Free GDPR Compliance Tool

Cookie Banner Checker

Find out if your website's cookie consent banner meets GDPR requirements. Detect missing reject buttons, pre-consent tracking, and compliance gaps in seconds.

Free · No account required · Results in under 30 seconds

A cookie banner is one of the most visible elements of GDPR compliance — and one of the most frequently implemented incorrectly. Data Protection Authorities across Europe have issued guidance and fines specifically targeting non-compliant consent banners. Our scanner checks whether your banner meets the requirements regulators actually enforce.

What the scanner checks for your cookie banner

Cookie banner detected

We check whether your website displays a cookie consent banner that is visible to users on their first visit.

Banner appears before tracking

We verify that the consent banner is shown before any tracking scripts or analytics tools load.

Reject option present

We check whether your banner offers a clear way to reject non-essential cookies — not just an 'Accept All' button.

Cookies set before consent

We detect if any cookies are placed before the user has made a consent choice — a clear GDPR violation.

Consent Mode configured

If Google Analytics or GTM is present, we check whether Consent Mode v2 is properly set up to honour user choices.

CMP tool identified

We detect which Consent Management Platform (CMP) is active on your site — OneTrust, Cookiebot, CookieYes, Usercentrics, Didomi, and many others — and flag if none is found.

Privacy Policy present

We verify your website has an accessible Privacy Policy — a mandatory requirement alongside any cookie consent mechanism under GDPR.

What makes a cookie banner GDPR compliant?

Under GDPR and the ePrivacy Directive (Cookie Law), consent for non-essential cookies must be freely given, specific, informed, and unambiguous. This means your cookie banner must meet a set of concrete requirements — not just 'exist'.

  • Users must be able to accept or reject cookies with equal ease
  • Pre-ticked boxes or opt-out mechanisms do not constitute valid consent
  • The banner must appear before any non-essential cookies are set
  • Consent must be as easy to withdraw as to give
  • Each category of cookies must be explained separately

The most common cookie banner mistakes

Regulators have identified and fined specific banner patterns repeatedly across Europe. Knowing what to avoid is as important as knowing what to include.

  • Hiding the reject button or making it smaller or greyer than 'Accept All'
  • Setting cookies before the user has made a choice
  • Using pre-ticked checkboxes for non-essential cookies
  • A 'cookie wall' that denies access unless cookies are accepted
  • Bundling consent for unrelated purposes into a single checkbox
  • Not providing a way to change or withdraw consent later

What happens if your cookie banner fails?

Non-compliant cookie banners are one of the most actively enforced GDPR issues in Europe. Several national DPAs run automated scanning tools specifically looking for banner violations.

  • France (CNIL): issued €150 million in fines to Google and Facebook for making cookie rejection too difficult
  • Italy (Garante): fined numerous companies for pre-ticking consent boxes
  • Germany (DSK): guidance explicitly requires reject buttons at the same level as accept
  • Repeated violations can lead to orders to stop processing — not just fines

Frequently asked questions

Ready to check your website?

Enter your URL below and get a free GDPR compliance scan in seconds.

Free scan No account required Results in under 30 seconds