— 9 min read — Maintenance, support & SLA

Cookie banner rules in the Netherlands 2026: what the DPA demands (and how to measure without one)

The Dutch DPA has been actively checking cookie banners since 2025 and is now imposing penalties. These are the 2026 rules, a checklist for your own banner and the way to measure reliably without one.

by RABZI Studio

In short: the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) has been actively checking cookie banners since April 2025, has warned more than 200 websites and is enforcing in 2026 with periodic penalties and fines. The rules: a reject button as prominent as the accept button, no tracking before the choice and no deceptive design. If all you want to know is how many visitors a page attracts, cookieless analytics lets you measure without a banner at all.

What the AP is enforcing in 2025 and 2026

Two laws govern cookies in the Netherlands. The Telecommunications Act (article 11.7a) says you need consent before you store or read anything on a visitor's device, unless it is strictly necessary or has negligible privacy impact. The GDPR governs what you do with the data afterwards. Tracking cookies process personal data, so the AP enforces through the GDPR. The ACM, the Dutch consumer and markets authority, supervises the Telecommunications Act.

In April 2025 the AP started large-scale checks, prompted by hundreds of consumer complaints about banners where the reject button was impossible to find or cookies were set before anyone had chosen. The first 50 warning letters went out on April 15, 2025. By mid-2025 more than 200 websites had been warned, and three quarters fixed their banner within the deadline. The rest faced enforcement in late 2025 and early 2026. For 2026 the AP has a structural budget of €500,000 per year for cookie supervision, and pre-consent tracking and cookie banners are explicitly on its priority list.

What the AP looks for:

  1. Rejecting is as easy as accepting. A reject button on the same layer, the same size and with the same contrast as the accept button. 'Settings' or 'More options' as the only alternative is not enough.
  2. No tracking before the choice. Until the visitor has chosen, no marketing or tracking cookies are set and the Meta, Google Ads, TikTok and LinkedIn pixels do not fire.
  3. No pre-ticked boxes and no 'continuing to scroll means you agree'.
  4. No deceptive design. A grey reject button next to a brightly colored accept button, confusing copy or a close icon that quietly accepts: the AP calls these dark patterns and holds you to them.
  5. Withdrawing is as easy as giving. A permanently reachable link or icon to change the choice.
  6. No cookie wall. Denying access unless someone accepts does not, in the AP's view, produce freely given consent.

The AP does not only send letters. In 2025 the drugstore chain Kruidvat received a €600,000 fine for tracking cookies without valid consent. That is the number that gave Dutch cookie enforcement a face.

Fines, periodic penalties and the warning letter

The process runs in steps. First a letter in which the AP describes what is wrong with your banner, with a deadline of a few weeks to fix it. If you do not respond, or not enough, an order subject to a periodic penalty follows: an amount per day or per week that you forfeit as long as the violation continues. In practice that is the sharpest instrument, because €2,000 a day does more than a one-off fine you can appeal. If the violation persists, the AP can impose a fine of up to €20 million or 4% of global annual turnover.

If you receive such a letter, do 3 things. Read exactly which violation is named, because the AP is specific. Fix it before the deadline and document what you changed, with screenshots and dates. Confirm in writing to the AP what you adjusted. Those who do that are usually done. Those who ignore the letter are on the list for the next round.

Work through the table with your own site open in a private window. Do it on mobile and desktop, because banners often look different there.

Element What we often see wrong How it should be
Reject button Only 'Accept' and 'Settings' 'Reject' next to 'Accept', same size and color contrast
Timing Pixels fire on page load Nothing beyond functional cookies until a choice is made
Default state Marketing pre-ticked All non-essential categories off by default
Close icon Closing counts as accepting Closing counts as rejecting
Copy 'We use cookies for a better experience' Specific: which categories, which parties, which purpose
Withdrawal Only through the browser Visible link or icon on every page
Evidence Nothing recorded Consent log with timestamp, banner version and choice
Third parties YouTube, Maps or Vimeo embeds always load Placeholder until consent is given

Three points are often forgotten. Embedded videos and maps set cookies without your banner knowing. A tag manager that fires on 'page view' bypasses the banner. And a banner that is fine on desktop but hides the reject button below the fold on mobile is, to the AP, a banner without a reject button.

Since March 2024 Google has required Consent Mode v2 from anyone who wants to use Google Ads audiences or remarketing in the EU. Consent Mode passes the visitor's choice to Google tags, which then behave accordingly. There are 2 variants:

  • Basic: tags only load after consent. No consent means no data, not even anonymous data.
  • Advanced: tags always load, but without consent they only send cookieless pings without identifiers. Google uses those to model part of the missing conversions.

Advanced gives more insight, but the AP looks critically at what goes to Google before consent. Our line: choose Advanced only if you have legally established that the pings contain no personal data, and document that assessment. If in doubt, Basic is the safe choice. In both cases GA4 itself remains a consent-requiring service as soon as you use the defaults: Google Signals on, advertising features on, data shared with Google.

