Skip to content

Compliance

Do I need a cookie consent banner

In the EU, non-essential cookies and tracking require opt-in consent before the script runs. Running analytics without it is the single most commonly enforced GDPR violation, and German data protection authorities have issued fines for exactly this configuration.

What 13x checks

This is rule compliance.cookie-consent in the public registry: Consent banner present when third-party scripts load. It runs on every audit, against the pages we actually fetched, and its result is derived from the response rather than estimated.

Surface
Compliance
Score weight
12 of the readiness score
Scope
Runs on every audited page
Applies
Only where the market or the page shape makes it relevant

Registry version 2026-07-30. Every rule is published, and the audit is deterministic — the same page produces the same finding every time.

The fix

The same text the audit hands you when this check fails on your own site.

You load third-party tracking with no consent mechanism detected: .

Two options, in order of preference:

1. Remove the tracker. A privacy-first analytics tool that sets no cookies and stores no personal data (Plausible, Fathom, or self-hosted Matomo configured without cookies) needs no banner at all. This is the cheapest fix and it removes the problem rather than managing it. 2. Add a real consent gate. The banner must block the script until the visitor opts in — not merely appear alongside it. Cookiebot, Usercentrics, Osano and Klaro all do this correctly when configured to block by category.

A banner with only an "OK" button and no genuine reject option is not valid consent under the GDPR.

Does your site have this problem?

13x checks this and 112 others against your live URL in about 30 seconds. No account, and every finding comes with the fix for your framework.

No signup. Results in 30 seconds.

More compliance checks