Cookie Banner
A cookie banner is a notification, typically shown as a pop-up or bar, that appears on a website to inform visitors about its use of cookies and how their data may be collected and used. Depending on the website's design and applicable law, it may let users accept, customize, or reject cookies. It is one of the most common ways websites present cookie-related information and, where required, gather user choices.
A cookie banner is a user-facing interface element displayed on a website to inform visitors about the placing of and access to cookies and similar technologies on their device, and to present controls for accepting, customizing, or rejecting non-exempt categories such as analytics and advertising cookies. In most EU jurisdictions, where a banner is used to obtain consent, that consent must generally be freely given, specific, informed, and unambiguous through a clear affirmative action to satisfy requirements derived from the ePrivacy Directive (as nationally implemented) and the GDPR; the same rules typically extend to non-cookie technologies such as pixels, local storage, SDKs, and fingerprinting. Requirements for banner design and behavior vary by jurisdiction, for example, EU and UK practice generally favors opt-in for non-essential cookies, while several US state frameworks rely more on opt-out mechanisms. A cookie banner is a presentation layer only; it is typically paired with, but distinct from, the underlying consent management platform (CMP) that handles preference storage, enforcement, and consent logging. This definition does not resolve contested questions about specific banner designs (such as button prominence or the use of cookie walls), which depend on facts and evolving guidance from data protection authorities not covered here.
Why it matters
The cookie banner is, for most users, the single most visible point of contact between a website and the privacy frameworks that govern it. In most EU jurisdictions and in the UK, where non-essential cookies such as analytics and advertising cookies generally require prior consent, the banner is typically the mechanism through which a site attempts to obtain that consent before those technologies are placed. Because valid consent under the GDPR must generally be freely given, specific, informed, and unambiguous through a clear affirmative action, the way a banner is worded and structured has direct consequences for whether the consent it collects can be relied upon.
Getting the banner wrong carries practical risk. If a banner sets non-exempt cookies before the user makes a choice, relies on pre-ticked boxes or implied consent, or presents options in a way that discourages rejection, the consent obtained may not meet EU standards, though whether any particular design is compliant depends on facts and on evolving guidance from data protection authorities. Design choices such as the relative prominence of accept and reject buttons, or the use of cookie walls, remain contested and are assessed case by case rather than by a single universal rule.
The banner also matters because it does not stand alone. The same underlying obligations typically extend to non-cookie technologies such as pixels, local storage, SDKs, and fingerprinting, so a banner that addresses only literal cookies may leave gaps. And because requirements differ by jurisdiction, EU and UK practice generally favoring opt-in for non-essential cookies while several US state frameworks rely more on opt-out mechanisms, organizations operating across regions often cannot rely on a single banner behavior everywhere.
Who it's relevant to
Inside Cookie Banner
Common questions
Answers to the questions practitioners most commonly ask about Cookie Banner.

