A banner is not enough: making cookie consent provable
A click on the banner does not show that consent was obtained. What has to be shown is who consented to what, under which version.
- Cookies
- KVKK
- GDPR
Cookie compliance is one of the topics organisations say they "sorted out quickly" and where the most is left undone. A banner goes on the site, an "accept" button is added, and the matter is closed. But the real question is not the banner: when a complaint arrives, what do you have?
Three common gaps
No inventory. Tags, pixels and third-party scripts have accumulated on the site over the years. What each one collects has never been documented. Without knowing what is on your own site, you cannot say which category you obtained consent for.
No record. The banner gets clicked, but nothing records who consented, when, under which banner version, and to which categories. The burden of proving consent sits with the controller; with no record there is no proof.
Refusal does not work. This is the technical gap we see most often. The user declines but analytics or marketing tags keep firing. In that state the banner stops delivering compliance and becomes evidence of the opposite.
Refusing has to be as easy as accepting
On the design side: accept and reject must be presented with equal weight. Setups where "accept" is a large coloured button while "settings" is a small link weaken the claim that consent was freely given.
Equally, withdrawing consent must be as easy as giving it. Leave a permanent route for the user to change their preference.
What needs recording
For a consent record to be useful it has to carry:
- A timestamp
- Which categories were consented to
- The version of the banner and text that was shown
- Which domain and language the consent applies to
The record does not need to identify the person; what matters is that the preference for that session can be reproduced.
The inventory goes stale on its own
A cookie inventory is not a document you produce once and leave. The marketing team adds a tag, an embed drops a new cookie, and the inventory quietly goes out of date. That makes periodic scanning as important as the inventory itself.
We run this chain — scanning, classification, banner, consent archive — in one flow with HEM Cookie. Even without the product the order stays the same: first learn what is on the site, then ask for consent.
This article is for information and does not constitute legal advice.

