Guide · Rules and requirements

Cookie banner rules: what is allowed and what is required?

The short answer: you need active consent before setting cookies or similar technologies that are not strictly necessary, and rejecting must be as easy as accepting. Analytics and marketing cookies therefore require consent, while cookies for the basket, login and security do not. Here we go through the rules, the dark patterns that keep appearing, and how to measure traffic with fewer cookies or none at all.

10 min read · Updated 1 October 2026

A marketing lead opens Google Analytics and sees that traffic has dropped by a third since the new cookie banner went live. Panic spreads, and someone suggests making the “Reject” button small and grey. That is exactly the reaction the rules are written to prevent, and it does not solve the problem. Traffic is probably the same as before. The measurement now simply counts only the users who said yes. The rest of this guide is about how to follow the rules and still get the numbers you need.

In Denmark the rules live in the cookie executive order, which Erhvervsstyrelsen enforces, and in GDPR, which Datatilsynet enforces. We build websites and apps, and our angle is the practical and technical one. Use this guide as a practical overview, and check specific questions in the authorities’ guidance or with a lawyer.

What do the rules say about cookie banners in Denmark?

The main rule is simple: you may only store or read information on the user’s device if it is strictly necessary to deliver the service the user explicitly asked for, or if the user has given informed consent. Consent must meet the GDPR standard. That means it must be freely given, specific, informed and given through an active choice. Scrolling on, clicking around or leaving a pre-ticked box in place does not count as consent.

  • No non-essential cookies or scripts before the user has said yes.
  • Reject must be as easy as accept, typically a button at the same level and of the same size.
  • Users must be able to choose categories, such as analytics and marketing separately.
  • Information about purpose, duration and which third parties receive data.
  • Consent must be as easy to withdraw as it was to give, for example through a link in the footer.
  • The choice must be documented, so you can show what the user agreed to.

Which cookies require consent, and which do not?

The line is drawn at “strictly necessary”. It is a narrow category. A cookie is necessary if the site cannot deliver what the user asked for without it. The fact that the company needs statistics is a good business reason, but that does not make analytics cookies strictly necessary in the legal sense. The table shows the typical categories.

Typical categories and the common assessment. Borderline cases depend on the specific setup and should be checked against Erhvervsstyrelsen’s guidance.

CategoryExamplesConsent needed?
Strictly necessaryShopping basket, login session, security, stored consent choice, load balancingNo
PreferencesLanguage or currency the user has chosenOften no, when the user asked for it, but assess case by case
AnalyticsGoogle Analytics, heatmaps, session recordingsYes
MarketingMeta Pixel, Google Ads, LinkedIn Insight, retargetingYes
Embedded contentYouTube, Vimeo, Google Maps, social mediaYes, when it sets cookies or reads data
Chat and supportChat widget that remembers the conversationDepends on whether the user starts the chat

What are dark patterns in a cookie banner?

Dark patterns are design choices that push the user towards the answer the company prefers. They are widespread in cookie banners, and EU authorities have made it clear that they can make consent invalid. If consent is invalid, you effectively have no consent, and the data has been collected without a basis. That is a poor trade for a few extra percentage points in your statistics.

Dark patterns

  • A large coloured “Accept all” and a small grey link to settings
  • Reject hidden in a second layer behind several clicks
  • Categories switched on by default or listed under “legitimate interest”
  • A close icon that counts as acceptance
  • The banner returns on every visit after a rejection

Lawful and honest

  • “Accept all” and “Reject all” side by side at the same size
  • “Customise” as a third option with categories switched off
  • Short, clear language about purposes and third parties
  • A close icon that equals reject or no change
  • A permanent footer link to change the choice
The same banner, designed two ways.

How do you implement a cookie banner correctly in code?

The most common mistake is technical. The banner looks right, but scripts from Google, Meta and others load as soon as the page opens, and the banner is pure decoration. Open your site in a private browser window, open the developer tools and look under Application and Network before you click anything. If you see third-party cookies or calls to tracking domains, the setup is wrong. It takes five minutes to check, and we recommend you do it today.

1

Map every script

List every tag, pixel, widget and embed and put each in a category.

2

Block by default

Non-essential scripts load only once consent for that category is given.

3

Show an equal choice

Accept, reject and customise on the first layer, accessible by keyboard and screen reader.

4

Store and document

The choice is stored in a necessary cookie and logged with time and banner version.

5

Test after every change

New marketing tags and widgets are checked before going live, so they do not bypass the banner.

How we build consent into a Next.js solution.

The banner must also be accessible. A banner that traps keyboard focus, or that screen readers cannot find, is a problem under the Accessibility Act for webshops and booking sites. And it must be light: a heavy banner script can hurt your speed and Core Web Vitals, especially INP and CLS if the banner pushes content down.

Google Consent Mode

If you use Google Ads or Google Analytics in the EEA, Google requires you to pass on the user’s consent status through Consent Mode. In the basic setup, Google’s tags do not load at all before consent. In the advanced setup, cookieless signals are sent even from users who rejected, and Google uses them to model figures. The legal assessment of the advanced variant is debated, so we recommend the basic setup unless a lawyer has approved otherwise.

Can you measure traffic without cookies?

Yes, to a degree. Some analytics tools are built to store nothing on the user’s device and not to identify individuals. They count page views, sources, devices and conversions at an aggregate level. Configured correctly, many assessments find they can be used without cookie consent, but GDPR still applies to the processing of IP addresses and similar on the server, and the assessment depends on the specific tool and its settings. Check the vendor’s documentation and read Erhvervsstyrelsen’s guidance.

