TL;DR: No, not automatically. A website with no analytics, no ad pixels, and no embedded third-party content generally doesn’t need a consent banner at all. What triggers the requirement is loading non-essential technologies, which for most small businesses means Google Analytics, an ad pixel, a session recorder, or an embedded map or video. Where your visitors are matters more than where you are: the EU and UK require an affirmative choice before non-essential trackers fire, while California is primarily an opt-out regime centered on the sale or sharing of personal information and honoring the Global Privacy Control signal. The “By continuing, you agree” banner is the worst of both worlds, since it isn’t valid consent in Europe and does nothing for a California opt-out. And a banner never makes you compliant on its own; it’s one control among several.
There’s an unhelpful amount of fear marketing in this category. Most articles open with a GDPR fine number large enough to make you install something immediately, which is convenient for the company that wrote the article.
Here’s the less dramatic version.
The question isn’t “do I have a website”
It’s “does my website load anything non-essential.”
Cookies and similar technologies split roughly into two buckets. Strictly necessary ones make the site work: keeping you logged in, remembering what’s in a cart, load balancing, basic security. These generally operate without consent, because a site that can’t hold a shopping cart isn’t a site.
Everything else is the category that triggers obligations. Analytics. Advertising and retargeting pixels. Session recording and heatmaps. A/B testing tools. Embedded YouTube videos, Google Maps, social feeds, and chat widgets, all of which typically set third-party cookies the moment they load.
If your site is genuinely a brochure with no analytics, no pixels, and no embeds, you likely don’t need a consent banner. That site is rarer than you’d think, though, because the embeds catch people. A Google Map on your contact page is a third-party tracker whether or not you think of it that way.
So the honest first step isn’t shopping for a banner. It’s finding out what your site actually loads. Open it in a private window, open your browser’s developer tools, look at the network requests and the cookies being set, and see how many domains that aren’t yours show up. Most people are surprised.
Where your visitors are matters more than where you are
This is the part that trips up US businesses. Privacy law here mostly follows the visitor, not the company. A three-person shop in Ohio that gets meaningful traffic from Germany is dealing with European rules for those visitors.
The EU and UK: ask first
The rule is consent before non-essential technologies load. Not after, and not implied. The clearest statement of it is the UK’s, in the ICO’s guidance (the ICO regulates the UK, not the EU, where the ePrivacy Directive and GDPR are applied by each member state’s own regulator). The practical requirements come down to:
- Strictly necessary cookies can operate without consent.
- Non-essential technologies need an affirmative choice first. Continuing to browse a page is not an affirmative choice.
- Rejecting has to be as easy as accepting. A prominent “Accept All” with a buried “manage preferences” link is a known enforcement target.
- People have to be able to withdraw consent later, which means some route back to the choice.
This is why “By continuing to use this site, you agree to our use of cookies” fails. It’s not a choice, it’s an announcement, and the trackers already fired before anyone read it.
California: a different regime, not a stricter one
The CCPA is built around a different idea. The central obligation for covered businesses is usually giving consumers the ability to opt out of the sale or sharing of personal information, and honoring the Global Privacy Control, a signal a visitor’s browser sends automatically.
Two things follow from that. First, “sharing” is broad enough to catch ordinary advertising pixels, so plenty of businesses that don’t think of themselves as selling data are covered by the concept. Second, and this is the part tools get wrong: California regulators have specifically warned that switching off cookies is not necessarily the same as completing the broader opt-out a consumer requested. A cookie banner is one piece of that obligation, not the whole of it.
Also worth saying plainly: whether the CCPA applies to you at all depends on thresholds many small businesses don’t meet. You’re covered if you clear any one of: roughly $26.6 million in annual gross revenue, data on 100,000+ consumers or households, or 50% or more of revenue from selling or sharing personal information. Being small on revenue alone doesn’t settle it, since the other two tests stand on their own. “Covered business” is doing real work in these sentences. Don’t assume you’re covered, and don’t assume you aren’t.
Why one global banner is the wrong shape
If you serve every visitor the same modal, you’re either over-asking Americans for consent that their law frames as an opt-out, or under-protecting Europeans by firing trackers before they choose. The regimes want different things.
That’s why geo-awareness is the feature that actually matters in a consent tool, and why it’s worth checking which pricing tier it lives on. In CookieYes, for instance, geo-targeting starts at the $25 Pro tier, not the $10 one.
When a banner is the wrong fix
A few situations where installing a banner is treating the symptom:
You don’t know what’s loading. A banner that blocks three trackers on a site running eleven is worse than none, because it looks finished. Audit first.
Your policy doesn’t match your site. A generated cookie policy listing trackers you don’t run, or omitting ones you do, is a documentation problem a banner doesn’t solve.
You installed analytics you never look at. Genuinely common. If nobody has opened that dashboard in a year, deleting the tracker removes the obligation entirely. Not every problem needs a purchase.
The banner is the fourth thing wrong with the site. If it’s also slow, also unmaintained, and also hasn’t been touched since 2023, a fifth tool bolted onto it isn’t the fix.
What “compliant” actually means here
No tool makes you compliant by installation. Every honest vendor in this space says a version of this, including Complianz, whose own documentation states that the site administrator remains responsible for configuring it correctly.
A consent banner is one control. The rest of the picture includes a privacy policy that describes what you actually collect, a cookie policy matching what actually loads, a way to handle data requests if you’re covered, and not firing trackers you failed to disclose. Buying software addresses one of those.
That’s not a reason to skip it. It’s a reason not to treat the purchase as the finish line.
So: do you need one?
Rough guide, not legal advice:
- No analytics, no pixels, no embeds, US-only visitors? Probably not.
- Any analytics or ad pixel, any meaningful EU or UK traffic? Yes, and it needs to block before consent.
- US-only with analytics and ads, above CCPA thresholds? You need an opt-out path and GPC handling more than you need a European-style consent gate.
- Selling into multiple regions? You need geo-aware behavior, which narrows your tool options and usually raises the price tier.
- Genuinely unsure whether you’re covered? That’s a lawyer question. It’s cheaper than guessing wrong.
The bottom line
Most small businesses do need something, because most small businesses run analytics and at least one ad pixel. But “something” is a smaller purchase than the category’s marketing suggests, and the specific something depends on where your visitors are.
The one answer that’s always wrong is leaving a “by continuing, you agree” banner up because it looks like a decision was made. It isn’t valid consent in Europe, it doesn’t deliver a California opt-out, and it convinces everyone internally that the box is ticked.
If you want the full tool-by-tool breakdown, best cookie consent tools for small businesses covers Termly, CookieYes, Complianz, Cookiebot, and iubenda with pricing. If you’re specifically looking to move off Termly, that comparison is here.
And if the honest answer is that you don’t want to own any of this, Surmado Sites is a managed website where the tracking and a location-aware consent banner are included rather than installed. Visitors in the EEA, the UK, Switzerland, and Canada see the banner before anything fires; visitors in California, Colorado, Connecticut, and Oregon get a working opt-out, and a Global Privacy Control signal is treated as a decline. It is not a full compliance platform, and the pillar post is explicit about which CMP features it doesn’t have. Current pricing is on the pricing page.
This is general information, not legal advice. Whether any of it applies to you depends on where you operate, who your visitors are, and what you collect. If the stakes are real, talk to a lawyer.