Web Design Kerry, Cork and all over Ireland.

Cookie consent GDPR: your 2026 compliance guide

Cookie consent under GDPR requires websites to obtain clear, affirmative user consent before placing any non-essential cookies on a visitor’s device. The General Data Protection Regulation sets four criteria that every valid consent must meet: freely given, specific, informed, and unambiguous. The ePrivacy Directive works alongside GDPR to govern cookie use specifically, and the Data Protection Commission in Ireland enforces both. Getting this wrong is not a minor oversight. Fines under GDPR can exceed €20 million for consent record failures alone, making compliance a business priority, not just a legal formality.

Strictly necessary cookies are exempt from consent requirements under GDPR. These are cookies without which the website simply cannot function. Session login cookies, shopping cart cookies, and load-balancing cookies all qualify. The exemption is narrow by design.

Cookies that always require consent include:

  • Analytics cookies such as Google Analytics, which track user behaviour across pages
  • Marketing and advertising cookies including social media pixels from platforms like Meta or LinkedIn
  • Personalisation cookies that remember user preferences beyond the current session
  • Social media embeds that load third-party scripts and set tracking cookies automatically

Misclassifying any of these as “strictly necessary” is one of the most common and costly mistakes Irish website owners make. Google Analytics and social media pixels are not strictly necessary by any regulatory definition, yet they appear on countless sites without proper consent.

A practical audit starts with scanning your site using a tool like a cookie scanner or browser developer tools. List every cookie your site sets, note its purpose and origin, then apply the strictly necessary test honestly. If the site would function without it, it needs consent.

Hands typing on laptop running cookie audit tools

Pro Tip: Run a fresh cookie scan after every plugin update or theme change. New scripts often introduce tracking cookies without any warning.

A GDPR-compliant cookie banner, formally called a consent notice or consent management interface, must meet specific design and content standards. Regulators across Europe have made clear that visual design choices carry legal weight.

The core requirements are:

  • Equal prominence for Accept and Reject buttons on the first layer of the banner
  • No pre-ticked boxes for any non-essential cookie category
  • No implied consent from scrolling, closing the banner, or continuing to browse
  • Granular options allowing users to accept analytics cookies but reject marketing cookies, for example
  • Clear identification of the data controller and the purpose of each cookie category
  • No cookie walls that block access to content unless non-essential cookies are accepted

The equal prominence rule deserves particular attention. French CNIL and Italian Garante enforcement has confirmed that hiding the Reject button behind a secondary menu while placing Accept prominently on the first layer violates GDPR. The user must face a genuinely free choice.

Cookie walls present a separate problem. EDPB Guidelines 05/2020 clarified that blocking content access unless a visitor accepts non-essential cookies renders consent non-freely given and therefore invalid. A paywall with a genuine alternative is a different matter, but a simple “accept cookies or leave” wall is unlawful.

Requirement Compliant approach Non-compliant approach
Accept/Reject buttons Equal size and colour on first layer Reject buried in settings menu
Pre-ticked boxes All boxes unticked by default Analytics pre-selected
Implied consent Explicit click required Scrolling treated as acceptance
Cookie wall None, or genuine paid alternative Content blocked without acceptance
Granular consent Per-category toggles Single accept-all only

Infographic comparing compliant and non-compliant cookie banner features

Pro Tip: Test your banner on a mobile device. Buttons that appear equal on desktop often render differently on smaller screens, which regulators treat as a design dark pattern.

Installing a consent management platform (CMP) is not enough on its own. The CMP must actively block non-essential scripts before the user interacts with the banner. Script deferral and lazy loading are insufficient. The script must not execute at all until consent is granted.

Follow these steps to implement prior blocking correctly:

  1. Audit all third-party scripts currently loading on your site, including tag manager containers, analytics snippets, and social media embeds.
  2. Wrap non-essential scripts in conditional logic that checks for consent before execution. Most CMPs handle this through tag templates or script attribute modifications.
  3. Test in a private browsing window with no existing cookies to confirm no non-essential cookies are set on first load.
  4. Handle single-page applications separately. Route changes in frameworks like React or Vue can trigger script re-execution. CMPs must re-evaluate consent on route changes using History API interception.
  5. Store consent records immediately after a user makes a choice.

Consent records are a legal requirement under GDPR Article 7(1). Each record must be tamper-evident and include the following data points:

Data element Purpose
Timestamp of consent Proves when consent was given
Policy version shown Links consent to specific notice text
Choices made per category Demonstrates granularity of consent
User identifier (anonymised) Ties record to a specific session
Withdrawal timestamp (if applicable) Confirms withdrawal was processed

The European Data Protection Board recommends re-asking for consent every 12 months or whenever your cookie policy changes materially. Consent given two years ago under a different policy version is not valid consent today.

