Do I need a cookie banner on my website in Ireland?
If your site sets any cookie that isn't strictly necessary for it to work, yes. The rule comes from Regulation 5(3) of the ePrivacy Regulations 2011, which says you may not store information on someone's device, or read information already there, without their consent. Regulation 5(5) carves out one exception: anything strictly necessary to provide the service the visitor actually asked for.
That is narrower than most people assume. A shopping basket that remembers what's in it is strictly necessary. Knowing how many people visited last month is not.
A plain brochure site with no analytics, no map and no video may genuinely need no banner at all. Most sites have at least one of those three.
What needs consent and what doesn't
| What's on the page | Sets a cookie? | Needs consent? | What to do |
|---|---|---|---|
| Session, login or basket | Yes | No | Strictly necessary under Regulation 5(5). Keep it working. |
| A contact form | Usually not | No | Form data is covered by your privacy policy, not by cookie rules. |
| Google Analytics or similar | Yes | Yes | The DPC is explicit that analytics cookies need consent. Nothing may load until the visitor agrees. |
| An embedded Google Map | Yes | Yes | The embed sets cookies as soon as it loads. Block it until consent, or link out to the map instead. |
| An embedded YouTube or Vimeo video | Yes | Yes | Same as the map. Block it until consent. |
| Facebook or Instagram feeds and share buttons | Yes | Yes | These track visitors across other sites, so they need consent and a clear explanation. |
| Fonts loaded from a CDN | No | Not a cookie question | No cookie is set, but the visitor's IP address goes to the font provider. Self-hosting the font avoids the question entirely. |
What the banner actually has to do
A banner on its own isn't enough, and a badly built one is worse than none because it records consent that was never validly given. The Data Protection Commission's guidance is specific:
- Nothing non-essential loads before the visitor agrees. Not analytics, not the map, not the video. A banner that appears while the tracking is already running does nothing.
- No pre-ticked boxes. You may not use pre-checked boxes, sliders or anything else set to "on" by default.
- Rejecting must be as prominent as accepting. If there's an "accept" button, there must be an equally visible way to reject, or to manage the choice by cookie type.
- They can change their mind later, as easily as they agreed. So there has to be a way back to the settings.
- You keep a record. Consent forms part of your record of processing under Article 30 of the GDPR, so you need to be able to show who agreed to what, and when.
- Consent expires. The DPC's position is six months as the outer limit, after which the visitor is asked again.
That last pair is the part people miss. The banner is the visible bit; the record is the bit that matters if anyone ever asks.
What we do about it
Every site we host includes SolidCookie, which is our own service — we built it because we needed it for our own sites and the alternatives were priced for companies much larger than our customers.
It puts the banner on your site in your own colours, scans the site to see what is actually being set, keeps the consent record, and hosts your cookie policy so there's a page to point at. It sells on its own for €9 a month per site. On our hosting plan it's included, at no extra charge.
It helps with your GDPR compliance rather than delivering it on its own, and nothing sold in a box does — compliance also covers how you handle enquiries, emails, photos and customer records. What it does do is handle the cookie part properly, which is the part a website is most visibly judged on.
What happens next. Tell us about your business. We build the site inside 48 hours of getting your details, you look at the finished site, and you pay only if you want it. €249 for one page, €349 for up to five, then €156 a year, ex VAT, with the consent banner included. Full details on the pricing page.
Common questions
Do I need a cookie banner on a small business website in Ireland?
Only if the site sets cookies that aren't strictly necessary for it to work. Analytics, embedded maps, embedded videos and social feeds all need consent. A brochure site with none of those may need no banner at all, though it still needs a privacy policy.
Does Google Analytics need consent in Ireland?
Yes. The Data Protection Commission is explicit that analytics cookies require consent, and the tag must not load until the visitor has agreed. Turning Analytics on without a working consent banner is the most common mistake on small business sites.
How long does cookie consent last?
The legislation doesn't set a period, but the Data Protection Commission considers six months the outer limit, after which the visitor should be asked to confirm their choices again. A consent tool handles this for you.
Is a cookie policy the same as a privacy policy?
No. A cookie policy lists what the site stores on a visitor's device and why. A privacy policy covers everything else you do with people's information — enquiries, emails, bookings, customer records. Most small sites need both, and they are usually two sections of the same page.
Sources
- S.I. No. 336/2011 — European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011, Irish Statute Book. Regulation 5(3) consent requirement and Regulation 5(5) exemption.
- Guidance on cookies and other tracking technologies, Data Protection Commission. Pre-checked boxes, equal prominence for rejection, withdrawal, the Article 30 record and the six-month limit.
- Do I need consent for analytics cookies?, Data Protection Commission. Analytics cookies require consent.
- SolidCookie, our own consent service. Standalone price and what it includes.