Guides

Do cookie banners make you GDPR compliant? (No — here's the rest)

2 June 2026 4 min read GuardianStack
On this page

Short answer: no. A cookie banner covers one obligation — getting consent before non-essential cookies load — and even then, most banners are set up in a way that doesn’t actually meet the rule. Real compliance also covers your privacy notice, contracts with the apps that handle your data, retention, and responding to data requests. The banner is the 10% of compliance your visitors can see — the risk lives in the 90% they can’t.

Cookies are governed by PECR (the Privacy and Electronic Communications Regulations), which works alongside UK GDPR. The core requirement is simple to state and easy to get wrong: non-essential cookies and similar tracking must not be set until the user has given consent.

“Non-essential” means anything not strictly required to deliver the service the visitor asked for — analytics, advertising pixels, some chat widgets, some reviews and personalisation tools. Cookies that are genuinely essential (keeping a shopping basket, security) don’t need consent, and the ICO recognises a few narrow exceptions for low-risk uses. But for most stores, analytics and advertising cookies need consent — and the line between essential and non-essential is where most slip.

In order, PECR expects the sequence below — and the very first step, holding tags until consent, is the one most banners skip.

Framework · What PECR requires, in order

The compliant cookie sequence — consent comes before the tags

A banner is step 3 of five. Most stores fire the tags at step 1 — before anyone has agreed to anything.

1Visitor arrivespage loads 2Hold tagsnon-essential off 3Ask consentaccept = reject 4Set on acceptnever before 5Record itwhat & when Essential cookies (basket, security) skip the queue — everything else waits for consent
Source: ICO — Guidance on the use of cookies and similar technologies (PECR)

Honest note: “compliant” isn’t a switch you flip. Cookie law has genuine grey areas — the ICO itself is still refining where low-risk analytics sits — so this guide points you at the signals that matter, not a verdict on your specific store. When a call is close, check the ICO’s own guidance or ask a specialist. It’s guidance, not legal advice.

A banner on the page is not the same as compliance. A store can have a perfectly nice-looking banner and still fail on every point below — because these failures are invisible from the front end, hidden in what loads in the background and in what never gets recorded.

Analysis · Why nice-looking banners still fail

Four failure modes — invisible from the front of the store

Each is a common way a banner that looks fine still breaches PECR.

Failure modeWhat you see on the storeWhy it fails PECR
Tags fire before consentAnalytics & ad scripts load the moment the page opensNon-essential cookies must not be set until consent is given
No genuine reject"Accept" is prominent; rejecting is hidden or several clicks awayConsent isn't freely given if refusing is harder than agreeing
Implied consent"By continuing to browse you agree"Consent must be a clear, affirmative action — not assumed
No consent recordNothing logs who agreed, to what, and whenYou can't evidence valid consent if the ICO or a customer asks
Source: ICO cookies guidance · PECR reg. 6 · UK GDPR Arts 4(11) & 7 (consent + accountability)

What compliance covers beyond cookies

Treating cookies as the whole job is the classic trap. Your banner is the visible tenth; the nine-tenths beneath it is a stack that a typical UK online business also carries — a privacy notice that matches your live app stack, Article 28 contracts with the apps that process your data, and a process for subject access requests. Cookie consent is an important layer, but one. Buying a banner and considering the job done is how the other obligations quietly drift out of compliance.

Framework · The banner is one layer

The obligation stack a UK store actually carries

A cookie banner sits at the top. The layers beneath it don't have a banner to remind you they exist.

1Cookie consentPECR reg. 6Consent before non-essential cookies load
2Privacy notice that matches realityUK GDPR Arts 13–14What you collect, why, who with, how long
3Processor contracts (DPAs)UK GDPR Art 28A contract with every app that processes data on your behalf (a processor)
4Data retentionUK GDPR Art 5(1)(e)A lawful reason to hold each type — and a point to delete
5Subject access requestsUK GDPR Art 15Usually a month to give a copy of their data — extendable, with some exemptions
THE 10% YOU SEE Cookie banner Privacy notice Processor DPAs Data retention Access requests the 90% you can't
Source: UK GDPR Arts 5, 13–14, 15, 28 · PECR

The reliable way to know whether your banner actually holds up is to look at what loads before consent, on the live site — not what the settings claim. That, plus the wider signals (privacy notice, security, business identity), is the kind of thing GuardianStack’s free public check looks at from the outside in about 30 seconds, in plain English, with each finding mapped to the rule behind it.

Diagnostic · Run this on your own store

Five checks that show whether your banner holds up

Answer these on the live site, not in the settings screen — the settings often claim more than the page does.

1
Load order

Open the site in a private window with the Network tab recording — do analytics or ad tags fire before you click anything?

2
Equal choice

"Reject all" is as easy to reach as "Accept all" — same screen, one click?

3
Reject works

When you decline, do the non-essential tags actually stay off?

4
Active consent

No pre-ticked boxes and no "by browsing you agree" — is it a clear opt-in?

5
Record kept

Is each consent logged (what and when) so you can evidence it later?

Source: GuardianStack public check · methodology at guardianstack.com/methodology

What getting this right actually buys you

The point isn’t dodging a fine — most stores never see one. It’s readiness. A store that handles cookies and the layers beneath them properly is one that can answer calmly when a customer asks what you do with their data, when a partner runs due diligence, or when a complaint lands. That’s the real return: not fear managed, but a business that looks after its customers’ data and can show its working.

The bottom line

A cookie banner is necessary but nowhere near sufficient. Make sure the one you have actually blocks tracking until consent and records it — then look past it to the wider GDPR obligations a UK Shopify store carries, the ones a banner was never going to cover.

Sources

The primary sources behind this guide — check them yourself:

Frequently asked questions

Is a cookie banner legally required in the UK?

If your site sets non-essential cookies (analytics, advertising, some widgets), then under PECR you must get consent before they load, and a compliant consent mechanism — usually a banner — is how you do it. Sites that only use strictly necessary cookies don't need consent for those.

Does having a cookie banner mean I'm GDPR compliant?

No. A banner addresses cookie consent under PECR. UK GDPR also requires a truthful privacy notice, processor contracts (Article 28 DPAs), data retention limits, and honouring data subject requests. Cookie consent is one obligation among several.

Why might my cookie banner not be compliant?

The most common reasons are that tracking scripts load before the visitor consents, that rejecting is harder than accepting, that consent is implied rather than actively given, or that there's no record of consent. All of these are invisible from the front of the site, which is why they persist.

See where your store actually stands

Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.

Run the free website check
← Back to all articles