ISMS Copilot
Free tool

GDPR cookie consent checker

Answer six questions to see whether your website or app needs prior consent before it sets cookies or trackers, whether you fall under the strictly-necessary exemption, and whether your consent banner meets the standard. The cookie rule is Article 5(3) of the ePrivacy Directive; the standard of consent is the GDPR standard. A structured assessment, not legal advice.

Based on Article 5(3) of the ePrivacy Directive 2002/58/EC and the GDPR consent standard (Articles 4(11) and 7), read with EDPB Guidelines 05/2020 on consent.

What valid cookie consent requires

Where you set or read non-essential cookies or trackers, consent must meet these conditions to be valid under Article 5(3) of the ePrivacy Directive and the GDPR consent standard. The checker above walks those conditions to indicate whether valid consent is required and where a typical banner falls short.

  • Give clear and comprehensive information before consent: what you store or read, why, how long cookies last, and who the third parties are, in plain language and before any non-essential cookie is set (Article 5(3); GDPR Articles 4(11) and 13).
  • Hold non-essential cookies and trackers until the user has actively agreed; let only strictly necessary items load beforehand (Article 5(3)).
  • Collect consent by a clear affirmative action: no pre-ticked boxes, no accept-only banners, and no consent inferred from silence, inactivity, or scrolling (Article 4(11); CJEU Planet49, Case C-673/17).
  • Make refusing as easy as accepting, with a reject option as prominent and easy as accept (Article 7, as read by the EDPB Cookie Banner Taskforce), and avoid conditioning access to the service on consent where that would make it not freely given (check national guidance on cookie walls).
  • Keep consent specific and granular, so users can agree to some purposes (for example analytics) and not others (for example advertising), rather than a single all-or-nothing choice (Article 4(11)).
  • Let users withdraw consent at any time, as easily as they gave it, for example through a persistent link that reopens the cookie settings (Article 7(3)).
  • Record consent so you can demonstrate it: who consented, when, to what information, and to which purposes (Article 7(1)).
  • Do not treat consent as permanent: refresh it when purposes or third parties change, and re-ask within a sensible period rather than relying on a years-old choice.

Frequently asked questions

Does this tool produce a binding determination?
No. It applies Article 5(3) of the ePrivacy Directive and the GDPR consent standard (Articles 4(11) and 7), read with the EDPB Guidelines 05/2020 on consent, to your answers and returns a structured assessment. Whether a specific cookie or tracker is strictly necessary is a fact-based judgement for your organisation, and Article 5(3) applies through national law, so the guidance of the competent authority in your country governs the detail. When the position is unclear, document your reasoning and take advice.
Do I always need a cookie consent banner?
Not always. You need prior consent (commonly collected through a banner) whenever you set or read non-essential cookies or trackers, such as analytics or advertising. If you use only strictly necessary cookies, you do not need consent for them, though you still tell users what you use and why. The trigger is non-essential storage or access, not the banner itself.
Which cookies count as strictly necessary?
Only those essential to deliver a service the user explicitly requested, or solely needed to carry out a transmission. Common examples are session and authentication cookies, security and load-balancing cookies, a shopping-cart cookie, and the cookie that stores the user's own consent choice. The test is judged against the requested service and is narrow: analytics, advertising, and most third-party trackers generally do not qualify.
Do analytics cookies need consent?
Generally yes. Analytics and measurement are not strictly necessary to deliver the service the user asked for, so they generally need prior consent under Article 5(3). A few national authorities allow a narrow exemption for certain privacy-preserving, first-party audience-measurement analytics under strict conditions, so check your national authority's guidance before relying on one rather than assuming it applies.
Are pre-ticked boxes or "by continuing you accept" valid consent?
No. GDPR consent must be unambiguous and given by a clear affirmative action (Article 4(11)). The CJEU held in Planet49 (Case C-673/17, judgment of 1 October 2019) that a pre-ticked checkbox the user must deselect is not valid consent for cookies. Accept-only banners, consent inferred from scrolling or continued browsing, and silence are not valid consent either.
Are cookie walls allowed?
It depends and is contested. The EDPB position is that conditioning access to a service on consent to non-necessary cookies generally makes consent not freely given, so a strict cookie wall usually undermines valid consent. Some national authorities permit limited "consent or pay" or equivalent models under specific conditions, so this is one of the areas where you should check your own competent authority's current guidance.
How is this different from a privacy policy or a DPIA?
This checks one specific question: whether you need prior consent before setting cookies or trackers, and whether your consent mechanism meets the standard. A privacy policy is your broader transparency notice under Articles 13 and 14, and a DPIA assesses high-risk processing under Article 35. They are related but distinct: our DPIA necessity checker and the other GDPR tools cover those.
Is there a written guide to this test?
Yes. The long-form companion guide 'Do I need cookie consent?' at /learn/do-i-need-cookie-consent walks the same screen in prose: whether Article 5(3) engages, the strictly-necessary classification, prior consent for non-essential items, the GDPR consent standard, the banner mechanism, and the national overlay (analytics exemptions and cookie walls). Use the guide to understand the test, and this checker to run it against your setup.

By ISMS Copilot. Based on Article 5(3) of the ePrivacy Directive 2002/58/EC and the GDPR consent standard (Articles 4(11) and 7), read with EDPB Guidelines 05/2020 on consent.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.