Guide · Rules and requirements
Cookie banner rules: what is allowed and what is required?
The short answer: you need active consent before setting cookies or similar technologies that are not strictly necessary, and rejecting must be as easy as accepting. Analytics and marketing cookies therefore require consent, while cookies for the basket, login and security do not. Here we go through the rules, the dark patterns that keep appearing, and how to measure traffic with fewer cookies or none at all.
10 min read · Updated 1 October 2026
A marketing lead opens Google Analytics and sees that traffic has dropped by a third since the new cookie banner went live. Panic spreads, and someone suggests making the “Reject” button small and grey. That is exactly the reaction the rules are written to prevent, and it does not solve the problem. Traffic is probably the same as before. The measurement now simply counts only the users who said yes. The rest of this guide is about how to follow the rules and still get the numbers you need.
In Denmark the rules live in the cookie executive order, which Erhvervsstyrelsen enforces, and in GDPR, which Datatilsynet enforces. We build websites and apps, and our angle is the practical and technical one. Use this guide as a practical overview, and check specific questions in the authorities’ guidance or with a lawyer.
What do the rules say about cookie banners in Denmark?
The main rule is simple: you may only store or read information on the user’s device if it is strictly necessary to deliver the service the user explicitly asked for, or if the user has given informed consent. Consent must meet the GDPR standard. That means it must be freely given, specific, informed and given through an active choice. Scrolling on, clicking around or leaving a pre-ticked box in place does not count as consent.
- No non-essential cookies or scripts before the user has said yes.
- Reject must be as easy as accept, typically a button at the same level and of the same size.
- Users must be able to choose categories, such as analytics and marketing separately.
- Information about purpose, duration and which third parties receive data.
- Consent must be as easy to withdraw as it was to give, for example through a link in the footer.
- The choice must be documented, so you can show what the user agreed to.
Which cookies require consent, and which do not?
The line is drawn at “strictly necessary”. It is a narrow category. A cookie is necessary if the site cannot deliver what the user asked for without it. The fact that the company needs statistics is a good business reason, but that does not make analytics cookies strictly necessary in the legal sense. The table shows the typical categories.
Typical categories and the common assessment. Borderline cases depend on the specific setup and should be checked against Erhvervsstyrelsen’s guidance.
| Category | Examples | Consent needed? |
|---|---|---|
| Strictly necessary | Shopping basket, login session, security, stored consent choice, load balancing | No |
| Preferences | Language or currency the user has chosen | Often no, when the user asked for it, but assess case by case |
| Analytics | Google Analytics, heatmaps, session recordings | Yes |
| Marketing | Meta Pixel, Google Ads, LinkedIn Insight, retargeting | Yes |
| Embedded content | YouTube, Vimeo, Google Maps, social media | Yes, when it sets cookies or reads data |
| Chat and support | Chat widget that remembers the conversation | Depends on whether the user starts the chat |
What are dark patterns in a cookie banner?
Dark patterns are design choices that push the user towards the answer the company prefers. They are widespread in cookie banners, and EU authorities have made it clear that they can make consent invalid. If consent is invalid, you effectively have no consent, and the data has been collected without a basis. That is a poor trade for a few extra percentage points in your statistics.
Dark patterns
- A large coloured “Accept all” and a small grey link to settings
- Reject hidden in a second layer behind several clicks
- Categories switched on by default or listed under “legitimate interest”
- A close icon that counts as acceptance
- The banner returns on every visit after a rejection
Lawful and honest
- “Accept all” and “Reject all” side by side at the same size
- “Customise” as a third option with categories switched off
- Short, clear language about purposes and third parties
- A close icon that equals reject or no change
- A permanent footer link to change the choice
How do you implement a cookie banner correctly in code?
The most common mistake is technical. The banner looks right, but scripts from Google, Meta and others load as soon as the page opens, and the banner is pure decoration. Open your site in a private browser window, open the developer tools and look under Application and Network before you click anything. If you see third-party cookies or calls to tracking domains, the setup is wrong. It takes five minutes to check, and we recommend you do it today.
Map every script
List every tag, pixel, widget and embed and put each in a category.
Block by default
Non-essential scripts load only once consent for that category is given.
