Cookie banners have similar requirements in the European Economic area (EEA), but simply using one does not guarantee a website is compliant in every EU country.
The Autoriteit Persoonsgegevens (AP), the Dutch Data Protection Authority, supervises the use of cookie banners in the Netherlands. By November 2025, more than 200 websites had received warnings about their cookie banners, and about three-quarters needed to change theirs following the AP's Cookie Consent rules.
Dutch Cookie Banner requirements are based on Article 11.7a of the Telecommunications Act and the GDPR where personal data is involved.
Tracking Cookies and many other non-essential cookies require clear user consent. AP requires websites to give visitors a genuine, informed choice to accept or reject Tracking Cookies and obtain consent before setting them.
Functional cookies and certain limited analytics cookies with little privacy impact may be used without Cookie Consent.
AP also provides guidelines for valid Cookie Consent. The Kruidvat case illustrates that dark patterns, such as using cookie walls or pre-ticked banner’s boxes, must be avoided.
This means compliance needs more than having Accept and Reject buttons on the banner. Banner configuration, prior consent, button design, default settings, and the scripts running behind the banner must be set correctly.
This guide explains how to create a compliant Cookie Banner for Dutch websites that meet AP’s requirements.
What Are the Dutch Cookie Banner Requirements Under the AP?
Dutch cookie banners must provide clear data processing purposes on the first layer of a banner, obtain prior consent before loading trackers, use equal button prominence for accepting and rejecting cookies without hiding choices or making them less visible, do not use pre-ticked boxes, use clear and concise language, make the withdrawal of consent as easy as giving consent, and do not confuse consent with legitimate interest.
The AP provides specific guidance on how to design clear cookie banners. Dutch Cookie Consent rules set 9 principles that can help businesses create a compliant Cookie Banner:
1. Provide information about the processing of personal data and the purpose thereof
Under the GDPR, consent must be freely given, specific, informed and unambiguous. The AP also stresses that users must clearly understand that they are accepting cookies or tracking rather than merely acknowledging that they have read a notice.
If a website processes large amounts of personal data for many different purposes, users should have a granular choice to accept or reject cookies for different purposes separately. Allow visitors to make an informed choice per purpose and use the personal data use only for that purpose.
AP encourages a 2-layer Cookie Banner design. The first layer should contain essential information, clearly stating that you process personal data and for which purposes. The second layer should provide further details regarding specific objectives.
Visitors should also know what cookies mean for their personal data before giving consent.
2. Do not use pre-ticked boxes
The AP doesn’t allow using pre-ticked boxes on the cookie pop-up by default. This does not constitute valid consent.
A website visitor should click on specific options and therefore actively make a choice.
3. Use clear and concise language
The AP requires using plain text on the cookie notice. Do not use vague or misleading language. The visitor must clearly understand that they are consenting to tracking cookies, not merely confirming they have read the text.
Also, use straightforward button wording, such as "Accept", "Agree", “Reject”, or “Decline”.
4. Present different choices on a single layer
The GDPR requires that declining cookies should be as easy as accepting them. Therefore, you should place the “Reject” and “Accept” buttons on the same layer. This means a user should not have to look through additional layers for the “Reject” button.
5. Do not hide certain choices or make them less visible
Businesses must ensure the “Reject” button is clearly visible and readable. Do not hide the button by forcing visitors to scroll down to reject cookies.
The decline button must also be clearly distinguishable from the cookie banner background.
6. Do not require extra clicks to decline consent
Declining cookies should not require more clicks than accepting them.
For example, you may not ask the visitor for extra confirmation after they have already chosen to reject cookies.
7. Do not use inconspicuous links in the text to refuse or decline cookies
The option to decline cookies should be as easy as accepting them.
For example, do not hide the decline choice as a link in a piece of text, thus forcing your website visitor to search unnecessarily.
8. Make the withdrawal of consent as easy as giving consent
Clearly state that your website visitor can withdraw consent at any time. Inform visitors that they can withdraw their consent before making a choice.
Also, inform visitors how they can withdraw their consent before making a choice.
The option to withdraw consent must always be easy and accessible, even outside of the cookie banner.
9. Do not confuse consent with legitimate interest
Tracking and many other types of cookies need cookie consent.
For functional and limited analytical cookies, businesses may rely on legitimate interest (yours or a third party’s). In this case, no consent is required.
If you use cookies based on legitimate interest, you must weigh the interests involved. You must also be able to demonstrate this evaluation of interests.
Even if you rely on legitimate interest, you must clearly inform website visitors how you process their personal data, and they must be able to easily object to functional and limited analytical cookies.
