ConsentProof
Published 2026-09-05

GDPR Cookie Banner Requirements — The Checklist Regulators Actually Use

ConsentProof is a cookie consent checker that scans any website with a real browser and records which cookies and third-party trackers fire before the visitor consents.

Six things a banner has to get right

Nothing non-essential runs before a choice. Reject is as easy as accept, on the first layer, with equal prominence. Purposes are separable rather than a single all-or-nothing switch. The information is specific about who receives the data. Consent can be withdrawn as easily as it was given. And the choice is recorded.

The first item is the one a scan can settle in under a minute, and it is also the one that most often fails on sites whose banner looks impeccable.

Dark patterns are enforcement bait

A prominent Accept all next to a greyed-out link labelled Manage preferences is the single most recognisable pattern in enforcement decisions, because it is visible in a screenshot and requires no technical analysis to describe.

Regulators have also acted where a reject choice was recorded and cookies were set anyway: the French CNIL's €150 million fine against SHEIN in 2025 included exactly that behaviour.

Proving it, later

The awkward question is not whether the banner is right today, but whether you can show what it did on a date months ago. That is why a scan result keeps an absolute UTC timestamp, a before and after screenshot pair, and a hash over the captured evidence.

Screenshots also cover the requirement a request log cannot: what the visitor was shown, and how the two options compared visually.

Frequently asked

Does a cookie banner need a reject button on the first layer?
Yes, in practice. Multiple EU regulators have taken the position that making rejection require extra clicks is not a free choice, and enforcement decisions have turned on it.
Can I load Google Analytics while the banner is showing?
No. While the banner is showing, no choice has been made, so non-essential storage and access have not been consented to. This is the single most common finding in our scans.
How do I prove my banner was compliant on a given date?
Keep dated evidence: a capture of what fired before consent, a screenshot of the banner as shown, and an absolute timestamp. A scan result here provides all three plus a SHA-256 of the capture.

Related

Try ConsentProof

Free public scan, no account needed.

Start free Pricing