Compliance

Cookie Banner Generator

Generate a GDPR and ePrivacy compliant cookie consent banner. Accept, reject and per-category toggles, no signup, no monthly fee. Copy the HTML, CSS and JS.

Last reviewed by the Radiatus Cloud team

Strictly necessary Always on. Exempt from consent under ePrivacy Article 5(3), so it cannot be toggled off.
Analytics Google Analytics, Plausible, Matomo with cookies.
Preferences Remembered settings such as language or theme.
Marketing Ad and remarketing pixels: Meta, LinkedIn, Google Ads.
Include Google Consent Mode v2 Emits the default denied state before gtag.js loads. Required for EEA and UK traffic if you run GA4 or Google Ads.
Add CCPA / CPRA opt-out link California uses opt-out, not opt-in. Adds a "Do Not Sell or Share My Personal Information" control.

The reject button is always generated with the same visual weight as accept. Regulators including France's CNIL have treated a hidden or downgraded refusal option as invalid consent, so it is not removable here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

What this generator produces

This tool builds a self-contained cookie consent banner you paste into your own site: one block of HTML, CSS and vanilla JavaScript with no external dependencies, no third-party script, and no per-domain licence. The banner stores the visitor's choice in a first-party cookie and exposes a small JavaScript API so your analytics and marketing tags can check consent before they fire.

Most consent tools on the market are hosted consent management platforms. They bill monthly, load a remote script on every page view, and route your visitors' consent records through a vendor. That is a reasonable trade for a large publisher managing hundreds of vendors under the IAB Transparency and Consent Framework. It is heavy for a small site that needs to block Google Analytics until someone clicks Accept.

Prior consent is the part most banners get wrong

Under the ePrivacy Directive as applied across the EU, and under the UK's PECR, non-essential cookies must not be written before the visitor consents. A banner that appears while Google Analytics has already set _ga is decorative, not compliant. The generated banner therefore ships with tags blocked by default: your tracking snippets go inside a type="text/plain" script block with a data-consent-category attribute, and the banner rewrites them to executable scripts only after the matching category is accepted.

Reject must be as easy as accept

The CNIL in France, the Garante in Italy and the EDPB have all landed in the same place: if accepting takes one click, refusing must take one click too. Banners that offer Accept prominently and hide refusal behind a settings panel have drawn fines. Every layout in this generator includes a Reject all button with the same visual weight as Accept all, on the first layer. You can restyle it, but the reject button cannot be removed from the output.

Categories

The generator produces four standard categories. Strictly necessary is always on and cannot be toggled, because those cookies are exempt from consent. Analytics, Preferences and Marketing each get an independent switch, and each writes its own flag into the consent cookie so your tags can check them separately.

What it does not do

This is a client-side banner, not a consent management platform. It does not maintain a signed audit log of consent records on a server, it does not participate in the IAB TCF, and it does not automatically discover which cookies your site sets. If you are an ad-tech publisher working with dozens of vendors, or you need to produce consent proof under audit, you need a full CMP. For a marketing site, a SaaS product page or a blog running analytics and a pixel or two, this is the proportionate tool.

Related tools

Frequently Asked Questions

Is a generated cookie banner legally compliant?

The banner gives you the mechanics regulators expect: no non-essential cookies before consent, a reject option as prominent as accept, granular per-category control, and a way to withdraw consent later. Compliance also depends on things a generator cannot know, such as whether your cookie list is accurate and whether your tags actually respect the consent signal. Treat the output as a correct foundation, not as legal advice, and have a practitioner review it if you operate at scale.

Do I need consent before loading Google Analytics?

In the EU and UK, yes. Analytics cookies are not strictly necessary, so they require prior consent. The generated banner blocks tagged scripts until the analytics category is accepted. If you use Google tags, pair this with Google Consent Mode v2 so the tags adjust behaviour rather than simply failing to load.

What is the difference between a cookie banner and a cookie policy?

The banner is the interactive consent control shown on arrival. The cookie policy is a static page that lists each cookie, its purpose, its provider and its retention period. GDPR transparency requirements expect both. Use this tool for the banner and the cookie policy generator for the page, and link the policy from the banner.

Does GDPR require a reject button on the first layer?

The GDPR itself requires that consent be freely given, which regulators have consistently interpreted as requiring refusal to be as easy as acceptance. France's CNIL made this explicit and has fined companies for burying the refusal option. Every layout here includes a first-layer Reject all button by default.

Does this work with CCPA or CPRA?

Partly. California operates on an opt-out model rather than opt-in, so a consent wall is not required. What you do need is a clear Do Not Sell or Share My Personal Information mechanism. The banner includes an opt-out mode that presents that link instead of a consent gate, which you can serve based on visitor region.

Where is the visitor's choice stored?

In a first-party cookie named rdt_consent on your own domain, holding a small JSON object with the accepted categories and a timestamp. Nothing is transmitted to Radiatus or to any third party. The consent cookie itself is strictly necessary and so is exempt from requiring consent.

How do visitors change their mind later?

The generated code exposes window.rdtConsent.open(), so you can wire any element (typically a Cookie settings link in the footer) to reopen the preference panel. The right to withdraw consent as easily as it was given is an explicit GDPR requirement, so include that link.

Will the banner slow my site down?

The output is roughly 4 KB of inline HTML, CSS and JavaScript with no network requests and no external dependencies. Hosted CMP scripts typically cost 50-200 KB plus a blocking third-party connection. Reserve the banner's height in CSS to avoid a layout shift, which the generated stylesheet does by default.

Privacy & Security

Generated locally in browser.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.