Gian Luca Partengo Gian Luca Partengo

Guides

Cookieless website: when you do not need a cookie banner—and when you do

Cookieless does not mean outside the rules. It means designing a website without unnecessary tracking, documenting what remains and activating a CMP only when the selected tools genuinely require consent.

Short answer

A website can operate without profiling cookies, equivalent identifiers or a consent banner. It must still provide notices that match its actual processing. If it uses only necessary technical tools and genuinely privacy-first measurement, a banner may not be needed; if it adds behavioural analytics, advertising, remarketing or other non-technical trackers, a CMP and prior blocking are required until the user chooses. The best solution is not to hide the banner: it is to avoid the technologies that make it necessary in the first place.

Gian Luca Partengo

Gian Luca Partengo
Web developer since 1995 · bespoke websites · Updated

Cookieless does not mean “no law”: it means no unnecessary tracking

The label describes a technical and design choice, not a legal exemption or a formula that applies regardless of what the website actually does.

In my approach, a website is cookieless by design when its normal functions do not install profiling cookies or use equivalent identifiers to follow people, build profiles or feed advertising campaigns.

The priority comes before the code: I collect only data that serves the website, choose proportionate tools and leave out integrations that add surveillance without creating a comparable benefit for the project.

A strictly necessary function may require technical state, for example in a members’ area or shopping cart. This is not profiling, but it must still be inventoried and described correctly.

ZERO

Profiling by default

No advertising, remarketing or cross-site identification installed simply because “everyone does it”.

MINIMUM

Necessary data

Every data point, script and supplier needs a clear and proportionate purpose.

CONTROL

Verifiable dependencies

The website remains understandable: we know what it loads, who it contacts and why.

Privacy Policy, Cookie Policy and terms still matter where relevant

Removing the banner does not remove processing: contacts, email, hosting, technical logs and suppliers must remain transparent.

Privacy Policy

Explains who processes data, for which purposes, on which legal bases, with which suppliers, retention periods and rights. It also matters on a tracker-free website that receives messages, enquiries or technical data.

Cookie Policy

Documents the cookies and similar technologies actually in use, even when they are only technical or the configuration does not require a consent banner.

Terms and conditions

They become relevant when the website governs sales, bookings, subscriptions, content or other contractual relationships. They do not depend on cookie use.

The consistency principle

Policies and interfaces must describe the real website. A generic document that lists absent trackers or omits active ones creates confusion and does not replace technical analysis.

When a cookie banner is not needed

The Italian Data Protection Authority distinguishes technical tools needed to provide a service from tools used for additional purposes. The former require information, not prior consent.

When you need a CMP with consent and prior blocking

If a purpose is not strictly necessary and requires consent, its script must not start while the person is still deciding.

  1. 01Inventory: identify scripts, cookies, storage, external calls and embeds
  2. 02Classification: separate necessary, preferences, measurement and marketing
  3. 03Prior blocking: hold non-technical tools until consent is given
  4. 04A real choice: accept, reject and customise with equal clarity

An information-only banner is not enough when consent is required

If the website loads the tracker anyway and merely displays a notice, tracking begins before the person can choose. That case requires a genuine consent management platform and prior blocking.

Why a cookieless website is often much faster

Speed does not come from the word cookieless. It comes from removing third-party code, requests, dependencies and browser work that tracking normally introduces.

Less JavaScript

Tag managers, pixels, advertising libraries and CMPs add parsing and execution on the main thread, especially on less powerful devices.

Fewer external requests

Every domain adds DNS resolution, connection time, transfer and variability outside the website hosting provider’s control.

Less instability

Banners, overlays and injected components can shift layout, delay interaction or compete with the main content.

More control

A shorter chain makes it easier to measure Core Web Vitals, find regressions and keep behaviour consistent over time.

A real advantage, not an automatic guarantee

A cookieless website can still be slow if images, code or hosting are poorly managed. Starting with fewer dependencies does, however, remove one of the most common and least controllable causes of slowdown.

Measure the website without turning this guide into a platform comparison

A cookieless project may include statistics when purpose, data and configuration remain proportionate. Choosing the product, however, needs a separate analysis.

Why I use iubenda even on websites without a banner

iubenda is not synonymous with a cookie banner. Policies and consent management are separate components, enabled according to what the real website needs.

Policy generation

Privacy and Cookie Policies remain accessible documents aligned with the project’s services, suppliers and languages.

Terms when needed

Sales, bookings and regulated services may need specific terms independently of cookies.

CMP only when needed

When non-technical trackers enter the project, the consent solution is enabled with categories, choices and consent evidence.

Blocking before choice

Scripts subject to consent must remain suspended until the person authorises them.

The cookieless method I apply to bespoke websites

I do not begin with a CMP to customise. I begin with the function list and try to avoid what would make a CMP necessary.

  1. 01

    Design only what is needed

    Locally hosted fonts, anti-spam forms without reCAPTCHA, static maps, video facades and no advertising pixel installed by default.

  2. 02

    Measure without following people

    When statistics are useful, I favour Plausible and essential goals instead of collecting everything for hypothetical future use.

  3. 03

    Document what exists

    Privacy Policy, Cookie Policy and any terms are aligned with the actual hosting, forms, analytics, suppliers and languages.

