Consent & Cookies

What is Cookie Banner?

A cookie banner is the notice displayed when a visitor first arrives on a website that explains its use of cookies and trackers and collects the visitor's consent or opt-out choice before non-essential tracking begins.

The banner is the visible tip of a consent system. Behind it sit a consent management platform that stores choices, script-blocking logic that enforces them, and a record store that proves them. A banner that exists only as UI — displaying while every tracker fires underneath — fails at the one job that matters.

What a compliant banner looks like depends on jurisdiction. For EU/UK visitors it must offer a genuine first-layer choice: accept and reject with equal prominence (several EU regulators have fined sites where rejecting took more clicks than accepting), purpose-level granularity at most one layer deep, no pre-ticked boxes, and no tracking until a choice is made. For California visitors the banner is less about opt-in and more about disclosure plus a working 'Do Not Sell or Share My Personal Information' pathway and honoring GPC signals automatically.

Design choices carry legal weight. Making 'Accept' a bright button and 'Reject' grey text, hiding refusal behind 'Settings,' or nagging repeatedly after refusal are dark patterns — and consent obtained through dark patterns is invalid by definition under the CPRA and by regulatory guidance in the EU. The banner must also link to the cookie policy and name purposes accurately, which requires knowing what the site actually sets.

Operationally, banners need maintenance: purposes and vendor lists drift out of date as tags change, translations must match the visitor's language, and the banner version shown must be recorded with each consent so you can later prove what the visitor agreed to.

Why it matters for eCommerce

A banner sits on every landing page of your funnel, so eCommerce teams tune it for conversion — which is exactly where dark-pattern risk creeps in. An equal-prominence accept/reject design, geo-targeted so EU shoppers get opt-in and US shoppers get opt-out mechanics, protects both conversion and defensibility. Test it like a feature: what fires when the shopper rejects everything?

Frequently asked questions

Does a cookie banner need a reject button?
For EU/UK visitors, regulators including France's CNIL have required that refusing consent be as easy as giving it — in practice, a first-layer reject option with prominence equal to accept. Burying rejection in a settings layer has drawn fines.
Can the banner just say 'by using this site you accept cookies'?
No. Continued browsing is not valid consent under GDPR — consent requires a clear affirmative action. Notice-only banners survive only where no consent is required at all, such as sites using strictly necessary cookies only.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Generate a free compliant cookie banner

← Back to all glossary terms