Consent banners: what has to be in one
A guide to a lawful cookie consent banner, with the consent guidance, cookie notice and privacy notice drafted for the business, for a fixed fee of £595 in five working days.
Consent banners: what has to be in one
Buy now, £595The cookie banner is the most visible compliance decision a website makes and the one most often made wrong: a banner that only informs, that offers accept but hides reject, that pre-ticks the boxes, that blocks the site until the visitor agrees, or that shows while the cookies fire anyway. The regulator has told the operators of the most visited sites what a lawful banner looks like and has started on the rest. This page explains what has to be in one, what must not be, and how the business keeps the records that prove the consent, and the pack provides the consent guidance for the business's own banner, with the cookie notice and privacy notice, for a fixed fee of £595, delivered in five working days.
Who this is for
Businesses in England and Wales with a website that sets non-essential cookies, and anyone who has been told their banner needs a reject button and wants to know what else it needs.
What matters in a consent banner
What the banner is for and the rule it serves
Consent must be obtained before non-essential cookies and similar technologies are set, under regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, with consent meaning the standard the UK GDPR sets (freely given, specific, informed, unambiguous, by a clear affirmative action), and the banner is the mechanism by which the site obtains that consent before the analytics, advertising and other non-essential technologies fire; the Information Commissioner's guidance on cookies sets what a compliant banner does, and the regulator's enforcement in this area has been against banners rather than against cookies, because the banner is where consent is or is not obtained.
The first layer and the two buttons that must be equal
The first layer the visitor sees must offer a way to accept non-essential cookies and a way to reject them with equal prominence (the same size, colour weight and position, both on the first layer, not reject hidden behind 'manage settings'), must state briefly what the cookies are for, and must link to the cookie notice and the privacy notice; the regulator's position since its letters to the largest sites is that a first layer with accept only, or with reject requiring extra clicks, does not obtain valid consent, and the guidance sets out the first-layer wording and layout for the business's site.
The second layer, the categories and the granular choice
Behind the first layer the visitor should be able to choose by category (strictly necessary, which cannot be switched off and should be explained; functional; analytics; marketing, with any further categories the site uses) and, where the business chooses, by provider within a category, with each category off until the visitor turns it on, a description of what each category does and which providers are in it, and a save button that applies the choice; the categories should match the cookie notice, because a visitor who refuses marketing and finds a marketing cookie set has a complaint the records cannot answer.
What must not be in a banner
A banner must not pre-tick the boxes, must not treat scrolling or continued browsing as consent, must not use a cookie wall that blocks access to the site unless the visitor accepts (except in the narrow cases the regulator has indicated, with a fair alternative), must not set non-essential cookies before the visitor has chosen, must not use design that nudges acceptance (a prominent accept and a greyed-out reject, confusing wording, a reject that reappears on every page), and must not claim a legitimate interest for cookies the regulation requires consent for; the practices the Competition and Markets Authority and the Information Commissioner have described as harmful design apply to the banner as much as to the checkout.
Withdrawal, the records and the re-ask
The visitor must be able to withdraw consent as easily as they gave it (a persistent link or icon that reopens the choices), the site must stop the cookies and delete what it can when consent is withdrawn, the business must keep a record of each consent (what was shown, what was chosen, when, by which identifier) as the evidence under Article 7 of the UK GDPR that consent was given, and the banner should re-ask after a period the business sets (commonly six to twelve months) or when the cookies change; the consent tool or the platform's banner usually keeps the records, and the guidance explains how to find and export them.
The 2025 Act, the regulator's enforcement and the banner's future
The Data (Use and Access) Act 2025 adds exceptions to the consent rule once in force (for cookies used solely for statistics to improve the service, for certain functionality the visitor would expect, and for a few other narrow purposes) on an opt-out basis with clear information, and raises the fines under the Regulations to the UK GDPR level, which changes the calculation for a business that has treated the banner as optional; the regulator has said it will enforce against sites that do not offer a reject option, and the guidance that comes with the pack explains how to configure the business's banner for the law as it stands and for the exceptions as they come in, with the cookie notice and privacy notice alongside, and electronic marketing to individuals requires consent under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 unless the soft opt-in applies, which the privacy notice addresses separately.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Does the reject button have to be on the first layer?
It does, with the same prominence as accept. A reject hidden behind 'manage settings' does not obtain valid consent, and that is the point the regulator has enforced.
Can we block the site until the visitor accepts cookies?
A cookie wall is not consent freely given, except in the narrow cases the regulator has indicated and with a fair alternative. The site should work with non-essential cookies refused.
How long does cookie consent last?
Until withdrawn, with the business re-asking after a period it sets, commonly six to twelve months, and whenever the cookies change. The records of each consent are kept as the evidence.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Using analytics and advertising pixels lawfully
- Cookie policy for a Squarespace or Wix website
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.