[ GDPR ]
GDPR cookie consent: what the law requires and how to set it up
Short answer: under the GDPR, consent only counts if it is freely given, specific, informed and unambiguous, shown by a statement or a clear affirmative action. You must be able to prove that consent was given, tell people they can withdraw it, and make withdrawing as easy as giving it. A cookie banner that blocks non-essential scripts until the visitor chooses, offers separate choices per category, and records each decision with a timestamp is built to support those requirements.
- Regulation (EU) 2016/679
- GDPR Art. 4(11)
- GDPR Art. 7
What the GDPR requires
The points below summarise the consent rules in the General Data Protection Regulation. Links go to gdpr-info.eu, a third-party reference copy that is easy to read article by article. The official text of the Regulation is published on EUR-Lex.
- Consent must be freely given, specific, informed and unambiguous. It is shown either by a statement or by a clear affirmative action. Article 4(11)
- The controller (the business running the website) must be able to demonstrate that the person consented. Article 7(1)
- When consent is requested inside a wider document, the request must be clearly distinguishable from the other matters and written in plain language. Article 7(2)
- People can withdraw consent at any time, they must be told so before they give consent, and withdrawing must be as easy as giving consent. Article 7(3)
- When judging whether consent was freely given, account is taken of whether a service is made conditional on consent to processing that is not necessary for that service. Article 7(4)
- The European Data Protection Board adopted Guidelines 05/2020 on consent on 4 May 2020. Read the guidelines directly for the regulator's interpretation.
How CookieJar handles it
CookieJar is a consent banner and record-keeping tool. It gives you controls that map onto the requirements above; how you configure and word your banner is still your decision. CookieJar is software, not legal advice.
- Blocks non-essential scripts until the visitor consents. Known trackers found by your site scan are held back and only run after the visitor allows their category. This supports the idea that consent comes from a clear affirmative action (Article 4(11)).
- Granular per-category choices. Visitors can allow or refuse preferences, analytics and marketing separately, which supports consent being specific (Article 4(11)).
- Consent receipts with a timestamp. Each choice — accept all, reject all, or saved preferences — is recorded with the categories chosen and the time, so you have a record to help demonstrate consent (Article 7(1)).
Step-by-step setup
These steps take you from sign-up to a live banner with consent records.
- Create a CookieJar account and add your website's domain.
- Run a scan so CookieJar can find the cookies and third-party scripts your site loads and sort them into categories.
- Review the categories. Keep only genuinely necessary items in the necessary category; everything else should wait for consent.
- Write your banner text in plain language and keep it separate from your terms and privacy policy, as Article 7(2) requires.
- Tell visitors in the banner that they can withdraw consent at any time, and give them a way to do it on your site that is as easy as accepting (Article 7(3)).
- Paste the CookieJar script tag into your site's <head> and publish.
- Visit your site in a private window, refuse all non-essential categories, and confirm that analytics and marketing scripts do not load.
- Check your consent records in the dashboard to confirm that each choice was logged with a timestamp.
Common mistakes
Each of these follows directly from the requirements above.
- Treating silence or inactivity as consent. Article 4(11) requires a statement or a clear affirmative action.
- Bundling every purpose into one "accept" choice. Consent must be specific, so offer separate choices per category.
- Keeping no record of who consented and when. Article 7(1) requires you to be able to demonstrate consent.
- Burying the consent request inside terms of service or a privacy policy. Article 7(2) requires the request to be clearly distinguishable and in plain language.
- Making it easy to accept but hard to change your mind. Article 7(3) requires withdrawal to be as easy as giving consent, and people must be told about it beforehand.
- Blocking access to the site unless visitors accept tracking that is not needed for the service. Article 7(4) treats this as a factor against consent being freely given.
- Relying only on a summary like this one. Read the official text on EUR-Lex and the EDPB guidelines for your own situation.
[ FAQ ]
Common questions
Last reviewed: 3 October 2026 by CookieJar team.
Need our DPA or security details?
One email and you'll have everything your security and legal teams need.