Free scan Install guides Developers Compare CMPs About Support Contact
Get Velo

Already have an account? Log in

Can you be fined for not having a cookie banner?

Compliance 14 August 2026· 6 min read
The Velo mascot holds up a rule book while a ghost eyes the cookie jar

All posts

Yes. In the EU and UK, regulators have issued cookie fines, and one of the failings they sanction is precisely a failure to tell visitors what you set. But the banner is not the duty. What creates exposure is storing non exempt cookies before consent, so a site setting only strictly necessary ones has far less to answer for.

The rule is about the cookies, not the banner

The banner is a mechanism people built to satisfy a duty. It is not the duty. That sits in the ePrivacy rules governing storage on a visitor's device, or reading what is already there, whether the thing stored is a cookie, a local storage value or a fingerprint. The GDPR then sets the standard for consent: freely given, specific, informed, and as easy to withdraw as to give.

That split matters, because it tells you where the exposure is. Nobody inspects your site for the presence of a banner. What creates risk is a tag that stored something before the visitor agreed to it.

The exemption is the part the scare pieces leave out. Cookies strictly necessary for a service the visitor explicitly asked for do not need consent: the session cookie keeping somebody logged in, the basket, a security token that blocks fraud, load balancing, and the record of the cookie choice itself. A brochure site that sets nothing else does not need a consent banner, and telling its owner otherwise is selling fear.

One duty survives, and it is the one people conflate with the banner. Telling visitors what you store and why is a transparency obligation in its own right, and it does not switch off because nothing you set needs consent. A cookie notice or privacy policy discharges it without an interrupting dialog. You owe an explanation, not a consent gate.

What actually needs consent

Everything whose purpose is measurement, advertising or personalisation: analytics however harmless you consider it, advertising and retargeting pixels, embedded video and social widgets that set their own cookies on load, A/B testing and session recording. If the visitor did not ask for it and the site works without it, assume it needs consent until you can show otherwise.

NEEDS CONSENT Analytics, however harmless Advertising and retargeting pixels Embedded video and social widgets A/B testing, session recording Set before consent, this is your exposure NO CONSENT NEEDED Keeping somebody logged in The contents of a basket Security and fraud tokens The cookie choice itself Strictly necessary, no consent needed
The consent requirement follows from the left column. A site with nothing in it still owes visitors an explanation, but not a consent gate.

What regulators have actually acted on

Read the decisions rather than the listicles and the picture is more specific than either side of the argument suggests. In the French case that the Conseil d'État went on to uphold, three separate failings were sanctioned: cookies installed automatically on arrival without consent, a defective refusal procedure, and a lack of clear and complete information for users. That third one matters here, because failing to tell people what you set is sanctionable on its own. A site with no banner and no notice is not merely outside the consent rules, it is also failing to inform.

The wider campaigns have been organised around a principle worth knowing: refusing cookies should be as easy as accepting them. Those cases involved banners that existed and made refusal harder than acceptance, or set the cookies anyway after a refusal. Having a banner is no defence if it behaves that way.

The very large fines that circulate in listicles went to a handful of global platforms with enormous audiences. Quoting them at a fifty page business site implies a comparison the enforcement record does not support, which is why we will not do it here.

A fine is not the only instrument. Regulators also issue orders to comply, telling an organisation to fix a defect within a deadline, which is a different thing from waking up to a penalty. The rules are national, too: several regimes make the failure to inform separately punishable, and authorities have issued modest penalties far below the headline figures, so "only the giants get fined" is not a safe reading either.

Check where you stand in ten minutes

Go and look at what your own site does before consent.

  1. Open the site in a private window and touch nothing

    No accept, no reject, no dismissing the banner. This is the state every first time visitor is in, and the state that gets assessed.

  2. List what is already stored

    In your browser's developer tools, read the cookies, local storage, session storage and IndexedDB for the page. Anything present at this point was set without consent, which is not automatically a fault: your consent tool has to store the choice itself, and your server may set a session or security cookie legitimately.

  3. Sort each item into two piles

    Does it serve something the visitor explicitly asked for, or does it measure, advertise or personalise? Vendor documentation will usually tell you what a given cookie is for, and anything you cannot identify belongs in the second pile until proven otherwise. Your own consent record and server session belong in the first.

  4. The second pile is your actual exposure

    Not the banner. This list. Fixing it means gating those tags behind consent rather than adding a banner on top and hoping.

  5. Now test refusal

    Reject, reload, and read the storage again. If the same items come back, you have the defect regulators have actually pursued. Our walkthrough of testing a cookie banner before going live covers the full sequence.

The honest risk picture

For a small or mid sized site the probability of a regulator arriving unprompted is lower than the listicles imply, because enforcement attention is finite and follows large audiences. That is worth saying plainly rather than leaving people to be frightened into a purchase.

The part the reassurance leaves out is that size is not a shield. A complaint from one annoyed visitor can start an inquiry regardless of how small you are, and some authorities have issued modest cookie penalties to ordinary companies rather than only to global platforms. Larger customers increasingly ask how consent is handled before they sign, and a missing answer stalls the deal. In several markets private claims, not regulators, have become the more active pressure.

So the useful framing is not "will I be fined". It is that consent is a small piece of hygiene with an unbounded tail, and it takes an afternoon to put right. For the mechanism rather than the anxiety, what a consent management platform actually does covers the gating, and Velo is our own take on making refusal as cheap to build as acceptance.

Common questions

What people ask about this topic.

Can you be fined for not having a cookie banner?

Yes, though not for the missing banner as an object. Regulators sanction the underlying failings, and in the leading French case upheld on appeal there were three: cookies installed without consent, a defective refusal procedure, and a lack of clear and complete information for users. A site with no banner and no notice can fall foul of the consent rules and the duty to inform at the same time. Conversely a site that sets nothing beyond strictly necessary cookies has no consent to collect, though it still owes visitors an explanation of what it stores.

Do you legally need a cookie banner?

You need a consent mechanism only if you set cookies that require consent. The duty comes from the ePrivacy rules on storing information on a visitor's device, with the GDPR setting the standard for what counts as consent. If everything you store is strictly necessary for something the visitor asked for, there is nothing to consent to. Transparency is separate and survives regardless: you still tell people what you store, which a cookie notice or privacy policy can do without an interrupting dialog.

Which cookies do not need consent?

Those strictly necessary for a service the visitor explicitly requested. In practice that covers the session cookie keeping somebody logged in, the contents of a basket, security and fraud tokens, load balancing, and the record of the cookie choice itself. Anything whose purpose is measurement, advertising or personalisation falls outside the exemption, including analytics you consider harmless.

What do regulators actually fine websites for?

For the specific defects rather than for the absence of a banner in the abstract. The leading French decision sanctioned three at once: setting cookies before consent, making refusal harder than acceptance, and failing to inform users clearly and completely. Enforcement campaigns have since been built around the principle that refusing cookies should be as easy as accepting them, which means an existing banner is no defence if it behaves that way.

Does a small business get fined for cookies?

It is less likely, because enforcement attention is finite and tends to follow large audiences, but size is not a shield. The rules are applied nationally and several regimes make the failure to inform separately punishable, with authorities issuing modest penalties well below the headline figures. A single visitor complaint can also start an inquiry regardless of your size, and regulators can issue an order to comply, giving you a deadline to fix a defect rather than a fine.

Your banner, your consent,
your data — all in one place.

Scan your site →
Pages Free scan Product Agencies Pricing Developers Install guides Compare CMPs
Company About Velo Blog Help Contact
Account Sign up Log in Get early access
GDPR CCPA
All rights reserved
© 2026 by Amplio Data