Having a cookie banner is not the same as having valid consent. Plenty of sites show a banner and still break the rules, because the banner is designed to push people toward "Accept" or because the trackers load before anyone clicks anything.
This post walks through what valid cookie consent means under GDPR, the seven rules regulators check in practice, and how to test your own banner in five minutes.
What makes cookie consent valid under GDPR?
Valid consent must be freely given, specific, informed and unambiguous. It must also be given before non-essential cookies are set, and it must be as easy to withdraw as it was to give. If any one of those is missing, the consent does not count, and every tracker that relied on it had no legal basis.
Those four words come from the GDPR's definition of consent. Article 7 of the GDPR adds the practical conditions: you must be able to prove consent was given, and withdrawal must be possible at any time. The ePrivacy rules then say this kind of consent is required before you store or read anything on a visitor's device, unless it is strictly necessary.
Put simply: the visitor has to understand what they are agreeing to, have a real choice, and actively say yes. Silence is not a yes.
Rule 1: Does the banner need a reject button?
Yes. A reject option must be on the same layer as the accept button. If "Accept all" is one click and refusing takes three clicks through a settings menu, the choice is not freely given. Regulators treat a missing first-layer reject button as one of the clearest violations.
The EDPB cookie banner taskforce report listed this as the first issue it found across real complaints. National regulators agreed that a banner with only "Accept" and "Settings" on the first layer does not collect valid consent.
The fix is simple. Put "Accept all" and "Reject all" side by side, with the same size and weight. Add "Settings" as a third option if you want to offer category choices.
Rule 2: Are pre-ticked boxes allowed?
No. A box that is already checked when the visitor opens the settings is not consent, because the visitor did nothing to give it. Every non-essential category must start switched off. Only the "necessary" category may be on by default, since it does not need consent in the first place.
Recital 32 of the GDPR is direct about this: silence, pre-ticked boxes or inactivity do not count as consent. The same logic applies to "by continuing to browse you accept cookies" notices. Scrolling is not a choice.
Rule 3: Honest button design
The design must not trick people. A bright green "Accept" next to a grey, low-contrast "Reject" link nudges people in one direction. The EDPB report looked at deceptive colours, contrast and link styling, and concluded that the refusal option must be clearly visible and readable.
There is no rule that both buttons must be identical. But if a reasonable visitor would miss the reject option, or struggle to read it, the banner fails. We covered the design side in more detail in how to make a good cookie banner.
Worth knowing: honest design does not have to kill your numbers. Our post on improving your cookie consent rate shows what moves the accept rate without dark patterns.
Rule 4: Can I use legitimate interest instead of consent?
Not for cookies. You cannot rely on legitimate interest to set or read non-essential cookies. The ePrivacy rules require consent for anything on the device that is not strictly necessary. A banner that switches on "legitimate interest" toggles by default is treated as non-compliant.
Legitimate interest still exists as a GDPR legal basis for other processing. It just does not replace consent for analytics and marketing cookies.
Rule 5: "Necessary" must really mean necessary
A cookie is strictly necessary only if the site cannot deliver the service the visitor asked for without it. Login sessions, shopping carts, security tokens and the cookie that stores the consent choice itself qualify. Analytics, A/B testing and ad pixels do not, however useful they are to you.
The EDPB report is clear that the site owner must be able to justify every cookie listed as essential. Putting GA4 in the "necessary" category to skip the banner is one of the easier things for a regulator to spot. Not sure which is which? Our guide on which cookies require consent sorts the common ones.
Rule 6: Nothing runs before the choice
Consent must come first. If Google Analytics, Meta Pixel or a YouTube embed loads the moment the page opens, the banner is decoration, even if it looks perfect. This is the rule that fails most often in practice, and it is the easiest to test.
It is also the one Norwegian regulators have already enforced. In June 2025, Datatilsynet inspected six websites that shared visitor data with third parties through tracking pixels, and fined one of them 250,000 NOK.
The way Consentify handles this is to not inject trackers at all until consent exists. You give us your GA4 or Meta Pixel ID, remove the tag from your own code, and the bundle only adds it after the visitor accepts that category. On a correct setup the tracker is not in your HTML at all.
Rule 7: How easy must it be to withdraw consent?
As easy as giving it. If accepting took one click in a banner, withdrawing should not require an email to your support team. A link or button in the footer or on the privacy page that reopens the consent settings is the common, accepted solution.
With Consentify you add an element with the ID revoke-consent-btn to your page. Clicking it reopens the consent panel, and changing the choice takes effect straight away.
How long is cookie consent valid?
GDPR does not set a fixed expiry. Most regulators expect you to ask again at a reasonable interval, and 6 to 13 months is the common range. Consentify stores the choice in a first-party cookie that lasts up to one year, and keeps consent records for 13 months.
This is also where the rules may change. The EU's Digital Omnibus proposal would require sites to respect a refusal for at least six months before asking again. We covered the current state of that in our Digital Omnibus explainer.
Do I need to prove that consent was given?
Yes. Article 7 puts the burden of proof on you. If a regulator asks, you need to show that a visitor consented, when, and to which categories. A banner that only stores the choice in the browser gives you nothing to show.
Consentify logs each decision with a hashed IP, the categories chosen and a timestamp, so you have a record without storing the raw IP address. Acceptance stats per domain show up in your dashboard.
How to test your own cookie banner in five minutes
- Open your site in a private window. Do not click anything.
- Is there a reject button on the first layer, as visible as accept?
- Open settings. Are all non-essential categories switched off?
- Before clicking, check what has loaded. No analytics or marketing requests should appear.
- Click reject. Browse two pages. Still no trackers?
- Find the link to change your choice. Can a normal visitor find it?
For the "what has loaded" step, a free GDPR scan is faster than digging through dev tools. It shows which trackers and cookies appear before consent. If you want the regulation background in one place, see our GDPR compliance overview.
Want a cookie banner that follows all seven rules out of the box? Start with Consentify for free. Reject button, unticked categories, consent records and revoke support are included on every plan.