GDPR compliance for websites
The General Data Protection Regulation governs how personal data is processed, and it reaches any organisation handling the data of people in the EU. For a website the practical question is narrower: what may load before a visitor has agreed to it, and can you show what they agreed to.
- European Union, since May 2018
- Applies wherever you are based
- Consent must be provable
From €10 a month. No credit card, no per-visitor billing.
What the GDPR asks for
Five obligations decide what a consent banner has to do. The rest of the regulation covers processing you do elsewhere.
- Consent freely given, specific, informed and unambiguous
- Refusing must be as easy as accepting
- Nothing non-essential loads before the visitor agrees
- Consent can be withdrawn as easily as it was given
- You can demonstrate what was consented to, and when
This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.
What Consent Studio does about it
Asks before anything loads
The banner appears first, and a tag you add in the tag manager waits for the visitor’s answer by default. A third-party script already in your markup is held once you mark it with its category, then released when that category is granted. Prior consent is the requirement most tools implement partially.
- Blocks by default
- Every tag
- First party delivery
Makes refusing as easy as accepting
Reject and Accept sit on the same screen at the same weight, and that is how the banner ships. This is the design pattern regulators have named and fined most often across the EU.
- Equal weight
- One click either way
- Withdrawal in the footer
Keeps a record you can produce
Each choice is stored with a timestamp against the version of the banner text that was on screen. Demonstrating consent means showing what the visitor actually saw, not what your settings say today.
- Timestamped
- Versioned wording
- Exportable
Where sites get GDPR consent wrong
Four failures account for most of what our first scan finds on a new customer’s site, and none of them looks broken.
The banner is shown but nothing is blocked
Analytics and advertising tags fire on the same page load that displays the banner. The visitor sees a question they have not answered while the answer is already being ignored. This is the single most common finding and it is invisible without a scan.
Refusing takes more clicks than accepting
One prominent Accept button, and refusal hidden behind a Manage preferences link, then a toggle, then Save. Regulators across the EU have treated the asymmetry itself as the violation, independently of what the tags then do.
The record does not say what was agreed to
A log entry reading yes to marketing is not evidence if the banner has been reworded twice since. Without the wording attached, the record proves that somebody clicked, which is not the thing the regulation asks you to demonstrate.
It was correct when it was installed
A configuration signed off in March does not cover the pixel a campaign added in July. Nothing alerts you, because a tag firing without consent behaves exactly like one firing with it.
Essential
€10/month
For a single site that has to be compliant, and stay that way.
- Unlimited pages and displays
- 200,000 consent actions a month
- The full stack, not a starter tier
Professional
€36/month
For growing teams that run on data, and the agencies serving them.
Try Professional for FreeEnterprise
From €250/month
For a volume, or an obligation, a standard plan cannot answer.
Explore EnterpriseAgencies & Resellers
Buy at a partner rate and resell client sites at your own price.
Discover Partner ProgrammePublic Sector
Government, healthcare and education run on Enterprise.
See Enterprise
Running under rules like these, in more than one country
Other rules that may apply to you
Common GDPR questions
Does the GDPR apply to my site if I am not in the EU?
Yes, if you offer goods or services to people in the EU or monitor their behaviour, which includes running analytics on visitors from the EU. Where your company is registered does not decide it. Where your visitors are does.
Do I need consent for analytics cookies?
In almost all cases yes, because analytics is not strictly necessary to deliver the page a visitor asked for. Some supervisory authorities have described narrow conditions for genuinely privacy-preserving first party measurement, and those conditions are narrower than most implementations meet.
Is a cookie banner enough on its own?
No. The banner asks the question and the regulation is about what happens next: nothing non-essential may load before the answer, the answer has to be respected afterwards, and you have to be able to demonstrate what it was. A banner with nothing enforcing it satisfies none of those three.
What is the difference between the GDPR and the AVG?
Nothing substantive. AVG is the Dutch name for the same regulation, and DSGVO is the German one. They are the same law, which is why this is one page rather than three, and why the old separate Dutch page now redirects here.
How long does consent last?
The regulation sets no fixed period, and asking again at a sensible interval is the usual practice. What matters more is that withdrawal stays as easy as granting was, which in practice means a way back into the banner from every page rather than a buried settings link.
Does Consent Studio make us compliant?
No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.
Where is our consent data stored?
In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.
Get Started with the Full Consent Stack
Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.
Read the documentation
Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.






