In short
- A banner is about storing or reading something on the visitor's device, not about analytics as such. Remove the cookie and the question changes, but it does not disappear.
- France (the CNIL) and the UK exempt some first-party analytics, under conditions. Germany and Austria usually still ask for consent in practice.
- In the US there is no cookie-consent law like the EU's. The rules are about selling and sharing personal data, which trckable does not do.
- Everything else on your page (ads, video, chat, social buttons) needs its own answer. An exempt analytics script does not cover it.
Two sets of rules, not one
People say "the GDPR requires a cookie banner". It does not, quite. Two laws sit side by side, and the banner comes from the second.
The GDPR governs personal data: what you may collect, on what legal basis, and what you owe the people it describes. The ePrivacy Directive, in Article 5(3), governs the device: you need the person's consent before storing information on it or reading information from it, unless that is strictly necessary to deliver a service they asked for. Each EU country wrote that into its own law, with its own exemptions.
So passing one test does not pass the other. A tool can be careful with personal data and still read the device. Another can touch the device and still be an exempt, low-risk measurement under local rules. That is why the table below is by country.
The table
| Where | Rule in short | Analytics without a banner? |
|---|---|---|
| EU, general | ePrivacy Directive, Article 5(3): consent before storing or reading information on a device, with exemptions set by each country | Depends on the country. Not by default |
| Germany | Section 25 of the TDDDG (formerly the TTDSG): consent, unless the access is strictly necessary | Depends on the purpose, and in practice usually needs consent (DSK guidance) |
| Austria | Telecommunications Act 2021, section 165: the same pattern | Generally no |
| France | The CNIL exempts audience measurement that meets its conditions: only for the site's own statistics, no cross-site tracking, no other use of the data, visitors told and able to refuse, with IP truncation and a 13-month cap on stored data | Yes, if every condition is met |
| UK | PECR asks for consent for storage and access. The Data (Use and Access) Act 2025 adds an exception for statistical analytics with an easy way to opt out; see the ICO's guidance | Increasingly yes. Check that the exception is in force for your setup |
| US | No federal cookie-consent law. State privacy laws, such as California's, regulate the sale and sharing of personal data and ask you to honour opt-out signals | Usually yes. Mind your other tools and tell visitors what you do |
These are the general lines as we understand them in October 2026. National rules and regulators' views move, so read your own authority's current guidance before you rely on a row.
Why removing the cookie is not the whole answer
European regulators read "accessing the device" widely. The EDPB, the body of EU data protection authorities, says in its guidelines on the technical scope of Article 5(3) that the rule is not limited to cookies: local storage, fingerprinting and reading device information fall under it too. A script that sends the page address, the referrer, the screen width and the language is reading the device, cookie or not.
That makes cookieless tracking a strong simplification and not an automatic exemption. It removes the storage, and with it most of the privacy risk. Whether a given country then lets you skip consent is the table's question. The longer reasoning is in cookieless analytics and GDPR.
Five questions that settle it
Answer these for your own site and you will know which row applies.
- Where are your visitors? The rules follow the visitor, not your company. A German visitor to a US site is still protected by German law.
- Does your script store or read anything on the device? A cookie, local storage, a stored ID, fingerprinting. If yes, you need consent unless the exemption for your country applies.
- Is the data used only for your own statistics? No cross-site tracking, no sharing, no advertising use. Exemptions usually depend on this.
- Can a visitor object? Exempt measurement typically still requires that people are told and can opt out.
- What else is on the page? Ads, embedded video, chat widgets and social buttons set their own cookies and need their own consent, whatever your analytics does.
What cookieless mode does in trckable
With the switch on, for every visitor wherever they live:
- nothing is stored in the browser: no cookie, no local storage, no queue of unsent events
- visitors are counted with a daily hash of their IP address and browser, and no IP address is stored anywhere
- the region and city are dropped, the country stays
- Do Not Track and Global Privacy Control are honoured
You give up recognising a returning visitor across days. A unique visitor is new each day, and counts are right within a day. That is the price of storing nothing, and for most sites it is a fair one.
What the exemptions usually ask for
The wording differs, but the conditions repeat: the data serves your own site's statistics only, nothing is tracked across sites or shared for others' purposes, visitors are told and can object, and data is not kept longer than needed (in trckable you choose how long a site's data is kept: 30 days to 3 years, or until you delete it). trckable loads nothing from another company, and Cloud data is hosted in the EU. Those facts help you meet the conditions. Whether your country's exemption applies to your setup is still your call, and your lawyer's.
If you keep the cookie
You may want a stable first-party visitor ID across days. Then ask first, in the EU and the UK, and ask properly: the Court of Justice has held that a pre-ticked box is not consent (Planet49, C-673/17). Refusing should be as easy as agreeing, and nothing non-essential should load before the answer.
trckable has its own cookie bar, where refusing is as easy as agreeing, and it can read a consent manager you already run (Google Consent Mode v2 or IAB TCF v2.2). A visitor who declines is not counted. The consent docs have the details.
Questions
- Do I need a cookie banner if I use cookieless analytics?
- Often not for the analytics itself in countries with an exemption, such as France when the conditions are met. In Germany and Austria consent is generally still expected. Other things on your page, such as ads or video embeds, may need a banner anyway.
- Do I need a banner in the US?
- There is no federal cookie-consent rule. State privacy laws focus on selling and sharing personal data and on honouring opt-out signals. trckable does not sell or share visitor data.
- Does the GDPR itself require a cookie banner?
- No. The banner comes from the ePrivacy rules about the device, which each country wrote into its own law. The GDPR sets the standard for what counts as valid consent once you need it.
- Is this legal advice?
- No. It is a plain summary of general lines, written by people who are not your lawyers. Rules are national and change, so ask a lawyer who knows the countries your visitors are in.
The newsletter
Notes on measuring what matters.
Occasional emails from Albi: new posts, one chart worth reading, what changed in trckable.
We send one email to confirm your address, and nothing more until you confirm. Every newsletter has a link to leave. What we keep, and who sends it: privacy.