Skip to main content

Menu

Choose a theme and configure high-contrast mode. Preferences are saved in your browser only.

User Preferences

Theme

Pick a palette or follow your system preference.

High Contrast

Sharper text and borders. System follows your OS setting.

Andrea Tenderocookie-consent, privacy, gdpr

What marketers get wrong about cookie consent

More than a decade has passed since cookie consent laws started to appear to protect users, and even though it is mandatory for website owners to comply with these laws, we still see a lot of marketers being quite lost regarding user consent.

We understand that legal documents are sometimes difficult to understand and especially to apply correctly, but after all these years, there’s a responsibility regarding our users’ data, and we have to act to protect it. Choosing the most common way to address cookie consent is usually the worst option, but that doesn’t mean it has to be difficult to implement. Zest, for example, is a straightforward, free, and accessible solution.

If you suspect that you might be doing something wrong with cookie consent, or you’re just curious to know what others get wrong, here are some of the most widespread misconceptions marketers have regarding cookie consent.

We thought this was already common knowledge, but after checking multiple websites we noticed that it’s not. Cookie consent policies change from country to country. Sometimes geographical areas adopt a common framework through organizations like the European Union, but there isn’t a single worldwide standard for cookie consent.

When deciding which consent policy to follow, the best approach is to identify your audience and be aware of the different requirements that come with being on the World Wide Web. If your website is accessible globally, complying with only one country’s rules may not be enough. You should consider where your visitors are located and choose a consent solution that adapts accordingly or follows the strictest applicable requirements whenever possible.

For example, the European Union generally requires users to actively opt in before non-essential cookies are placed, while other jurisdictions may have different requirements or focus more on opt-out mechanisms. Building your consent experience around clear choices and explicit user action is often the safest and most user-friendly approach.

Ultimately, cookie consent shouldn’t be about doing the bare minimum to satisfy a legal requirement. It should be about respecting your users’ privacy regardless of where they are located. If your consent solution puts users in control of their data from the start, you’re far more likely to meet both legal expectations and your users’ trust.

Some marketers still don’t understand what data requires consent when it comes to cookies, and it shows. The confusion usually starts with how cookies are classified. Cookies can be classified in three ways: by purpose, by origin, and by lifespan. However, only one of these classifications actually determines whether consent is required: the purpose classification.

The purpose classification is the one that matters for consent, as cookies fall into two broad categories:

  • Strictly necessary cookies: These are essential for the website to function properly. They enable core features such as security, authentication, load balancing, and shopping carts. Because they are necessary to provide the service requested by the user, they do not require consent, only that users are informed about them.
  • Non-essential cookies: These include analytics, advertising, personalization, and social media cookies. Since they are not required for the website to function, users must give their consent before they are stored or accessed.

Yes, the other two classifications also provide useful information, but they don’t determine whether consent is required. The deciding factor is always the cookie’s purpose.

For example, a first-party analytics cookie and a third-party advertising cookie can both require consent because neither is strictly necessary. The same applies to a cookie’s lifespan. A persistent cookie may be strictly necessary and not require consent, while a session cookie used for analytics does require consent. In other words, it doesn’t matter who sets the cookie or how long it lasts, what matters is why it’s being used.

3. That all data provided needs the same security level

Not all data provided by users is the same, so it shouldn’t be handled the same way. Saving the items in a user’s shopping cart doesn’t require the same level of protection as storing their payment card details or account credentials.

The level of security should always match the sensitivity of the data and the potential impact if it were exposed. While most marketers don’t intentionally collect special category (sensitive) personal data, they regularly handle personal information such as names, email addresses, phone numbers, purchase history, and browsing behavior. Even if this data isn’t considered sensitive under the GDPR, it still deserves appropriate security measures to protect users’ privacy.

The key takeaway is simple: not all personal data carries the same level of risk, so not all of it requires the same level of protection. Organizations should assess the risks associated with the data they collect and apply security measures accordingly.

This is probably the most common misconception regarding cookie compliance. Many marketers think that installing a plugin that claims to comply with cookie laws is the easiest way to implement a cookie banner. What they don’t tell you is that the majority of these plugins don’t fully comply with the law. They often lack regular updates, include questionable design choices, and fail to meet key legal and technical requirements, leaving websites exposed to compliance risks and potential penalties.

Among the most common compliance issues we’ve found in popular cookie consent plugins are:

  • Poor banner design, including accessibility issues and questionable design choices, such as using different sizes or colors for the Accept and Decline buttons to influence users’ decisions.
  • Payment-related issues that can remove the banner from your site without warning, leaving you without any cookie consent mechanism.
  • Support for only one legal framework, leaving your website without proper protection in other geographical regions. In addition, some plugins don’t allow you to manually update the legal framework, forcing you to wait for the provider to implement changes.
  • Cookies firing before consent has been obtained from the user.
  • Conflicts with other plugins or themes that prevent the banner from appearing or functioning correctly.
  • Poor mobile responsiveness, making it difficult for users to interact with the banner on smaller devices.

