Skip to content
FI
Security 6 min read · Updated 08/2026

Website cookies and consent in Europe

A cookie banner is only the visible part of the job. The important question is what the website stores, reads or sends before and after a visitor makes a choice. A polished banner can still sit above tracking that starts immediately.

Begin with an inventory of the site's actual technologies and purposes. Then configure the consent mechanism, explain the processing clearly and test the result. Rules can depend on national implementation and the precise setup, so a tool's marketing label is not a legal conclusion.

What cookies do

Cookies are small pieces of browser-held information used for purposes such as maintaining a session, remembering a preference or recognising a visitor. Similar privacy questions can arise from other storage and tracking techniques, so reviewing cookies alone may miss relevant behaviour.

A shopping basket and an advertising identifier do not have the same purpose. Classify technologies by what they actually do, not by the category a plugin has assigned automatically.

The EDPB explains that storing or accessing cookies generally requires informed consent, with an exception for technically necessary cookies. The precise necessity of a feature must be assessed in context. EDPB cookie guidance.

Purpose What to assess
Login or a requested basket Whether the technology is strictly necessary for the requested service
Preferences Whether the stored choice is necessary in the actual implementation
Analytics The exact tracking, configuration and applicable local rules
Advertising Consent before non-essential tracking and clear information about recipients

Do not assume that all analytics tools are identical. “Self-hosted”, “cookieless” and “EU-based” are descriptions, not automatic exemptions. Review the data flows, identifiers and relevant supervisory guidance. Where personal data is processed, the wider GDPR requirements also remain relevant.

Make the choice meaningful

Consent needs a genuine affirmative choice. Do not preselect optional purposes or interpret scrolling, closing the banner or continuing to browse as acceptance. Explain the purposes in language a visitor can understand.

Offer a clear refusal route alongside acceptance and a way to choose categories where appropriate. Avoid visual design that hides refusal or pressures the user into accepting. The EDPB's cookie-banner taskforce discusses problematic banner practices. EDPB taskforce report.

Keep a persistent way to revisit the choice, commonly a cookie-settings link. Withdrawing consent should be as easy as giving it. For an English site serving several countries, ensure that the visible explanation and controls are understandable to the intended visitors.

A consent management platform can help present choices, manage categories and retain evidence. Assess whether it integrates with your scripts, embedded media, tag manager and language versions. Check current pricing and licensing against your actual domains and traffic rather than relying on an old comparison table.

Tools such as Cookiebot and WordPress consent plugins still need correct configuration. Automated classification should be reviewed. Installing a tool does not itself establish that your site complies.

Assign ongoing ownership. A new marketing tag or embedded video can change the data flow after the initial setup. Include consent review in the normal release process, not just the original website project.

Test the behaviour, not only the banner

Open a clean browser session and inspect storage and network activity before making a choice. Then test refusing optional processing, accepting selected purposes and withdrawing consent. Repeat on important pages and mobile layouts.

Check embedded maps, videos, forms and third-party widgets. Some load from templates outside the tag manager. A banner can appear to work while those integrations behave independently.

Record the result and the configuration tested. Avoid judging compliance from a screenshot or an external scanner alone. An outside audit cannot reliably see every interaction or the complete legal context.

Keep the information and contracts aligned

Explain the controller, purposes, recipients, retention and relevant rights in the appropriate privacy information. Review processor agreements and international data flows where relevant. The EDPB lawful-processing guide provides the official starting framework.

Hosting the site in Finland does not decide how a third-party marketing platform processes visitor data. ResaHost web hosting and the data processing agreement describe the hosting relationship; your chosen tracking and customer-data uses need their own assessment.

Use the business website launch guide to include consent testing before publication. Revisit it after content and plugin changes through WordPress maintenance.

Frequently asked questions

Does a small brochure site need a banner?

It depends on the technologies used. A site using only genuinely necessary functions may not need optional consent choices, but it still needs appropriate privacy information.

Does an old banner have to be replaced?

Assess what it does now. Age alone does not answer whether its choices and technical behaviour are suitable.

Read next

Security

Small Business Cybersecurity: A Practical Action Guide

Read guide →
Security

Managed Security or DIY? Compare Scope and Responsibility

Read guide →
Security

Mobile VPN for Business: Secure Access Without Myths

Read guide →

Cookie settings

The English website does not load optional analytics or marketing tags. There are no optional cookies to choose here.

Read our cookie information for details about necessary website functionality and external services.

Read the cookie information