Guides

Explained Clearly - Data Tracking Consent

Taras Shynkarenko
Taras Shynkarenko
•Updated: •6 min read
Explained clearly - Data tracking consentExplained clearly - Data tracking consent

TL;DR, Quick Answer

6 min read

Valid GDPR consent requires a real choice, clear information, specific purposes, affirmative action, and withdrawal that is as easy as giving consent.

This overview puts the topic Data tracking consent into useful context. A banner collects clicks, not necessarily data tracking consent: under GDPR the person needs a real, informed choice that is as easy to withdraw as it was to give.

This matters for analytics because many website tracking tools rely on cookies or similar technologies. In Europe and the UK, non-essential analytics and advertising technologies often require consent before they run.

The EDPB explains valid consent as freely given, specific, informed, and unambiguous, with the ability to withdraw consent later (EDPB consent FAQ). Its consent guidelines provide deeper interpretation (EDPB Guidelines 05/2020).

For tracking, that means:

  • Freely given: Users must be able to refuse without unfair pressure.
  • Specific: Separate purposes need separate choices.
  • Informed: Users need clear information about what data is collected, who receives it, and why.
  • Unambiguous: Consent requires a clear affirmative action.
  • Withdrawable: Withdrawal must be possible at any time and should be as easy as giving consent.

Pre-ticked boxes, silence, inactivity, or "by continuing to browse" are not reliable consent mechanisms.

A privacy policy alone does not create consent. Notice tells people what you do. Consent asks for permission before a specific processing activity.

For analytics, a valid consent flow should explain:

  • Which analytics tools will run.
  • Whether cookies or similar technologies are used.
  • What purposes apply: analytics, advertising, personalization, A/B testing, session replay.
  • Whether data is shared with third parties.
  • Whether data is transferred internationally.
  • How the person can refuse or withdraw.

If the banner says "we use cookies to improve your experience" while also loading ad pixels, behavioral profiling, and conversion APIs, the consent is unlikely to be informed or specific.

A hand tapping a smartphone screen, illustrating the quick accept-or-reject decision a cookie banner asks users to make.

Common problems include:

  • Only showing "Accept" on the first layer.
  • Hiding "Reject" inside settings.
  • Using low-contrast reject buttons.
  • Preselecting analytics or advertising toggles.
  • Bundling analytics and advertising into one switch.
  • Loading trackers before consent.
  • Making withdrawal harder than acceptance.
  • Treating legitimate interest as a workaround for cookies that require consent.

The EDPB Cookie Banner Taskforce reported concerns with practices such as pre-ticked boxes and reject options that are harder to find than accept options (EDPB report PDF).

Banner mistakes versus the GDPR standard
Common banner mistakes
  • Only showing "Accept" on the first layer
  • Hiding "Reject" inside settings
  • Preselecting analytics or advertising toggles
  • Bundling analytics and advertising into one switch
  • Loading trackers before consent
What the standard requires
  • Freely given: refusal without unfair pressure
  • Unambiguous: consent needs a clear affirmative action
  • Specific: separate purposes need separate choices
  • Withdrawable: leaving is as easy as joining
Each row on the left breaks the requirement on the right.

A compliant analytics setup starts before the banner design:

  1. Inventory all tags, cookies, SDKs, pixels, and scripts.
  2. Classify each purpose.
  3. Decide which tools are strictly necessary and which are optional.
  4. Block optional tools until the required consent is given.
  5. Store consent state without using it for extra tracking.
  6. Provide a persistent way to change preferences.
  7. Log enough consent evidence to demonstrate compliance.

For some low-risk audience measurement tools, certain regulators allow narrow exemptions when strict conditions are met. CNIL, for example, describes conditions for audience measurement trackers that may be exempt from consent when limited to measuring the audience on behalf of the publisher (CNIL). Do not assume every analytics tool qualifies.

Withdrawal Must Be Real

Withdrawal is where consent programs fail. If accepting takes one click, refusing or withdrawing should not require searching through a footer, logging into an account, emailing support, or navigating a maze of toggles.

Good practice:

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

  • Keep a visible cookie or privacy preferences link.
  • Let users turn off categories individually.
  • Stop future tracking after withdrawal.
  • Avoid dark patterns in the settings panel.
  • Explain whether previously collected data will be retained or deleted.

Privacy-First Alternative

The cleanest consent banner is the one you do not need because your site does not use optional trackers. Cookieless, privacy-first analytics can answer core business questions with aggregate data, no advertising IDs, no cross-site tracking, no full IP storage, and no profiling.

You still need to review local ePrivacy rules and your exact implementation. But reducing tracking is more reliable than trying to make a manipulative consent interface legally acceptable.

Consent is not a growth hack. It is a user choice. If your analytics strategy only works when users are pushed into accepting, the strategy is already telling you something.

If you rely on consent, keep enough evidence to demonstrate what happened without creating a new tracking problem. Useful records include the consent version, timestamp, categories accepted or rejected, interface language, and the mechanism used to change preferences. Avoid storing unnecessary identifiers solely for consent proof.

Also review consent after major changes. Adding a new ad vendor, session replay tool, or analytics purpose can require a fresh choice because the old consent may not cover the new processing.

A developer testing a website on a laptop in a fresh browser window, reflecting the consent QA checks described here.

Test consent like a product feature. In a fresh browser profile, load the site and confirm optional analytics, advertising, replay, and personalization scripts do not fire before a choice. Click reject and verify they remain blocked. Click accept for one category and verify only that category loads. Then withdraw consent and confirm future page loads respect the new state.

Keep screenshots or logs for each state. This gives engineering, legal, and marketing the same evidence. It also catches subtle bugs, such as a tag manager firing a pixel before the consent manager initializes or a server-side event continuing after browser consent was withdrawn.

Consent QA in four passes
1
Fresh profile, no choice made. Confirm optional analytics, advertising, replay, and personalization scripts stay silent.
2
Click reject. Verify every optional script stays blocked.
3
Accept one category. Confirm only that category loads, nothing else.
4
Withdraw consent. Confirm future page loads respect the new state.
Run each pass in a fresh browser profile and keep a screenshot or log of the result.

Test consent in the browser, not only in the banner settings. Before any choice, after rejection, after analytics-only consent, after marketing consent, and after withdrawal, inspect network calls, cookies, local storage, pixels, tag-manager triggers, SDKs, and server-side events.

If relying on a narrow analytics exemption, document the exact configuration: audience-measurement purpose, no advertising reuse, no cross-site tracking, limited identifiers, short retention, publisher-only access, and clear user information. If optional tags still fire before a valid choice, the consent layer is cosmetic.

Frequently Asked Questions

Consent that is not freely given, specific, informed, unambiguous, and withdrawable is not valid. Pre-ticked boxes, silence, inactivity, or "by continuing to browse" are not reliable mechanisms. The EDPB spells out these conditions in its consent guidance.

A privacy policy is notice, not consent. Notice tells people what you do, while consent asks permission before a specific processing activity starts. A banner that only points to a privacy policy skips the affirmative action GDPR requires.

Legitimate interest does not substitute for consent when a cookie legally requires it. Treating legitimate interest as a workaround is listed among the common cookie banner mistakes. Non-essential analytics and advertising technologies in Europe and the UK generally still need consent before they run.

Why do regulators flag reject buttons hidden in settings?

The EDPB Cookie Banner Taskforce reported concerns about reject options that are harder to find than accept options. Hiding reject inside settings, or using a low-contrast reject button, undermines the freely given requirement. Refusal is supposed to be as available as acceptance.

A consent flow should explain which analytics tools will run, whether cookies or similar technologies are used, and what purposes apply. Those purposes include analytics, advertising, personalization, A/B testing, and session replay. The flow should also cover whether data goes to third parties or moves internationally, and how someone can refuse or withdraw.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Only a narrow set does. CNIL, for example, describes conditions for audience measurement trackers that may be exempt when limited to measuring the audience on behalf of the publisher. Every other analytics tool should be assumed to need consent unless proven otherwise.

As easy as giving it. If accepting takes one click, refusing or withdrawing should not require digging through a footer, logging into an account, emailing support, or working through a maze of toggles.

Useful records include the consent version, timestamp, categories accepted or rejected, interface language, and the mechanism used to change preferences. Avoid storing extra identifiers just to prove consent, since that creates a new tracking problem.

Adding a new ad vendor, session replay tool, or analytics purpose can require a fresh choice. The consent someone gave earlier may not cover processing that did not exist yet when they agreed.

In a fresh browser profile, confirm optional analytics, advertising, replay, and personalization scripts do not fire before a choice is made. Click reject and verify they stay blocked, then accept one category and confirm only that category loads, then withdraw and check that future page loads respect the new state.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Articles