Features Pricing Documentation Blog For agencies Contact
Sign in Try for free

Guide

What a cookie banner that withstands inspection should look like

Twelve rules that decide whether consent is valid. Each comes with a specific provision — a regulation, a directive or a judgment — and an example of how it looks done wrong and done right. No „we recommend“, just what the rules actually require.

Applies to both SK and CZ Updated 24 July 2026 12 rules · 10 myths debunked
01

Rejection is possible right in the first layer

If a visitor only sees „I agree“ and has to look for the rejection a click further into the settings, the consent is not freely given — it is coerced through inconvenience. Rejection must be available on the same screen and just as easily as acceptance.

This is the most common cause of fines in the Czech Republic and, at the same time, the mistake that most default banners of e-shop platforms have.

Wrong

This site uses cookies

We use cookies to improve your experience.

I agree Settings

There is no way to reject — the only visible route is consent. „Settings“ is not a rejection, it is one more click on top.

Correct

This site uses cookies

Necessary cookies are always on. You decide about the rest.

Allow all Deny all Settings

Both acceptance and rejection are in one place, one click each. Detailed settings are a third, supplementary option.

02

Not a single measurement script runs before consent

The law does not speak of a cookie banner — it speaks of storing information on a device and accessing it. Until the visitor clicks, Google Analytics, the Meta pixel, Sklik and the chat widget must not run. A banner that merely appears while the scripts run in the background is decoration with no legal effect.

It is precisely this that drew the highest Czech cookie fines.

Wrong
google-analytics ✓ sentfacebook pixel ✓sklik ✓

Cookie consent

I understandMore

The banner asks, but the trackers sent the data long ago. The consent is moot — the data left before it.

Correct
analytics — blockedmarketing — blocked

This site uses cookies

Allow allDeny all

The scripts are blocked until a decision is made. Exactly the categories the visitor permitted run — and nothing more.

03

No category is pre-ticked

Consent must be an unambiguous indication of wishes — that is, an active action. A toggle that is already on when the settings open is not consent, because the visitor has done nothing. The Court of Justice of the EU ruled on this unambiguously in the Planet49 case.

There is only one exception: technically necessary cookies. They are always on, cannot be turned off, and no consent is required for them.

Wrong

Cookie settings

Necessary
Analytics
Marketing
Save

Everything is switched on in advance. Whoever just clicks „Save“ has consented without deciding.

Correct

Cookie settings

Necessary always active
Analytics
Marketing
Save and close

The optional categories are off. The necessary ones are marked as permanently active and it is explained why.

04

Neither closing with the X nor scrolling is consent

If a visitor closes the banner or merely scrolls the page, they have expressed nothing — and it must not be interpreted as consent. The EDPB states this explicitly: continued browsing or scrolling does not meet the requirement of an unambiguous action.

The correct solution: after closing, the optional cookies remain off and the banner can be reopened at any time.

Wrong

We use cookies

By continuing to browse the site you consent to the use of cookies.

The text claims that browsing alone is consent. It is not — and the close button here works as silent consent.

Correct

This site uses cookies

Closing the window launches nothing beyond the necessary cookies.

Allow allDeny all

The close button is equivalent to rejection and this is stated. The decision can be changed at any time.

05

The buttons look equivalent

It is not enough that a rejection exists — it must not be visually suppressed. A large green „Accept“ next to grey „Reject“ text is deceptive design: the design pushes towards one option, so the resulting consent is not freely given.

A practical criterion: both options have comparable size, contrast and placement. They need not be identical, but they must not be in a different weight class.

The same logic applies to the text on the buttons. The rules do not require identical wording — but if one option names exactly what will happen and the other does not, uncertainty arises precisely on the rejection side.

Wrong

Your privacy

Accept all reject

The rejection is small, grey and without a button. The eye barely registers it — and that is exactly the point.

Correct

Your privacy

Allow all Deny all

The same size, the same shape, readable contrast in both cases. The choice is the visitor's, not the designer's.

