Do You Need a Cookie Banner? A Plain-English Guide for Small Apps
Cookie banners are required when you set non-essential cookies or trackers for EU and UK visitors — not for every cookie. What counts as essential, when you need consent, what a compliant banner must do, and how to avoid needing one at all.
Cookie banners are everywhere, so it's easy to assume every site needs one. Not quite. Whether you need one depends on what your site stores on visitors' devices and who your visitors are.
This is general information, not legal advice. Rules vary by country and change; for anything high-stakes, ask a lawyer.
The rule in one sentence
Under EU and UK law (the ePrivacy rules, alongside GDPR), you need a visitor's consent before storing or reading non-essential information on their device — cookies, localStorage, tracking pixels and similar. Strictly necessary storage doesn't need consent.
It's about what the cookie is for, not that it's a cookie.
Essential: no consent needed
Storage needed to provide the service the visitor asked for:
- Login session cookies.
- Shopping cart contents.
- Security cookies (CSRF tokens, fraud prevention, load balancing).
- Remembering their cookie choice itself.
- Often, a preference they explicitly set (like language) — usually treated as necessary for that feature.
You should still mention these in your privacy policy. (What is a cookie?)
Non-essential: consent needed
- Analytics that use cookies or identifiers (Google Analytics in its usual setup, Hotjar, many product-analytics tools).
- Advertising and retargeting pixels (Meta, Google Ads, LinkedIn Insight Tag).
- Embedded content that tracks — some YouTube embeds, social widgets, chat widgets.
- A/B testing and personalisation cookies, in most interpretations.
If any of these load for EU/UK visitors before they agree, you need a banner — and you need to actually block them until consent.
What a compliant banner must do
Many banners you see aren't compliant. A proper one:
- Blocks non-essential scripts until the visitor opts in. Loading Google Analytics and then showing a banner doesn't count.
- Makes "Reject" as easy as "Accept" — same level, same prominence. No hiding reject behind "Settings."
- Doesn't use pre-ticked boxes.
- Explains what is used and why, with a link to more detail.
- Lets people change their mind later (a "Cookie settings" link in the footer).
- Records the choice.
"By continuing to browse you accept cookies" is not valid consent in the EU.
The easiest option: don't need one
For many small apps, the cleanest solution is to only use essential cookies:
- Use cookieless, privacy-friendly analytics (Plausible, Fathom, Simple Analytics, Umami and similar) that don't store identifiers on the device. Many such setups are generally regarded as not needing consent — check the tool's own guidance for your jurisdiction. (Analytics for beginners)
- Skip ad pixels until you actually run ads.
- Use privacy-enhanced embeds (e.g. YouTube's
youtube-nocookie.com) or click-to-load embeds.
No banner means a cleaner site and no consent drop-off in your data.
If you do need one
- A consent management platform (Cookiebot, CookieYes, Osano, Klaro — the last is open source) scans your site, shows a banner and blocks scripts until consent.
- If you use Google tags with EU traffic, look into Google Consent Mode, which Google requires for some advertising features in the EEA.
- Test it: open your site in a private window, don't click anything, and check the browser's dev tools (Application → Cookies, and the Network tab) to confirm nothing non-essential loads. (Browser developer tools)
Outside the EU and UK
- US: no general cookie-consent law, but several state privacy laws (California's CCPA/CPRA among them) require notice and opt-out rights for "selling/sharing" data, which can include ad tracking.
- Elsewhere: rules vary — Brazil, Canada, and others have their own.
If you have EU/UK visitors at all, the EU rules are the practical baseline.
And your privacy policy
A banner doesn't replace a privacy policy. You need one regardless if you collect any personal data. (Does my app need a privacy policy?, GDPR basics)
The summary
- Consent is needed for non-essential storage — analytics, ads, tracking — not for logins and carts.
- A valid banner blocks scripts until opt-in and makes reject as easy as accept.
- Cookieless analytics and no ad pixels often means no banner needed.
- You still need a privacy policy.
EasySpawn hosts your app on servers in the EU (Germany and Finland), so your app's data and self-hosted analytics can stay in the EU too. See how it works or join the waitlist.
Related: GDPR Basics for App Builders · Does My App Need a Privacy Policy? · What Is a Cookie? · Terms of Service for Your App
Keep reading
The OWASP Top 10 (2025) Explained for Beginners and App Builders
The OWASP Top 10 is the most widely used list of web application security risks. All ten 2025 categories in plain English — from broken access control to supply chain failures — with what each looks like in an AI-built app and how to prevent it.
What Is a JWT? JSON Web Tokens Explained Simply
Supabase, Firebase, Auth0, and Clerk all hand your app JWTs. What a JSON Web Token is, its three parts, why anyone can read it but nobody can forge it, how apps use it for login, and the mistakes AI-generated code makes with tokens.