Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →

What does GDPR require for cookies?

GDPR requires websites to obtain explicit, informed consent from visitors before setting non-essential cookies. Necessary cookies (e.g. session, security) are exempt, but analytics, marketing, and preference cookies require prior opt-in consent.

  • Prior consent required before setting non-essential cookies
  • Granular controls — visitors must be able to accept or reject each category individually
  • Proof of consent must be stored for regulatory audits
  • Visitors must be able to withdraw consent as easily as they gave it

Frequently asked questions about cookies and GDPR

Yes. The ePrivacy Directive (transposed into national law in every member state) together with GDPR requires prior consent for any cookie that is not strictly necessary for the service the user requested. Data protection authorities regularly fine websites that set analytics or marketing cookies before consent.

Only those strictly necessary for the service explicitly requested by the user: login sessions, shopping carts, language preference, security tokens, load balancing. Analytics, personalization and advertising cookies always require consent.

Under GDPR, fines can reach EUR 20 million or 4% of global annual turnover. National ePrivacy laws add their own penalties; in Romania, for example, consent violations carry fines from 5,000 to 100,000 lei or up to 2% of turnover, and the authority issued cookie-related fines in 2026.

No. Consent must be a clear affirmative action, such as clicking "Accept". Scrolling, continued browsing or pre-ticked boxes are not valid, and "Reject" must be as visible and as easy to use as "Accept".

European authorities recommend re-displaying the banner after at most 6–12 months. Withdrawal must be as easy as giving consent: a permanent "Cookie settings" link in the footer or a preferences button available on every page.

The simplest way is an automatic scan. CookieFix crawls your pages with a real browser, lists cookies and localStorage items, classifies them by category and blocks them until consent. The free plan includes one manual scan per month plus automatic monthly rescans.

Make your website GDPR compliant today

Set up CookieFix in 5 minutes and ensure your website meets all GDPR cookie requirements.

Create free account