Do you need a cookie banner for website analytics? (GDPR and ePrivacy, 2026)
This article explains how the rules generally work. It is not legal advice. Your situation depends on your country, your other tools and how you configure them, so check with a lawyer or your data protection officer.
Cookie banners cost you data: a large share of visitors decline or ignore them, and those visits disappear from your reports. So it's worth asking whether your analytics needs a banner at all. The short answer: it depends on what the tool does on the visitor's device and what data it collects, not on the word "analytics".
Two different rules: ePrivacy and GDPR
People often mix these up, but they cover different things.
- ePrivacy (Article 5(3) of the ePrivacy Directive, implemented as national cookie laws such as PECR in the UK) covers storing or reading information on the user's device: cookies, local storage, and in many interpretations fingerprinting. It requires consent unless the storage is strictly necessary for a service the user asked for. Analytics usually isn't strictly necessary.
- GDPR covers processing personal data, wherever it happens. It doesn't always require consent: you need a legal basis, and legitimate interest can work for privacy-friendly analytics if you collect little data and don't use it for advertising.
The cookie banner is mostly an ePrivacy requirement. That's why the way a tool counts visitors matters so much.
Classic analytics: why GA4 usually needs consent
Google Analytics 4 sets first-party cookies (_ga) to recognise returning visitors, and Google can use the data for its own purposes depending on your settings. Under ePrivacy that's storage on the device, so in the EU and UK it generally needs consent before it loads. Google's Consent Mode can model the visitors who decline, but those numbers are estimates.
What "cookieless" changes
A cookieless tool that stores nothing on the device and reads nothing from it does not trigger the cookie rule in the first place. There's no cookie to consent to. Such tools typically count unique visitors on the server, for example with a hash of the IP address, user agent, site and a salt that rotates every day and is then deleted, so the same person can't be recognised the next day or across sites.
Two caveats:
- GDPR still applies to the request itself. The IP address is personal data, even if it's only used for a moment. Good tools discard it immediately, store no identifiers, and don't share data for advertising, which supports a legitimate-interest basis.
- Regulators are widening their reading of "access to the device". The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3) argue that some tracking techniques without cookies can still fall under the rule. Tools that rely on a daily-rotating server-side hash and keep nothing on the device are generally seen as the low-risk end, but this is an evolving area.
The CNIL exemption for audience measurement
France's CNIL allows some analytics to run without consent, even with cookies, if the tool is strictly limited to measuring the site's audience for the site owner. Among the conditions: the data produces anonymous statistics only, it isn't combined with other processing or shared with third parties for their own use, cross-site tracking is impossible, and visitors are informed and can object. The CNIL published a self-assessment tool for vendors in 2025. Other regulators have similar but not identical positions, so the exemption doesn't automatically apply everywhere.
Checklist: analytics without a banner
- No cookies, local storage or fingerprinting on the visitor's device.
- No full IP addresses stored; identifiers that rotate at least daily.
- No cross-site tracking and no use of the data for advertising.
- Data kept only as long as needed, with a processor agreement (DPA) from the vendor.
- A plain-language section in your privacy policy saying what you measure and how to object.
- No other tool on the page that needs consent anyway (ad pixels, chat widgets, embedded videos). If you have those, you'll need a banner for them regardless.
Where PageLens fits
PageLens doesn't use cookies or local storage and doesn't fingerprint devices. Visitors are counted with a daily-rotating hash, the IP address is never stored, and data is never used for advertising. That's the setup the checklist describes. Features that identify people, such as pagelens.identify() for signed-in users or session replay, are opt-in, and you should cover them in your privacy policy when you turn them on.