  4. 04

    Enable consent when required

    If the business model requires advertising, remarketing or other trackers, I add a CMP, prior blocking, testing and ongoing configuration maintenance.

Explore the services included with bespoke websites and the project price ranges.

Five practical scenarios: yes, no or assessment required

The answer does not depend on the size of the website but on its tools, purposes and configuration.

Scenario What happens Banner Correct action
Essential company website Hosting, technical logs and contact form without trackers Normally no Consistent policies and periodic technical checks
Aggregated privacy-first analytics Essential statistics with no declared persistent identifiers May not be needed Check configuration, events, contract and notice
Behavioural analytics Identifiers, sessions, segments or advertising integrations Usually yes CMP, prior blocking and technical consent management
Meta Pixel, Ads or remarketing Profiling, attribution and advertising audiences Yes No loading before consent; accessible choice and withdrawal
External video, map or chat Possible third-party calls and identifiers It depends Use privacy-first facades or block the embed until an appropriate choice

These examples are indicative. A final assessment must examine the published website, network requests, contracts and actual purposes.

Verified primary sources

This guide separates Italian rules from suppliers’ technical claims. Sources must be revisited when services, settings or guidance change.

  1. Italian Data Protection Authority — cookies and other tracking tools

    Italian rules on technical tools, consent, banners, analytics and equivalent identifiers.

    Open source
  2. EUR-Lex — ePrivacy Directive

    The European text on storing information and accessing a user’s terminal equipment.

    Open source
  3. iubenda — Privacy Controls and Cookie Solution

    Separates policies, banners, preferences, consent collection and solution configuration.

    Open source
  4. web.dev — optimise third-party JavaScript

    The performance effects of external scripts, network requests and main-thread execution.

    Open source

Sources accessed and verified on 23 July 2026. This guide is informational and does not replace legal advice on a specific case.

Frequently asked questions about cookieless websites, banners and tracking

Direct answers to the questions that most often confuse policies, cookies, tracking and consent.

Is a cookieless website exempt from GDPR?

No. It may process data through forms, email, hosting, logs or suppliers even without cookies. Its notices and legal bases must therefore match its actual processing.

Does a website without cookies need Privacy and Cookie Policies?

A Privacy Policy remains necessary when personal data is processed. A Cookie Policy documents actual cookies and similar technologies, even when they are only technical and do not require consent.

Can I always avoid the banner if I do not use cookies?

No. Fingerprinting, localStorage, server-side identifiers and embeds can perform equivalent tracking. The complete behaviour of the website must be assessed.

Do technical cookies require consent?

Under the Italian Authority’s guidance, tools strictly needed for a service require information but not prior consent. They must genuinely be technical and proportionate.

Does cookie-free analytics always avoid a banner?

No. Equivalent identifiers, events, transmitted data, the supplier’s role, purposes and possible combinations must also be assessed. The absence of cookies is one element, not the whole test.

How do I choose between privacy-first and advanced analytics?

Start with decisions you will actually make. If traffic, sources and essential goals are enough, a proportionate tool reduces complexity. Ecommerce, advertising and segmentation may justify deeper tools and the corresponding consent system.

Is an information-only banner sufficient?

Only when there is no need to collect consent. When non-technical trackers are present, a notice is not enough: the scripts must remain blocked until a valid choice is made.

Does cookieless automatically mean faster?

Not automatically. Reducing tags, pixels, CMPs and external calls does remove a great deal of JavaScript and network activity that often slows pages. Images, code and hosting still matter.

Why use iubenda if the website has no banner?

To manage Privacy and Cookie Policies and, where needed, terms and conditions. The CMP is a separate component enabled only when the website’s technologies require consent.

Can I add Meta Pixel after launch?

Yes, but it changes the privacy scope. Before activation, update policies and purposes, configure the CMP and prior blocking, test choices and withdrawal and verify the published website.

Do a YouTube video or Google Map stop a site being cookieless?

They can introduce third-party calls and tracking. Where possible, I use local previews and load the embed only after an appropriate action or choice.

How can I check whether my website is genuinely cookieless?

Audit cookies, browser storage, network requests, scripts, iframes, forms and events. Repeat the check after new integrations and never rely only on the policy text.

Did you find this guide useful? Share it.

No social tracker loads before you choose an action.

Next step

Do you want a fast website that collects only what it needs?

Explore the design standards for custom websites: proportionate analytics, consistent policies and a complete CMP only when the technologies used genuinely require one.

Test evidence

Mobile PageSpeed Insights: 100 in every category

PageSpeed Insights result from 28 July 2026: 100 for Performance, Accessibility, Best Practices and SEO on mobile.
Google PageSpeed Insights · Lighthouse mobile · verified 28 July 2026 Open the verifiable report
© 1995–2026 Gian Luca Partengo · All rights reserved.

GLP AI

GLP AI assistant

Answers based on the public content of this website.

Tell me what you need from your website. I will look through GLP services and Articles and point you towards the most relevant route.

Ready

You are interacting with an AI system, which can make mistakes: its answers are not binding quotations. Do not enter personal, sensitive or confidential data. Questions are sent to OpenAI to generate the answer and are not saved by this website. Read the Privacy Policy.

Search