This article explains how the rules generally work. It isn’t legal advice, and the details differ by country and by how a tool is configured. If consent decisions carry real risk for your business, check with a lawyer or your data protection officer.
“No cookies, so no cookie banner” is one of the most repeated lines in privacy-friendly analytics marketing. It’s often roughly right, but it skips over how the rules actually work. If you understand the two separate questions underneath it, you can make a sensible decision for your own site instead of trusting a slogan.
Two different laws, two different questions
In the EU and UK, analytics touches two sets of rules:
- The ePrivacy rules (in the EU, the ePrivacy Directive as implemented by each country; in the UK, PECR). Their famous Article 5(3) says that storing information on, or reading information from, a user’s device needs consent, unless it’s strictly necessary for a service the user asked for. This is the “cookie law”.
- The GDPR. It applies whenever you process personal data, meaning information about an identified or identifiable person. It requires a legal basis (consent is only one of six), transparency, data minimisation and so on.
A cookie banner is mostly about the first question. Your privacy policy and your choice of legal basis are about the second. A tool can do well on one and badly on the other.
The ePrivacy rule isn’t really about cookies
Here’s the part slogans leave out. Article 5(3) talks about storing or accessing information on the device. It doesn’t care whether that’s a cookie, localStorage, sessionStorage, IndexedDB or a fingerprint computed from device characteristics. European regulators have said as much in their guidance on tracking techniques.
So when you evaluate a “cookieless” analytics tool, the better questions are:
- Does it store anything on the visitor’s device? What, and for how long?
- Does it read device characteristics to build an identifier (fingerprinting)?
- Can what it stores be used to recognise the same person across other sites?
Tools answer these differently. Some store nothing at all and count visitors with a daily-rotating hash computed on the server. Some keep a random ID in localStorage so they can recognise a returning browser. Cool Analytics is in the second group: it sets no cookies, but it keeps a random, first-party ID in the browser’s storage so it can tell a new visit from a returning one and show a visitor’s journey. It never uses the IP address as an identifier and never shares data across sites.
When analytics may not need consent
Several European regulators accept that simple audience measurement can be done without consent if it’s tightly limited. France’s CNIL is the best-known example: it has published conditions under which audience-measurement trackers are exempt from consent. Paraphrased, they include:
- The purpose is strictly limited to measuring the audience of the site, for the site owner only.
- The data produces anonymous statistics only and isn’t combined with other data or passed to third parties.
- It doesn’t track people across different sites or apps.
- Identifiers and data are kept for limited periods (the CNIL’s guidance uses 13 months for trackers and 25 months for the data).
- Visitors are told about it and can object.
Other countries are stricter or looser, and the EU-level reform of the ePrivacy rules has been stuck for years. In the UK, recent legislation widened the exemptions for analytics, with conditions. That’s why the honest answer is “it depends where your visitors are and how the tool is set up”.
What privacy-friendly analytics changes under GDPR
On the GDPR side, a tool built for privacy usually makes your life much easier:
- No IP storage. IP addresses are personal data. Good tools use them only briefly (for example to look up a country or city) and then discard them.
- No names, emails or ad IDs. Visitors are random IDs or nothing at all, not profiles.
- No data sharing. The data isn’t used for advertising or sold.
- Short, known retention. You know how long data is kept and can delete it.
Many site owners rely on legitimate interests as the GDPR legal basis for this kind of minimal, first-party measurement, with a clear explanation in the privacy policy and an easy way to opt out. Whether that’s right for you depends on your situation, but it’s a far easier position to defend than shipping full advertising trackers.
How this compares to Google Analytics
Google Analytics 4 uses cookies (_ga and friends) by default, sends data to Google and can link with advertising products. In most EU countries that means a consent banner, and GA4’s Consent Mode exists precisely to deal with visitors who decline. Several European regulators have also ruled against specific Google Analytics setups in the past over data transfers to the US, although the 2023 EU–US Data Privacy Framework changed that picture.
The practical effect: with GA4 and a banner, every visitor who clicks “Reject” disappears from your reports. With a minimal, first-party tool you may not need to ask, and if you do ask, the request is much easier to justify. We dig into the numbers side of this in why GA4 and privacy-friendly analytics never agree.
A practical checklist
For any analytics tool you’re considering:
- Read its documentation on exactly what it stores in the browser and for how long.
- Check whether it stores IP addresses, and whether it fingerprints.
- Check where data is hosted and who can access it.
- Check whether data is used for anything besides your own statistics.
- Look up your main audience’s regulator guidance (CNIL in France, the ICO in the UK, and so on).
- Describe the tool in your privacy policy in plain language, and offer an opt-out.
- If you sell to cautious customers (healthcare, public sector, finance), get a lawyer’s sign-off.
Not sure where you stand? Our free “Do I need a cookie banner?” checker walks through these questions in a couple of minutes. It gives you a direction, not a legal opinion.
Offering an opt-out
Even if you decide consent isn’t required, letting people opt out is good practice and builds trust. With Cool Analytics, you can call window.hb.ignore() from a “Don’t measure my visits” link in your privacy policy, and that browser won’t be counted again. Site owners can also open their own site once with #hb-ignore at the end of the URL to exclude themselves.
<a href="#" onclick="window.hb && window.hb.ignore(); this.textContent = 'Done — you won\'t be counted.'; return false;">
Don't measure my visits
</a>The short version
- “Cookieless” is about the technology. Consent rules are about storing or reading anything on the device, cookie or not.
- Privacy-friendly analytics drastically lowers your GDPR risk because it collects so little personal data.
- Whether you can skip the banner depends on the tool’s exact behaviour and your visitors’ countries. Several regulators exempt tightly limited audience measurement.
- Be transparent, offer an opt-out, and check the guidance that applies to you.
If you’re comparing tools on this front, our pages on Cool Analytics vs Google Analytics and vs Plausible set out what each one stores.