Most cookie banners manage the rare double: they annoy every visitor and fail GDPR. The rules are clearer than the internet pretends — here’s the version that satisfies both regulators and users.
What consent legally means
Freely given, specific, informed, and as easy to refuse as to accept. That single sentence outlaws most banners you see: pre-ticked boxes, “Accept” in bold with refusal hidden in settings, walls that block content until you surrender, and “legitimate interest” toggles for plain marketing cookies.
What must load before consent — nothing tracking
Analytics, ad pixels and marketing tags wait until the visitor agrees. Strictly necessary cookies (cart, login, language) run without consent — that’s the law’s actual carve-out, not a loophole for renaming your tracker “necessary”.
The banner that converts
Two equal buttons, plain words, one sentence: “We use cookies for analytics and marketing — okay?” Accept / Decline, same size, same color weight. Ironically, honest banners get more acceptance: visitors reward not being tricked, and decline-rate data tells you the truth about your audience.
The mistake that invalidates everything
A perfect banner over a site that fires trackers anyway. Consent tools must actually gate the scripts — test with your browser’s network panel, not the vendor’s promise. This is configuration work we include in every site we build; ask us to check yours — the network panel doesn’t lie.
Frequently Asked Questions
Consent that is freely given, specific, informed — and refusing must be as easy as accepting.
No — pre-ticked consent has been explicitly rejected; the visitor must actively choose.
Strictly necessary ones — cart, login, language — but not analytics or marketing renamed as necessary.
Usually the opposite — visitors reward not being tricked, and clear banners often get more genuine acceptance.
Open the browser network panel before consenting — if trackers fire anyway, the banner is decoration, not compliance.
Not in standard configuration in the EU — analytics needs consent unless configured to a genuinely anonymized mode.

