« This site uses cookies. Do you accept ? » This banner is seen on almost all sites — and many handle it poorly: missing, poorly made, or deceptive. Yet this is not a detail: it is a LEGAL OBLIGATION, and a sign of a site’s seriousness regarding the privacy of its visitors. If you have a site, you must understand what cookies are, when a banner is required, and how to implement it correctly. Here’s how to properly manage the cookie banner, without unnecessary legal jargon.
Cookies and consent: what are we talking about?
Let’s start with the basics, without jargon. A COOKIE is a small file that a site deposits on the visitor’s device (via their browser) to remember information: for example, your cart on a store, your login, your preferences, or to TRACK you for audience measurement or advertising purposes. Not all cookies are equal: there are cookies STRICTLY NECESSARY for the site’s operation (keeping your cart, your session); and NON-ESSENTIAL cookies: audience measurement (traffic statistics), targeted advertising, tracking via social networks or third-party services. The DISTINCTION is crucial for consent. The RULE (especially in the European Union, via the GDPR and related regulations): for NON-ESSENTIAL cookies (tracking, non-exempt statistics, advertising), the site must obtain the visitor’s CONSENT BEFORE depositing them; hence the famous banner. Strictly necessary cookies, on the other hand, do not require consent (but their presence is generally mentioned). What this implies for the banner: it must INFORM (which cookies, for what), request CONSENT for non-essential ones BEFORE activating them, and allow REFUSAL as easily as acceptance. Note: the regulation is PRECISE and evolving; data protection authorities (such as the CNIL in France) publish recommendations and sanction non-compliance; a « for show » poorly made banner is not compliant. What to remember to start: if your site uses NON-ESSENTIAL cookies (which is the case as soon as you add traffic statistics, advertising, or third-party modules that track), you MUST implement a compliant consent banner; this is not optional; it is both a legal obligation and a sign of respect for your visitors. The good news: tools greatly facilitate this implementation — we’ll get to that.
Cookies are small files that websites use to remember your choices or track you. Some are essential (like keeping your shopping cart), but others (like ads or analytics) need your permission. A good cookie banner tells you what cookies are used, lets you say yes or no easily, and respects your choice.
A WordPress site using Google Analytics (a non-essential cookie) must show a banner before loading the tracker. If a visitor clicks “Reject All,” the analytics script must not run, and the site must still be usable. A compliant tool like “CookieYes” handles this automatically.

What a compliant banner must respect
A compliant cookie banner follows precise principles: here are the main ones, in line with the authorities’ recommendations. CLEARLY INFORM: explain that the site uses cookies, which ones, and for what purpose (functionality, statistics, advertising…); a link to a detailed page (cookie/privacy policy) is expected. Request consent BEFORE deposit: non-essential cookies must NOT be deposited until the visitor has consented; the banner must appear BEFORE, and trackers only activated AFTER acceptance. Allow REFUSAL as easily as acceptance: this is a KEY point and often overlooked; it must be as simple to say NO as to say YES; a « Reject all » button must be as accessible and visible as the « Accept all » button (not hidden, not requiring multiple clicks against a single one for acceptance). Collect FREE, CLEAR, and INFORMED consent: the visitor must understand and choose freely; no pre-checked boxes for acceptance, no « forced » or deceptive consent. Allow GRANULAR choice: ideally, the visitor can accept or refuse by CATEGORY (statistics, advertising…), not just all or nothing. Do NOT BLOCK access to the site in case of refusal (except for specific cases); refusing cookies must not prevent browsing the site. KEEP a record of consent: be able to prove that consent was obtained. Allow CHANGING one’s mind: the visitor must be able to easily revoke their choice (a link to modify cookie preferences). Respect for PRIVACY: all this is part of a broader approach to protecting your visitors’ personal data (our guides on protecting personal data). What to avoid: « dark patterns » banners (designed to push for acceptance: « Accept all » clearly visible and colorful, refusal hidden or complicated); they are NON-COMPLIANT and increasingly sanctioned. In summary, a compliant banner: informs, requests consent before deposit, allows refusal as easily as acceptance, offers an informed and granular choice, does not block the site, keeps a record, and allows changing one’s mind. These principles may seem numerous, but dedicated tools apply them for you: that’s their purpose.
