Custodia-AdminA cookie banner is not a consent management solution. Here's what you actually need — and how to get there without enterprise pricing.
A cookie banner is not a consent management solution. Here's what you actually need — and how to get there without enterprise pricing.
Here's a scenario that plays out thousands of times a day: a small business owner installs a cookie consent banner plugin, sees the popup appear on their site, and checks "GDPR compliance" off their list.
Except they're probably not compliant.
A cookie banner — the popup that says "This site uses cookies" with an Accept button — is the visible tip of a much larger iceberg. Real consent management involves:
Most cookie banner tools handle maybe two or three of these. That's why "we have a cookie banner" and "we have proper consent management" are very different statements.
GDPR's consent requirements are specific and strict. Valid consent must be:
The visitor must have a genuine choice. That means:
Consent must be given for each distinct purpose. Bundling everything into one "I agree" button isn't specific consent. Your banner should separate:
Before consenting, the visitor needs to know:
Consent requires a clear affirmative action. Scrolling, continuing to browse, or closing the banner doesn't count. The visitor must actively click a consent button.
You need to prove that consent was given. That means logging:
Adding complexity: GDPR and CCPA take fundamentally different approaches to consent.
Under GDPR, non-essential cookies cannot be set until the visitor actively opts in. No consent = no cookies. This is the stricter model.
Under CCPA/CPRA, you can set cookies by default but must give California residents the ability to opt out of the "sale" or "sharing" of their personal information. This means you need a "Do Not Sell or Share My Personal Information" link.
If your website serves visitors from both regions — and most websites do — you need a consent mechanism that adapts based on the visitor's location:
This jurisdiction-aware behavior is something most basic cookie banner tools simply don't offer. They show the same popup to everyone.
In 2024, Google made Consent Mode v2 a requirement for advertisers using Google Ads with audiences from the European Economic Area. If you run Google Ads and target EU users, this isn't optional.
Google Consent Mode is a framework that lets your consent banner communicate with Google tags (Analytics, Ads, etc.). Instead of simply blocking or allowing Google scripts, Consent Mode tells them the user's consent status:
ad_storage: consent for advertising cookiesanalytics_storage: consent for analytics cookiesad_user_data: consent for sending user data to Google for advertisingad_personalization: consent for personalized advertisingWithout Consent Mode v2:
With Consent Mode v2:
Consent Mode v2 requires your cookie banner to send the right signals to Google's tag. Basic cookie banner tools that just block/allow scripts don't support this — they need specific Consent Mode integration.
Here's what separates a proper cookie consent management tool from a basic banner:
The tool should crawl your website and automatically discover all cookies and trackers. You shouldn't have to manually list every cookie — that's error-prone and goes stale immediately.
Non-essential scripts must be blocked before consent is given, not just hidden behind a banner while they load anyway. This requires the consent tool to intercept and control script loading at the browser level.
The banner should adapt based on where the visitor is located. An EU visitor gets GDPR-compliant opt-in. A California visitor gets CCPA-compliant opt-out. Someone from a US state without a privacy law might see a simplified notice.
Visitors should be able to consent to analytics but not marketing, or functional but not analytics. All-or-nothing consent is not GDPR-compliant.
Every consent event should be logged with timestamp, choices made, banner version, and visitor jurisdiction. This is your proof of compliance if challenged.
For any business running Google Analytics or Google Ads, Consent Mode v2 support is essential.
Visitors must be able to change their consent preferences at any time. A persistent "Cookie Settings" link (typically in the footer) that re-opens the preference panel is the standard approach.
Your consent banner categorizes cookies and trackers. Your privacy policy describes them. If these two documents tell different stories, you have a compliance gap. The best solutions keep them in sync automatically.
Enterprise consent management platforms like OneTrust and Cookiebot Pro deliver most of these capabilities. But the pricing reflects their enterprise focus:
For a 10-person SaaS startup or a small e-commerce store, these prices are hard to justify — especially when you need the full compliance stack (consent + policy + monitoring + DSARs), not just a banner.
Custodia takes a different approach: consent management as part of a complete privacy compliance platform, priced for small businesses.
Custodia's consent banner isn't configured from a template. It's generated from an actual scan of your website. The scanner detects every cookie and tracker, classifies them by purpose, and the banner reflects exactly what's on your site.
When your site changes — new trackers appear, old ones are removed — the banner updates automatically based on the next scan.
Custodia detects visitor location and adapts the consent experience:
Consent Mode v2 signals are sent automatically based on visitor consent choices. No additional configuration needed. Your Google Analytics and Ads continue to function properly in both consented and non-consented scenarios.
Your consent banner, privacy policy, and compliance dashboard all draw from the same scan data. Add a new tracker to your site, and:
Everything stays in sync without manual effort.
Custodia Starter includes full consent management at $29/month. One site, consent banner, privacy policy, compliance dashboard, and weekly scans. No per-page-view pricing. No hidden tiers for essential features.
See every cookie and tracker on your site in 60 seconds. No signup required.
Last updated: March 2026
Originally published at Custodia Privacy Blog