Free GDPR Compliance Tool
Cookie Banner Checker
Find out if your website's cookie consent banner meets GDPR requirements. Detect missing reject buttons, pre-consent tracking, and compliance gaps in seconds.
Free · No account required · Results in under 30 seconds
A cookie banner is one of the most visible elements of GDPR compliance — and one of the most frequently implemented incorrectly. Data Protection Authorities across Europe have issued guidance and fines specifically targeting non-compliant consent banners. Our scanner checks whether your banner meets the requirements regulators actually enforce.
What the scanner checks for your cookie banner
Cookie banner detected
We check whether your website displays a cookie consent banner that is visible to users on their first visit.
Banner appears before tracking
We verify that the consent banner is shown before any tracking scripts or analytics tools load.
Reject option present
We check whether your banner offers a clear way to reject non-essential cookies — not just an 'Accept All' button.
Cookies set before consent
We detect if any cookies are placed before the user has made a consent choice — a clear GDPR violation.
Consent Mode configured
If Google Analytics or GTM is present, we check whether Consent Mode v2 is properly set up to honour user choices.
CMP tool identified
We detect which Consent Management Platform (CMP) is active on your site — OneTrust, Cookiebot, CookieYes, Usercentrics, Didomi, and many others — and flag if none is found.
Privacy Policy present
We verify your website has an accessible Privacy Policy — a mandatory requirement alongside any cookie consent mechanism under GDPR.
What makes a cookie banner GDPR compliant?
Under GDPR and the ePrivacy Directive (Cookie Law), consent for non-essential cookies must be freely given, specific, informed, and unambiguous. This means your cookie banner must meet a set of concrete requirements — not just 'exist'.
- •Users must be able to accept or reject cookies with equal ease
- •Pre-ticked boxes or opt-out mechanisms do not constitute valid consent
- •The banner must appear before any non-essential cookies are set
- •Consent must be as easy to withdraw as to give
- •Each category of cookies must be explained separately
The most common cookie banner mistakes
Regulators have identified and fined specific banner patterns repeatedly across Europe. Knowing what to avoid is as important as knowing what to include.
- •Hiding the reject button or making it smaller or greyer than 'Accept All'
- •Setting cookies before the user has made a choice
- •Using pre-ticked checkboxes for non-essential cookies
- •A 'cookie wall' that denies access unless cookies are accepted
- •Bundling consent for unrelated purposes into a single checkbox
- •Not providing a way to change or withdraw consent later
What happens if your cookie banner fails?
Non-compliant cookie banners are one of the most actively enforced GDPR issues in Europe. Several national DPAs run automated scanning tools specifically looking for banner violations.
- •France (CNIL): issued €150 million in fines to Google and Facebook for making cookie rejection too difficult
- •Italy (Garante): fined numerous companies for pre-ticking consent boxes
- •Germany (DSK): guidance explicitly requires reject buttons at the same level as accept
- •Repeated violations can lead to orders to stop processing — not just fines
Frequently asked questions
Related compliance tools
Google Analytics GDPR Checker
Check if Google Analytics is loading before consent and Consent Mode v2 is configured.
Privacy Policy Checker
Verify your Privacy Policy meets GDPR Art. 13 disclosure requirements.
GDPR Scanner
Full GDPR compliance scan covering cookies, trackers, consent, and more.
AI Act Compliance Check
Assess your organisation's compliance with the EU AI Act.
Ready to check your website?
Enter your URL below and get a free GDPR compliance scan in seconds.