Profiling by default
No advertising, remarketing or cross-site identification installed simply because “everyone does it”.
Guides
Cookieless does not mean outside the rules. It means designing a website without unnecessary tracking, documenting what remains and activating a CMP only when the selected tools genuinely require consent.
Short answer
A website can operate without profiling cookies, equivalent identifiers or a consent banner. It must still provide notices that match its actual processing. If it uses only necessary technical tools and genuinely privacy-first measurement, a banner may not be needed; if it adds behavioural analytics, advertising, remarketing or other non-technical trackers, a CMP and prior blocking are required until the user chooses. The best solution is not to hide the banner: it is to avoid the technologies that make it necessary in the first place.
The label describes a technical and design choice, not a legal exemption or a formula that applies regardless of what the website actually does.
In my approach, a website is cookieless by design when its normal functions do not install profiling cookies or use equivalent identifiers to follow people, build profiles or feed advertising campaigns.
The priority comes before the code: I collect only data that serves the website, choose proportionate tools and leave out integrations that add surveillance without creating a comparable benefit for the project.
A strictly necessary function may require technical state, for example in a members’ area or shopping cart. This is not profiling, but it must still be inventoried and described correctly.
No advertising, remarketing or cross-site identification installed simply because “everyone does it”.
Every data point, script and supplier needs a clear and proportionate purpose.
The website remains understandable: we know what it loads, who it contacts and why.
Removing the banner does not remove processing: contacts, email, hosting, technical logs and suppliers must remain transparent.
Explains who processes data, for which purposes, on which legal bases, with which suppliers, retention periods and rights. It also matters on a tracker-free website that receives messages, enquiries or technical data.
Documents the cookies and similar technologies actually in use, even when they are only technical or the configuration does not require a consent banner.
They become relevant when the website governs sales, bookings, subscriptions, content or other contractual relationships. They do not depend on cookie use.
The consistency principle
Policies and interfaces must describe the real website. A generic document that lists absent trackers or omits active ones creates confusion and does not replace technical analysis.
If a purpose is not strictly necessary and requires consent, its script must not start while the person is still deciding.
An information-only banner is not enough when consent is required
If the website loads the tracker anyway and merely displays a notice, tracking begins before the person can choose. That case requires a genuine consent management platform and prior blocking.
Speed does not come from the word cookieless. It comes from removing third-party code, requests, dependencies and browser work that tracking normally introduces.
Tag managers, pixels, advertising libraries and CMPs add parsing and execution on the main thread, especially on less powerful devices.
Every domain adds DNS resolution, connection time, transfer and variability outside the website hosting provider’s control.
Banners, overlays and injected components can shift layout, delay interaction or compete with the main content.
A shorter chain makes it easier to measure Core Web Vitals, find regressions and keep behaviour consistent over time.
A real advantage, not an automatic guarantee
A cookieless website can still be slow if images, code or hosting are poorly managed. Starting with fewer dependencies does, however, remove one of the most common and least controllable causes of slowdown.
A cookieless project may include statistics when purpose, data and configuration remain proportionate. Choosing the product, however, needs a separate analysis.
iubenda is not synonymous with a cookie banner. Policies and consent management are separate components, enabled according to what the real website needs.
Privacy and Cookie Policies remain accessible documents aligned with the project’s services, suppliers and languages.
Sales, bookings and regulated services may need specific terms independently of cookies.
When non-technical trackers enter the project, the consent solution is enabled with categories, choices and consent evidence.
Scripts subject to consent must remain suspended until the person authorises them.
I do not begin with a CMP to customise. I begin with the function list and try to avoid what would make a CMP necessary.
Locally hosted fonts, anti-spam forms without reCAPTCHA, static maps, video facades and no advertising pixel installed by default.
When statistics are useful, I favour Plausible and essential goals instead of collecting everything for hypothetical future use.
Privacy Policy, Cookie Policy and any terms are aligned with the actual hosting, forms, analytics, suppliers and languages.
If the business model requires advertising, remarketing or other trackers, I add a CMP, prior blocking, testing and ongoing configuration maintenance.
Explore the services included with bespoke websites and the project price ranges.
The answer does not depend on the size of the website but on its tools, purposes and configuration.
| Scenario | What happens | Banner | Correct action |
|---|---|---|---|
| Essential company website | Hosting, technical logs and contact form without trackers | Normally no | Consistent policies and periodic technical checks |
| Aggregated privacy-first analytics | Essential statistics with no declared persistent identifiers | May not be needed | Check configuration, events, contract and notice |
| Behavioural analytics | Identifiers, sessions, segments or advertising integrations | Usually yes | CMP, prior blocking and technical consent management |
| Meta Pixel, Ads or remarketing | Profiling, attribution and advertising audiences | Yes | No loading before consent; accessible choice and withdrawal |
| External video, map or chat | Possible third-party calls and identifiers | It depends | Use privacy-first facades or block the embed until an appropriate choice |
These examples are indicative. A final assessment must examine the published website, network requests, contracts and actual purposes.
This guide separates Italian rules from suppliers’ technical claims. Sources must be revisited when services, settings or guidance change.
Italian rules on technical tools, consent, banners, analytics and equivalent identifiers.
The European text on storing information and accessing a user’s terminal equipment.
Separates policies, banners, preferences, consent collection and solution configuration.
The performance effects of external scripts, network requests and main-thread execution.
Sources accessed and verified on 23 July 2026. This guide is informational and does not replace legal advice on a specific case.
Direct answers to the questions that most often confuse policies, cookies, tracking and consent.
No. It may process data through forms, email, hosting, logs or suppliers even without cookies. Its notices and legal bases must therefore match its actual processing.
A Privacy Policy remains necessary when personal data is processed. A Cookie Policy documents actual cookies and similar technologies, even when they are only technical and do not require consent.
No. Fingerprinting, localStorage, server-side identifiers and embeds can perform equivalent tracking. The complete behaviour of the website must be assessed.
Under the Italian Authority’s guidance, tools strictly needed for a service require information but not prior consent. They must genuinely be technical and proportionate.
No. Equivalent identifiers, events, transmitted data, the supplier’s role, purposes and possible combinations must also be assessed. The absence of cookies is one element, not the whole test.
Start with decisions you will actually make. If traffic, sources and essential goals are enough, a proportionate tool reduces complexity. Ecommerce, advertising and segmentation may justify deeper tools and the corresponding consent system.
Only when there is no need to collect consent. When non-technical trackers are present, a notice is not enough: the scripts must remain blocked until a valid choice is made.
Not automatically. Reducing tags, pixels, CMPs and external calls does remove a great deal of JavaScript and network activity that often slows pages. Images, code and hosting still matter.
To manage Privacy and Cookie Policies and, where needed, terms and conditions. The CMP is a separate component enabled only when the website’s technologies require consent.
Yes, but it changes the privacy scope. Before activation, update policies and purposes, configure the CMP and prior blocking, test choices and withdrawal and verify the published website.
They can introduce third-party calls and tracking. Where possible, I use local previews and load the embed only after an appropriate action or choice.
Audit cookies, browser storage, network requests, scripts, iframes, forms and events. Repeat the check after new integrations and never rely only on the policy text.
Next step
Explore the design standards for custom websites: proportionate analytics, consistent policies and a complete CMP only when the technologies used genuinely require one.