Customer Impact

Website & Development

Is a cookie banner mandatory in Belgium? The DPA rules explained

Copy for AI

A cookie banner is not as such legally required in Belgium, but the moment your website sets cookies that are not strictly necessary (analytics, marketing, tracking), the law requires you to ask for valid consent beforehand. In practice, a cookie banner is the only workable way to collect that consent. The real obligation therefore does not sit in the banner, but in the consent behind it. In this article you will read where the rules come from, what the Data Protection Authority (DPA) expects exactly from your banner, and how to keep it both compliant and conversion-friendly.

It is not the banner itself that is mandatory, but the consent for non-essential cookies. The legal basis lies in article 129 of the Electronic Communications Act (ECA), which transposes the European ePrivacy directive, in combination with the GDPR for the meaning of consent. In short: for every cookie that is not strictly necessary to make your site work, the visitor must give free, specific, informed consent beforehand through an active act.

If you only use strictly necessary cookies, for example to remember a shopping cart or a logged-in session, you need neither consent nor a banner. But most B2B websites run analytics, embed videos or use advertising pixels, and those do fall under the consent requirement. An important detail: “strictly necessary” is interpreted narrowly. A cookie that mainly serves your interest (such as statistics for yourself) does not count as necessary, even if it feels indispensable to you.

The core of the DPA’s approach is simple: refusing must be as easy as accepting. In October 2023 the DPA published a cookie checklist that bundles its expectations. The most important points for your banner:

  • An equivalent reject button. There must be a “reject all” button at the same level as “accept all”, in the first layer of the banner, equally visible and equally accessible. A banner with only “accept” and a hidden “settings” link does not comply.
  • No pre-ticked boxes. Consent must be an active choice. Categories ticked by default do not produce valid consent.
  • No deceptive design (dark patterns). You may not steer the choice with colour, font size or placement, for example a bright green accept button next to a grey, barely legible reject button.
  • Consent per purpose. The visitor must be able to choose per category (analytics, marketing, and so on), not just all or nothing.
  • Easy withdrawal. Consent must be as easy to withdraw as it was to give. In practice this means a permanent, visible element (for example a fixed icon or link) that lets your visitor adjust their choice later.

The DPA also expects you to publish a clear cookie policy that transparently explains which cookies you set, for what purpose and for how long. That policy is your proof of transparency and should be findable from every page.

Under the GDPR you must moreover be able to demonstrate that the consent was valid. In practice this means you record when and for what a visitor consented, so that you have a trail in case of an inspection or a complaint. A good consent management tool does this automatically, but it remains your responsibility as data controller to actually retain that record.

Everything that is not strictly necessary for your site to function. The distinction determines whether you have to ask for consent or not, so it pays to classify your cookies honestly:

  • Strictly necessary (no consent): session cookies, the cookie that remembers the language choice, security and load-balancing cookies. These directly serve the visitor’s interest.
  • Consent required: analytics (including Google Analytics), marketing and remarketing pixels, social media embeds, A/B testing tools and embedded content that collects data.

A common mistake is thinking you may simply load analytics “because it is anonymous”. As soon as the tool sets or reads cookies that are not strictly necessary, the consent requirement applies. In practical terms: those scripts may only fire after the visitor accepts, not before. A banner that shows but loads the tracking in the meantime is not compliant.

A correct banner and a well-performing website are not mutually exclusive, quite the opposite. Honest choices and trust work in your favour. Three principles:

Make the choice calm rather than aggressive. A banner that blocks the entire page with a shouty overlay damages both your compliance and your first impression. A neat, clear banner with two equivalent buttons looks more professional and builds more trust on your B2B website. In B2B nobody buys from a site that immediately feels like a trick.

Watch your loading speed. Many cookie tools inject heavy scripts and let the banner “jump” over your content while the page loads. That costs you points on Core Web Vitals and pushes your bounce rate up. Choose a lightweight solution, load the banner without layout shift and defer non-essential scripts until after consent.

Do not put the banner in the way of your conversion path. Your real goal is leads, not clicks on “accept”. Make sure your most important call-to-action and your forms stay visible, even with the banner open. Anyone who wants to optimise their forms gains nothing if the cookie banner overlaps the input field on mobile.

Our experience ties in with the broader thesis behind our web design: steer on real results and on trust, not on vanity tactics. A banner that respects visitors performs better in the long run than one that forces consent. If you want to dive deeper into the build choices, you will find the full context in our B2B website guide.

The DPA actively monitors and can impose fines for violations. Cookie walls that block access for anyone who refuses fall explicitly under this: whoever refuses a cookie that requires consent must still be able to keep using your site. Deceptive banners and loading tracking before consent are classic stumbling blocks too.

Besides the legal risk there is a commercial risk. A non-compliant banner undermines trust, and in B2B trust is often the decisive factor in a long sales cycle. A few concrete checks you can do today: is “reject all” as prominent as “accept all”? Do your analytics and marketing scripts only fire after consent? Can a visitor adjust their choice later on? Is your cookie policy findable on every page? Three times “no” means there is work to be done.

The short summary

A cookie banner is not literally mandatory in Belgium, but the moment you set non-essential cookies, valid consent certainly is, and a banner is the practical solution for that. The DPA expects an equivalent reject button, no pre-ticked boxes, no deceptive design, choice per purpose and a simple way to withdraw consent. A cookie wall that shuts out those who refuse is not allowed. The good news: an honest, fast and calm banner is not only compliant, it also strengthens the trust your leads rely on.

Wondering whether your website is built in a compliant and conversion-focused way? Schedule your free intake and we will look at it together.

Free website scan

Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.

Where should we send your report?

We only use your details for your scan. No spam, unsubscribe anytime.