Introduction
*Updated for 2026 compliance practices.*
Understanding whether websites should block all cookies until consent is a critical compliance topic for website owners validating consent, tags, and disclosures. Under the GDPR and ePrivacy Directive, the default position is that non-essential cookies and trackers must not be set or accessed before the user has given unambiguous consent. This guide provides technical implementation guidance—not legal advice—to help you configure your site correctly, avoid common pitfalls, and verify your setup with scanning tools like GDPRChecker.
Legal Requirements and Compliance Expectations
While the GDPR does not explicitly say "block all cookies until consent," the EDPB guidelines make it clear that pre-ticked boxes, implied consent, or continued browsing do not constitute valid consent. The ePrivacy Directive (the "cookie law") requires prior consent for storing or accessing information on a user's device, with a narrow exception for strictly necessary cookies.
Key compliance expectations include: - **Prior blocking**: Non-essential cookies must be blocked by default. This requires technical measures, not just a banner. - **Granular consent**: Users must be able to choose which categories of cookies they accept. - **Easy withdrawal**: Withdrawing consent must be as easy as giving it. - **Documentation**: You must keep records of consent, including what the user was told and when they consented.
For Google Analytics users, the situation is nuanced. With Google Consent Mode v2, you can deploy Google tags in a way that they respect consent signals without setting cookies until consent is granted. Our Google Analytics GDPR compliance guide explains how to configure this correctly.
Common Mistakes and How to Avoid Them
Many websites fail to achieve proper prior blocking due to these common mistakes:
- **Firing tags before consent**: Even if a banner is displayed, tags may still fire on page load. This often happens when Google Consent Mode default commands are not set correctly or when tags are not configured to wait for consent.
- **Assuming a CMP handles everything**: Not all CMPs automatically block tags. Some only record consent but rely on the tag manager to enforce it. Verify your CMP's capabilities.
- **Ignoring "Reject All" functionality**: A banner that only offers "Accept" or "Customize" without an easy "Reject All" option is non-compliant. Users must be able to refuse all non-essential cookies with one click.
- **Not blocking third-party scripts**: Embedded content like YouTube videos, social media widgets, or advertising pixels often set cookies. These must be blocked until consent is obtained.
- **Forgetting about cookie updates**: If you add new tags or change your site, you must re-audit and ensure blocking remains effective. Regular scans with GDPRChecker can catch these gaps.
How to Validate with GDPRChecker
GDPRChecker's scanning tools help you verify that your prior blocking implementation is working correctly. Here's how to use it:
- **Run a pre-consent scan**: GDPRChecker will simulate a first visit to your site and check for any network requests that set cookies before consent. It identifies trackers, cookies, and consent banner behavior.
- **Check banner disclosures**: The scanner verifies that your consent banner is present, that it provides the required information, and that the "Reject" option is functional.
- **Monitor ongoing compliance**: On paid plans, GDPRChecker can continuously monitor your site for new trackers or consent gaps, providing alerts when something changes.
- **Validate Google Consent Mode v2**: If you use Google Consent Mode, GDPRChecker can diagnose whether default consent states are correctly set and whether tags are respecting consent signals. See our [Google Consent Mode v2 checker guide](/guides/google-consent-mode-v2-checker) for details.
After making changes, always re-scan to confirm that no non-essential cookies slip through. This evidence can also serve as part of your compliance documentation.
Real-World Examples
**Example 1: E-commerce site with Google Analytics and Facebook Pixel** An online store uses Google Analytics 4 and Facebook Pixel for conversion tracking. Before implementing prior blocking, both tags fired on page load, setting cookies immediately. After configuring Google Consent Mode v2 with default "denied" and integrating a CMP that triggers consent updates, the tags only fire when the user clicks "Accept." GDPRChecker's pre-consent scan confirmed zero non-essential cookies before consent.
**Example 2: Content publisher with ad networks** A news website relies on multiple ad networks. They implemented a CMP that blocks all ad scripts by default. However, they forgot to block a social media share widget that set cookies. A GDPRChecker scan flagged the widget, and they added it to the blocking list. They now run weekly scans to catch any new third-party scripts.
**Example 3: SaaS company using Google Tag Manager** A B2B SaaS company uses Google Tag Manager with various marketing tags. They set up consent triggers but mistakenly left one tag firing on "All Pages" without a consent check. After a GDPRChecker scan revealed the issue, they corrected the trigger and now use GDPRChecker's monitoring to prevent future misconfigurations.
Implementation Checklist
Use this checklist to ensure your website correctly blocks cookies until consent:
- Audit all cookies and trackers using a scanner like GDPRChecker.
- Classify each cookie as strictly necessary or non-essential.
- Choose a consent mechanism (CMP, tag manager, or custom).
- Configure default blocking for all non-essential tags.
- If using Google Consent Mode v2, set default consent states to "denied."
- Design a consent banner with "Accept All," "Reject All," and "Customize" options.
- Ensure the "Reject All" button is as prominent as "Accept All."
- Test that no non-essential cookies are set before consent using browser tools and GDPRChecker.
- Verify that third-party embeds (videos, social media) are blocked until consent.
- Document your implementation and keep records of consent.
- Schedule regular scans with GDPRChecker to catch new trackers or configuration drift.
- Update your privacy policy to accurately reflect your cookie practices.
FAQ
What is "should websites block all cookies until consent"? It refers to the GDPR requirement that non-essential cookies and trackers must not be set on a user's device before they have given explicit consent. This means implementing technical measures to block such cookies by default, typically through a consent management platform or tag manager configuration.
Do I need to block all cookies until consent for GDPR? Yes, for non-essential cookies. The GDPR and ePrivacy Directive require prior consent for any cookies that are not strictly necessary for the website's basic functionality. Essential cookies, like those for a shopping cart or login session, can be set without consent.
How do I implement blocking all cookies until consent? Start by auditing your cookies, then configure your consent mechanism to block non-essential tags by default. Use a tag manager with consent triggers or Google Consent Mode v2 with default "denied" states. Test thoroughly with browser tools and GDPRChecker scans.
How can I verify blocking with a scanner? Use GDPRChecker's pre-consent scan to simulate a first visit. It checks for network requests that set cookies before consent and reports any violations. Regular scans help ensure ongoing compliance as your site changes.
What are common mistakes when blocking cookies until consent? Common mistakes include firing tags before consent, not providing a "Reject All" button, forgetting to block third-party scripts, and assuming a CMP automatically blocks all tags. Regular testing and scanning can catch these issues.
Which cookies and trackers should I check for? Check all analytics, advertising, social media, and functional cookies that are not strictly necessary. This includes Google Analytics, Facebook Pixel, LinkedIn Insight Tag, YouTube embeds, and any other third-party services that set cookies.
How often should I review my cookie blocking setup? Review your setup whenever you add new tags, change your site, or update your consent mechanism. Additionally, schedule regular scans—at least monthly—to catch unintended changes. GDPRChecker's monitoring can automate this.
What evidence should I keep for compliance? Keep records of your cookie audit, consent mechanism configuration, and consent logs. GDPRChecker scan reports can serve as evidence that your site blocks cookies correctly before consent. Documentation should be readily available for supervisory authorities.
Next Steps
Ensuring your website blocks all non-essential cookies until consent is not just a legal checkbox—it builds trust with your users and protects your business from enforcement risks. Start by scanning your site with GDPRChecker to identify any pre-consent cookies, then follow the implementation steps in this guide. For deeper dives into related topics, explore our guides on whether you need a CMP if you don't run Google Ads and Google Consent Mode v2 diagnostics.
Ready to verify your compliance? Run a free scan with GDPRChecker now and close any consent gaps before they become a problem.
Next step
Run a GDPRChecker scan to validate consent behavior, trackers, and disclosures after you implement the checklist above.
Practical examples
Example 1: A small ecommerce site
A shop changes its cookie banner wording before a seasonal campaign. The operator records the previous and new banner version, tests Reject all and Accept all, and stores screenshots plus the resulting network checks. That creates a clear before-and-after record without relying on memory.
Example 2: A B2B lead-generation site
A marketing team adds a form analytics tag through its tag manager. Before publishing, it documents the consent category, the tag trigger, the privacy notice update, and a test showing that the request does not fire after a visitor rejects optional cookies.
Example 3: A multi-page content site
An editor notices that a new embedded video adds a third-party request. The team scans the affected pages, compares the result with the last scan, updates the cookie disclosure if necessary, and keeps the scan report with the deployment reference.
Article schema
```json { "@context": "https://schema.org", "@type": "Article", "headline": "Should Websites Block All Cookies Until Consent? A Practical GDPR Guide", "description": "Learn whether websites should block all cookies until consent under GDPR. Step-by-step implementation, common mistakes, and how to verify compliance with GDPRChecker's scanner.", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.gdprchecker.online/guides/should-websites-block-all-cookies-until-consent" }, "publisher": { "@type": "Organization", "name": "GDPRChecker", "url": "https://www.gdprchecker.online" } } ```
Copyright and editorial notice
© GDPRChecker
This original AI-assisted editorial draft was selected, reviewed, and published by GDPRChecker. All rights are reserved where protected by applicable law. Do not reproduce the article without permission.