Blog

Do you need a cookie banner for website analytics? (GDPR and ePrivacy, 2026)

This article explains how the rules generally work. It is not legal advice. Your situation depends on your country, your other tools and how you configure them, so check with a lawyer or your data protection officer.

Cookie banners cost you data: a large share of visitors decline or ignore them, and those visits disappear from your reports. So it's worth asking whether your analytics needs a banner at all. The short answer: it depends on what the tool does on the visitor's device and what data it collects, not on the word "analytics".

Two different rules: ePrivacy and GDPR

People often mix these up, but they cover different things.

The cookie banner is mostly an ePrivacy requirement. That's why the way a tool counts visitors matters so much.

Classic analytics: why GA4 usually needs consent

Google Analytics 4 sets first-party cookies (_ga) to recognise returning visitors, and Google can use the data for its own purposes depending on your settings. Under ePrivacy that's storage on the device, so in the EU and UK it generally needs consent before it loads. Google's Consent Mode can model the visitors who decline, but those numbers are estimates.

What "cookieless" changes

A cookieless tool that stores nothing on the device and reads nothing from it does not trigger the cookie rule in the first place. There's no cookie to consent to. Such tools typically count unique visitors on the server, for example with a hash of the IP address, user agent, site and a salt that rotates every day and is then deleted, so the same person can't be recognised the next day or across sites.

Two caveats:

The CNIL exemption for audience measurement

France's CNIL allows some analytics to run without consent, even with cookies, if the tool is strictly limited to measuring the site's audience for the site owner. Among the conditions: the data produces anonymous statistics only, it isn't combined with other processing or shared with third parties for their own use, cross-site tracking is impossible, and visitors are informed and can object. The CNIL published a self-assessment tool for vendors in 2025. Other regulators have similar but not identical positions, so the exemption doesn't automatically apply everywhere.

Checklist: analytics without a banner

Where PageLens fits

PageLens doesn't use cookies or local storage and doesn't fingerprint devices. Visitors are counted with a daily-rotating hash, the IP address is never stored, and data is never used for advertising. That's the setup the checklist describes. Features that identify people, such as pagelens.identify() for signed-in users or session replay, are opt-in, and you should cover them in your privacy policy when you turn them on.

Try PageLens on your site

Create a free PageLens account: 7-day trial, no card, no cookie banner needed.

Start free trial

Keep reading