Do you need a cookie banner for website analytics?
If your analytics sets cookies, as Google Analytics does, you need a banner for visitors in the EU and UK. You can usually get rid of it by switching to analytics that stores nothing on visitors' devices and only counts in aggregate, then telling visitors about it and giving them a way to opt out. That's enough in the US, Canada and the UK. In the EU it depends on the country: France exempts analytics like this if it meets strict conditions, and other regulators haven't said either way. This post covers what to do in each case, and the paperwork that goes with it.
What to do, by where your visitors are
| Where your visitors are | With cookie-based analytics (e.g. GA4) | With analytics that stores nothing (e.g. Foresite) |
|---|---|---|
| US | No opt-in banner for analytics alone. Offer an opt-out if data is sold or used for targeted ads | Mention it in your privacy notice |
| Canada | Notice and implied consent are usually enough outside Quebec | Mention it in your privacy notice |
| UK | Banner, unless your setup fits the new statistics exception | Privacy notice plus an opt-out link |
| France | Banner | No banner, if the tool meets the CNIL's conditions |
| Rest of the EU | Banner | Uncertain; see step 4 below |
Your dashboard's country report tells you which rows apply to you.
Step 1: Check what your analytics does
Two separate rules decide this. People say "GDPR cookie banner", but the banner comes from the other one.
- The device rule: do you store or read anything on the visitor's device? In the EU that's Article 5(3) of the ePrivacy Directive, and in the UK it's regulation 6 of PECR. If you do, you need consent unless an exemption applies. It covers any information, personal or not (Planet49, paragraphs 68 to 71).
- The data rule: do you process personal data, and on what lawful basis? That's the GDPR. An IP address can count as personal data even for a website that can't name anyone (Breyer).
To check your current setup, open your site, then DevTools, then the Application tab. Look under Cookies and Local Storage for anything your analytics set. If you're on Google Analytics 4, you'll find _ga and _ga_<container-id>, cookies that recognise the same browser for two years by default. No exemption anywhere in the EU covers those. The UK's new exception rarely does either, because Google can use the data for its own products and GA connects to advertising. Google requires you to collect consent where the law calls for it anyway (EU user consent policy, and consent mode for European traffic since March 2024).
So with GA4 and EU or UK visitors, you're choosing between keeping the banner and switching tools.
Step 2: Switch to analytics that collects little
A banner costs you more than it looks.
- You lose visitors from your reports. After the GDPR's opt-in rules arrived, an online travel site could see 12.5% fewer consumers (Aridor, Che and Salz, RAND Journal of Economics, 2023). A lawful banner has to make "Reject" as easy as "Accept" (the CNIL fined Google €150 million over exactly that), and every visitor who rejects disappears from your stats.
- Google's guesses won't fill the gap. GA4's behavioural modelling only switches on at 1,000 events a day from visitors who declined and 1,000 daily users who accepted. Most small sites never get there.
- Your pages get slower. A consent tool is one more third-party script on every page, as we measured in another post.
The regulators who've written exemptions agree on what analytics has to look like to qualify: the CNIL's conditions and self-assessment, the UK's new statistics exception, and the EDPB's comments on the EU's proposed one. Look for a tool where:
- it measures your site, for you, and nothing else;
- the vendor is your processor and never uses the data for itself;
- nobody is followed across sites, or kept recognisable for long;
- the output is aggregate statistics, not profiles of individuals;
- IP addresses are used briefly, if at all, and location stays coarse;
- nothing feeds advertising, retargeting or ad-campaign measurement;
- visitors are told about it and can object.
Foresite was built to that list. It stores nothing on visitors' devices: no cookies, no localStorage. It counts a visitor once a day using a one-way hash of their IP address and browser details, mixed with the site and a random secret that's destroyed at the end of each day. That's the combination the CNIL recommends for device-based identifiers: one specific to each site, with a time limit. The IP address and browser details stay in memory just long enough for that hash and a country and region lookup, and are never written to disk. Nobody, including us, can follow a visitor from one day to the next or from one site to another. We act only as your processor, under a data processing agreement, and never use your visitors' data for ourselves. The tracking script is open source, so you can check exactly what it sends. How we count has the details.
Step 3: Do the paperwork
Switching tools removes the cookies. It doesn't remove your duty to tell people. These three things take about half an hour, and you need them in every country.
1. Add a paragraph to your privacy notice. For Foresite, you can adapt this:
Replace example.com with your own domain.
2. Give visitors a way to object. That link is the opt-out. Opening it stores one flag in that visitor's browser, at their request, and Foresite stops counting them. The UK exception requires "a simple means of objecting, free of charge", and the CNIL recommends one too.
3. Write down your legitimate-interests assessment. In the EU and UK, briefly processing IP addresses needs a lawful basis under the GDPR, usually legitimate interests (Article 6(1)(f)). Keep a short note answering three questions:
- Purpose: why do you need analytics? For example, to see which pages people use and where they come from, so you can improve the site.
- Necessity: is there a less intrusive way? Aggregate counts with nothing stored on devices is about as light as analytics gets.
- Balance: does it override visitors' interests? No profiles, no cross-site tracking, no advertising, IP addresses not stored, and an opt-out on offer.
That note covers the data rule. In the EU it doesn't settle the device rule, which is step 4.
Step 4: Decide what to do about the EU
Here's the part most "no banner needed" claims leave out. In October 2024, the European Data Protection Board (EDPB, the EU's regulators acting together) adopted Guidelines 2/2023, which say the device rule isn't only about cookies. A script that makes the browser send information "clearly falls within the scope" (paragraph 33), and so can collecting the IP address (paragraph 55) or the User-Agent (paragraph 43). Every analytics script does those things, cookieless ones included, ours included.