- CLEARLY INFORM: Explain which cookies are used and why, with a link to a detailed policy.
- REQUEST CONSENT BEFORE DEPOSIT: Non-essential cookies must wait for user permission.
- ALLOW REFUSAL EASILY: “Reject all” must be as simple as “Accept all.”
- COLLECT FREE, CLEAR, INFORMED CONSENT: No pre-checked boxes or forced acceptance.
- ALLOW GRANULAR CHOICE: Let users pick which cookie categories to accept.
- DON’T BLOCK THE SITE: Refusing cookies shouldn’t block access.
- KEEP A RECORD: Prove that consent was obtained.
- ALLOW CHANGING MIND: Let users revoke consent later.
The practical solution: a consent management tool (CMP). Good news: you don’t have to code a compliant banner yourself or master all the legal details; DEDICATED TOOLS do it for you. They are called « consent management platforms » (or CMP): these are modules (often an extension for your site system, or a service to integrate) specifically designed to manage the cookie banner in compliance. What they do: they display a compliant banner (information, balanced accept/refuse buttons, choice by category), BLOCK non-essential cookies until the visitor consents, record consent, and allow the visitor to modify their choice; many update according to regulatory changes. How to proceed: if your site is on a common system (like WordPress), look for a reputable consent management/cookie banner extension (there are free and paid ones); install it, configure it (indicate your cookie categories, customize the text and appearance to match your site), and it handles the rest. A few tips: choose a SERIOUS tool, up to date with the authorities’ recommendations (not just any); check that it allows refusing as easily as accepting (some poorly configured tools are not compliant; configure it correctly); ensure it actually blocks trackers BEFORE consent (a banner that displays but still allows cookies to be deposited is useless). Complete with a « Cookie Policy » or « Privacy » page detailing the cookies used and to which the banner refers. A well-configured tool puts you in compliance without advanced technical or legal expertise; it’s by far the best approach for most site creators. Invest a little time in its proper setup: that’s what makes the difference between a compliant banner and a « for show » banner that protects neither your visitors nor you.

Cookie banner and visitor experience
A cookie banner must balance compliance AND respect for the visitor’s experience: a few principles of balance. DON’T be aggressive: the banner is necessary, but it shouldn’t ruin the arrival on your site; avoid it covering all content in an anxiety-inducing way, or being impossible to handle; a clear, polite banner with obvious choices is resolved in an instant and leaves a good impression. Be HONEST rather than manipulative: a loyal banner (where refusing is as simple as accepting, where you understand what you’re accepting) inspires TRUST; on the contrary, a deceptive banner (pushing for acceptance, hiding refusal) annoys informed visitors and harms your image, in addition to being non-compliant; transparency pays off in the long run. Minimize COOKIES: the best way to simplify the banner is to LIMIT non-essential cookies; ask yourself: do I really need all these trackers? The fewer you use, the simpler your banner and the more you respect your visitors; some privacy-respecting analytics solutions even reduce the need for consent. VISUAL COHERENCE: customize the banner to match your site (colors, tone); a well-designed banner contributes to professionalism. DON’T FORGET mobile: the banner must be readable and usable on smartphones, without blocking the entire screen. Think about the USER JOURNEY: the link to modify preferences (to revoke a choice) must remain accessible (often in the footer). The BALANCE to find: between the legal obligation (inform, obtain real consent) and the visitor’s comfort (not overwhelming them); a good banner does both: it is compliant AND discreet, honest AND simple to handle. See the banner not as a regulatory chore to rush through, but as a MOMENT of RELATION with your visitor: how you ask for their consent says a lot about the respect you show them; a loyal and clear banner is a first sign of trust. In summary: be compliant and honest, minimize cookies, care about presentation, think mobile, and let the visitor be in control of their choice, including changing it; thus, your banner protects your visitors, puts you in compliance, and serves your image rather than harming it.
