Withdrawal as easy as giving; no tracking or targeted ads aimed at children |
| California (CCPA/CPRA) | Opt-out | No prior consent needed for adults | A Do Not Sell or Share link; honour Global Privacy Control |
| Brazil (LGPD) | Consent expected | Consent for most non-essential cookies, per ANPD guidance | A way to refuse and to choose by category |
| US children (COPPA) | Parental consent | Verifiable parental consent for ads or profiling | Internal-operations uses only without consent |
For India, the consent text itself should follow the itemised notice in section 5; the DPDP consent notice template shows the structure. This table is a summary, not legal advice.
What do regulators usually find wrong with cookie banners?
The findings repeat. The EDPB's cookie banner taskforce reported in 2023 that the most common problems were a missing reject button on the first layer, pre-ticked boxes, and designs that made accepting easier than refusing through colour or contrast. The CJEU had already held in Planet49 that a pre-ticked box is not consent.
Two more come up in audits: tags that fire before the visitor chooses, which no banner design can fix, and no record of what the visitor actually agreed to. A record that says which notice version was shown, what was chosen and when is what lets you prove consent when it is challenged.
The things people ask us
Do I need a cookie banner if I only use Google Analytics?
Yes, for visitors in the EU, UK, India or Brazil. Analytics is not strictly necessary, so it needs consent before it loads. The UK is adding narrow exemptions for some first-party analytics; Google Analytics sends data to a third party and is not the case those exemptions are built for.
Do I need a cookie banner if my site has no cookies?
Not if nothing non-essential is stored or read on the device. Local storage, pixels and SDK identifiers count the same as cookies, so check with a scan: third-party scripts often set cookies their owners never mention.
Is a cookie banner required in India?
The DPDP Act has no cookie-specific rule, but cookies and identifiers linked to a person are personal data. Analytics and advertising need notice and consent under sections 5 and 6, from 13 May 2027. Tracking and targeted advertising directed at children are prohibited outright.
Is an implied-consent banner enough?
Not in the EU, UK or India. Continuing to browse, scrolling or a notice that only says cookies are used is not a clear affirmative action. Consent has to be given before the tags fire, by a click on an accept button.
Does California require a cookie banner?
No opt-in banner is required for adults. If you meet a CCPA threshold and share data for behavioural advertising, you need a Do Not Sell or Share link and must honour the Global Privacy Control signal.
Does this tool send my answers anywhere?
No. It runs in your browser and nothing you tick is sent to TryTrustable.
Do local storage and pixels need consent too?
Yes, under the EU and UK rules. Article 5(3) covers any storing of or access to information on a device, whatever the technology. Under DPDP and CCPA the test is whether the data identifies a person.
Is Google Consent Mode enough on its own?
No. It passes a consent choice to Google's tags; you still need a banner that collects a valid choice and keeps a record of it.
Do we need a banner for embedded YouTube videos?
Usually yes for EU, UK and Indian visitors, because the player sets cookies for the provider's own purposes. Load the embed only after consent, or use the provider's reduced-cookie mode and check what it still sets.
How often should we re-check what our site loads?
After every change to tags or third-party scripts, and on a regular schedule, because tag managers add tags without a code change.
Does a cookie wall that blocks the site until you accept count as consent?
In the EU, regulators generally treat consent that is a condition of access as not freely given, though positions differ by country. Check current guidance for the markets you serve.
A banner is the easy part. Proof is the work.
The consent platform blocks tags until the visitor chooses, records which notice they saw, and shows a regulator what fired and when. We will set it up on your site on the call.