Just as with withdrawing consent, it must be clear to the visitor how they can object.
Many website owners do not develop their own cookie banners, but instead use a Consent Management Platform (CMP).
To comply with AP cookie consent rules, the AP recommends using CMPs, that often offer additional privacy features, such as standard texts for processing purposes, automatic scanning of cookies and trackers, and the ability to block scripts until consent is received.
CookieScript CMP is valued by users. In 2025, CookieScript received its fourth consecutive badge in a row as the leader on G2, and became the best CMP on the market for a whole year!
It’s also a Google-certified CMP with the Golden tier in Google’s tiering system, and is recommended by Google to use with its analytics and marketing tools.
CookieScript CMP offers the following features, needed for global privacy compliance:
- Integrations with systems like Wix, Shopware, OpenCart, etc.
- Highly customizable cookie banner.
- Google Consent Mode v2 integration
- IAB TCF v2.2 integration
- Google Tag Manager integration
- Global Privacy Control
- Certification by Google
- CookieScript API
- Cookie Scanner
- Consent recordings
- Third-party cookie blocking
- Geo-targeting
- Self-hosted code
- Cookie banner sharing
- Cross-domain cookie consent sharing
When Is Cookie Consent Required in the Netherlands?
Not every cookie requires consent in the Netherlands. Functional cookies and limited analytics cookies, when they have little impact on a visitor's privacy, can be set without consent, while tracking and many other non-essential cookies require consent.
For example, cookies needed to keep products in a shopping cart, remember essential technical settings, or provide a service specifically requested by the visitor could be classified as strictly necessary cookies, and thus, do not need user consent.
By contrast, advertising, profiling and cross-site tracking cookies commonly require opt-in consent under Dutch cookie law.
Note: businesses must obtain prior consent, meaning that it must come before the relevant tracking takes place. Showing a cookie banner while advertising pixels, analytics tools or other non-essential cookies are already running in the background violates the GDPR.
The same principle applies after rejection. If a visitor selects Reject All, all trackers must stop loading, including your website’s cookies, a tag manager’s scripts, and any marketing or analytics script from third parties.
This is why Dutch cookie compliance needs to be checked at both the banner level and the technical level. The cookie banner design should comply with the GDPR. The signal, reflecting user choice, must reach all vendors and other third parties that set cookies and other trackers on the site.
Cookie Walls, Pre-Ticked Boxes, and Other Practices to Avoid
Several common cookie banner design practices can undermine valid consent.
The AP does not allow using cookie walls. A cookie wall prevents people from accessing a website or app unless they agree to tracking. According to the AP, cookie walls are not permitted under the GDPR because they do not constitute valid consent. Cookie consent must be freely given. Using cookie walls violates this principle since users have to accept tracking if they want to access the website.
Pre-ticked boxes are another example of invalid cookie consent. Only strictly necessary cookie categories could be selected by default when the visitor first sees the banner. The AP explicitly advises organizations not to select checkboxes for optional cookie categories.
The Kruidvat case illustrates well the case of Pre-ticked boxes. The AP found that Kruidvat.nl had used a pre-ticked option on their cookie banner for tracking cookies. In 2024, the regulator initially imposed a €600,000 fine on AS Watson, the company behind Kruidvat. After an objection, the AP reduced the fine to €50,000, but the underlying finding that the cookie-consent mechanism was invalid remained.
The AP has also warned more than 200 Dutch websites that their banners have the same problem with pre-ticked consent boxes.
Pre-ticked options fail because silence or inactivity does not mean an affirmative decision. If a user simply continues scrolling without changing a default that already permits tracking, the website cannot treat that inactivity as an active expression of consent.
Netherlands cookie banner requirements also forbid using dark patterns: banner’s design choices that push visitors toward the option preferred by the website rather than helping them make a neutral decision. Examples include making the Accept All button much easier to find than Reject All, hiding rejection inside a settings menu, or requiring more steps to refuse cookies than to accept them. The AP's guidance clearly states that rejecting cookies should be as easy as accepting them.
The Kruidvat enforcement analysis also highlights a broader technical risk: websites can violate privacy regulations when tracking begins before consent or continues after rejection. Websites must control script behavior, which is just as important as the correct cookie banner.
With CookieScript Cookie Scanner, you can automatically scan your website for cookies, tracking pixels, local storage, and other trackers:
How to Create a Compliant Cookie Banner for Dutch Websites
To create a compliant cookie banner for visitors in the Netherlands, obtain explicit consent for non-essential cookies, implement prior consent, avoid pre-ticked boxes for optional categories, use equal button prominence, avoid dark patterns, make consent reversible, use plain language, and test the banner design and behavior.
