← ALL REGULATIONS

GDPR cookie consent, and what makes it valid.

In the EU, a site needs opt-in consent before it sets any cookie that is not strictly necessary. The ePrivacy Directive sets that rule, and the GDPR defines valid consent: freely given, specific, informed, an active choice, and as easy to withdraw as to give.

GDPR at a glanceOpt-in before tracking
Applies to
Any site that stores or reads cookies on devices in the EU or EEA, wherever the site is based
Cookie rule
ePrivacy Directive, Article 5(3)
Valid consent
GDPR, Articles 4(11) and 7
Enforced by
National regulators, such as CNIL in France, IMY in Sweden and the DPC in Ireland
Penalties
GDPR fines up to €20 million or 4% of worldwide annual turnover. Cookie rules are often enforced under national law.
WHAT GDPR REQUIRES

Five things every EU cookie banner has to get right.

THE RULEAsk before setting non-essential cookiesAnalytics, advertising and most personalisation cookies need consent first. Only cookies strictly necessary for a service the visitor asked for are exempt.
WITH KATLAIn GDPR mode, the cookie guard refuses every cookie outside the functional category until the visitor chooses, and deletes any that were set before it ran.
THE RULEMake refusing as easy as acceptingPre-ticked boxes are not consent (the Planet49 ruling, 2019), and most European regulators treat a banner with no way to refuse on its first layer as a breach. Scrolling or browsing on is not consent either.
WITH KATLAAccept, Reject and Customise sit together on the first layer of the banner, and nothing is pre-selected.
THE RULELet visitors withdraw as easily as they agreedArticle 7(3) requires withdrawing consent to be as easy as giving it, so the choice has to stay reachable after the banner closes.
WITH KATLAA floating settings icon, or your own "Cookie settings" link calling katla.open(), reopens the choice on any page.
THE RULEBe able to show the consentArticle 7(1): the site has to be able to demonstrate that a visitor consented, to what, and when.
WITH KATLAEach decision is stored with its categories, its time and a truncated IP address, and can be queried and exported through the API, CLI or MCP server. Katla keeps the latest decision per visitor.
THE RULESay what each cookie doesConsent is only informed if the visitor can see which cookies are used, what for, and who sets them.
WITH KATLAKatla scans the site, classifies every cookie it finds and generates the cookie policy from that list, in 13 languages.

GDPR questions, answered

A summary for website owners, not legal advice. Reviewed against the sources below.

Do analytics cookies need consent under GDPR?
In most EU countries, yes. The ePrivacy Directive only exempts cookies that are strictly necessary for a service the visitor asked for, and analytics is not. A few regulators, such as France’s CNIL, exempt narrowly configured audience measurement under their own conditions.
Is a cookie wall allowed?
The EDPB’s consent guidelines say that making access to content conditional on accepting cookies does not produce freely given consent. Some regulators accept a paid alternative under strict conditions, and the rules differ by country.
Does GDPR apply to a site outside the EU?
The cookie rule follows the device: it applies when a site stores or reads information on a device in the EU. The GDPR itself applies to companies outside the EU that offer goods or services to people in the EU or monitor their behaviour.
How long does a consent last?
The law sets no fixed period, and regulators expect you to ask again after a reasonable time: France’s CNIL recommends about six months. Katla stores a choice for 12 months.
Where does Katla keep consent records?
In the EU. Katla runs in AWS’s eu-central-1 region, in Frankfurt, and stores each record with a truncated IP address rather than the full one.
RELATED REGULATIONS

See what your site sets before anyone asks.

The free plan scans your site, classifies every cookie and generates the policy, without a card. The cookie checker needs no account at all.

Get started free