Pro Tip: Keep consent logs for at least three years. Regulators investigating a complaint may request records going back well beyond the standard retention period.

Common pitfalls to avoid and best practices for long-term compliance

The most persistent compliance failures are not technical. They are design choices that nudge users towards acceptance. Regulators in Italy and France have enforced against dark patterns including asymmetric button design, deceptive labelling such as “Accept” versus “Learn more” instead of “Reject,” and coercive language implying harm from declining.

Avoid these specific mistakes:

  • Mislabelling cookies as strictly necessary when they serve analytics or marketing purposes
  • Making withdrawal harder than consent. GDPR Article 7(3) requires withdrawal to be as easy as giving consent. A persistent “Manage Preferences” link satisfies this. Requiring an email request does not.
  • Failing to update the consent notice after adding new plugins, scripts, or third-party integrations
  • Ignoring the simplest compliance path. If your site does not set non-essential cookies, you do not need a consent banner at all. Auditing and removing unnecessary trackers is often more effective than managing complex consent flows.
  • Assuming a CMP alone is sufficient. A CMP that does not block scripts before consent provides no legal protection.

Long-term compliance requires a regular review cycle. Scan your cookies quarterly, review your consent notice text after any policy change, and test the banner’s technical behaviour after every significant site update. Businesses that treat compliance as a one-time task consistently face enforcement risk.

For website owners thinking about digital marketing strategies, reducing your reliance on third-party tracking cookies also improves your marketing resilience as browser restrictions on third-party cookies tighten across Chrome, Safari, and Firefox.

Pro Tip: Appoint one person in your organisation to own cookie compliance. Shared responsibility almost always means no one checks until a problem arises.

Regulatory audits by the Data Protection Commission in Ireland typically focus on three areas: what the banner looks like, whether scripts are blocked before consent, and whether consent records exist. Being prepared means having clear answers to each.

When an audit or complaint arises, gather the following immediately:

  • Screenshots and recordings of your consent banner as it appears to first-time visitors
  • Consent log exports showing timestamps, policy versions, and user choices
  • Technical evidence that non-essential scripts do not fire before consent, such as network request logs from a clean browser session
  • A copy of your current cookie policy and the date it was last updated
  • Records of any consent re-requests triggered by policy changes

Maintaining consent logs for three or more years is the standard recommended by compliance practitioners. The Data Protection Commission can investigate complaints from any point within its statutory timeframe, so older records matter.

Integrating compliance into your ongoing website maintenance schedule is the most practical approach. Treat a cookie audit the same way you treat a security update: scheduled, documented, and never skipped.

Egg Design builds websites with compliance built in

GDPR cookie consent compliance is not a feature you bolt on after launch. It is a structural part of how a website is built, configured, and maintained.

https://eggdesign.ie

Egg Design has over 17 years of experience building bespoke WordPress websites for Irish businesses, including museums, tour operators, and visitor-centric organisations. Every site Egg Design delivers includes cookie consent integration, prior-blocking configuration, and a clear cookies policy aligned with current GDPR requirements. As an approved vendor in Ireland’s Digital That Delivers programme, Egg Design also provides ongoing support to keep compliance current as regulations evolve. If your site needs a compliant foundation, speak to Egg Design’s WordPress development team about building or upgrading your website.

FAQ

Cookie consent under GDPR is the requirement to obtain freely given, specific, informed, and unambiguous agreement from a user before placing any non-essential cookies on their device. The Planet49 ruling confirmed that pre-ticked boxes do not meet this standard.

You need a cookie banner only if your site sets non-essential cookies such as analytics or marketing trackers. Sites that use only strictly necessary cookies are exempt from the consent requirement entirely.

Consent records must be kept long enough to demonstrate compliance if challenged. Compliance practitioners recommend retaining records for at least three years, as regulators can investigate complaints well after the fact.

No. EDPB Guidelines 05/2020 established that blocking content access unless a visitor accepts non-essential cookies makes consent non-freely given and therefore invalid under GDPR.

The European Data Protection Board recommends re-asking for consent every 12 months or whenever your cookie policy changes materially. Consent obtained under an outdated policy version does not remain valid indefinitely.

Are you ready to grow your business online?

Book a free 30-minute consultation to discuss your web design needs, boosting online sales, or getting top-notch support and maintenance.

BOOK A FREE CONSULTATION