22 July 2026 / 7 min read
GDPR and cookies for a small business: what you actually need
The rule does not depend on whether you have a banner, but on which cookies you set. Here is how to tell the difference.
Cookies have become a muddle where everybody adds a banner because everybody has one, and few know why. The rule is simpler than it looks and comes down to one question: does your site set cookies that are not necessary for it to work.
Two kinds of cookies
Essential cookies are the ones without which the site does not work: a logged-in session, basket contents, a remembered language, a note that you already saw the notice. These do not require consent. Describing them in the privacy policy is enough.
Everything else, analytics, marketing pixels, remarketing, embedded videos and maps that set their own cookies, requires consent before being set. Not after, before: the cookie must not be placed until the user agrees.
Why an accept-only banner is often not enough
If you set non-essential cookies, the user must be able to refuse them as easily as they accept them. A banner offering only Accept, or with a pre-ticked box, is not valid consent. AZOP has said so plainly in its cookie guidance.
This is not theory. AZOP has issued fines over cookies: 20,000 and 30,000 euros against two gambling companies. Those were sites using marketing and analytics cookies with a banner that offered no real choice.
A worked example: this site
The site you are reading stores three things: that you have seen the notice, your chosen language, and a marker that you have already visited in this session. There is no analytics, no marketing pixels, and the fonts are on our own server so nothing loads from somebody else’s.
That is why the notice has only a confirm button: there is nothing to refuse, because nothing optional is set. Had we added Google Analytics, that same notice would immediately become non-compliant and would need a real choice.
A banner does not make a site compliant. Compliance comes from what the site does; the banner only describes it.
What a small business actually needs
- A list of the cookies the site actually sets, verified rather than copied from another site
- A privacy policy naming who processes data, on what legal basis, and for how long it is kept
- Named processors: the service your contact form goes through, the host, a newsletter tool
- Consent alongside the contact form, with a checkbox that is not pre-ticked
- A cookie notice offering a real choice if you set anything beyond the essentials
- AZOP named as the supervisory authority, with its address
The most common mistake
A privacy policy copied from another site. Such text usually lists tools you do not use and omits the ones you do. A false statement is worse than an incomplete one, because it claims something easily checked. If your policy says you share no data with third parties while your contact form goes through an external service, that is not true.
FAQ
Frequently asked questions
You do not have to ask for consent if you only set essential cookies. A short notice linking to the privacy policy is useful because it shows you know what you are doing, but it is not a consent obligation.
They usually set their own cookies as soon as they load, so consent is needed before loading. The fix is to load them only after consent, or to replace a map with an image and a link.
The statutory ceiling of 20 million euros applies to the gravest breaches by large processors and is not a realistic scenario for a small business. In practice AZOP first warns and orders compliance. The fines issued over cookies were in the tens of thousands of euros and concerned companies handling large volumes of data.
