Find out exactly what your consent banner needs to include. Answer 3 quick questions about your visitors, cookies, and site type to get jurisdiction-specific requirements.

Do I Need a Cookie Consent Banner?

Whether you need a consent banner depends on two factors: where your visitors are located and what cookies/scripts your site uses. Under GDPR (EU/EEA), any non-essential cookie requires explicit opt-in consent before being set. Under CCPA (California), you need an opt-out mechanism but not prior consent.

Consent Requirements by Region

  • EU/EEA (GDPR) — Opt-in consent required. Must have Reject All button. No pre-checked boxes. Cookie walls banned.
  • UK (UK GDPR) — Same as EU. Enforced by ICO.
  • California (CCPA/CPRA) — Opt-out model. "Do Not Sell/Share" link required. Must honor Global Privacy Control.
  • Brazil (LGPD) — Consent required, similar to GDPR but allows legitimate interest for some cookies.

What Makes a Valid Consent Banner?

  1. No cookies before consent — tracking scripts must not fire until user clicks Accept
  2. Equal Accept/Reject options — Reject must be as easy as Accept (same prominence, no dark patterns)
  3. Granular choices — users must be able to select specific cookie categories
  4. Easy withdrawal — users must be able to change their consent at any time
  5. No pre-checked boxes — all non-essential categories must be unchecked by default
  6. Record keeping — you must be able to prove when and how consent was given