Cookie banners explained: do you need one?
A cookie banner is needed if your website uses non-essential cookies (analytics, ads, embeds) for EU or UK visitors under GDPR and PECR.
Quick answer
Cookie banners are consent pop-ups required when a website sets non-essential cookies, such as analytics or advertising trackers, for visitors in the UK or EU. If your site only uses strictly necessary cookies, you don't legally need one.
£17.5m
maximum UK GDPR fine, or 4% of global turnover
Source: ICO, 2024
2 laws
govern cookies in the UK: UK GDPR and PECR
0
banners needed if you only use strictly necessary cookies
Cookie banners feel like pointless friction, a box everyone clicks “accept” on without reading. But they exist for a real reason: UK and EU law says you must ask before you track. The genuinely tricky part isn’t the banner itself, it’s knowing which of your cookies actually need consent, and most owners are surprised to learn that running Google Analytics alone puts them on the hook.
You need a cookie banner if your website sets any non-essential cookies, such as analytics, advertising, or embedded media, for visitors in the UK or EU. If your site only uses strictly necessary cookies, you don’t legally need one.
What a cookie banner is for
A cookie banner is the consent notice that asks visitors whether they agree to non-essential cookies before those cookies run. Two UK laws apply:
- PECR (Privacy and Electronic Communications Regulations), governs cookies and tracking.
- UK GDPR, governs the personal data those cookies collect.
The EU equivalent is the ePrivacy Directive plus EU GDPR. Same principle: consent first, tracking second.
The core rule
You may set strictly necessary cookies without asking. For everything else, analytics, ads, social embeds, you must get the visitor’s consent BEFORE the cookie loads.
Which cookies actually need consent
This is where most sites get it wrong. “Strictly necessary” is a narrow category, not a loophole:
| Cookie type | Example | Consent needed? |
|---|---|---|
| Strictly necessary | Shopping basket, login session, security | No |
| Analytics | Google Analytics, Hotjar | Yes |
| Advertising | Meta Pixel, Google Ads retargeting | Yes |
| Embedded media | YouTube video, social feed | Yes |
| Preferences | Saved language or region | Often yes |
If you run Google Analytics, the Meta Pixel, or embed a YouTube video, you’re using non-essential cookies. That means you need a banner.
When you genuinely don’t need one
You can skip the banner only if every cookie you set is strictly necessary. In practice that means:
- A simple brochure site with no analytics, no tracking pixels, and no embedded third-party content.
- A site that uses only session cookies for core function, like a login or basket.
The moment you add Analytics to measure visits, which nearly every business wants, you cross the line. See things every website needs for where tracking usually creeps in.
How to do it properly
A compliant banner isn’t just a single “OK” button. The ICO has been clear that Reject must be as easy as Accept:
Audit your cookies
List every cookie and script your site sets, including ones added by plugins, fonts, embeds and third-party tools.
Classify each one
Sort them into strictly necessary versus analytics, advertising and preferences.
Block before consent
Configure non-essential cookies so they don't fire until the visitor agrees. A banner that only hides cookies but still loads them isn't compliant.
Offer a real choice
Show Accept and Reject with equal prominence. No pre-ticked boxes. Link to a plain-English cookie policy.
Record and honour it
Store the visitor's choice, let them change it later, and make sure rejected cookies actually stay off.
Common mistakes that breach the rules
- Cookies that load BEFORE the visitor clicks anything.
- “Accept” far more prominent than “Reject”, or no Reject at all.
- Pre-ticked consent boxes.
- A banner with no way to withdraw consent later.
What it costs to get wrong
The headline penalty under UK GDPR is up to £17.5m or 4% of global turnover. The ICO rarely throws that at a small business, it usually warns first. The realistic risks for a small firm:
- Complaints to the ICO from privacy-aware visitors.
- Lost trust when people see tracking they didn’t agree to.
- Trouble if a larger partner or client audits your compliance.
Key takeaway
Most small-business websites need a cookie banner because they run analytics or pixels. If you only use strictly necessary cookies, you don’t. Either way, never load non-essential cookies before the visitor says yes.
This sits alongside the wider privacy picture, read what GDPR means for websites for the bigger obligations like privacy policies and data requests.
Cookie consent is fiddly because the cookies hide inside plugins, fonts and embeds you may not even know are running. We audit the full cookie list on the sites we manage, set up a compliant consent banner that blocks tracking until visitors agree, and keep a plain-English cookie policy in place, part of the done-for-you website service so you’re not left guessing.
Start with an honest audit: open your own site, check what loads before you click anything, and if analytics or pixels fire on arrival, your banner needs fixing.
Frequently asked questions
Do I need a banner if I only have Google Analytics?
Yes. Google Analytics sets non-essential analytics cookies, so under UK and EU law you must get consent before it loads. The banner should let visitors accept or reject analytics, and Analytics should only run after they accept.
Are cookie banners legally required in the UK?
Only if your website uses non-essential cookies such as analytics, advertising, or embedded content like YouTube or social feeds. Sites that use strictly necessary cookies only, for example a shopping basket or login, don't need a consent banner. Most business sites do use non-essential cookies, so most need one.
What happens if I don't have one?
If you set non-essential cookies without consent you breach PECR and UK GDPR. The ICO can issue fines up to £17.5m or 4% of global turnover, though it usually warns smaller businesses first. The bigger day-to-day risk is losing visitor trust and exposure to complaints.
Is a pre-ticked Accept box allowed?
No. Consent must be a clear, affirmative action, so pre-ticked boxes and assumed consent aren't valid under GDPR. Reject must be as easy as Accept, and cookies must stay off until the visitor actively agrees.
Written by the A1 Digital team
We handle the entire online presence for small businesses, website, branded email, Google, AI search, content and reviews, for one simple monthly plan. No tech headaches, no lock-in.
On this page
Keep reading
What is GDPR and what does it mean for your website?
GDPR is an EU and UK law on handling personal data. It applies to your website whenever you collect visitor info via forms, cookies or analytics.
DefinitionWhat is an SSL certificate and why your site needs one
An SSL certificate encrypts the connection between your website and visitors. It's the padlock and the HTTPS, and your site looks broken without it.
List11 things every small-business website needs
Clear messaging, speed, mobile design, visible contact, one strong CTA, trust signals, SSL, SEO, schema, analytics and ownership. The 11 essentials.