Allow all/Reject

An asymmetric pair. The first button says exactly what will happen. The second does not — do I reject everything, or does it save what I have set on the toggles? If there are category toggles above the buttons, that question is entirely justified. The uncertainty arises only on the rejection side.

I agree/Settings

That is not a pair. „Settings“ is not a rejection but a further step — see rule 01.

Accept all/Reject all

Symmetric and unambiguous. Both options name the same scope, so the visitor knows what a click will give them — regardless of what they have set above.

06

Consent can be given separately for each purpose

Consent must be specific. A single „I agree to everything“ button with no option to permit only analytics and reject advertising does not meet the condition — the visitor must be able to distinguish the purposes.

The established categories: necessary, functional, analytics, marketing. Each with its own toggle and an explanation of what it is for.

Wrong

Cookies

Do you agree to the use of all cookies on this site?

Yes, I agreeNo

All or nothing. The visitor cannot permit traffic measurement and reject advertising — the consent is not specific.

Correct

Cookie settings

Necessary always
Functional
Analytics
Marketing
Save and close

Each purpose has its own toggle. Analytics yes, advertising no — and it is one click.

07

The cookie list is complete and specific

Informed consent means the visitor knows exactly what they are permitting: the cookie's name, what it is for, how long it lasts and who has access to it. The line „we use third-party cookies“ does not satisfy the duty to inform.

In practice this is the most common point of discrepancy: an e-shop declares five cookies and actually stores thirty. The list must match reality — and be updated whenever a new tool is added to the site.

Wrong

What cookies we use

On our website we use necessary cookies and third-party cookies for analytics and marketing purposes.

actually stored: 33listed: 1

A generic sentence without a single name. The visitor doesn't know what they are consenting to — and an inspection will find this out within minutes.

Correct

Analytics cookies 4

_ga · Google Analytics13 months
_gid · session differentiation24 hours
_ga_XXXX · session state13 months
hjSession · Hotjar30 minutes

The name, provider, purpose and duration for each cookie. The list is generated from a scan of the website, not from guesswork.

08

Withdrawing consent must be as easy as giving it

This is not an interpretation — GDPR says it literally. If consent can be given with one click on the banner, it must also be possible to withdraw it with one click. Not by email, not by a request, not by deleting cookies in the browser.

A common solution: a permanent „Cookie settings“ link in the footer or a floating icon that reopens the banner.

Wrong

If you wish to withdraw your consent, write to us at [email protected] or delete the cookies in your browser settings.

Consent with one click, withdrawal by email. An obvious imbalance, which the rule expressly prohibits.

Correct

Cookie settings

Change or withdraw your decision at any time.

A permanent link in the footer opens the same banner. Withdrawal is one click, just like consent.

09

The website works for those who reject too

Conditioning access to content on consent to marketing cookies means the consent is not freely given — the visitor has no real choice. The so-called cookie wall is therefore inadmissible.

Equally unacceptable is a banner that covers the whole screen and cannot be bypassed other than by consenting.

Wrong

Accept cookies to continue

The page content is available after consent is given.

Accept and continue

Without consent, the visitor cannot reach the content. That is not a choice, it is a condition.

Correct

This site uses cookies

Allow allDeny all

The content is readable, the banner takes up the bottom strip. Rejection blocks nothing.

10

After a rejection, the banner does not ask again on every visit

Repeatedly popping up the banner after a visitor has rejected is pressure — the aim is to get them to „click it away“ once, just for some peace. This too is about the freedom of consent.

The Czech authority recommends specific figures: a consent validity of around 12 months and not asking again for at least 6 months after a rejection.

Wrong
3rd visit todaybanner shown 3×

We use cookies

I agreeno

The rejection is not saved, the banner keeps asking over and over. Fatigue instead of a free decision.

Correct

🍪 Cookie settings

The decision holds for 12 months. All that remains is a discreet link for anyone who wants to change it themselves.

11

The banner can be operated with a keyboard and read by a screen reader

The European Accessibility Act has applied since 28 June 2025. If a cookie banner cannot be operated with a keyboard, or a screen reader skips over it, some people cannot reach the choice at all — and the e-shop has a problem beyond GDPR.

