A cookie banner is where your site collects consent. This post takes each requirement in GrantCookie’s GDPR guide and sets out what it means for the banner your visitors see.
The standard for consent
The GDPR is the EU’s data protection law, and the UK GDPR is the UK’s version. It defines valid consent as freely given, specific, informed and unambiguous. The ePrivacy rules, PECR in the UK, require that consent before a non-essential cookie is set, although since February 2026 the UK exempts some low-risk cookies.
The GDPR reaches beyond Europe. It affects organisations elsewhere that offer goods or services to people in the EU or UK, or monitor their behaviour there, for example with tracking cookies. The GDPR guide lists six requirements, which come down to five jobs for a banner and its consent log.
Ask before setting non-essential cookies
You need opt-in consent, given by a clear affirmative action, before setting non-essential cookies. The guide describes what GrantCookie’s banner does here: it blocks non-essential cookies until the visitor chooses, with no pre-ticked boxes. No optional category is switched on until the visitor turns it on.
Make refusing as easy as accepting
The guide asks you to avoid dark patterns that nudge users towards accepting all cookies. Getting this wrong has been costly: France’s regulator, the CNIL, fined Google €150 million in January 2022 because refusing cookies took more clicks than accepting them. On GrantCookie’s banner, Reject all is one click and the same size as Accept all, and the two sit side by side.
Explain what the cookies do
The guide asks for clear information about what each cookie does and who receives the data. GrantCookie’s banner has a switch for each category: necessary, preferences (functional), analytics and marketing. Each category says in plain words what it is for, and every label can be changed, so the wording can be your own.
Behind the banner, with an account, the scanner crawls your whole site, lists every cookie, tracker and pixel it finds, sorted into categories, and names the third parties that set them. It re-checks on every scheduled scan, so the banner asks about what is really there. Scans run monthly on Free, weekly on Growth and daily on Scale.
A banner collects consent, but you still need a cookie policy that explains what you collect and why. The cookie policy generator turns the scanner’s inventory into draft cookie policy text for you to review and check before you publish it. Check the inventory too: a scan may not find cookies on pages behind a login, cookies set by scripts that load only in certain conditions, or cookies added since the last scan. The generator’s output is not legal advice.
Let visitors change their mind
Withdrawing consent must be as easy as giving it, and users must be able to change their preferences at any time. A re-open control stays on every page, so visitors can go back to withdraw or change their choice.
Keep proof of every choice
You must keep a record of every consent so you can prove it was obtained lawfully. GrantCookie stores each choice with the time in UTC, a consent ID and the categories allowed. The record also keeps the banner version the visitor saw, so it shows the question as well as the answer. Every plan includes the consent log, and Growth and Scale let you export it.
Why it matters
GDPR penalties reach up to €20 million or 4% of worldwide annual turnover, whichever is higher. Under the UK GDPR the cap is £17.5 million or 4%, and since February 2026 it has also applied to UK cookie breaches.
Checking your own banner
Read the full GDPR guide, then compare your banner with the points above. The cookie consent banner page shows how GrantCookie’s banner works, and a free scan checks one public page of your site for the known trackers and third-party services in its HTML and the cookies its server sets. The guide is general guidance, not legal advice, so check your specific obligations with a qualified adviser.

