What a cookie banner that withstands inspection should look like
Twelve rules that decide whether consent is valid. Each comes with a specific provision — a regulation, a directive or a judgment — and an example of how it looks done wrong and done right. No „we recommend“, just what the rules actually require.
Applies to both SK and CZUpdated 24 July 202612 rules · 10 myths debunked
01
Rejection is possible right in the first layer
If a visitor only sees „I agree“ and has to look for the rejection a click further into the settings, the consent is not freely given — it is coerced through inconvenience. Rejection must be available on the same screen and just as easily as acceptance.
This is the most common cause of fines in the Czech Republic and, at the same time, the mistake that most default banners of e-shop platforms have.
There is no way to reject — the only visible route is consent. „Settings“ is not a rejection, it is one more click on top.
✓ Correct
This site uses cookies
Necessary cookies are always on. You decide about the rest.
Allow allDeny allSettings
Both acceptance and rejection are in one place, one click each. Detailed settings are a third, supplementary option.
02
Not a single measurement script runs before consent
The law does not speak of a cookie banner — it speaks of storing information on a device and accessing it. Until the visitor clicks, Google Analytics, the Meta pixel, Sklik and the chat widget must not run. A banner that merely appears while the scripts run in the background is decoration with no legal effect.
It is precisely this that drew the highest Czech cookie fines.
The banner asks, but the trackers sent the data long ago. The consent is moot — the data left before it.
✓ Correct
analytics — blockedmarketing — blocked
This site uses cookies
Allow allDeny all
The scripts are blocked until a decision is made. Exactly the categories the visitor permitted run — and nothing more.
03
No category is pre-ticked
Consent must be an unambiguous indication of wishes — that is, an active action. A toggle that is already on when the settings open is not consent, because the visitor has done nothing. The Court of Justice of the EU ruled on this unambiguously in the Planet49 case.
There is only one exception: technically necessary cookies. They are always on, cannot be turned off, and no consent is required for them.
Everything is switched on in advance. Whoever just clicks „Save“ has consented without deciding.
✓ Correct
Cookie settings
Necessary always active
Analytics
Marketing
Save and close
The optional categories are off. The necessary ones are marked as permanently active and it is explained why.
04
Neither closing with the X nor scrolling is consent
If a visitor closes the banner or merely scrolls the page, they have expressed nothing — and it must not be interpreted as consent. The EDPB states this explicitly: continued browsing or scrolling does not meet the requirement of an unambiguous action.
The correct solution: after closing, the optional cookies remain off and the banner can be reopened at any time.
By continuing to browse the site you consent to the use of cookies.
The text claims that browsing alone is consent. It is not — and the close button here works as silent consent.
✓ Correct
This site uses cookies
✕
Closing the window launches nothing beyond the necessary cookies.
Allow allDeny all
The close button is equivalent to rejection and this is stated. The decision can be changed at any time.
05
The buttons look equivalent
It is not enough that a rejection exists — it must not be visually suppressed. A large green „Accept“ next to grey „Reject“ text is deceptive design: the design pushes towards one option, so the resulting consent is not freely given.
A practical criterion: both options have comparable size, contrast and placement. They need not be identical, but they must not be in a different weight class.
The same logic applies to the text on the buttons. The rules do not require identical wording — but if one option names exactly what will happen and the other does not, uncertainty arises precisely on the rejection side.
The rejection is small, grey and without a button. The eye barely registers it — and that is exactly the point.
✓ Correct
Your privacy
Allow allDeny all
The same size, the same shape, readable contrast in both cases. The choice is the visitor's, not the designer's.
✕
Allow all/Reject
An asymmetric pair. The first button says exactly what will happen. The second does not — do I reject everything, or does it save what I have set on the toggles? If there are category toggles above the buttons, that question is entirely justified. The uncertainty arises only on the rejection side.
✕
I agree/Settings
That is not a pair. „Settings“ is not a rejection but a further step — see rule 01.
✓
Accept all/Reject all
Symmetric and unambiguous. Both options name the same scope, so the visitor knows what a click will give them — regardless of what they have set above.
06
Consent can be given separately for each purpose
Consent must be specific. A single „I agree to everything“ button with no option to permit only analytics and reject advertising does not meet the condition — the visitor must be able to distinguish the purposes.
The established categories: necessary, functional, analytics, marketing. Each with its own toggle and an explanation of what it is for.
Do you agree to the use of all cookies on this site?
Yes, I agreeNo
All or nothing. The visitor cannot permit traffic measurement and reject advertising — the consent is not specific.
✓ Correct
Cookie settings
Necessary always
Functional
Analytics
Marketing
Save and close
Each purpose has its own toggle. Analytics yes, advertising no — and it is one click.
