GDPRChecker

Home / Knowledge Base / The European Data Protection Board Publishes Examples of Non-Compliant Practices: A Practical Guide for Website Owners

Website Compliance

The European Data Protection Board Publishes Examples of Non-Compliant Practices: A Practical Guide for Website Owners

This guide explains how website owners can interpret and act on the European Data Protection Board's published examples of non-compliant practices. It covers key requirements, a step-by-step implementation plan, common mistakes, and how to validate compliance using GDPRChecker's scanner. The article includes practical advice on cookie banners, consent mode, and regular audits, along with an FAQ and implementation checklist.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

August 2026

Reading time

12 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

*Updated for 2026 compliance practices.*

The European Data Protection Board (EDPB) regularly publishes examples of non-compliant practices to guide organizations in interpreting and applying the GDPR. For website owners, these examples are not just theoretical—they highlight real-world failures in consent management, cookie banners, and data disclosures that can lead to enforcement actions. Understanding these examples is crucial for anyone responsible for a website's compliance posture. This guide translates the EDPB's published examples into actionable steps, helping you identify and fix gaps before they become problems. We'll cover what these examples mean, how to implement compliant practices, common mistakes, and how to validate your setup using GDPRChecker's scanning tools.

What is The European Data Protection Board Publishes Examples of Non-Compliant Practices: A Practical Guide for Website Owners?

The European Data Protection Board Publishes Examples of Non-Compliant Practices: A Practical Guide for Website Owners is the practical process a website owner uses to document, check, and improve the relevant consent or privacy controls. In this guide, it means keeping evidence that can show what visitors were told, which choices they made, and how tracking behavior matched those choices at the time of a review.

What the European Data Protection Board Publishes Examples of Non-Compliant Practices Means for Website Owners

The EDPB's published examples of non-compliant practices serve as a benchmark for supervisory authorities across the EU. When the board highlights a specific practice—such as pre-ticked consent boxes, deceptive cookie banners, or insufficient information in privacy policies—it signals a harmonized interpretation that regulators are likely to enforce. For website owners, this means that ignoring these examples is a significant risk. The examples often focus on areas where technical implementation meets legal requirements: cookie consent mechanisms, transparency in data collection, and the validity of user consent. For instance, the EDPB has consistently emphasized that consent must be freely given, specific, informed, and unambiguous. This directly impacts how you design your cookie banner, configure your consent management platform (CMP), and integrate services like Google Consent Mode. By studying the EDPB's examples, you can proactively align your website with regulatory expectations, reducing the likelihood of complaints or fines. It's not enough to simply have a cookie banner; it must function in a way that respects user choices and provides clear information, as outlined in the board's guidance.

Requirements and Compliance Expectations

The EDPB's examples clarify several key requirements for website compliance. First, consent must be obtained before any non-essential cookies or trackers are set. This means that your website should block all such scripts until the user has made an affirmative choice. Pre-consent network requests—where trackers fire before the user interacts with the banner—are a common non-compliant practice highlighted by the board. Second, cookie banners must offer a genuine choice. This includes a clear "Reject All" option that is as prominent as the "Accept All" button. Designs that nudge users toward acceptance or make rejection difficult are considered non-compliant. Third, the information provided must be comprehensive and easily accessible. Your privacy policy should clearly list all cookies and trackers, their purposes, and the data they collect. The EDPB has also stressed the importance of keeping consent records as evidence of compliance. For website owners, these expectations translate into technical requirements: implementing a robust CMP, configuring tag managers to respect consent signals, and regularly auditing your site for unauthorized data collection. Tools like GDPRChecker can help verify that your implementation meets these standards by scanning for pre-consent requests, banner behavior, and disclosure gaps.

How to Implement Step by Step

Implementing compliant practices based on the EDPB's examples involves a systematic approach. Here's a step-by-step guide:

  1. **Audit Your Current Setup**: Use a scanner like GDPRChecker to identify all cookies, trackers, and network requests on your site. Pay special attention to requests that fire before user consent.
  2. **Choose a Compliant CMP**: Select a consent management platform that supports granular consent, records user choices, and integrates with your tech stack. Ensure it can block scripts prior to consent.
  3. **Configure Your Cookie Banner**: Design a banner that includes clear "Accept All" and "Reject All" buttons of equal prominence. Avoid pre-ticked boxes or implied consent. The banner should not obscure content but must be noticeable.
  4. **Integrate Google Consent Mode**: If you use Google services, implement Google Consent Mode v2 to adjust tag behavior based on consent state. This ensures that even without consent, you can collect anonymized, cookieless data. Refer to our [Google Consent Mode v2 guide](/guides/google-consent-mode-v2-guide) for detailed instructions.
  5. **Update Tag Manager Triggers**: In Google Tag Manager or similar tools, set up triggers that fire only after the appropriate consent is granted. Use consent state variables to control tag firing.
  6. **Revise Your Privacy Policy**: Clearly list all data processing activities, including cookies, trackers, and third-party services. Explain how users can withdraw consent. Link to this policy from your cookie banner.
  7. **Test the Reject Flow**: Verify that when a user clicks "Reject All," all non-essential cookies and trackers are indeed blocked. Use browser developer tools and GDPRChecker's scanner to confirm.
  8. **Record Consent**: Ensure your CMP logs consent choices with timestamps, which can serve as evidence of compliance.
  9. **Regularly Rescan**: After any website changes, run a new scan with GDPRChecker to catch new compliance gaps. Consider scheduling periodic scans as part of your maintenance routine.

Common Mistakes and How to Avoid Them

Many website owners inadvertently replicate the non-compliant practices highlighted by the EDPB. Here are the most frequent mistakes and how to avoid them:

  • **Pre-Consent Data Collection**: One of the most common issues is trackers firing before the user interacts with the cookie banner. This often happens with analytics scripts or marketing pixels. To avoid this, configure your CMP to block all such scripts by default and only unblock them after consent. Use GDPRChecker's pre-consent request check to identify any early firing tags.
  • **Deceptive Banner Design**: Banners that use dark patterns—such as making the "Accept All" button brightly colored and the "Reject All" button a subtle link—are non-compliant. Ensure both options are equally visible and easy to click. The EDPB has specifically called out designs that manipulate user choice.
  • **Insufficient Information**: A cookie banner that only says "We use cookies" without detailing purposes or third-party involvement fails the transparency requirement. Your banner should link to a comprehensive privacy policy and, ideally, provide a summary of cookie categories directly in the banner.
  • **Ignoring the Reject Flow**: Some implementations only test the accept path, leaving the reject path broken. For example, rejecting all cookies might still leave functional cookies active, or the page might reload without applying the user's choice. Always test both flows thoroughly.
  • **Not Updating After Changes**: Adding a new marketing tool or updating a plugin can introduce new trackers that bypass your CMP. Regular scanning with GDPRChecker helps catch these changes before they become compliance issues.
  • **Misunderstanding Consent Mode**: Google Consent Mode v2 requires specific implementation to pass consent signals to Google tags. A common mistake is enabling Consent Mode but not configuring the default consent state correctly, leading to unauthorized data collection. Use our [Google Consent Mode v2 checker](/guides/google-consent-mode-v2-checker) to validate your setup.

How to Validate with GDPRChecker

GDPRChecker provides a practical way to verify that your website aligns with the EDPB's examples of compliant practices. The scanner checks for several key compliance indicators:

  • **Pre-Consent Network Requests**: It identifies any requests made to third-party domains before the user has given consent. This is a direct check against one of the most common non-compliant practices.
  • **Cookie Banner Behavior**: The scanner analyzes whether your banner appears correctly, offers clear choices, and respects user decisions. It can detect if the banner fails to block trackers after rejection.
  • **Disclosure Gaps**: GDPRChecker reviews your privacy policy link and checks for the presence of necessary disclosures, helping you maintain transparency.
  • **Consent Mode Integration**: For sites using Google services, the scanner verifies that consent signals are being sent correctly, ensuring that tags behave appropriately based on consent state.

To use GDPRChecker, simply enter your website URL and run a scan. The results will highlight any issues, allowing you to fix them promptly. For ongoing compliance, consider using GDPRChecker's monitoring features (available on paid plans) to receive alerts when new compliance gaps appear. This proactive approach helps you stay ahead of regulatory expectations and avoid the pitfalls illustrated by the EDPB's examples.

Implementation Checklist

Use this checklist to ensure your website avoids the non-compliant practices published by the EDPB:

  1. Run a GDPRChecker scan to establish a baseline of current compliance issues.
  2. Identify all cookies and trackers on your site and categorize them by purpose.
  3. Implement a CMP that blocks non-essential scripts before consent.
  4. Design a cookie banner with equally prominent "Accept All" and "Reject All" buttons.
  5. Configure Google Consent Mode v2 with correct default consent states.
  6. Update tag manager triggers to fire only after appropriate consent is received.
  7. Revise your privacy policy to include all required disclosures and link it from the banner.
  8. Test the reject flow to ensure all non-essential trackers are blocked upon rejection.
  9. Verify that consent records are being logged with timestamps.
  10. Rescan with GDPRChecker after implementing changes to confirm fixes.
  11. Schedule regular scans (e.g., monthly) to catch new compliance gaps.
  12. Document your compliance measures as evidence for supervisory authorities.