Show an equal choice
Accept, reject and customise on the first layer, accessible by keyboard and screen reader.
Store and document
The choice is stored in a necessary cookie and logged with time and banner version.
Test after every change
New marketing tags and widgets are checked before going live, so they do not bypass the banner.
The banner must also be accessible. A banner that traps keyboard focus, or that screen readers cannot find, is a problem under the Accessibility Act for webshops and booking sites. And it must be light: a heavy banner script can hurt your speed and Core Web Vitals, especially INP and CLS if the banner pushes content down.
Google Consent Mode
If you use Google Ads or Google Analytics in the EEA, Google requires you to pass on the user’s consent status through Consent Mode. In the basic setup, Google’s tags do not load at all before consent. In the advanced setup, cookieless signals are sent even from users who rejected, and Google uses them to model figures. The legal assessment of the advanced variant is debated, so we recommend the basic setup unless a lawyer has approved otherwise.
Can you measure traffic without cookies?
Yes, to a degree. Some analytics tools are built to store nothing on the user’s device and not to identify individuals. They count page views, sources, devices and conversions at an aggregate level. Configured correctly, many assessments find they can be used without cookie consent, but GDPR still applies to the processing of IP addresses and similar on the server, and the assessment depends on the specific tool and its settings. Check the vendor’s documentation and read Erhvervsstyrelsen’s guidance.
- Cookieless, privacy-friendly analytics for overall traffic and sources, ideally hosted in the EU.
- Conversions measured on the server: how many bookings, orders and enquiries actually came in?
- Google Search Console for keywords, clicks and rankings, which requires nothing on your site.
- Full analytics and ad tracking for the users who said yes, as a supplement.
- Campaign links with UTM parameters, so you can see which campaigns produce results.
The combination gives an honest picture. Orders and bookings in your own system are the numbers that matter most to the business, and they do not depend on consent. That is why we recommend building measurement of the key actions into the backend, so you can see results without adding more scripts to the site.
What does a cookie consent solution cost?
There are ready-made solutions, known as consent management platforms, from both Danish and international vendors. They scan your site, generate a cookie policy and handle documentation. The price typically depends on the number of pages and visitors, from free plans for small sites up to a few hundred kroner a month. The real cost usually sits in the setup, if the site has many scripts that must be sorted and blocked correctly.
Typical price levels. The number of scripts and third parties decides how much setup is needed.
| Solution | Typical price | Fits |
|---|---|---|
| No non-essential cookies | DKK 0 and no banner | Sites with cookieless analytics and no ad tracking |
| Ready-made consent platform | Free to a few hundred DKK/month | Most company sites and webshops |
| Setup and clean-up of scripts | DKK 3,000–15,000 | Sites with many tags from past campaigns |
| Custom consent solution in code | Part of the build | New solutions with few, known third parties |
The cheapest solution is the one few people think of: use fewer third parties. Every pixel, heatmap and widget you remove is one less thing to ask about, document and maintain. Many sites we take over carry tags from campaigns that ended years ago.
Checklist: is your cookie banner lawful?
- Open the site in a private window: are third-party cookies set before you click anything?
- Do “Reject all” and “Accept all” sit on the first layer at the same size and weight?
- Are all categories other than necessary switched off by default?
- Does the banner explain purposes and third parties in language an ordinary customer understands?
- Can users change their choice through a permanent link or icon?
- Does the solution store proof of the choice with time and version?
- Are YouTube, maps and social media set up as click-to-load?
- Can the banner be operated by keyboard and read by a screen reader?
- Is the cookie policy up to date with the tools you actually use today?
- Are new tags approved by one responsible person before they go on the site?
The cookie rules are one part of a bigger picture. Read our guide to GDPR for websites and apps too, and add the cookie check to your website launch checklist. If you get a new website with us, we are happy to help you set up consent correctly and choose the lightest way to measure. See our pricing, or get a fixed price within 24 hours.
Questions about cookie banners
Do the cookie rules also cover localStorage and pixels?
How often may we ask for consent again?
May we use a cookie wall where users must accept to see the site?
Do we need to keep proof of consent?
What about embedded YouTube videos and Google Maps?
Who enforces the cookie rules in Denmark?
Want us to build it for you?
You get a fixed-price proposal within 24 hours.
