Consent before anything optional
The ePrivacy rules require consent before a site stores or reads non essential cookies. For visitors in the EU, EEA and Switzerland, Velo starts with every Consent Mode v2 signal denied until they choose.
In the EU and the wider EEA, optional cookies and trackers need consent before they run. Velo starts every visitor there with everything denied, and keeps proof of each choice.
General information, checked September 2026. Not legal advice.
The ePrivacy rules require consent before a site stores or reads non essential cookies. For visitors in the EU, EEA and Switzerland, Velo starts with every Consent Mode v2 signal denied until they choose.
Consent has to be specific and informed. Visitors pick analytics, ads, functional and personalisation separately, and your tags follow what they chose.
Article 7 says you must be able to demonstrate consent. Each decision is stored as an unchangeable record with a receipt id, the region and the banner version it answered.
Withdrawing has to be as easy as consenting. A small floating button stays on the page so visitors can reopen their choices at any time.
Two pieces of European law meet on your cookie banner. The ePrivacy Directive says a site may store or read information on a visitor's device only with consent, unless it is strictly necessary for a service the visitor asked for. The GDPR then sets the standard for that consent: freely given, specific, informed and unambiguous, and given by a clear action.
In practice that means no analytics or advertising tags before a choice, a reject option as easy to find as accept, no boxes ticked in advance, and a simple way to change the decision later. Design counts too. The European Data Protection Board's cookie banner taskforce report of 2023 flags banners that offer accept on the first layer with no way to reject there, and reject buttons whose text is too faint to read.
The banner is only part of it. Your privacy notice has to explain the purposes and name the third parties, and you need to be able to show what each visitor agreed to.
From the first script tag to the first recorded choice.

Install it with the Google Tag Manager template or paste one script tag. Guides cover WordPress, Shopify, Webflow and other platforms.

Velo scans your pages, lists the cookies and scripts it finds and suggests a category for each one. You confirm or change them.

Pick colours, wording and languages. Reject sits next to accept on the first layer.

Visitors in the EU and EEA get opt in defaults, with every consent signal denied until they choose. Each choice lands in your consent log with its receipt id.
Velo handles the banner, the regional defaults and the records. These parts stay with you.
What teams ask about GDPR and cookies.
The duty to ask before placing non essential cookies comes from the ePrivacy Directive, as each EU country applies it. The GDPR sets the standard that consent must meet: freely given, specific, informed, unambiguous and as easy to withdraw as to give.
No. The Court of Justice ruled in Planet49 (2019) that boxes ticked in advance do not give valid consent, and European regulators treat scrolling or continued browsing the same way. Velo asks for an active choice.
Supervisory authorities can order changes and fine. The GDPR allows fines of up to 20 million euros or 4% of worldwide annual turnover, whichever is higher, and cookie banners are a regular enforcement topic.
Velo handles the consent layer: defaults, choices, records and withdrawal. Compliance also depends on your privacy notice, your vendors and how your tags are set up. This page is general information, not legal advice.
If you use Google advertising products with visitors in the EEA, Google requires consent signals, which you can pass through Consent Mode v2. Velo sends them for you, starting denied in the EU.
Website privacy, in one place.
Scan your site →