Skip to main content
HeboraHeboraGDE 015
  • FRFrançais
  • ENEnglish
  • NLNederlands
Home›SEO & GEO in Belgium›Cookies · pre-publication test
Cookies · pre-publication test

Cookie banner in Belgium: what must be blocked before consent

A polished banner is not enough. If Analytics, a pixel, a video or an advertising tool already sets a tracker before the choice, the real behaviour contradicts the interface.

Written and checked by Hebora on 15 August 2026.

Shop owner and adviser testing cookie consent on a phone and laptop
Field checkTest before acceptance, after refusal and after withdrawal — on every relevant device.

Short answer

Non-essential trackers must wait for valid consent

The Belgian Data Protection Authority requires prior consent for cookies that are not strictly necessary, a genuine choice, refusal as accessible as acceptance and easy withdrawal. Necessary cookies may operate without consent, but they must genuinely be necessary.

Before choiceNo non-essential tracker should leave the device.
Same levelReject must be as accessible as accept.
Easy withdrawalChanging one’s mind cannot become a hidden journey.
€50,000Actual fine in the Roularta media case; not an automatic rate for every SME.

What a cookie banner must do in practice

  • Before any choice: load only what is strictly necessary for the requested service.
  • At the first level: explain purposes and offer accept/reject without artificially steering the user.
  • By purpose: provide granular choices when several uses exist.
  • After the choice: keep useful evidence, honour refusal and make withdrawal easy.

A cookie name is not the only evidence. Network requests, browser storage, scripts and embedded components must be observed.

A real fine is not a universal price list

The Belgian DPA fined Roularta €50,000 in a case covering several news websites and specific cookie failures. It is a real decision that shows how rules are applied, not the “standard invoice” for a small website.

Depending on the case, other outcomes include remediation orders, processing restrictions and GDPR sanctions. Severity, duration, number of people, cooperation and corrective action are among the factors assessed.

Hebora’s cookie audit, evidence by evidence

  1. Zero state. Fresh browser, no choice: capture network requests, cookies, local storage and scripts.
  2. Three journeys. Accept, reject, then withdraw; desktop and mobile.
  3. Source of every tracker. CMS, tag manager, video, map, chat, payment, analytics or advertising.
  4. Correction. Prior blocking, purpose-based activation, removal where possible and a permanent preferences link.
  5. Delivery. Before/after table, network captures, supplier list and factual copy for the DPO or lawyer.

A website with no non-essential tracker does not need to invent a banner. Removing a needless tool can be better than adding a consent layer.

Clear boundary

Hebora performs technical audits and corrections. This content is not legal advice, does not certify compliance and does not replace a lawyer or DPO when your situation needs legal interpretation.

Verified official sources

  • Belgian Data Protection Authority — cookies and other trackers (official guidance in French)
  • Belgian Data Protection Authority — Roularta cookie case, €50,000 fine (official source in French)
  • EUR-Lex — General Data Protection Regulation (GDPR)

Sources checked on 15 August 2026.

Technical audit

Test my banner before publication

Hebora captures network activity before a choice, after refusal and after withdrawal on mobile and desktop, then corrects actual tracker loading.

Test my trackers

Continue the review

AI-built website: what still needs checking in Belgium

The website owner must still check business disclosures, legal grounds, notices to individuals, cookies, security, supplier contracts and — when applicable — e-commerce and accessibility rules. The platform helps build; it does not make those decisions for you.

Lovable Cloud and GDPR: who is responsible for what in Belgium?

Lovable’s DPA generally describes the customer as controller and Lovable as processor for data handled on the customer’s behalf. The customer still configures the app, informs users, chooses data and integrations, and handles requests to exercise data rights.

AI chatbot on a Belgian website: what must you disclose and check since 2 August 2026?

Article 50 of the AI Act requires providers to design direct-interaction systems so people are informed that they are interacting with AI, unless that is obvious. The website owner must also check its own duties as deployer and data controller.

HeboraHebora
Catalogue
Hebora, Belgium
Entry
GDE 015
Edition
2026
  • HEB 04Websites
  • HEB 05Visibility
  • HEB 06Automation
  • HEB 07AI Assistant

Index

Services for small businessesHebora projectsConstruction and homeClient referencesWebsite assessmentContact HeboraAbout HeboraBusiness introducerHebora guides
Legal noticePrivacy policy© 2026 Hebora
  • Home
  • Work
  • Services
  • Contact
  • 0My offer
  • Legal
AssessmentThe audit of your siteBusiness introducerYou introduce, we buildGuidesPractical guides, nothing soldClient reviewsWhat our clients say about us
HeboraHeboraPRIV / 01

YOUR CHOICE

Cookies, no detours.

No advertising cookies. Your language and favourite projects stay on this device.

OPTIONS

What this device remembers.

Privacy policy