Warning: the cookie banner is a legal obligation, and a « for show » or deceptive banner is not compliant. Don’t take this lightly: mistakes can expose you to penalties and harm your visitors. First, the ABSENCE or fake banner: if your site uses non-essential cookies (traffic statistics, advertising, third-party modules that track) without a compliant consent banner, you are in violation; data protection authorities (like the CNIL in France) monitor and sanction; a simple « This site uses cookies, OK » banner without a real way to refuse or prior blocking of trackers is NOT ENOUGH. Second, cookies deposited BEFORE consent: a common trap is to display a banner but still allow non-essential cookies to be deposited upon arrival; this is non-compliant: non-essential trackers must only activate AFTER consent; check that your tool actually blocks them beforehand. Third, DIFFICULT refusal: making acceptance easy (a large « Accept all » button) and refusal complicated or hidden (no visible « Reject all » button, refusal in multiple clicks) is explicitly NON-COMPLIANT and sanctioned; refusing must be AS EASY as accepting; these « dark patterns » are in the authorities’ sights. Fourth, PRE-CHECKED boxes or forced consent: consent must be a POSITIVE and free act; no pre-checked boxes, no « by continuing, you accept » that forces the hand. Fifth, forgetting the INFORMATION page and the ability to CHANGE one’s mind: the visitor must be able to inform themselves in detail and revoke their choice. Sixth, believing this only concerns LARGE sites: the regulation also applies to small sites using non-essential cookies; a showcase site with simple tracking traffic statistics is concerned. Finally, the regulation EVOLVES: what was tolerated yesterday may not be today; hence the interest of an up-to-date consent tool. This is not just a legal risk: a loyal banner RESPECTS your visitors and their privacy; a deceptive banner deceives them. The right approach: use a serious and up-to-date consent management tool, configure it correctly (refusal as easy as acceptance, blocking before consent), minimize your cookies, and document everything in a dedicated page; if in doubt about your specific situation, refer to the official recommendations of data protection authorities.

Frequently asked questions
Am I required to have a cookie banner?
It depends on the cookies your site uses: if you use NON-ESSENTIAL cookies, then yes, it is mandatory. The distinction is key. Cookies STRICTLY NECESSARY for the site’s operation (remembering a cart, a login session, a language choice) do NOT require consent; a site that only uses these has lighter obligations (inform, but no strict consent banner). However, as soon as your site uses NON-ESSENTIAL cookies — audience measurement/traffic statistics (via most analytics tools), advertising, social network buttons that track, third-party modules that follow visitors — you MUST obtain consent BEFORE depositing them, via a compliant banner. Yet, most sites use at least tracking traffic statistics: they are therefore concerned. Don’t believe that only « big » sites are targeted: a small showcase site with a simple classic analytics tool is too. To know if you are concerned: list the cookies and trackers on your site (the modules you have added: analytics, advertising, social networks, maps, embedded videos…); if there are non-essential ones, the banner is required. In doubt, consider that you are, and implement a consent tool: that’s being cautious. Note: some « privacy-respecting » analytics solutions reduce the need for consent by avoiding tracking cookies — an option to simplify.
cookie consent banner with 'Accept All' and 'Reject All' buttons.” loading=”lazy” />How to easily implement a compliant banner?
