Skip to content
HEM Bilişim
2 min readHEM Bilişim

A banner is not enough: making cookie consent provable

A click on the banner does not show that consent was obtained. What has to be shown is who consented to what, under which version.

  • Cookies
  • KVKK
  • GDPR

Cookie compliance is one of the topics organisations say they "sorted out quickly" and where the most is left undone. A banner goes on the site, an "accept" button is added, and the matter is closed. But the real question is not the banner: when a complaint arrives, what do you have?

Three common gaps

No inventory. Tags, pixels and third-party scripts have accumulated on the site over the years. What each one collects has never been documented. Without knowing what is on your own site, you cannot say which category you obtained consent for.

No record. The banner gets clicked, but nothing records who consented, when, under which banner version, and to which categories. The burden of proving consent sits with the controller; with no record there is no proof.

Refusal does not work. This is the technical gap we see most often. The user declines but analytics or marketing tags keep firing. In that state the banner stops delivering compliance and becomes evidence of the opposite.

Refusing has to be as easy as accepting

On the design side: accept and reject must be presented with equal weight. Setups where "accept" is a large coloured button while "settings" is a small link weaken the claim that consent was freely given.

Equally, withdrawing consent must be as easy as giving it. Leave a permanent route for the user to change their preference.

What needs recording

For a consent record to be useful it has to carry:

  • A timestamp
  • Which categories were consented to
  • The version of the banner and text that was shown
  • Which domain and language the consent applies to

The record does not need to identify the person; what matters is that the preference for that session can be reproduced.

The inventory goes stale on its own

A cookie inventory is not a document you produce once and leave. The marketing team adds a tag, an embed drops a new cookie, and the inventory quietly goes out of date. That makes periodic scanning as important as the inventory itself.

We run this chain — scanning, classification, banner, consent archive — in one flow with HEM Cookie. Even without the product the order stays the same: first learn what is on the site, then ask for consent.


This article is for information and does not constitute legal advice.

This article is for information and does not constitute legal advice. Write to us about your specific situation.

Related articles

Looking for help on this?

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation