Is a cookie banner legally required?
For most websites that set non-essential cookies, yes. The EU GDPR and ePrivacy rules require opt-in consent before tracking cookies run, the UK ICO enforces the same standard, and several US state laws require a working opt-out. A properly configured consent banner is the practical way sites meet these duties.
When consent is required
Any cookie or tracker that is not strictly necessary for the site to function needs prior opt-in consent in the EU and UK. That covers analytics, advertising pixels, chat widgets that drop identifiers, and most third-party embeds. Strictly necessary cookies, like a login session or shopping cart, are exempt.
When an opt-out is enough
US state privacy laws such as the CCPA in California generally work on an opt-out model: you may set cookies by default, but you must offer a clear way to refuse sale or sharing of data and honor browser opt-out signals like Global Privacy Control. Many sites serve both models by geotargeting their banner.
What happens without one
Regulators in Europe have issued fines to sites of all sizes for dropping tracking cookies before consent. Beyond fines, ad platforms now gate features on consent signals, so a missing or broken banner quietly degrades analytics and advertising data even where enforcement is unlikely.