MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
According to the Dutch Data Protection Authority (AP), a cookie wall that only grants visitors access to your website after they accept tracking cookies violates privacy legislation. The GDPR requires that consent for tracking cookies freely . With a cookie wall, the visitor has no real choice: no agreement, no access. That is not free consent and is therefore not legally valid. As a business owner, it is therefore better to remove a cookie wall and replace it with a proper cookie banner featuring an equivalent decline button and clear information.
What exactly is a cookie wall?
A cookie wall is a pop-up or overlay that blocks the entire website until the visitor agrees to the placement of cookies. It boils down to a take it or leave it: if you accept the tracking cookies, you can enter. If you refuse, the website remains inaccessible. Many websites used this structure because tracking yields valuable data for advertising and analysis.
The problem is that you are forcing consent in that way. And under privacy legislation, forced consent is not valid consent.
Why does a cookie wall violate privacy legislation?
The General Data Protection Regulation (GDPR) sets strict requirements for consent. Consent must free, specific, informed, and unambiguous . It is primarily about that first point: free choice.
The Dutch Data Protection Authority has clarified in an interpretation of the standard that a visitor does not make a free choice when access to the website is made conditional on accepting tracking cookies. In such cases, there is no real alternative. According to the DPA, the following applies: visitors must be able to refuse cookies without adverse consequences. A website that completely blocks access does not comply with this. Virtually all European privacy regulators share this position.
An intermediate form, in which refusers are shown only a heavily stripped-down version of the site, is also a sensitive issue. The basic principle remains that it must be possible to refuse without the visitor being punished for it.
Which cookies fall under this?
Not every cookie requires consent. The distinction is important:
- Functional cookies are necessary for the website to work (such as a shopping cart or login details). No permission is required for this.
- Tracking cookies monitor visitor behavior, often across multiple websites, and regularly share that data with third parties. Prior consent is required for this.
- Similar techniques such as fingerprinting and tracking pixels are subject to the same rules as tracking cookies.
Analytical cookies occupy an intermediate position: privacy-friendly, non-intrusive analytics can be used without consent under certain conditions. When in doubt, play it safe and ask for consent. A privacy and data protection can assess which category your cookies fall under.
What should you do as an entrepreneur instead of a cookie wall?
Removing the cookie wall alone is not enough. You must give visitors a real, informed choice. In practice, this comes down to the following steps:
- Replace the cookie wall with a cookie banner featuring an equivalent decline button. “Accept” and “Decline” must be equally easy to select.
- Only place tracking cookies after consent. As long as the visitor has not made a choice or refuses, no tracking cookies may be placed.
- Do not use pre-checked boxes. Consent must be an active choice; boxes checked by default do not count as valid consent.
- Keep the website accessible to those who refuse. Refusal must not lead to exclusion or an unusable site.
- Clearly state which cookies you use, for what purpose, and with which parties you share data.
- Make withdrawing just as easy as giving. Visitors must be able to change their choice later.
A good cookie statement is an integral part of this. In it, you transparently explain which cookies your website places and why. You often want to combine this with an up-to-date privacy statement and a disclaimer.
What risks do you run with a cookie wall?
The Dutch Data Protection Authority has indicated that it will monitor cookie usage more strictly and has written to organizations regarding this. In recent years, the regulator has been given extra capacity to check more frequently whether websites request consent in the correct manner. Those who do not comply with the rules run various risks:
- Enforcement and fines. The GDPR empowers the supervisory authority to impose substantial fines for violations. The exact amount depends on the nature and severity of the violation.
- Reputational damage. Customers value the careful handling of their data; an unlawful cookie wall undermines that trust.
- Invalid consent. Consent obtained via a cookie wall may not be legally valid, rendering your tracking basis invalid.
That the regulator actually enforces this is evident from a concrete example: the Dutch Data Protection Authority imposed a fine of €600,000 on the organization behind Kruidvat.nl because the website placed tracking cookies without valid consent. Pre-ticked boxes and a banner that made refusing unnecessarily difficult, among other things, played a role in this. For an SME entrepreneur, it is wise to anticipate these types of risks rather than waiting for an inspection or complaint.
And what about the ePrivacy Regulation?
For a long time, a European ePrivacy Regulation in preparation, intended to tighten and harmonize the rules regarding cookies, among other things. That process was ultimately not completed: the European Commission withdrew the proposal because Member States and sectors could not reach an agreement and the text had since been deemed outdated.
In practice, therefore, little changes. The current GDPR and the interpretation of the Dutch Data Protection Authority remain leading, and the supervisory authority can still enforce the rules. However, there are European plans to anchor cookie rules in a different way; these must go through a legislative process and are not yet final. The advice remains the same: base your decisions on the strict standard and monitor developments so that you can adjust your cookie policy in a timely manner.
Frequently asked questions about the cookie wall
Is a cookie wall prohibited?
According to the Dutch Data Protection Authority, a cookie wall that makes access to the website conditional on accepting tracking cookies does not comply with the GDPR. This is because consent is not freely given. In practice, therefore, it is better not to use such a cookie wall.
Am I allowed to deny visitors entry if they do not accept cookies?
No. The AP's starting point is that visitors must be able to refuse tracking cookies without adverse consequences. The website must also remain accessible to those who refuse.
Do I need permission for all cookies?
Not for functional cookies that are necessary for the website to work. However, prior consent is required for tracking cookies and similar techniques such as fingerprinting and tracking pixels. Privacy-friendly analytics can be used without consent under certain conditions.
What is the difference between a cookie wall and a cookie banner?
A cookie wall blocks the entire website until you agree. A proper cookie banner allows the visitor to freely choose between accepting and declining, while the website remains accessible. That second approach is the right route.
Can I get a fine for incorrect cookie usage?
Yes. The Dutch Data Protection Authority can impose fines when a website places tracking cookies without valid consent. A well-known example is the €600,000 fine for the organization behind Kruidvat.nl. The amount of a fine depends on the nature and severity of the violation.
What must be included in a cookie statement?
A cookie statement describes which cookies your website places, for what purpose, how long they are stored, and with which parties data is shared. You also explain how visitors can withdraw their consent.
Cookie wall resolved and website legally compliant?
Are you unsure whether your website still uses a cookie wall or if your cookie policy complies with the GDPR? The privacy and data protection at MKB Juristen are happy to help. We map out your cookie usage, draft a suitable cookie declaration, privacy statement , and disclaimer , and ensure that your website complies with privacy legislation. This helps you avoid unnecessary risks and fines.
Want to get it right from the start? Schedule a no-obligation consultation and we'll look together at what your website needs.