  • Cookieless, privacy-friendly analytics for overall traffic and sources, ideally hosted in the EU.
  • Conversions measured on the server: how many bookings, orders and enquiries actually came in?
  • Google Search Console for keywords, clicks and rankings, which requires nothing on your site.
  • Full analytics and ad tracking for the users who said yes, as a supplement.
  • Campaign links with UTM parameters, so you can see which campaigns produce results.

The combination gives an honest picture. Orders and bookings in your own system are the numbers that matter most to the business, and they do not depend on consent. That is why we recommend building measurement of the key actions into the backend, so you can see results without adding more scripts to the site.

What does a cookie consent solution cost?

There are ready-made solutions, known as consent management platforms, from both Danish and international vendors. They scan your site, generate a cookie policy and handle documentation. The price typically depends on the number of pages and visitors, from free plans for small sites up to a few hundred kroner a month. The real cost usually sits in the setup, if the site has many scripts that must be sorted and blocked correctly.

Typical price levels. The number of scripts and third parties decides how much setup is needed.

SolutionTypical priceFits
No non-essential cookiesDKK 0 and no bannerSites with cookieless analytics and no ad tracking
Ready-made consent platformFree to a few hundred DKK/monthMost company sites and webshops
Setup and clean-up of scriptsDKK 3,000–15,000Sites with many tags from past campaigns
Custom consent solution in codePart of the buildNew solutions with few, known third parties

The cheapest solution is the one few people think of: use fewer third parties. Every pixel, heatmap and widget you remove is one less thing to ask about, document and maintain. Many sites we take over carry tags from campaigns that ended years ago.

Checklist: is your cookie banner lawful?

  1. Open the site in a private window: are third-party cookies set before you click anything?
  2. Do “Reject all” and “Accept all” sit on the first layer at the same size and weight?
  3. Are all categories other than necessary switched off by default?
  4. Does the banner explain purposes and third parties in language an ordinary customer understands?
  5. Can users change their choice through a permanent link or icon?
  6. Does the solution store proof of the choice with time and version?
  7. Are YouTube, maps and social media set up as click-to-load?
  8. Can the banner be operated by keyboard and read by a screen reader?
  9. Is the cookie policy up to date with the tools you actually use today?
  10. Are new tags approved by one responsible person before they go on the site?

The cookie rules are one part of a bigger picture. Read our guide to GDPR for websites and apps too, and add the cookie check to your website launch checklist. If you get a new website with us, we are happy to help you set up consent correctly and choose the lightest way to measure. See our pricing, or get a fixed price within 24 hours.

Questions about cookie banners

Do the cookie rules also cover localStorage and pixels?
Yes. The rules concern storing and accessing information on the user’s device, whatever the technology. That covers cookies, localStorage, sessionStorage, tracking pixels and in many cases fingerprinting, where a profile is built from the browser’s characteristics. The name “cookie banner” is therefore slightly misleading. The question is always whether the technology is strictly necessary for the service the user asked for. If it is not, it requires consent. Ask your developer for a list of everything the site stores on the user’s device, including what goes beyond cookies.
How often may we ask for consent again?
There is no fixed period in the rules, but consent must be current and the user’s choice must be respected. If a user has rejected, you should not ask again on every visit, because repeated prompts can pressure people into saying yes. Many companies renew consent after six to twelve months, and when you add new purposes or new vendors you must ask again. Store the user’s choice in a necessary cookie so the banner does not reappear over and over. Follow Erhvervsstyrelsen’s guidance for current practice.
May we use a cookie wall where users must accept to see the site?
It is one of the most debated questions in this area. The starting point is that consent must be freely given, so consent that is a condition for seeing the content at all is problematic. Models exist where users choose between accepting and paying, but the assessment is case by case and practice is still developing in the EU. For an ordinary company site, webshop or booking solution, our clear recommendation is to avoid it. It costs more in lost visits and trust than it gains in data. If you are considering it, get a legal assessment first.
Do we need to keep proof of consent?
Yes, you must be able to demonstrate that the user consented. A consent tool typically stores an anonymous ID, the time, which categories were accepted and which version of the banner the user saw. That is enough to document the choice without storing more personal data than necessary. If you build your own solution, it must do the same. Remember to keep previous versions of the cookie policy too, so you can show what the user was told at the time consent was given.
What about embedded YouTube videos and Google Maps?
Embedded videos, maps and social media typically set cookies or read data from the user’s device as soon as they load. They therefore require consent. The neatest solution is a click-to-load box: the user sees a still image of the video or map with a short note that the content comes from a third party, and a click loads it. Alternatively, you can host the video yourself and show a static map image with a link to directions. Both are also faster, which helps your ranking in Google.
Who enforces the cookie rules in Denmark?
Erhvervsstyrelsen (the Danish Business Authority) enforces the cookie rules themselves, meaning the rules on storing and accessing information on the user’s device. Datatilsynet enforces GDPR, which comes into play when cookies collect personal data, as analytics and marketing cookies almost always do. Both authorities have published guidance, and it is worth reading them together, because the consent requirements in practice rest on the same definition. For a specific borderline question, look to the guidance from those two authorities and to a lawyer.

Want us to build it for you?

You get a fixed-price proposal within 24 hours.

Dennis Nielsen

Dennis Nielsen

Head of Operations, Ceptiv

Free consultation

One free hour of advice before you start.

Describe your project and I will contact you as soon as possible, so we can schedule a no-obligation meeting. You leave with practical advice on how to get your project off to a good start.

  • Free
  • 1 hour
  • No obligation