Cookie consent banner

Cookie Banner for GDPR and ePrivacy Consent

Deploy a cookie consent banner that records visitor choices, supports granular preferences, and integrates with Google Consent Mode v2. Growth adds dashboard-managed tracker blocking and replay verification.

Technical checks only, not legal advice.

Need a broader website GDPR compliance check? Use the online GDPR validator to review cookie consent, tracker behavior, policy links, and consent evidence in one flow.

A banner wired to your live runtime

Most cookie banners collect a click and leave teams guessing what happened next. GDPRChecker's consent banner is delivered through a site-specific runtime, records category choices, and gives the dashboard heartbeat and UI evidence. Growth adds managed tracker blocking rules for teams that need pre-consent enforcement controlled from the dashboard.

Equal choices by default

Accept all and Reject all appear on the first layer with equal visual weight. Granular category controls are available in a Manage preferences panel. No dark patterns, no confirm-shaming copy, no pre-ticked non-essential categories. The banner is designed to meet the parity expectations published by CNIL, ICO, and the EDPB.

Consent records you can show an auditor

Every consent event is logged with timestamp, category choices, and policy version identifier. Records are immutable and exportable — addressing GDPR Article 7(1) accountability without requiring you to build a consent database.

What the cookie banner includes

  • Accept all and Reject all with equal visual weight on first layer
  • Granular category controls (analytics, marketing, functional)
  • Runtime delivery, consent records, and owner diagnostics
  • Growth tracker blocking tied to consent categories
  • Google Consent Mode v2 integration with correct defaults
  • Consent log with timestamps, choices, and policy version
  • Persistent footer link for consent preference changes
  • Cookie policy and privacy policy links from the banner footer
  • Mobile layout with both buttons visible without scrolling

First-layer design that meets current regulatory expectations

The first-layer banner presents Accept all and Reject all with matching size, font weight, color contrast, and tap target area. A Manage preferences link sits alongside them for users who want granular category control. Install the runtime early in the HTML head so the banner and consent defaults initialize before marketing tags. Growth customers can also configure tracker blocking rules from the dashboard. Mobile layout shows both buttons without scrolling. The footer of every page includes a persistent Privacy settings link so users can change their mind without clearing cookies. This design reflects the coordinated guidance published by European data protection authorities since 2020 — CNIL's formal notices, the EDPB dark patterns guidelines (05/2022), and enforcement decisions from the Spanish AEPD, Belgian APD, and German DSK.

Category configuration that matches your actual tag inventory

Configure categories by purpose: strictly necessary, analytics, marketing, and optional functional. Each category gets a short explanation visible in the preference panel. Toggle defaults for non-essential categories are off — users must actively enable analytics or marketing. You can review and reclassify detected cookies and trackers in the inventory as your stack changes. Categories stay synchronized between the banner, consent log, and cookie declaration; Growth also connects those categories to tracker blocking rules.

Google Consent Mode v2 integration built in

When Google tags are present on your site, the banner updates Consent Mode v2 parameters (analytics_storage, ad_storage, ad_user_data, ad_personalization) based on the user's actual category choices. Denied defaults are set before tags load. When a user grants or denies consent, the consent update call reflects the correct state for each parameter. This integration is built into the platform — you do not need to write or maintain Consent Mode wiring separately.

Cookie declaration and policy synchronization

A banner that looks correct but links to an outdated cookie policy is a common compliance gap. GDPRChecker connects the banner to the cookie inventory and declaration workflow: scan your site to detect cookies and trackers, review and classify each item, and publish a cookie declaration. The banner links to your published policy. Policy consistency checks compare the latest declaration against the latest scan and flag discrepancies. When you add new marketing tools, the inventory catches them and prompts a review.

Verification: prove the banner works, don't just assume

After publishing your banner, run a compliance scan that simulates a first-time EU visitor in a clean browser session. The scanner reports: is the consent UI detected on the page? Do analytics or marketing requests fire before any consent interaction? Are privacy and cookie policy links reachable? On Growth, replay verification can also confirm blocking behavior before and after consent. Use the report to verify that your setup works — not only that the banner renders correctly. Schedule recurring scans with change alerts so you are notified when a new tag or plugin update changes the consent flow.

Notice-only banner vs consent enforcement banner

What to checkNotice-only / basic bannerGDPRChecker consent banner
Pre-consent blockingTags fire unconditionally before any user choiceGrowth can block analytics and marketing scripts until matching consent is stored
Reject all buttonOften hidden in settings panel or absentFirst-layer button with equal visual weight to Accept all
Consent recordsTypically absent — at most a cookie says 'accepted'Logged per event: timestamp, categories, policy version — exportable
Consent Mode v2Not integrated — Google tags use default behaviorBuilt-in: denied defaults before tags load, correct grant/deny updates
Cookie declaration syncPolicy written once, rarely updated to match live tagsInventory review workflow keeps declaration aligned with detected cookies
Ongoing verificationNo post-deploy testing — regressions go unnoticedScheduled scans with change alerts catch new trackers and regressions

Linkable asset

Cookie banner reference page for agencies, guides, and implementation checklists

This page is built to be cited when explaining what a modern GDPR cookie banner should include: first-layer Accept and Reject choices, granular preferences, Consent Mode v2 updates, consent records, and verification after publish.

  • Useful for web agencies writing client implementation guides.
  • Useful for SaaS teams comparing notice-only banners with consent enforcement.
  • Useful for privacy checklists that need a practical banner example plus scanner verification.

Suggested citation anchors

GDPR cookie bannercookie consent bannercookie banner with Consent Mode v2cookie banner verification

Frequently asked questions

Does a cookie banner make my site GDPR compliant?
A properly configured cookie banner is an important part of website compliance, but it is not the whole picture. A banner must collect valid consent, log consent choices for accountability, connect to accurate privacy and cookie policies, and, when your risk model requires it, block non-essential scripts until consent. Growth adds dashboard-managed tracker blocking; Pro covers one protected website with banner publish, runtime monitoring, legal pages, and consent evidence. Full GDPR compliance also requires lawful processing purposes, data processing agreements with vendors, and data subject rights procedures — none of which a banner alone addresses.
Should my cookie banner have a Reject all button?
Yes. European data protection authorities — including CNIL, ICO, AEPD, and the EDPB — now treat a first-layer Reject all button with equal prominence to Accept all as the expected standard. Banners that hide rejection behind a settings panel or style Reject as a low-contrast text link risk findings of invalid consent. GDPRChecker's default banner design includes both buttons with matching visual weight.
Where should the cookie banner script be placed in my HTML?
Place the GDPRChecker runtime script high in the HTML head before Google Tag Manager, analytics scripts, and marketing pixels. This lets the banner and consent defaults initialize early and gives the dashboard accurate heartbeat evidence. If you use Growth tracker blocking, early placement is also required so blocking rules are available before third-party tags run.
Does the cookie banner work with WordPress, Shopify, or Webflow?
Yes. The banner is platform-agnostic — it loads as a JavaScript snippet in your site template and works regardless of the CMS or hosting platform. For WordPress, add the snippet to the theme header or via a code injection plugin. For Shopify, use the theme customizer or checkout settings. For Webflow, add it in the site-wide custom code section. The same scanner verification steps apply regardless of platform.
How do I test that my cookie banner actually blocks trackers?
Open a private browser window with DevTools Network tab open. Navigate to your site and confirm the banner appears, consent choices persist, and consent records are captured. If you use Growth tracker blocking, also check requests to google-analytics.com, googletagmanager.com, connect.facebook.net, and similar domains before and after consent. Finally, run a GDPRChecker compliance scan as an independent second opinion. Repeat this test after every GTM container publish or plugin update.
How often should I update my cookie banner?
Review your banner configuration whenever you add a new marketing tool, change processing purposes, or onboard a new analytics vendor. At minimum, run a compliance scan monthly to confirm the banner is still detected and the cookie declaration still matches detected cookies. If you use Growth tracker blocking, re-run blocking checks after each tag-manager change. For managed sites, automated scheduled scans with change alerts catch regressions between manual reviews.

Related GDPRChecker tools

GDPRChecker provides automated technical checks, templates, and operational guidance. It does not provide legal advice and does not guarantee compliance with GDPR, UK GDPR, ePrivacy, CCPA, PIPEDA, Law 25, or any other law.