The reality is that installing a plugin doesn’t automatically make your website compliant. A cookie consent solution still needs to be configured correctly, maintained over time, and regularly reviewed to ensure it complies with the regulations that apply to your visitors. We’ve written about the hidden cost of “free” consent banners and why most cookie banners are probably illegal.

5. That you don’t have to make it accessible for everyone

Like the previous misconception, this is a general issue as hardly any marketer pays enough attention to accessibility. But when it comes to cookie consent, it’s even more important. An inaccessible cookie banner can prevent people with disabilities from being properly informed about how their data is managed and from exercising their privacy choices.

Besides creating a poor user experience, an inaccessible consent banner can also lead to compliance issues. If some users cannot easily understand or interact with your cookie preferences, you cannot be certain that everyone has been given the same opportunity to make an informed decision.

Making your cookie consent banner accessible should be a priority. Unfortunately, many cookie consent plugins that look great from a design perspective are not accessible in practice. They may not work well with screen readers, keyboard navigation, or sufficient color contrast, making it difficult (and sometimes even impossible) for some users to manage their privacy preferences.

Moreover, the language used should be easy to understand. Users should know exactly what they are consenting to without having to interpret legal jargon or confusing wording. Compliance is important, but it’s not enough if users can’t make an informed decision.

Accessibility isn’t just another box to tick. It’s part of respecting your users and ensuring that everyone has equal access to information and control over their personal data.

6. That complying with laws is enough

There is a lot more to cookies than simply complying with the law. Security, how users’ data is stored, and how consent is managed are just as important.

For example, users’ consent preferences should be stored securely and updated every time a user changes them. If that information is stored on a third-party server, you’re not going to have the same level of control over how it is stored, managed, or protected.

We recommend that you are the one collecting and storing that information so you can decide how it is managed, secured, and retained. If you leave that responsibility to a third party, such as a cookie consent plugin, you may end up facing problems that affect your website (when, for example, losing access to consent records if you switch providers to unexpected service interruptions or additional costs).

Compliance is the starting point, not the finish line. The way you manage consent behind the scenes is just as important as collecting it in the first place.

Some marketers add their cookie consent banner and then forget about it, thinking it will remain compliant forever. But that’s simply not true. Cookie regulations are constantly evolving because their main goal is to protect users as the internet changes. And we all know how fast the internet evolves. You only have to look at how AI has changed the way data is collected, processed, and managed.

Your cookie declaration should be reviewed regularly and updated whenever necessary. As we mentioned before, many marketers trust that their cookie consent plugin will automatically keep everything compliant, but that doesn’t always happen. You need to check it yourself. And, to be honest, it’s much better to stay informed about cookie regulations than to rely entirely on a third-party tool. That way, you’ll know your website is actually compliant and avoid the potentially significant fines that come with getting it wrong.

Stay up to date with cookie regulations, understand how they affect your website, review your cookie declaration regularly, and update it whenever needed. Don’t activate your cookie consent banner and then forget about it. If you’re not sure where to start, we put together a 101 guide on dealing with cookie consent that walks through the basics.

8. That hiding withdrawal is better

Last but not least, hiding the option to withdraw consent from users might seem like a great way to keep collecting their data, but it’s actually a terrible idea from a compliance perspective. Some marketers think they’ll get better results by making the withdrawal option difficult to find, but they’re sailing close to the wind.

Most cookie regulations are very clear about the importance of transparency. If users can easily accept cookies but struggle to withdraw their consent, your website could be considered misleading or even deceptive. Is collecting a little more data really worth the risk of receiving a significant fine?

We always recommend being as transparent as possible when it comes to cookie consent. Make it just as easy for users to withdraw their consent as it is to give it. Not only will this create a better experience for your users, but it will also help you stay compliant and avoid unnecessary penalties.

Conclusion

As you’ve seen, there are several misconceptions about cookie consent banners that can lead to legal issues, affecting not only your website but also your business financially. These mistakes are far more common than you might think. We’ve seen them on countless websites that believe they’re fully compliant with cookie regulations when, in reality, they are far from it. If a supervisory authority reviews their implementation, the result could be significant fines.

We recommend reviewing every point covered in this article and, above all, choosing a cookie consent solution that you can manage yourself instead of relying entirely on a third-party plugin. Make sure your banner is accessible, easy to understand, and transparent about how users’ data is handled. Finally, stay up to date with cookie regulations and review your implementation regularly. Cookie compliance isn’t something you should leave to luck, it’s far more important than most people think.

Andrea @ FreshJuice

Own your cookie banner.

Zest is free and MIT-licensed, and it doesn't phone home to anyone.
Drop the script in and you're done.