Many business owners treat a cookie consent banner as a formality — a pop-up visitors click through before getting on with whatever brought them to the site. From a legal standpoint, that framing gets it backwards. The banner is a symptom. The real issue is whether your website is activating non-essential tracking technologies before obtaining legally valid consent from visitors. Get that wrong, and fines are possible — not because the banner is missing, but because data is being collected without the legal basis required to collect it.
What Are Cookies and Why Do They Require Consent?
Cookies are small files placed on a visitor’s device that allow websites to remember preferences, track sessions, measure performance, and deliver targeted advertising. Not all cookies carry the same legal weight. Strictly necessary cookies — those required for the website to function, like session authentication or shopping cart persistence — generally do not require consent under most privacy frameworks.
Non-essential cookies are the ones that create legal obligations. These include analytics cookies (like Google Analytics, which tracks visitor behavior), advertising and retargeting cookies (which follow users across sites to deliver personalized ads), and social media pixels (like the Meta Pixel, which connects your visitors’ behavior to advertising platforms). When these technologies activate before a visitor has agreed to their use, the business may be collecting personal data without a valid legal basis — which is where regulatory exposure begins.
What Does Legally Valid Cookie Consent Look Like?
The European Union’s General Data Protection Regulation (GDPR), specifically Articles 4(11) and 7, sets out the strictest definition of valid consent in wide use today. Under GDPR, consent must be:
- Freely given — visitors must have a genuine choice to accept or decline without being penalized for refusing
- Specific — visitors should be able to consent to some categories of cookies and decline others
- Informed — visitors must understand what is being collected, why, and whether it will be shared with third parties
- Unambiguous — silence, inactivity, and pre-ticked checkboxes do not constitute consent; an affirmative action is required
- Withdrawable — users must be able to withdraw consent as easily as they gave it
- Documented — businesses must be able to demonstrate when and how consent was obtained if a regulator asks
A banner that says only “We use cookies” with a single “Accept” button does not meet GDPR’s standard. There must be a genuine “Reject” or “Decline” option at the same level of prominence, and non-essential cookies must remain inactive until the visitor affirmatively accepts them.
Can Your Business Actually Be Fined?
Yes — and the fines are not hypothetical. European data protection authorities have imposed significant penalties for cookie consent violations. France’s CNIL fined Google €150 million and Facebook €60 million in January 2022 for making it more difficult to reject cookies than to accept them — a violation of the requirement that consent be freely given. The Irish Data Protection Commission and other EU regulators have taken similar enforcement actions against companies whose banners were designed to nudge users toward acceptance rather than offering a genuine choice.
In the United States, the framework is different but not without teeth. California’s Consumer Privacy Act (CCPA), as amended by the CPRA, does not require affirmative consent before placing analytics or advertising cookies. Instead, it requires businesses to give consumers clear notice that their personal information may be shared or sold, and to offer a “Do Not Sell or Share My Personal Information” option. Businesses that fail to provide this notice or honor opt-out requests are subject to enforcement by the California Privacy Protection Agency (CPPA) — which has opened formal enforcement proceedings against companies — and can face civil penalties of $2,500 per violation and $7,500 per intentional violation.
Colorado, Connecticut, and Virginia privacy laws also impose consent requirements for certain uses of personal data, including targeted advertising in some contexts. As more states pass comprehensive privacy legislation, the patchwork of requirements is growing.
If Your Website Serves International Visitors, GDPR May Apply to You
GDPR applies to any organization — regardless of where it is based — that offers goods or services to EU residents or monitors their behavior. If your website is accessible to EU visitors, accepts orders from EU customers, or shows EU visitors geo-targeted content or advertising, you are almost certainly within GDPR’s reach. The regulation does not have a revenue threshold below which small businesses are exempt.
This means a U.S. e-commerce business with a modest EU customer base can face GDPR enforcement for inadequate cookie consent practices. GDPR’s maximum penalties reach €20 million or 4% of global annual revenue, whichever is higher, for serious violations — though regulators typically calibrate penalties to the scale and nature of the business and the violation.
Practical Steps to Reduce Cookie Consent Risk
Use a Consent Management Platform (CMP). Tools like OneTrust, Cookiebot, Usercentrics, or Osano automatically detect cookies on your site, present compliant consent options based on the visitor’s location, and block non-essential trackers from loading until consent is given. A well-configured CMP is the most practical way to meet the technical requirements of GDPR-style consent across different jurisdictions.
Conduct a cookie audit. Many businesses do not know exactly what tracking technologies are active on their site because plugins, analytics integrations, and marketing tools are added incrementally over time. A cookie audit maps every cookie and tracker to its purpose, its data recipient, and the legal basis for its use. This audit should be repeated whenever the site’s technology stack changes significantly.
Review your privacy policy. Your privacy policy must accurately describe the cookies and tracking technologies your site uses, the categories of data collected, how that data is used, with whom it is shared, and how users can exercise their rights. A generic policy that does not reflect your actual practices provides little legal protection and may itself be a compliance violation.
Do not treat “reject” as a second-class option. Regulators across jurisdictions have made clear that consent flows that are designed to discourage rejection — through dark patterns, extra steps, or lower-prominence “decline” buttons — are themselves a violation. The accept and reject options should be equally easy to find and use.
Document everything. Record what consent was obtained, when, from which users, and under what version of your consent notice. If a regulator investigates, the ability to produce consent records is essential. Most CMPs handle this automatically.
Contact the Business and Privacy Attorneys at Revision Legal
If you have questions about cookie consent obligations or data privacy compliance for your business, contact the experienced internet law and privacy attorneys at Revision Legal. We help businesses understand which privacy laws apply to them, review and update their cookie consent practices, and respond to regulatory inquiries. You can reach us through the form on this page or by calling (855) 473-8474.