This is general information, not legal advice.

Most publishers assume advertising requires a consent banner. It requires one when the advertising tracks people. Advertising that does not track people is a different situation.

What actually triggers the requirement

Under the EU ePrivacy Directive — the "cookie law" — consent is required to store information on, or read information from, a user's device, unless it is strictly necessary to provide the service the user asked for.

Note what it does not say. It does not say "advertising requires consent". It says storing or reading device data does.

Separately, the GDPR governs processing personal data, which includes IP addresses and any cross-site identifier.

What you can serve without consent

Advertising that does none of the following:

An ad selected purely from the page's context — subject matter, and at most a coarse device category discarded immediately — does not store or read device data and does not process personal data. There is a strong argument no consent is needed.

This is roughly what "contextual advertising" means, and it is why some publishers run ads in the EU with no banner at all.

Where the line sits

Frequency capping is the interesting case. Limiting how many times someone sees an ad requires remembering something.

If the count lives in the visitor's own browser storage on the site they are visiting, and is never sent anywhere as an identifier, the picture is much better than a third-party cookie — but it is still writing to the device, so it is not automatically exempt. Some regulators would consider it non-essential. Take advice if you rely on it.

Conversion tracking is fine when it uses click-ID passthrough: an id in a URL, stored first-party on the advertiser's own site. Nothing is stored on your side, and the id means nothing beyond that one advertiser.

Anything that follows a person between sites needs consent. That is what the rules were written for.

What to check with your ad server

Ask directly, and get it in writing:

  1. Does it set any cookie? If yes, you need a banner.
  2. Does it store IP addresses? If yes, you are processing personal data.
  3. Does it use any cross-site identifier?
  4. Is there a data processing agreement available?

If the answers are no, no, no and yes, your advertising is probably not what is triggering a banner.

The rest of your site still counts

This is the trap. Your ad server can be perfectly clean and you still need a banner because of Google Analytics, an embedded YouTube video, a Facebook pixel, or a chat widget.

Cookieless advertising removes one reason for a banner. It does not remove the others. Audit the whole page before concluding you can drop it.

Why it is worth caring

A consent banner costs you real money. Refusal rates of 30–60% are typical, and every refusal removes a visitor from whatever depends on consent. There is also good evidence banners hurt engagement generally.

Being able to run advertising without one is a genuine competitive advantage — and it is a selling point with sponsors too, since your delivery is not gated on a click-through rate on a dialog.