According to the Dutch regulator, a compliant cookie banner needs to combine clear design with correct consent management, blocking all non-essential scripts before consent.
When configuring a cookie banner for Dutch websites, use the following AP cookie banner guidelines:
- Obtain explicit consent for non-essential cookies
Continuing to scroll, browse, or ignore the banner does not mean users consent to tracking. - Implement prior consent
Block non-essential scripts and trackers until the visitor provides the required consent. - Do not use pre-ticked boxes for optional categories
Optional cookie categories must be switched off by default for Dutch visitors. - Use equal button prominence
Users should be able to reject cookies from the same banner layer from which they can accept them. Do not hide Reject All in other layers or in the text. - Avoid dark patterns
Do not intentionally make rejection harder, less obvious or more time-consuming than acceptance. - Make consent reversible
Dutch cookie compliance requires giving visitors an easily accessible way to reopen their cookie preferences and withdraw or modify consent later. - Use plain language
Use plain text on the cookie notice without dense legal jargon or vague purposes for data collection. Clearly state who you are, what data you collect, and for what reasons (e.g., analytics, marketing) in simple Dutch or English.
It is also important to test the banner design and behavior implementation. Open the website as a new visitor and check which cookies and trackers appear before interacting with the banner. Then test Reject All, category-specific choices, and Accept All separately. Use an incognito window to test the banner, and test it on different devices.
Use automatic cookie scanners, such as CookieScript Cookie Scanner, to scan your website for cookies and other trackers:
Pay particular attention to tag managers and third-party integrations. A marketing pixel added months after the cookie banner was configured can create a prior-consent problem if it loads independently of the CMP.
Finally, review your cookie banner periodically. Websites change: analytics platforms are replaced, new advertising tags are introduced, plugins add trackers and marketing teams deploy new technologies. The banner and Cookie Declaration should continue to reflect what the website actually does.
CookieScript CMP could be used for consent management. It scans websites for cookies and automatically updates the Cookie Declaration, manages script execution, blocks non-essential scripts until consent is given, records user consent, and helps to implement prior consent.
Frequently Asked Questions
How to create a compliant cookie banner in the Netherlands?
To create a compliant cookie banner for visitors in the Netherlands, obtain explicit consent for non-essential cookies, implement prior consent, avoid pre-ticked boxes for optional categories, use equal button prominence, avoid dark patterns, make consent reversible, use plain language, and test the banner design and behavior. Use CookieScript CMP for cookie scanning and consent management.
What are the Dutch cookie banner requirements in 2026 under the AP?
Under the Autoriteit Persoonsgegevens (AP), Dutch cookie banners must provide clear data processing purposes on the first layer of a banner, obtain prior consent before loading trackers, use equal button prominence for accepting and rejecting cookies without hiding choices or making them less visible, do not use pre-ticked boxes, use clear and concise language, make the withdrawal of consent as easy as giving consent, and do not confuse consent with legitimate interest.
When is cookie consent required in the Netherlands?
Not every cookie requires consent in the Netherlands. Functional cookies and limited analytics cookies, when they have little impact on a visitor's privacy, can be set without consent, while tracking and many other non-essential cookies require consent. Businesses must obtain prior consent before setting non-essential cookies. Use CookieScript Cookie Scanner to scan your website for cookies and other trackers.
What is valid cookie consent under Dutch law?
According to the Dutch Data Protection Authority AP, valid consent must be freely given, specific, informed, unambiguous, not based on pre-ticked choices, easy to refuse, and easy to revoke. Users must clearly understand that they are accepting cookies or tracking. Do not load tracking cookies, analytics cookies, advertising pixels, and other non-essential cookies before consent. CookieScript CMP can help complying with the Dutch cookie law.
What is the Kruidvat cookie banner case?
The Kruidvat case illustrates the fine for violating cookie banner requirements in the Netherlands, imposed by the Dutch regulator AP. The AP found that Kruidvat.nl had used a pre-ticked option on tits cookie banner for tracking cookies. In 2024, the regulator initially imposed a €600,000 fine on AS Watson, the company behind Kruidvat, that was later reduced to €50,000. CookieScript CMP can help avoid penalties for non-compliance.
What design practices are prohibited by the Dutch cookie law?
The Autoriteit Persoonsgegevens (AP) prohibits using pre-checked boxes, dark patterns on the cookie banner, and loading non-essential or Third-Party Cookies before explicit consent. CookieScript CMP can help comply with the Dutch cookie law.