The simplest and most reliable way is to use a CONSENT MANAGEMENT TOOL (a « CMP »), without coding or mastering all the legal details. In practice: if your site is on a common system (like WordPress), install a DEDICATED EXTENSION for the cookie banner/consent management, reputable and up to date with the authorities’ recommendations (there are free and paid ones); configure it by indicating your site’s cookie categories, customizing the text and appearance to match your design; it will then display a compliant banner and manage consent automatically. Points to check during configuration: that the banner allows refusing as easily as accepting (a « Reject all » button as visible as « Accept all »); that it actually BLOCKS non-essential cookies UNTIL the visitor consents (and not just displays a message); that it offers a choice by category; that it records consent and allows modifying it. Complete with a « Cookie Policy » (or privacy) page detailing the cookies used, to which the banner refers. A good tool well configured does all the technical compliance work for you; the bulk of your effort is to properly SET IT UP (especially the accept/refuse balance and prior blocking), because a poorly configured tool can remain non-compliant. Avoid DIYING a simplistic « home-made » banner (just an « OK » message) that blocks nothing and doesn’t allow refusal: it is not compliant. In summary: serious consent extension + good configuration (easy refusal, blocking before consent) + information page = compliant banner, without advanced expertise.

Can I force visitors to accept cookies?
No: consent must be FREE, and forcing acceptance is non-compliant. You cannot: pre-check acceptance boxes (consent must be a positive act by the visitor); consider that « continuing to browse means acceptance » (this is no longer accepted); make REFUSAL impossible or much harder than acceptance (refusing must be as simple as accepting); or, in principle, BLOCK access to your site if non-essential cookies are refused (except for specific cases; refusing tracking must not prevent viewing the content). In short, the visitor must be able to say NO to non-essential cookies as easily as they can say yes, and continue using your site. Practices that push for acceptance (« dark patterns »: « Accept all » button clearly visible and refusal hidden, guilt-inducing wording, etc.) are explicitly targeted and sanctioned by data protection authorities. Why this rule? Because consent obtained under duress or deception is not real consent; the spirit of the regulation is to let the visitor truly be in control of their data. What to do if you care about your statistics? Respect the visitor’s choice (if they refuse, you won’t have their tracking data, that’s how it is); or use privacy-respecting audience measurement solutions that require less, or no, consent. But don’t try to force the issue: in addition to being illegal, a visitor who feels trapped loses trust in you. Transparency and respect for choice are both mandatory and beneficial for your image.
What to remember
The cookie banner is not a decorative detail: it is a LEGAL OBLIGATION as soon as your site uses NON-ESSENTIAL cookies (tracking traffic statistics, advertising, third-party modules that follow visitors) — which concerns most sites, small and large. Strictly necessary cookies (cart, session) do not require consent, but everything else DOES, and BEFORE deposit. A COMPLIANT banner must: clearly inform (which cookies, why, with a detailed page); request consent BEFORE activating non-essential trackers; allow REFUSAL as easily as acceptance (key point often overlooked: « Reject all » as visible as « Accept all »); collect free and informed consent (no pre-checked boxes, no forced consent); offer a choice by category; not block site access in case of refusal; keep a record; and allow changing one’s mind. The PRACTICAL SOLUTION: a consent management tool (CMP) — a dedicated, reputable, and up-to-date extension; install it, configure it well (especially: refusal as easy as acceptance, and real blocking of cookies before consent), and complete with a « Cookie Policy » page. MISTAKES to avoid: no banner at all, a fake banner that blocks nothing, cookies deposited before consent, difficult refusal (« dark patterns » sanctioned), pre-checked boxes, forgetting the ability to change one’s mind, and believing only large sites are concerned. For the VISITOR EXPERIENCE: be compliant AND honest (a loyal banner inspires trust; a deceptive banner annoys and harms your image), minimize your cookies (fewer trackers = simpler and more respectful banner), care about presentation and think mobile. See the banner not as a chore but as a moment of relation: how you ask for consent reflects the respect you show your visitors. A compliant, loyal, and well-designed banner puts you in compliance, protects your visitors’ privacy, and serves your credibility.



Your activity deserves a real online presence: showcase site, store, SEO — we create the site that suits you.
Leave a Reply
You must be logged in to post a comment.