07
The cookie list is complete and specific
Informed consent means the visitor knows exactly what they are permitting: the cookie's name, what it is for, how long it lasts and who has access to it. The line „we use third-party cookies“ does not satisfy the duty to inform.
In practice this is the most common point of discrepancy: an e-shop declares five cookies and actually stores thirty. The list must match reality — and be updated whenever a new tool is added to the site.
On our website we use necessary cookies and third-party cookies for analytics and marketing purposes.
actually stored: 33listed: 1
A generic sentence without a single name. The visitor doesn't know what they are consenting to — and an inspection will find this out within minutes.
✓ Correct
Analytics cookies 4
_ga · Google Analytics13 months
_gid · session differentiation24 hours
_ga_XXXX · session state13 months
hjSession · Hotjar30 minutes
The name, provider, purpose and duration for each cookie. The list is generated from a scan of the website, not from guesswork.
08
Withdrawing consent must be as easy as giving it
This is not an interpretation — GDPR says it literally. If consent can be given with one click on the banner, it must also be possible to withdraw it with one click. Not by email, not by a request, not by deleting cookies in the browser.
A common solution: a permanent „Cookie settings“ link in the footer or a floating icon that reopens the banner.
If you wish to withdraw your consent, write to us at [email protected] or delete the cookies in your browser settings.
Consent with one click, withdrawal by email. An obvious imbalance, which the rule expressly prohibits.
✓ Correct
Cookie settings
Change or withdraw your decision at any time.
Data protectionCookie settingsContact
A permanent link in the footer opens the same banner. Withdrawal is one click, just like consent.
09
The website works for those who reject too
Conditioning access to content on consent to marketing cookies means the consent is not freely given — the visitor has no real choice. The so-called cookie wall is therefore inadmissible.
Equally unacceptable is a banner that covers the whole screen and cannot be bypassed other than by consenting.
The page content is available after consent is given.
Accept and continue
Without consent, the visitor cannot reach the content. That is not a choice, it is a condition.
✓ Correct
This site uses cookies
Allow allDeny all
The content is readable, the banner takes up the bottom strip. Rejection blocks nothing.
10
After a rejection, the banner does not ask again on every visit
Repeatedly popping up the banner after a visitor has rejected is pressure — the aim is to get them to „click it away“ once, just for some peace. This too is about the freedom of consent.
The Czech authority recommends specific figures: a consent validity of around 12 months and not asking again for at least 6 months after a rejection.
The rejection is not saved, the banner keeps asking over and over. Fatigue instead of a free decision.
✓ Correct
🍪 Cookie settings
The decision holds for 12 months. All that remains is a discreet link for anyone who wants to change it themselves.
11
The banner can be operated with a keyboard and read by a screen reader
The European Accessibility Act has applied since 28 June 2025. If a cookie banner cannot be operated with a keyboard, or a screen reader skips over it, some people cannot reach the choice at all — and the e-shop has a problem beyond GDPR.
The minimum: a visible focus, tab-key operation, sufficient contrast of both text and buttons, and closing with the Esc key.
Light-grey text on white, and the tab key skips the banner. Inaccessible to some visitors.
✓ Correct
This site uses cookies
Necessary cookies are always on.
Allow allDeny all
focus visiblecontrast 7.1 : 1
A visible focus, readable contrast, keyboard operation. The same choice for everyone.
12
It is clear who processes the data and where the details are
Consent is informed only when the visitor knows whom they are giving it to. The banner must state the controller (or unambiguously point to them) and a link to the privacy policy.
If the policy is hosted on the banner provider's domain, that is not a problem — but it must be clear from it that the controller is the e-shop in question, not the provider.
Neither the controller's name nor a link to the policy. The visitor has no idea who they are giving consent to.
✓ Correct
Cookies on eshop.sk
Controller: Firma s. r. o., Company ID 12 345 678. Details in the Privacy Policy.
Allow allDeny all
The controller is named and the policy is one click away. The consent is informed.
Watch out for one more thing:
the banner can be perfect and the website will still fail to comply if the cookie list drifts apart from reality. All it takes is for a marketer to add a new pixel — the declaration goes stale and rule 7 falls. That is why it makes sense to check the website regularly, not to set up the banner once and forget about it.
What people say after conferences
Ten myths circulating among marketers
Most of them sound logical and spread in good faith. The problem is that none of them holds up under inspection — and some lead precisely to the behaviour that draws fines.
„
Anyone who doesn't want to be tracked can install an ad blocker. It's up to the visitor.
Myth
The rule does not place the obligation on the visitor, but on whoever stores information on their device. The wording is unambiguous: storing information on, or accessing information in, a terminal device is possible only with the consent of the user. The fact that someone can defend themselves does not remove the obligation to ask for consent in the first place.
An analogy from another field: a seller cannot argue that the customer should have inspected the goods themselves. The obligation lies with the one who acts.