FAQ

What is the European Data Protection Board publishes examples of non-compliant practices? The European Data Protection Board (EDPB) publishes examples of non-compliant practices to clarify how GDPR rules should be applied in real-world scenarios. These examples cover areas like cookie consent, transparency, and data subject rights, helping website owners understand what constitutes a violation and how to avoid common pitfalls.

Do I need the European Data Protection Board publishes examples of non-compliant practices for GDPR? While you don't "need" the examples themselves, you must comply with the GDPR principles they illustrate. The EDPB's examples provide authoritative guidance on what regulators consider non-compliant, so ignoring them increases your risk of enforcement actions. Implementing practices aligned with these examples is essential for compliance.

How do I implement the European Data Protection Board publishes examples of non-compliant practices? Implementation involves auditing your website, configuring a compliant CMP, designing a clear cookie banner, integrating consent signals (e.g., Google Consent Mode), and updating your privacy policy. Regular testing and scanning with tools like GDPRChecker ensure your setup remains compliant over time.

How can I verify the European Data Protection Board publishes examples of non-compliant practices with a scanner? GDPRChecker scans your website for pre-consent network requests, banner behavior, and disclosure gaps—key areas highlighted in EDPB examples. After making changes, rescan to confirm that trackers are blocked before consent and that user choices are respected.

What are common the European Data Protection Board publishes examples of non-compliant practices mistakes? Common mistakes include pre-consent data collection, deceptive banner designs, insufficient information, broken reject flows, and failing to update after site changes. These directly mirror the non-compliant practices the EDPB warns against.

Which cookies and trackers should I check for the European Data Protection Board publishes examples of non-compliant practices? Check all non-essential cookies and trackers, especially those from analytics, advertising, and social media plugins. Focus on any that fire before consent, as these are a primary concern in EDPB examples. GDPRChecker's scan can identify these for you.

How often should I review the European Data Protection Board publishes examples of non-compliant practices? Review your compliance whenever the EDPB publishes new examples or guidance, and at least quarterly. Additionally, rescan your website after any changes to plugins, tags, or third-party services to ensure ongoing compliance.

What evidence should I keep for the European Data Protection Board publishes examples of non-compliant practices? Keep records of consent choices (timestamps and preferences), documentation of your CMP configuration, privacy policy versions, and scan reports from GDPRChecker. This evidence demonstrates your efforts to align with EDPB guidance and can be crucial during an investigation.

Comparison: common implementation approaches

| Approach | Best for | Evidence to retain | Trade-off | | --- | --- | --- | --- | | A shared consent record | Smaller sites with one banner and a limited set of tags | Consent choice, timestamp, policy version, and affected pages | Requires a reliable process when the banner changes | | A tag-manager based record | Teams that control analytics and advertising tags centrally | Consent defaults, trigger conditions, publish history, and test results | Can miss scripts added outside the tag manager | | A CMP or external consent platform export | Sites with multiple domains, vendors, or regional workflows | Vendor configuration, consent events, retention settings, and audit exports | Adds provider configuration and recurring review work |

Choose the approach that matches the site's tracking complexity, then verify that the stored evidence can explain what a visitor saw and what tags were allowed at that time.

Practical examples

Example 1: A small ecommerce site

A shop changes its cookie banner wording before a seasonal campaign. The operator records the previous and new banner version, tests Reject all and Accept all, and stores screenshots plus the resulting network checks. That creates a clear before-and-after record without relying on memory.

Example 2: A B2B lead-generation site

A marketing team adds a form analytics tag through its tag manager. Before publishing, it documents the consent category, the tag trigger, the privacy notice update, and a test showing that the request does not fire after a visitor rejects optional cookies.

Example 3: A multi-page content site

An editor notices that a new embedded video adds a third-party request. The team scans the affected pages, compares the result with the last scan, updates the cookie disclosure if necessary, and keeps the scan report with the deployment reference.

> This guide is technical implementation guidance for website owners. It is not legal advice.

Article schema

```json { "@context": "https://schema.org", "@type": "Article", "headline": "The European Data Protection Board Publishes Examples of Non-Compliant Practices: A Practical Guide for Website Owners", "description": "Learn what the European Data Protection Board's examples of non-compliant practices mean for your website. Step-by-step implementation, common mistakes, and how to verify compliance with GDPRChecker's scanner.", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.gdprchecker.online/guides/the-european-data-protection-board-publishes-examples-of-non-compliant-practices" }, "publisher": { "@type": "Organization", "name": "GDPRChecker", "url": "https://www.gdprchecker.online" } } ```

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification