Guide

GDPR Cookie Consent: Everything You Need to Know

Cookies are the most visible touchpoint between your website and data protection law. This guide explains which cookies require consent under GDPR, what makes that consent legally valid, how to categorize cookies correctly, and how to implement a banner that keeps you compliant without driving visitors away.

The legal framework

Which Cookies Need Consent?

The requirement to obtain consent for cookies does not come from the GDPR alone. It originates in the ePrivacy Directive (Directive 2002/58/EC, as amended by Directive 2009/136/EC), commonly known as the "Cookie Law." The ePrivacy Directive specifically addresses the storage of information on, and access to information from, a user's terminal equipment — which includes cookies, local storage, device fingerprinting, and similar tracking technologies. The GDPR then sets the standard for what valid consent looks like.

Under Article 5(3) of the ePrivacy Directive, storing or accessing information on a user's device requires the user's prior consent, except when the storage is strictly necessary for providing a service explicitly requested by the user. This means every cookie that is not strictly necessary for the website to function as the visitor expects requires informed, freely given consent before it can be set. Not after. Not during. Before.

This is a critical distinction that many websites get wrong. The default state of a new visitor's browser must be free from non-essential cookies until that visitor has made an affirmative choice to accept them. Loading Google Analytics on page load and then showing a consent banner is a violation. The analytics script — and the cookies it sets — must wait until the visitor has actively consented to the analytics category.

In practice, cookies fall into four categories, each with different consent requirements. Understanding these categories is the foundation of any compliant cookie implementation.

Strictly Necessary

Cookies essential for the basic functioning of the website. These enable core features that the visitor has explicitly requested, such as logging in, maintaining a shopping cart, or processing a payment. Examples include session cookies that keep a user logged in, CSRF tokens that protect form submissions, load balancer cookies that route traffic to the correct server, and shopping cart cookies that remember items between pages. These cookies do not require consent because without them the service the visitor requested would not work. However, you must still disclose their existence in your cookie policy.

No consent needed

Analytics & Performance

Cookies used to collect information about how visitors use your website. This category includes tools like Google Analytics, Adobe Analytics, Hotjar, Matomo, Mixpanel, Heap, and similar services that measure page views, session duration, bounce rates, scroll depth, click patterns, and conversion funnels. Even though these cookies may seem harmless from the website owner's perspective, they collect personal data — including IP addresses, device identifiers, and behavioral profiles — and therefore require explicit consent before being set.

Consent required

Functional & Preferences

Cookies that remember choices the visitor has made to enhance their experience beyond basic functionality. Examples include remembering a visitor's language preference, storing their preferred font size or display theme, remembering a username for faster login (without actually authenticating), or saving regional settings like currency or time zone. While these cookies improve user experience, they are not strictly necessary for the website to function. The visitor can use the site without them, even if the experience is less convenient. Therefore, consent is required before setting them.

Consent required

Marketing & Advertising

Cookies used to track visitors across websites, build advertising profiles, and serve targeted advertisements. This category includes Google Ads remarketing cookies, the Meta (Facebook) Pixel, LinkedIn Insight Tag, TikTok Pixel, Twitter conversion tracking, programmatic advertising cookies from demand-side platforms, and retargeting cookies from networks like Criteo and AdRoll. These cookies are the most privacy-invasive category and are subject to the strictest scrutiny from data protection authorities. Consent is absolutely mandatory, and many enforcement actions have specifically targeted the unauthorized use of marketing cookies.

Consent required

An important nuance: the "strictly necessary" exemption is narrow and must be interpreted restrictively. A cookie is only exempt if it is genuinely essential for a service the user has actively requested. A website owner cannot simply relabel analytics or marketing cookies as "strictly necessary" to avoid the consent requirement. Data protection authorities, particularly the French CNIL and the Austrian DSB, have issued guidance making clear that analytics cookies — even first-party analytics — are not strictly necessary and do require consent, unless configured in a way that is both anonymous and purely statistical with no cross-site tracking capability.

Article 7 & EDPB guidelines

What Makes Consent Valid Under GDPR?

The GDPR defines consent in Article 4(11) as "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." Article 7 then sets out the conditions that must be met for consent to be valid. The European Data Protection Board (EDPB) has further clarified these requirements in its Guidelines 05/2020 on consent under Regulation 2016/679, which provide detailed practical guidance on each element.

For cookie consent to hold up under GDPR scrutiny, it must satisfy all four of the following requirements simultaneously. If any one of these conditions is not met, the consent is invalid, and any data processing that relies on it is unlawful.

1

Freely Given

Consent must represent a genuine, free choice. The visitor must be able to refuse consent without suffering any detriment. This means you cannot use "cookie walls" that block access to website content until the visitor accepts all cookies. It means the option to reject cookies must be presented as prominently and as easily accessible as the option to accept them. If accepting cookies requires one click but rejecting them requires navigating through multiple layers of settings, the consent is not freely given. The EDPB has explicitly stated that there must be no negative consequences for visitors who do not consent. They should still be able to access the same content and services. Additionally, consent cannot be bundled as a non-negotiable part of terms of service. It must be sought separately, with its own distinct mechanism, so the visitor can consent to cookies independently of agreeing to your general terms.

2

Specific

Consent must be granular, not monolithic. A single "I agree to all cookies" button does not satisfy the specificity requirement. Visitors must be able to consent to different purposes or categories of cookies independently. At minimum, your consent mechanism should allow visitors to accept or reject analytics cookies separately from marketing cookies, and both separately from functional cookies. The EDPB guidelines make clear that consent must be given for each distinct purpose. If you use cookies for analytics and for advertising, those are two different purposes, and the visitor must be able to say yes to one and no to the other. A consent banner that only offers "Accept All" and "Reject All" without the ability to make granular choices per category does not meet the specificity requirement, although offering these as shortcut options alongside a "Manage Preferences" alternative with per-category toggles is generally considered compliant.

3

Informed

Before making a choice, the visitor must be told clearly and in plain language what they are consenting to. The consent mechanism must communicate at minimum the identity of the data controller (your organization), the specific purposes for which cookies will be used, the categories of cookies that will be set, who will have access to the data collected by those cookies (including any third parties), the duration of the cookies, and how the visitor can withdraw consent later. This information does not need to appear in the first layer of a consent banner — it can be accessible via a "More Information" or "Cookie Policy" link — but it must be available before the visitor makes their choice. Vague descriptions like "we use cookies to improve your experience" do not satisfy the informed consent requirement. Visitors need to know specifically which cookies are set, by which companies, and for what concrete purposes.

4

Unambiguous

Consent must be expressed through a clear affirmative action. The visitor must do something — click a button, toggle a switch, check a box — that unequivocally signals their agreement. This requirement explicitly rules out several common practices. Pre-ticked checkboxes are not valid consent, as confirmed by the Court of Justice of the European Union in the Planet49 case (C-673/17). Scrolling through a webpage is not valid consent. Continuing to browse after seeing a banner is not valid consent. Inactivity or silence does not constitute consent. The visitor's action must be deliberate and must relate specifically to the processing in question. A general "I agree to the terms" checkbox on a registration form is not sufficient consent for cookie processing. The action must be specific to cookies and to the particular categories of cookies being accepted.

Beyond these four requirements, GDPR also mandates that the data controller must be able to demonstrate that consent was obtained. Article 7(1) states: "Where processing is based on consent, the controller shall be able to demonstrate that the data subject consented to the processing of his or her personal data." This means your website must keep records of each visitor's consent choice, including what was consented to, when, and what information was presented to the visitor at the time of consent. If a data protection authority asks you to prove that a specific visitor consented to marketing cookies, you need to be able to produce that evidence.

Finally, Article 7(3) guarantees the right to withdraw consent at any time. Your website must provide a mechanism — equally as easy as the mechanism used to give consent — for visitors to change their cookie preferences. If a visitor accepted all cookies but later wants to revoke consent for marketing cookies, they must be able to do so without disproportionate effort. This is typically implemented via a persistent "Cookie Settings" link in the footer or a floating privacy icon that reopens the consent preferences panel.

Deep dive

Cookie Categories Explained

Understanding the four cookie categories in detail is essential for proper classification. Misclassifying a cookie — labeling a marketing cookie as "strictly necessary," for example — is a compliance violation that data protection authorities specifically look for during audits. Below is an expanded look at each category, with concrete examples of the specific cookies you are likely to find on a typical website.

Strictly Necessary Cookies

These cookies are the bare minimum required for your website to deliver the service the visitor is using. Without them, the requested functionality would break. They do not require consent but must still be disclosed in your cookie policy.

  • Session identifiers — Cookies like PHPSESSID, JSESSIONID, or connect.sid that maintain the user's session on the server. Without these, the server cannot associate consecutive requests with the same visitor, and features like login, multi-step forms, and shopping carts would not function.
  • Authentication tokens — Cookies that store encrypted authentication state, such as JWT tokens or session cookies set after login. These allow the website to know the visitor is authenticated without requiring them to re-enter credentials on every page.
  • CSRF protection tokens — Cookies like _csrf or XSRF-TOKEN that protect against cross-site request forgery attacks. These are a security mechanism essential for safe form submissions.
  • Load balancer cookies — Cookies set by infrastructure components like AWSALB (AWS Application Load Balancer) or __cfduid (legacy Cloudflare) that route the visitor to the correct server instance. These are technical necessities invisible to the user.
  • Cookie consent preferences — The cookie that stores the visitor's own consent choice (e.g., cookieconsent_status) is itself strictly necessary, because without it the website cannot remember whether the visitor has already made a decision and would have to show the banner on every page load.
  • Shopping cart cookies — On e-commerce sites, cookies that maintain the contents of the visitor's cart between pages and during the checkout flow are strictly necessary for the purchasing service the visitor has requested.

Analytics and Performance Cookies

These cookies gather data about how visitors interact with your website. The information is typically aggregated and used to understand traffic patterns, identify usability issues, and measure the effectiveness of content. Despite their analytical nature, they involve the collection of personal data and require consent.

  • Google Analytics — Sets cookies like _ga (expires after 2 years), _ga_<container-id> (expires after 2 years), and _gid (expires after 24 hours). These track unique visitors, sessions, and pageviews. Google Analytics collects IP addresses, browser information, referring URLs, and detailed behavioral data across your site.
  • Hotjar — Sets cookies like _hjSessionUser and _hjSession to record heatmaps, session recordings, scroll depth, and click patterns. Hotjar captures detailed behavioral data that can be linked to individual visitors.
  • Matomo (Piwik) — Sets cookies like _pk_id and _pk_ses. Although Matomo can be configured for cookieless tracking, its default configuration uses cookies that track individual visitors and therefore requires consent.
  • Microsoft Clarity — Sets cookies like _clck and _clsk to power session recordings and heatmaps. Similar to Hotjar in its data collection approach.
  • Mixpanel, Heap, Amplitude — Product analytics tools that set persistent cookies to track user behavior across sessions, including feature usage, conversion funnels, and retention metrics.

Functional and Preferences Cookies

These cookies enhance the user experience by remembering choices the visitor has made, but they are not essential for the website's core functionality. The website would still work without them, even if the experience were less tailored.

  • Language preferences — A cookie that stores the visitor's selected language (e.g., lang=fr) so that subsequent page loads display content in their chosen language without requiring them to select it again. While convenient, the website can default to a standard language without this cookie.
  • Display preferences — Cookies that store visual settings such as dark mode/light mode preference, font size selection, or sidebar collapsed/expanded state. These personalize the interface but are not essential for content delivery.
  • Region and currency — Cookies that remember a visitor's geographic region or preferred currency for pricing display. An e-commerce site can function without these by defaulting to its base currency.
  • Recently viewed items — Cookies that track which products or pages a visitor has recently viewed to display a "recently viewed" section. This is a convenience feature, not a core function.
  • Embedded content preferences — Cookies that remember whether a visitor has opted to load embedded YouTube videos, social media feeds, or other third-party content widgets.

Marketing and Advertising Cookies

These cookies track visitor behavior across websites to build advertising profiles and serve targeted ads. They are the most privacy-invasive category, often involving extensive cross-site tracking by third-party advertising networks. Consent is mandatory, and enforcement scrutiny in this category is the highest.

  • Google Ads / DoubleClick — Cookies like IDE (expires after 13 months), _gcl_au, and conversion tracking cookies that follow visitors across the Google advertising network to measure ad effectiveness and serve retargeted ads.
  • Meta (Facebook) Pixel — The _fbp cookie and associated JavaScript pixel that tracks visitor activity on your website and links it to their Facebook profile for ad targeting and conversion measurement. This is one of the most commonly flagged cookies in GDPR enforcement actions.
  • LinkedIn Insight Tag — Sets cookies like li_sugr, bcookie, and lidc to track professional profile data and enable LinkedIn ad retargeting.
  • TikTok Pixel — The _ttp cookie and JavaScript tracker that measures TikTok ad conversions and enables retargeting based on website behavior.
  • Retargeting networks — Cookies from platforms like Criteo (cto_bundle), AdRoll (__adroll), and other demand-side platforms that build cross-site visitor profiles for programmatic ad targeting.
  • Affiliate tracking — Cookies set by affiliate networks to attribute conversions to specific partners, often involving cross-site tracking and long expiration periods.

Practical implementation

Implementing a Compliant Cookie Banner

A cookie consent banner is the primary mechanism through which websites collect consent. But simply displaying a banner is not enough. The banner must meet specific behavioral and design requirements to produce legally valid consent. Many websites have banners that look compliant at first glance but fail under closer inspection because of how they handle cookie blocking, button design, or preference management. Here are the concrete requirements your cookie banner must satisfy.

  • Block non-essential cookies before consent. This is the most critical requirement and the one most frequently violated. Your consent banner must appear before any analytics, functional, or marketing cookies are set. Scripts that set these cookies — Google Analytics, Facebook Pixel, Hotjar, advertising tags — must not execute until the visitor has actively consented to the relevant category. This typically requires a consent management platform (CMP) that intercepts and blocks these scripts until consent is recorded, or a tag management system configured to fire tags only after consent signals are received.
  • Show Accept and Reject buttons with equal prominence. Both the "Accept" and "Reject" (or "Decline") buttons must be visually equivalent. They must be the same size, the same color intensity, in the same visual layer, and require the same number of clicks to activate. A design where "Accept All" is a bright, primary-colored button and "Reject" is a small, gray text link below it is a dark pattern that violates the "freely given" requirement. Many enforcement actions, particularly by the French CNIL, have specifically cited asymmetric button design as the basis for finding consent invalid.
  • Allow granular, category-level choices. Beyond simple Accept/Reject, your banner must offer visitors the ability to make choices at the category level. A "Manage Preferences" or "Customize" option should open a panel where visitors can toggle individual cookie categories on or off — for example, accepting analytics cookies but rejecting marketing cookies. Each category should include a clear description of its purpose and examples of the cookies it includes. The strictly necessary category should be shown as always active and not toggleable, to communicate transparency about which cookies are set regardless of choice.
  • Remember the user's choice. Once a visitor makes a consent decision, your website must store that decision (typically in a strictly necessary cookie) and not show the banner again on subsequent visits. If a visitor rejects all cookies, the banner should not reappear every time they load a new page in an attempt to pressure them into accepting. The consent record should persist for a reasonable duration — most implementations use 6 to 12 months — after which the banner can reappear to refresh consent. If you change the cookies on your site or add new categories, you should re-prompt visitors for consent on those new categories.
  • Make it easy to change preferences later. GDPR Article 7(3) requires that withdrawing consent must be as easy as giving it. Your website must provide a persistent, easily accessible mechanism for visitors to reopen the consent preferences panel and change their choices at any time. This is commonly implemented as a "Cookie Settings" link in the website footer, a floating privacy shield icon, or a link in the privacy policy. The mechanism must allow visitors to modify their category-level choices and must take effect immediately — if a visitor revokes consent for marketing cookies, those cookies must be deleted and the associated scripts must stop executing.
  • Avoid dark patterns entirely. Dark patterns are design choices that manipulate visitors into making a particular choice, typically accepting all cookies. In addition to asymmetric button design, dark patterns include: using confusing double negatives in labels ("Don't not track me"), placing the reject option in an unexpected location, using color psychology to make the accept button more inviting, requiring more clicks to reject than to accept, using guilt-tripping language ("Are you sure you don't want the best experience?"), and auto-closing the banner after a timeout and treating the lack of interaction as acceptance. The EDPB and multiple national data protection authorities have published guidance specifically targeting dark patterns in cookie consent interfaces.

A practical note on implementation: the easiest way to meet all of these requirements is to use a consent management platform that handles cookie blocking, consent recording, and preference management automatically. Building a compliant banner from scratch requires not just the visual interface but also the technical infrastructure to intercept scripts, manage consent state, provide an API for tag managers, and maintain an auditable consent log. For most websites, using a dedicated solution is far more reliable than attempting a custom implementation.

What to avoid

Common Cookie Consent Mistakes

Despite years of GDPR enforcement and clear regulatory guidance, most websites still make at least one of the following cookie consent mistakes. Each of these has been the basis for enforcement actions, fines, or formal complaints to data protection authorities. Review this list against your own website to identify issues that need to be fixed.

  1. Pre-ticked checkboxes

    Displaying a consent preferences panel where cookie categories are already checked by default. The Court of Justice of the European Union ruled definitively in the Planet49 case (C-673/17, October 2019) that pre-ticked checkboxes do not constitute valid consent. Consent must result from an active, deliberate choice by the user. All non-essential cookie categories must be off by default, with the visitor explicitly toggling them on to indicate acceptance. This is one of the most clearly settled questions in GDPR cookie law, yet it remains one of the most common violations found on websites across Europe.

  2. No reject button, or a hidden reject option

    Presenting a cookie banner with a prominent "Accept All" button but no equally visible option to reject. Some banners hide the reject option inside a "Manage Preferences" submenu, requiring two or more additional clicks compared to accepting. Others use tiny gray text for "Reject" while displaying a large colored button for "Accept." The CNIL fined Google 150 million euros and Facebook 60 million euros in January 2022 specifically because their cookie banners made it significantly harder to refuse cookies than to accept them. Rejecting must be a single action, presented at the same level and with the same visual weight as accepting.

  3. Cookie walls that block content

    Forcing visitors to accept cookies before they can access any website content. A cookie wall displays a full-screen overlay that prevents the visitor from reading or interacting with the page until they click "Accept." While some jurisdictions have debated whether cookie walls can be permissible in limited circumstances (such as when a genuine, equivalent alternative is offered), the EDPB's position is that cookie walls generally do not result in freely given consent. If the visitor's only realistic options are "accept cookies or leave the website," the consent is not a genuine choice. The vast majority of data protection authorities consider cookie walls non-compliant.

  4. Bundling cookie consent with terms of service

    Combining cookie consent with acceptance of terms of service or a privacy policy in a single action. For example, a registration form with a single checkbox that says "I agree to the Terms of Service and consent to the use of cookies." GDPR Recital 43 and EDPB guidelines are clear: consent for different processing operations must be sought separately. A visitor must be able to agree to terms of service without consenting to marketing cookies, and vice versa. Bundling them into a single action makes the consent non-specific and therefore invalid under GDPR.

  5. Setting cookies before consent is obtained

    Loading tracking scripts and setting non-essential cookies as soon as the page loads, before the visitor has interacted with the consent banner. This is the most technically consequential mistake because it means the damage is done before the visitor even has a chance to refuse. Many websites load Google Analytics, Facebook Pixel, and advertising scripts in the page's HTML or through a tag manager that fires on page load, with the consent banner appearing alongside or after these scripts have already executed. Consent must be obtained before cookies are set. Scripts must be blocked or deferred until consent is recorded. Retroactive consent is not valid consent.

  6. "By continuing to browse, you agree" implied consent

    Displaying a banner that states something like "By continuing to use this website, you consent to our use of cookies" and treating the visitor's continued browsing as consent. The EDPB has explicitly stated that scrolling, swiping, or continuing to browse does not constitute a clear affirmative action and therefore cannot be valid consent. The Planet49 ruling reinforced that consent must be an active, unambiguous declaration of wishes. Merely continuing to use a website does not meet this standard. Despite this being clearly settled law, many websites across Europe still use this approach, and it has been the subject of numerous complaints to data protection authorities.

  7. Asymmetric button design (dark patterns)

    Using visual design to steer visitors toward accepting cookies. Common techniques include making the "Accept All" button a large, brightly colored primary button while making "Reject All" a small, muted text link; placing the accept button in a prominent position and the reject button in an unexpected location; using positive, encouraging language for accept ("Yes, give me the best experience!") and negative, guilt-tripping language for reject ("No, I prefer a degraded experience"); or using color contrast to make the accept button visually dominant. These are dark patterns that undermine the "freely given" requirement. The CNIL, AEPD (Spain), NAIH (Hungary), and several other European authorities have issued specific guidance identifying these design manipulations as non-compliant.

  8. Not allowing users to withdraw consent

    Failing to provide an accessible mechanism for visitors to change their cookie preferences after the initial choice. Under GDPR Article 7(3), withdrawing consent must be as easy as giving it. If your consent banner appears once, records the visitor's choice, and then provides no way to change that choice later, you are violating this requirement. A persistent "Cookie Settings" link or icon must be available on every page, allowing visitors to reopen the consent panel, modify their category selections, and have those changes take effect immediately. Cookies from categories the visitor has revoked must be deleted and the associated scripts must cease executing.