There's no need to deal with withdrawing consent — anyone who wants to can delete the cookies in their browser.
Myth
GDPR says literally that withdrawing consent must be as easy as giving it, and it is the controller's job to ensure this. If consent is given with one click on the banner, withdrawing it must not mean digging around in the browser settings.
On top of that, it doesn't even work technically: deleting cookies does not withdraw consent — it only erases its trace in the browser. The server knows nothing of any change, the consent record remains, and server-side measurement keeps running.
The authority itself said a cookie banner isn't mandatory. So why should we have one?
Half-truth
This was indeed said — and it is the most frequently twisted sentence in the whole topic. In its updated recommendations (March 2023) the Czech authority stated that if a website uses exclusively technical cookies, it need not have a banner. In that case it is enough to satisfy the duty to inform, for example with a document in a visible place.
But the moment Google Analytics, the Meta pixel or Sklik runs on a website, consent is mandatory — and a banner is the only practical way to obtain and prove it. So the line „a banner is not mandatory“ applies to websites that measure nothing. That is not the case for any e-shop.
We don't collect personal data, just anonymous traffic statistics.
Myth
If analytics assigns a visitor a unique identifier in order to recognise them on their next visit, it is not anonymous — it is pseudonymous. GDPR expressly counts online identifiers, including cookies, among personal data.
And above all: the ban on storing data on a device applies regardless of whether personal data is involved. It is the device itself that is protected, not merely what happens to the data afterwards. That is why IP anonymisation in Google Analytics does not help either — it solves a different problem than the one at hand.
For remarketing, legitimate interest is enough for us; no consent is needed.
Myth
Legitimate interest is a valid legal basis under GDPR — but it never gets a say. Before we even reach the question of a legal basis, the special ePrivacy rule applies: non-technical cookies may be stored only with consent. There is no other route.
Legitimate interest can be a legal basis for what you do with the data afterwards — never a substitute for consent to obtaining it from the device.
We turned on Consent Mode v2, so we've got cookies sorted.
Myth
Consent Mode is not consent — it is a way of telling Google about a decision you have already obtained somewhere. By itself it collects nothing and proves nothing.
Without a banner that actually requests and records consent, Consent Mode merely keeps reporting „denied“ indefinitely — and on top of that the e-shop has no proof that it ever obtained consent. During an inspection, proof is the very first thing the authority will ask for.
We have it written in our terms and conditions, which the customer agreed to.
Myth
Consent to processing must be clearly distinguishable from other matters. A provision hidden among delivery times and the complaints procedure does not meet this condition — and moreover it does not apply to visitors who ordered nothing and never saw the terms and conditions.
What is more, the cookies are stored the moment you enter the site, long before anyone reaches the point of accepting the terms at checkout.
We're a small firm with two people. GDPR is surely for big corporations.
Myth
GDPR has no size threshold. The only relief for companies under 250 employees concerns keeping records of processing activities — and even that does not apply when the processing is regular, which running a website with analytics always is.
Practice confirms it: the Czech authority fines ordinary small and medium e-shops, not just large platforms. In 2023 it imposed cookie fines totalling CZK 4.44 million.
The banner is supplied to us by the platform, so the platform is responsible for it.
Myth
The controller of personal data is whoever determines the purposes and means of processing — that is, the website's owner. The platform or banner provider is at most a processor. The authority conducts proceedings against the website's controller.
So the line „it runs on platform X“ cannot be used as a defence. If a platform's default banner has no rejection in the first layer or launches scripts before consent, it is the e-shop's problem, not the platform's.
Until someone reports us, no one takes any interest in us.
Myth
The supervisory authority acts on its own initiative too, not just on a complaint. Moreover, a cookie banner is publicly visible — to assess it, it is enough to open the website and look into the developer tools. It is not something that can be kept hidden.
During the transitional period, the Czech authority sent out more than 120 warning letters to controllers it had selected itself, and then moved on to fines.
The full list of rules, guidelines and decisions the guide refers to.
Regulation
Regulation (EU) 2016/679 — GDPRDefinition of consent (Art. 4(11)), conditions for consent and its withdrawal (Art. 7), the duty to inform (Art. 12–13), data protection by design (Art. 25).
Directive
Directive 2002/58/EC — ePrivacyArticle 5(3): storing information on, and accessing information in, a user's device is possible only with their consent, except for what is technically necessary.
National law · IE
Regulation 5(3) of the Privacy and Electronic Communications Regulations 2011 (S.I. No. 336 of 2011)
The national transposition of the cookie rule. Supervisory authority:
Data Protection Commission
This guide summarises the requirements arising from the listed rules, guidelines and decisions as at 24 July 2026. It is not legal advice — a specific assessment depends on which tools a website uses. If you find an inaccuracy, write to us and we will correct it.