The minimum: a visible focus, tab-key operation, sufficient contrast of both text and buttons, and closing with the Esc key.

Wrong

Cookies

We use cookies to personalise content and ads.

Accept Reject
no focuscontrast 1.9 : 1

Light-grey text on white, and the tab key skips the banner. Inaccessible to some visitors.

Correct

This site uses cookies

Necessary cookies are always on.

Allow all Deny all
focus visiblecontrast 7.1 : 1

A visible focus, readable contrast, keyboard operation. The same choice for everyone.

12

It is clear who processes the data and where the details are

Consent is informed only when the visitor knows whom they are giving it to. The banner must state the controller (or unambiguously point to them) and a link to the privacy policy.

If the policy is hosted on the banner provider's domain, that is not a problem — but it must be clear from it that the controller is the e-shop in question, not the provider.

Wrong

Cookies

This site uses cookies. By clicking you consent.

OK

Neither the controller's name nor a link to the policy. The visitor has no idea who they are giving consent to.

Correct

Cookies on eshop.sk

Controller: Firma s. r. o., Company ID 12 345 678. Details in the Privacy Policy.

Allow allDeny all

The controller is named and the policy is one click away. The consent is informed.

Watch out for one more thing: the banner can be perfect and the website will still fail to comply if the cookie list drifts apart from reality. All it takes is for a marketer to add a new pixel — the declaration goes stale and rule 7 falls. That is why it makes sense to check the website regularly, not to set up the banner once and forget about it.

What people say after conferences

Ten myths circulating among marketers

Most of them sound logical and spread in good faith. The problem is that none of them holds up under inspection — and some lead precisely to the behaviour that draws fines.

Anyone who doesn't want to be tracked can install an ad blocker. It's up to the visitor.

Myth

The rule does not place the obligation on the visitor, but on whoever stores information on their device. The wording is unambiguous: storing information on, or accessing information in, a terminal device is possible only with the consent of the user. The fact that someone can defend themselves does not remove the obligation to ask for consent in the first place.

An analogy from another field: a seller cannot argue that the customer should have inspected the goods themselves. The obligation lies with the one who acts.

There's no need to deal with withdrawing consent — anyone who wants to can delete the cookies in their browser.

Myth

GDPR says literally that withdrawing consent must be as easy as giving it, and it is the controller's job to ensure this. If consent is given with one click on the banner, withdrawing it must not mean digging around in the browser settings.

On top of that, it doesn't even work technically: deleting cookies does not withdraw consent — it only erases its trace in the browser. The server knows nothing of any change, the consent record remains, and server-side measurement keeps running.

The authority itself said a cookie banner isn't mandatory. So why should we have one?

Half-truth

This was indeed said — and it is the most frequently twisted sentence in the whole topic. In its updated recommendations (March 2023) the Czech authority stated that if a website uses exclusively technical cookies, it need not have a banner. In that case it is enough to satisfy the duty to inform, for example with a document in a visible place.

But the moment Google Analytics, the Meta pixel or Sklik runs on a website, consent is mandatory — and a banner is the only practical way to obtain and prove it. So the line „a banner is not mandatory“ applies to websites that measure nothing. That is not the case for any e-shop.

We don't collect personal data, just anonymous traffic statistics.

Myth

If analytics assigns a visitor a unique identifier in order to recognise them on their next visit, it is not anonymous — it is pseudonymous. GDPR expressly counts online identifiers, including cookies, among personal data.

And above all: the ban on storing data on a device applies regardless of whether personal data is involved. It is the device itself that is protected, not merely what happens to the data afterwards. That is why IP anonymisation in Google Analytics does not help either — it solves a different problem than the one at hand.

For remarketing, legitimate interest is enough for us; no consent is needed.

Myth

Legitimate interest is a valid legal basis under GDPR — but it never gets a say. Before we even reach the question of a legal basis, the special ePrivacy rule applies: non-technical cookies may be stored only with consent. There is no other route.

Legitimate interest can be a legal basis for what you do with the data afterwards — never a substitute for consent to obtaining it from the device.

We turned on Consent Mode v2, so we've got cookies sorted.

Myth

Consent Mode is not consent — it is a way of telling Google about a decision you have already obtained somewhere. By itself it collects nothing and proves nothing.

Without a banner that actually requests and records consent, Consent Mode merely keeps reporting „denied“ indefinitely — and on top of that the e-shop has no proof that it ever obtained consent. During an inspection, proof is the very first thing the authority will ask for.

We have it written in our terms and conditions, which the customer agreed to.

Myth

Consent to processing must be clearly distinguishable from other matters. A provision hidden among delivery times and the complaints procedure does not meet this condition — and moreover it does not apply to visitors who ordered nothing and never saw the terms and conditions.

What is more, the cookies are stored the moment you enter the site, long before anyone reaches the point of accepting the terms at checkout.

We're a small firm with two people. GDPR is surely for big corporations.

Myth

GDPR has no size threshold. The only relief for companies under 250 employees concerns keeping records of processing activities — and even that does not apply when the processing is regular, which running a website with analytics always is.

Practice confirms it: the Czech authority fines ordinary small and medium e-shops, not just large platforms. In 2023 it imposed cookie fines totalling CZK 4.44 million.

The banner is supplied to us by the platform, so the platform is responsible for it.

Myth

The controller of personal data is whoever determines the purposes and means of processing — that is, the website's owner. The platform or banner provider is at most a processor. The authority conducts proceedings against the website's controller.

So the line „it runs on platform X“ cannot be used as a defence. If a platform's default banner has no rejection in the first layer or launches scripts before consent, it is the e-shop's problem, not the platform's.

Until someone reports us, no one takes any interest in us.

Myth

The supervisory authority acts on its own initiative too, not just on a complaint. Moreover, a cookie banner is publicly visible — to assess it, it is enough to open the website and look into the developer tools. It is not something that can be kept hidden.

During the transitional period, the Czech authority sent out more than 120 warning letters to controllers it had selected itself, and then moved on to fines.

What this follows from

The full list of rules, guidelines and decisions the guide refers to.

Regulation
Regulation (EU) 2016/679 — GDPR Definition of consent (Art. 4(11)), conditions for consent and its withdrawal (Art. 7), the duty to inform (Art. 12–13), data protection by design (Art. 25).
Directive
Directive 2002/58/EC — ePrivacy Article 5(3): storing information on, and accessing information in, a user's device is possible only with their consent, except for what is technically necessary.
National law · IE
Regulation 5(3) of the Privacy and Electronic Communications Regulations 2011 (S.I. No. 336 of 2011) The national transposition of the cookie rule. Supervisory authority: Data Protection Commission
Judgment
Court of Justice of the EU, C-673/17 Planet49 A pre-ticked box is not valid consent; consent must be an active action.
Guideline
EDPB — Guidelines 05/2020 on consent Scrolling and continued browsing are not consent; the conditions for cookie walls.
Guideline
EDPB — Guidelines 03/2022 on deceptive design Visually favouring one option over another as a deceptive interface pattern.
Guideline
EDPB — Guidelines 2/2023 on the technical scope of Art. 5(3) The rule also covers techniques other than cookies — for example device fingerprinting or localStorage.
Supervision CZ
Office for Personal Data Protection (CZ) — cookies Rejection in the first layer, a recommended consent validity of 12 months and a gap of 6 months after a rejection.
Supervision SK
Office for Personal Data Protection of the Slovak Republic The supervisory authority for Slovakia; this is where complaints and applications to open proceedings are directed.
Accessibility
Directive (EU) 2019/882 — European Accessibility Act Effective from 28 June 2025; it also applies to e-shop interfaces, including the cookie banner.

Not sure how your website stands?

Cookienovo checks the website, generates a cookie declaration from an actual scan and sets up the banner so that it passes all twelve points.

Try for free

Have you heard that banners will soon disappear anyway? We checked it against EU documents →

This guide summarises the requirements arising from the listed rules, guidelines and decisions as at 24 July 2026. It is not legal advice — a specific assessment depends on which tools a website uses. If you find an inaccuracy, write to us and we will correct it.