Cookie banners explained: do you need one?
Guide

Cookie banners explained: do you need one?

A cookie banner is needed if your website uses non-essential cookies (analytics, ads, embeds) for EU or UK visitors under GDPR and PECR.

A1 Digital A1 Digital · written & reviewed by the team 3 min read Updated 9 July 2026

Quick answer

Cookie banners are consent pop-ups required when a website sets non-essential cookies, such as analytics or advertising trackers, for visitors in the UK or EU. If your site only uses strictly necessary cookies, you don't legally need one.

£17.5m

maximum UK GDPR fine, or 4% of global turnover

Source: ICO, 2024

2 laws

govern cookies in the UK: UK GDPR and PECR

0

banners needed if you only use strictly necessary cookies

Cookie banners feel like pointless friction, a box everyone clicks “accept” on without reading. But they exist for a real reason: UK and EU law says you must ask before you track. The genuinely tricky part isn’t the banner itself, it’s knowing which of your cookies actually need consent, and most owners are surprised to learn that running Google Analytics alone puts them on the hook.

You need a cookie banner if your website sets any non-essential cookies, such as analytics, advertising, or embedded media, for visitors in the UK or EU. If your site only uses strictly necessary cookies, you don’t legally need one.

A cookie banner is the consent notice that asks visitors whether they agree to non-essential cookies before those cookies run. Two UK laws apply:

  • PECR (Privacy and Electronic Communications Regulations), governs cookies and tracking.
  • UK GDPR, governs the personal data those cookies collect.

The EU equivalent is the ePrivacy Directive plus EU GDPR. Same principle: consent first, tracking second.

The core rule

You may set strictly necessary cookies without asking. For everything else, analytics, ads, social embeds, you must get the visitor’s consent BEFORE the cookie loads.

This is where most sites get it wrong. “Strictly necessary” is a narrow category, not a loophole:

Cookie type Example Consent needed?
Strictly necessary Shopping basket, login session, security No
Analytics Google Analytics, Hotjar Yes
Advertising Meta Pixel, Google Ads retargeting Yes
Embedded media YouTube video, social feed Yes
Preferences Saved language or region Often yes

If you run Google Analytics, the Meta Pixel, or embed a YouTube video, you’re using non-essential cookies. That means you need a banner.

When you genuinely don’t need one

You can skip the banner only if every cookie you set is strictly necessary. In practice that means:

  1. A simple brochure site with no analytics, no tracking pixels, and no embedded third-party content.
  2. A site that uses only session cookies for core function, like a login or basket.

The moment you add Analytics to measure visits, which nearly every business wants, you cross the line. See things every website needs for where tracking usually creeps in.

How to do it properly

A compliant banner isn’t just a single “OK” button. The ICO has been clear that Reject must be as easy as Accept:

1

Audit your cookies

List every cookie and script your site sets, including ones added by plugins, fonts, embeds and third-party tools.

2

Classify each one

Sort them into strictly necessary versus analytics, advertising and preferences.

3

Block before consent

Configure non-essential cookies so they don't fire until the visitor agrees. A banner that only hides cookies but still loads them isn't compliant.

4

Offer a real choice

Show Accept and Reject with equal prominence. No pre-ticked boxes. Link to a plain-English cookie policy.

5

Record and honour it

Store the visitor's choice, let them change it later, and make sure rejected cookies actually stay off.

Common mistakes that breach the rules

  • Cookies that load BEFORE the visitor clicks anything.
  • “Accept” far more prominent than “Reject”, or no Reject at all.
  • Pre-ticked consent boxes.
  • A banner with no way to withdraw consent later.

What it costs to get wrong

The headline penalty under UK GDPR is up to £17.5m or 4% of global turnover. The ICO rarely throws that at a small business, it usually warns first. The realistic risks for a small firm:

  • Complaints to the ICO from privacy-aware visitors.
  • Lost trust when people see tracking they didn’t agree to.
  • Trouble if a larger partner or client audits your compliance.

Key takeaway

Most small-business websites need a cookie banner because they run analytics or pixels. If you only use strictly necessary cookies, you don’t. Either way, never load non-essential cookies before the visitor says yes.

This sits alongside the wider privacy picture, read what GDPR means for websites for the bigger obligations like privacy policies and data requests.

Cookie consent is fiddly because the cookies hide inside plugins, fonts and embeds you may not even know are running. We audit the full cookie list on the sites we manage, set up a compliant consent banner that blocks tracking until visitors agree, and keep a plain-English cookie policy in place, part of the done-for-you website service so you’re not left guessing.

Start with an honest audit: open your own site, check what loads before you click anything, and if analytics or pixels fire on arrival, your banner needs fixing.

Frequently asked questions

Do I need a banner if I only have Google Analytics?

Yes. Google Analytics sets non-essential analytics cookies, so under UK and EU law you must get consent before it loads. The banner should let visitors accept or reject analytics, and Analytics should only run after they accept.

Are cookie banners legally required in the UK?

Only if your website uses non-essential cookies such as analytics, advertising, or embedded content like YouTube or social feeds. Sites that use strictly necessary cookies only, for example a shopping basket or login, don't need a consent banner. Most business sites do use non-essential cookies, so most need one.

What happens if I don't have one?

If you set non-essential cookies without consent you breach PECR and UK GDPR. The ICO can issue fines up to £17.5m or 4% of global turnover, though it usually warns smaller businesses first. The bigger day-to-day risk is losing visitor trust and exposure to complaints.

Is a pre-ticked Accept box allowed?

No. Consent must be a clear, affirmative action, so pre-ticked boxes and assumed consent aren't valid under GDPR. Reject must be as easy as Accept, and cookies must stay off until the visitor actively agrees.

cookies gdpr privacy compliance websites
Share Link copied
A1 Digital

Written by the A1 Digital team

We handle the entire online presence for small businesses, website, branded email, Google, AI search, content and reviews, for one simple monthly plan. No tech headaches, no lock-in.