
Cookies and GDPR: Compliance Guide for Cookie Banners 2026
EDPB and AKI have tightened cookie banner rules for 2024-2026. 'Accept all' dark patterns are no longer permitted. Learn the new requirements.
Author: Meiko Neuman
Founder and web strategist, Kodulehe Haldus
What are cookies from a legal perspective?
Cookies are text files that a website stores on a user's device. According to the GDPR and the ePrivacy Directive, they are divided into:
| Type | Example | Consent required? |
|---|---|---|
| Strictly necessary | Session ID, shopping cart | No |
| Functional | Language selection | No (if set by user) |
| Analytics | Google Analytics, Hotjar | YES |
| Marketing | Facebook Pixel, Google Ads | YES |
New EDPB and AKI rules (2024-2026)
The European Data Protection Board released the Cookie Banner Taskforce report in 2024. The Estonian Data Protection Inspectorate (AKI) follows these guidelines.
What is FORBIDDEN:
❌ "Accept all" button being greener or larger than "Reject all" ❌ "Reject all" hidden behind a second click (e.g., "Settings → Reject all") ❌ Pre-ticked checkboxes ❌ Cookie walls ("Accept or you cannot access content") ❌ Dark patterns (e.g., "Are you sure?" prompts after clicking Reject) ❌ Storing cookies before consent (including loading the GA script)
What is MANDATORY:
✅ "Accept all" and "Reject all" must be the same size and on the same level ✅ Granular choice (analytics separate from marketing) ✅ Withdrawing consent must be as easy as giving it ✅ A list of all cookies (name, purpose, duration, provider) ✅ No non-essential scripts loaded without prior consent
Technical Implementation
Easiest option: SaaS tools - **[Cookiebot](https://www.cookiebot.com/)** – ~€10-50/month, auto-scanning - **[Iubenda](https://www.iubenda.com/)** – Comprehensive, excellent legal templates - **[Termly](https://termly.io/)** – A more affordable alternative
Free open-source options: - **[Klaro](https://klaro.kiprotect.com/)** – GDPR-compliant and highly customisable - **[Cookie Consent](https://cookieconsent.orestbida.com/)** – Minimalist and lightweight - **[CookieYes](https://www.cookieyes.com/)** – Free up to 25k impressions/month
Custom (if you have a developer): Implement [Google Consent Mode v2](https://support.google.com/google-ads/answer/10000067) – this allows GA to function, even without full consent (anonymous mode).
Google Analytics 4 and GDPR
GA4 is not GDPR-compliant by default. Take these steps: 1. Disable IP address collection (GA4 anonymises by default – verify this) 2. Disable Google signals and Ads personalisation (unless consent is given) 3. Set Data Retention to 2 months (Admin → Data Settings → Data Retention) 4. Add Consent Mode v2 5. Sign a DPA with Google (automatic for EU accounts)
Common Mistakes in Estonia
Based on our GDPR audits of Estonian websites:
- 89% of sites load GA before consent
- 76% use "Reject all" as a hidden button
- 54% do not list the cookies used
- 42% enable Facebook Pixel automatically
In 2024, the AKI issued compliance requirements to 12 Estonian companies, including two major e-commerce stores.
Fines
- France: Google €150M, Amazon €35M (2021-2022)
- Estonia: up to €20M (theoretical upper limit)
Action Plan
- Scan your site – Cookie-Script.com
- List all cookies – name, purpose, duration
- Choose a tool (Cookiebot, Klaro, etc.)
- Install Consent Mode v2
- Test – users must be able to "Reject all" with 1 click
- Maintain logs – keep consent history for 1-3 years
Further Reading
Need help setting up your cookie banner? Check out our website maintenance services.
Need help with your website?
Our team maintains, optimises and protects your website. Pricing is agreed based on scope.
Request a quoteAbout the author
Meiko Neuman — Founder and web strategist, Kodulehe Haldus. Meiko leads the Kodulehehaldus team and has spent over a decade helping companies maintain and optimise their websites for measurable business results. He writes about website management, SEO, AEO/GEO and the commercial side of the web.