Being in scope "does not systematically mean that consent needs to be collected" (paragraph 56). It means going without a banner rests on an exemption, and the EU leaves exemptions to each country's regulator. The EDPB and the European Data Protection Supervisor said in February 2026 that audience measurement has no exemption of its own under the current law (Joint Opinion 2/2026, footnote 103). The Commission's Digital Omnibus proposal would add one for aggregate audience measurement by a site "solely for its own use", but it's still waiting for a committee vote in the European Parliament, so don't plan on it yet.
So, for your EU visitors:
- If they're mostly in France, the CNIL's exemption is the clearest in Europe. Its developer guidance notes that "most large audience measurement offerings do not fall within the scope of the exemption, regardless of their configuration". Lightweight tools are what it has in mind. Check your tool against its self-assessment. Foresite doesn't meet every point yet; see below.
- If they're elsewhere in the EU, you have two reasonable options. One is to run privacy-preserving analytics without a banner, with the paperwork from step 3, on the grounds that a regulator would treat it as low-risk. The CNIL, the UK and the Commission's own proposal all point that way, but no regulator in your country has confirmed it. The other is to show a banner to EU visitors only, so the rest of your audience never sees it.
- If the EU is a small share of your traffic, the first option is what most small sites choose. If EU visitors are your core market or your sector is regulated, such as health or finance, ask a lawyer.
Why Foresite, and where it falls short
Foresite is built to make steps 2 and 3 easy: nothing on the device, no IP addresses kept, no way to follow anyone, processor only, a ready-made opt-out link, and a script you can read. It costs from $4 a month for unlimited sites, with a 7-day free trial, no card needed.
We'd rather you hear the limits from us:
- The EDPB's reading applies to us too. Our script sends a request, and our server receives the IP address and User-Agent, so in the EU our case for no banner rests on an exemption, like every cookieless tool's.
- As shipped, we don't tick every CNIL box. Foresite reads UTM campaign tags, recognises ad click IDs to label paid traffic, and supports goals and revenue. The CNIL wants campaign and conversion tracking off by default. It also suggests rounding counts to the nearest ten and keeping data no longer than 25 months. We show exact counts and keep data for as long as you're subscribed. We haven't published a CNIL self-assessment.
- "Unique visitors" means unique per day. The same person on Monday and Tuesday counts twice. That's the price of not recognising anyone.
No analytics tool can make your site "GDPR compliant". That depends on everything else your site does too. What a tool can do is collect so little that the questions above have short, easy answers.
Checklist: questions for any analytics tool
Ask these of whatever you're considering, ours included, and get the answers in writing:
- Does it store anything on the device? Check DevTools' Application tab.
- What does the script send, and can you read the script?
- Is anything that identifies a visitor kept beyond a day, or shared across sites?
- What happens to IP addresses? Stored, truncated or discarded? How precise is the location?
- Is the vendor only your processor? Look for a data processing agreement, and for clauses that let the vendor use your data for benchmarks, product improvement or advertising.
- Does it connect to ad platforms, or offer session replay, cross-site tracking or user-level profiles?
- Where is the data stored, and for how long?
- Can visitors opt out, with a link you can put in your privacy notice?
The shorter and duller the answers, the stronger your case for going without a banner. If a tool keeps a long-lived visitor ID or feeds advertising, plan on a banner.
The rules in more detail
European Union
Article 5(3) allows storing or reading information on a device without consent only to transmit a communication or where "strictly necessary" to provide a service the user "explicitly requested". Analytics isn't what the visitor asked for, so on a strict reading it doesn't qualify. EU regulators said so in Opinion 04/2012, while calling first-party analytics low-risk. Each country writes the directive into its own law. France's CNIL exempts audience measurement used only for the site's own audience that produces only anonymous statistics, isn't combined with other data or passed to third parties, and doesn't track people across sites. Its July 2025 self-assessment adds that the vendor must act only as the site's processor, and recommends location no finer than the city and a way for visitors to object.
United Kingdom
The Data (Use and Access) Act 2025 added new exceptions to PECR, in force since 5 February 2026. Storing or reading information no longer needs consent if its sole purpose is collecting "information for statistical purposes about how the service is used with a view to making improvements", the information isn't shared except to make those improvements, visitors are clearly told about it, and they get "a simple means of objecting, free of charge". The ICO's guidance adds that it's about "how your service is used, not about who uses it", an outside provider must be your processor, and it "does not apply to purposes related to online advertising".
United States
No US law requires an opt-in banner for analytics. About 20 states have comprehensive privacy laws (IAPP tracker), and they work on opt-out: visitors can refuse the "sale" of their data, its "sharing" for targeted advertising (as California puts it), and profiling. Analytics run by a service provider purely for you usually triggers none of these. Ad pixels usually do. Some states require opt-in consent for sensitive data such as health information, which matters if your pages reveal it. The bigger US risk has been lawsuits under old wiretap laws, especially California's CIPA, over pixels and chat widgets. SB 690, signed on 30 September 2026, ends private "pen register" suits over website tracking from 1 January 2027, but leaves the wiretap claims in place.
Canada
PIPEDA has no cookie-specific rule. It requires meaningful consent, which can be implied when the information isn't sensitive, the use is within people's reasonable expectations, and there's no meaningful risk of significant harm. Even for tracking-based advertising, the privacy commissioner accepts opt-out consent under conditions. Quebec is stricter: Law 25 (section 8.1) requires you to tell people about technology that can identify, locate or profile them, and to keep those functions off until they turn them on. PIPEDA's proposed replacement, Bill C-36, is awaiting second reading.