  9. Not listing all cookies in the cookie policy

    Having a cookie policy that lists some cookies but fails to account for all of them, or using vague descriptions that do not identify specific cookies, their providers, purposes, and expiration periods. The "informed" element of consent requires that visitors have access to comprehensive information about every cookie that may be set on their device. This means your cookie policy must be regularly audited and updated whenever new scripts, plugins, or services are added to your website. Many websites install a WordPress plugin or embed a third-party widget without realizing it sets additional cookies that are not disclosed in their cookie policy. Automated cookie scanning tools can help keep your cookie inventory current and your disclosures accurate.

  10. Ignoring consent for third-party embeds

    Embedding third-party content — YouTube videos, Google Maps, social media feeds, chat widgets — that sets cookies without considering these within the consent framework. When a visitor loads a page with an embedded YouTube video, YouTube sets cookies on the visitor's device for tracking purposes, even if the visitor does not play the video. These third-party cookies must be blocked until the visitor has consented to the relevant category. Compliant implementations use placeholder content (such as a static thumbnail with a "Load video" button) until consent is obtained, then replace the placeholder with the actual embed. This applies to all third-party content that sets cookies, not just video players.

The FixGDPR solution

How FixGDPR Automates Cookie Consent Compliance

Implementing fully compliant GDPR cookie consent from scratch is a significant technical and legal undertaking. You need to inventory every cookie on your site, classify each one correctly, build a consent mechanism that blocks scripts before consent and unblocks them after, design an interface that meets the EDPB's requirements for freely given, specific, informed, and unambiguous consent, store consent records for auditing purposes, and keep everything updated as your site evolves. FixGDPR handles all of this automatically.

Automatic cookie scanning

FixGDPR scans your website with a headless browser, detecting every cookie, tracking script, and storage mechanism that your site sets during a first-time visit. The scan identifies first-party and third-party cookies, their expiration periods, and the scripts that set them. You get a complete, accurate cookie inventory without manually inspecting DevTools or reading documentation for every plugin and service on your site.

Intelligent categorization

Each cookie detected by the scanner is automatically classified into the correct category — strictly necessary, analytics, functional, or marketing — using a database of known cookies and AI-powered classification for unknown ones. You can review and override the categorization if needed, but in most cases the automatic classification is accurate and saves hours of manual research.

Script blocking before consent

FixGDPR automatically blocks non-essential cookies and scripts before consent is given. When a visitor first arrives at your site, only strictly necessary cookies are set. Analytics, functional, and marketing scripts are held in a queue and executed only after the visitor has consented to the corresponding category. If a visitor rejects all cookies, no non-essential scripts are ever loaded. This is the most technically challenging part of cookie compliance, and FixGDPR handles it without requiring you to modify your site's code.

Compliant banner with equal buttons

The FixGDPR consent banner is designed from the ground up to meet EDPB requirements. Accept and Reject buttons are displayed with identical size, color weight, and visual prominence. A "Manage Preferences" option opens a category-level panel with clear descriptions and toggles. No dark patterns. No pre-ticked boxes. No hidden reject options. The banner is fully customizable to match your brand while maintaining compliance.

Consent records and audit log

Every consent decision is recorded with a timestamp, the categories consented to, and the version of the cookie policy presented. This audit trail allows you to demonstrate compliance to data protection authorities if requested. Records are stored securely and can be exported for reporting purposes. When your cookie inventory changes, consent versions are automatically incremented so visitors are re-prompted for the new configuration.

Continuous monitoring

Websites change constantly. New plugins are installed, marketing scripts are added, and third-party services update their tracking behavior. FixGDPR runs scheduled re-scans of your website to detect new cookies that have appeared since the last scan. If new cookies are found, you are notified and the cookie inventory is updated. This ensures your consent mechanism and cookie policy stay accurate over time, even as your site evolves.

Get started

Make your cookie consent compliant today.

Scan your website for free in 30 seconds, then implement a fully compliant consent banner that meets every GDPR requirement — no code changes needed.

Related Resources

Continue learning about cookie compliance.

GDPR Consent Banner Guide

How to build or choose a consent banner that meets GDPR and ePrivacy requirements without frustrating your visitors or harming your conversion rate.

Dark Patterns and GDPR

A detailed examination of design manipulation techniques that violate GDPR, including cookie consent dark patterns, deceptive button design, and regulatory enforcement trends.

Free Cookie Checker

Scan any website to see exactly what cookies it sets, which ones are compliant, and which ones need to be fixed. No account required, results in 30 seconds.

Google Consent Mode Guide

How to implement Google Consent Mode v2 to maintain analytics and advertising functionality while respecting visitor consent choices under GDPR.