Cookieless analytics as an alternative

The Dutch Telecommunications Act has an exemption for analytics with negligible privacy impact. If you only count page views, sources and devices, set no cookies, do not store IP addresses and share nothing with third parties, you do not need consent for it. In 2026 there are mature tools for exactly that:

  • Plausible (EU-hosted, open source) from about €9 per month, or free on your own server.
  • Umami (open source), free self-hosted, with dashboards you can share with clients.
  • Simple Analytics (Dutch), from about €9 per month, with a useful AI layer.
  • Matomo in cookieless mode, for those who want more depth while keeping full control.

For 80% of small-business sites that is enough: you see which pages work, where visitors come from and how many fill in a form. Combine it with server logs for conversions and you can drop the banner entirely. Nothing changes for your search visibility, because Search Console keeps working as before.

What it means for advertising and conversion tracking

This is where it pinches. If you advertise on Google, Meta or LinkedIn you want to report conversions back to the platform, and that generally requires consent. With an honest reject button we see 30 to 50% of visitors in Dutch online stores decline. That is not data loss, that is the reality that was always there.

What does help, within the rules:

  • Server-side tagging. You send events from your own server to the platforms, with better data quality and less interference from ad blockers. Note: it does not replace consent, it makes measurement after consent more reliable.
  • Meta's Conversions API and Google's Enhanced Conversions, tied to consent status.
  • Modelling through Consent Mode, which statistically fills part of the gaps.
  • First-party data: email, customer accounts and orders in your own systems, where you are allowed to say something.

For a online store that means less pixel data, but cleaner data. If you steer campaigns on margins and customer value from your own order system instead of platform reports, you barely notice the reject button.

Also keep an eye on Brussels. In November 2025 the European Commission proposed, in its Digital Omnibus package, to move the cookie rules into the GDPR, recognize browser settings as a valid choice and exempt low-risk analytics. In 2026 that is still a proposal, not law. Until that changes, what the AP enforces is what counts.

Implementation in 1 day

Getting a banner in order is not a multi-week project. This is how we do it in 1 working day:

  1. Inventory (1 hour). Scan of all cookies and scripts, including those from embeds and the tag manager.
  2. Categorization (1 hour). Functional, analytics, marketing, with an owner and purpose per script.
  3. Banner (2 hours). A CMP such as Cookiebot, CookieYes or a lightweight custom implementation, with a reject button on the first layer and a consent log.
  4. Tag manager (2 hours). Every tag behind consent-based triggers, Consent Mode v2 configured, embeds behind placeholders.
  5. Testing (1 hour). In a private window, on 3 devices, with a cookie scanner before and after the choice.
  6. Documentation (1 hour). Cookie statement updated, processing register amended, screenshots archived.

RABZI estimate: clients on our website maintenance plans (Care from €95 per month) get the cookie check and the annual re-audit included. A one-off consent and measurement setup, including Consent Mode v2, server-side tagging or a cookieless analytics stack, falls under conversion and digital marketing from €1,950 excl. VAT. You get a banner that is correct, a measurement setup that works and a file you can show the AP.

Companies that do receive a letter often hear it together with other compliance questions: accessibility and, for suppliers to critical sectors, the Dutch Cyber Security Act. It pays to look at all 3 at once.

Frequently asked questions

Is a cookie banner mandatory in the Netherlands in 2026? No. A banner is mandatory if you use cookies or scripts that require consent, such as marketing pixels, remarketing or embedded video. If you only use functional cookies and privacy-friendly, cookieless analytics, a clear cookie statement is enough and you do not need a banner.

Can I use Google Analytics 4 without consent? Only if you configure GA4 in a privacy-friendly way: no Google Signals, no advertising features, no data sharing with Google, IP anonymization and a data processing agreement. Many organizations do not get there and put GA4 behind the banner instead. A cookieless alternative is often simpler and just as useful.

What do I do if I receive a letter from the Dutch DPA? Read which violation is named, fix it before the deadline, record the change with screenshots and dates and confirm in writing to the AP what you did. Three quarters of the warned websites were done with that. Ignoring the letter leads to an order subject to a periodic penalty.

Does a real reject button cost me conversion data? You will see fewer conversions in the advertising platforms, because 30 to 50% of visitors decline. The conversions themselves do not disappear. With server-side tagging, Consent Mode modelling and steering on your own order system you keep enough visibility to optimize campaigns.

Conclusion

The 2026 cookie banner rules are not new, the enforcement is. A reject button next to the accept button, nothing loading before the choice, no tricks and a provable consent log: with that you are ready for the AP. If all you want to know is how your site performs, cookieless analytics lets you drop the banner altogether. Want to be sure your banner and measurement setup are right? Book an intro call, we check your site within 2 business days and tell you exactly what needs to happen.

Sources

Related

Reply < 1 business day · Available for new projects

Let’s build something.

Tell us about your project. You will hear back within one business day and receive a concrete proposal within a week.

info@rabzi.nl · ...