Cookie consent under GDPR is one of the most misunderstood parts of privacy law. Regulators across the EU have issued billions in fines. Not because companies ignored cookies, but because their consent flows had small flaws that added up.
What the law actually requires
GDPR is clear on four points. Consent must be freely given, specific, informed, and unambiguous. In plain terms, that means two things. Users must be able to say no as easily as they say yes. And tracking cookies cannot fire until they do.
The three most common mistakes
Pre-ticked boxes. A checkbox that defaults to "yes" for analytics or advertising is not valid consent. The user has to take a clear, active step to agree.
A hidden reject option. If your banner has a bold "Accept All" button but hides "Reject" behind a "Manage Preferences" link, regulators treat that choice as unfair. Reject should be as easy to find as accept.
Cookies that fire before consent. This is the most common technical failure. Analytics tags load the moment the page renders, before the user has answered the banner at all.
What a compliant flow looks like
A compliant setup does three things. It shows a clear choice up front. It fires no non-essential cookies until the user makes that choice. And it stores a record of what they chose. If a user rejects, the next page load should respect that decision. No trackers, no exceptions.
Running a free CookieGap scan shows you exactly which of these your site passes or fails, with a compliance score and specific fixes.
See where your site stands
Run a free CookieGap scan and get a compliance report in under a minute.
Scan your site free