HubSpot cookie banner: set it up, and know what it doesn’t block

When HubSpot’s own banner is enough, when you need a consent tool, the new editor step by step, and what declining does to your reports.

Updated · 12 minutesBy Matthew Labrooy, Managing Director

A website of Example GmbH with a cookie banner offering Accept and Decline, an embedded video behind it already marked loaded. Beside it, two lists: tracking cookies, analytics and an ad pixel wait for the banner; a tag pasted into the header, an embedded video and a heatmap script run anyway.
In short

HubSpot’s cookie banner (called the consent banner in HubSpot’s settings) controls HubSpot’s own tracking cookies, plus Google Analytics, Google Tag Manager and ad pixels when you connect them through HubSpot. The banner doesn’t block anything you paste into your site’s code yourself, such as a LinkedIn tag, Hotjar or an embedded YouTube video.

HubSpot’s banner is enough for a site that runs on HubSpot with HubSpot’s own integrations. A WordPress site with a dozen scripts needs a consent tool, which then passes the visitor’s choice to HubSpot. Which banner type and wording your site needs is your data protection officer’s call.

Where
Settings > Privacy & Consent > Cookies, one set of banners per domain
Edition
The banner on every plan, free included. The style editor from Marketing Hub or Content Hub Starter
Version
Every account moves to the new editor (v2); the automatic move started on 11 May 2026
Blocks
HubSpot tracking cookies, and Google and ad tags connected through HubSpot. Not scripts you added by hand
When visitors decline
Forms still work. The contact arrives without its page history, often as direct traffic

HubSpot’s cookie banner or a consent tool: which do you need?

The answer depends on which scripts run on your site, and who can stop them before the visitor says yes. HubSpot’s banner can only hold back what HubSpot loads itself.

Your set-upWhat we’d useWhy
Website, blog and landing pages on HubSpot. Google Analytics or Tag Manager connected in HubSpot’s settingsHubSpot’s bannerThe banner controls everything that loads, and passes the choice to Google through Consent Mode
Site on HubSpot, plus tags pasted into the header (LinkedIn Insight Tag, Hotjar, a chat from another vendor)HubSpot’s banner, with each pasted tag wrapped in HubSpot’s consent listenerPasted tags fire before consent unless a developer ties them to the banner
Site on WordPress, TYPO3 or another CMS with the HubSpot tracking code and several other toolsA consent tool (Cookiebot, Usercentrics, Borlabs Cookie and similar)The consent tool scans the whole site and blocks every tag until consent. HubSpot gets the choice through its consent API
Main site on WordPress with its own consent tool, landing pages on a HubSpot subdomainThe consent tool on the main site, HubSpot’s banner only on the HubSpot subdomainOne banner per domain. Otherwise visitors click away two banners
You need a record of each consent, IAB TCF signals for ad networks, or one consent across several domainsA consent toolHubSpot’s banner doesn’t offer these

Our view: on a pure HubSpot site, a second tool adds cost and a second place where things break. As soon as tags arrive from other places, a consent tool is the cleaner choice, because one tool then decides for every script on the page.

What the HubSpot cookie banner blocks, and what it doesn’t

With an opt-in banner, HubSpot waits for the visitor’s choice before it sets its tracking cookies. Everything else depends on how a tool got onto the page.

On your pageBefore consentWhat decides it
HubSpot tracking cookies (__hstc, hubspotutk, __hssc)Not setThe banner
Necessary cookies (the consent choice itself, bot protection)SetAlways on, they need no consent
Google Analytics 4 or Tag Manager, connected under HubSpot’s integrationsHeld back, or cookieless pings with Consent ModeThe banner
Google Analytics or Tag Manager pasted into the header as codeRunsYou, with your own consent code
Ad pixels added with HubSpot’s ads tool (Meta, LinkedIn, Google)No cookies until opt-inThe banner. One pixel per network through HubSpot
Ad pixels inside Google Tag ManagerRun, unless GTM checks consentYour Tag Manager set-up
HubSpot formsShow and submitAlways. The contact is created, without page history
HubSpot chatShowsIts own setting, “Consent to collect chat cookies”, in the chatflow
Embedded YouTube or Vimeo video, maps, heatmaps, other vendors’ chatsRunNothing in HubSpot. Wrap them in the consent listener, or use a consent tool

Check it yourself in a private browser window. Open your site, don’t click the banner, and look at the cookies in the browser’s developer tools. Every non-necessary cookie you see there was set without consent.

How to set up the HubSpot cookie banner, step by step

These steps use the new editor (v2). If you see a button “Switch manually” at the top of the Cookies tab, your account still runs the old editor; switch first and assign each old policy to its domain. You need permission to edit website settings.

  1. Step 01

    Open the banners for your domain

    Go to Settings > Privacy & Consent > Cookies. HubSpot domains appear on their own. For a site outside HubSpot, click Add external domain; HubSpot checks that its tracking code runs there. www.example.com and example.com count as two domains, so add the one your site really loads on.
    HubSpot, Add external domain: note that www.example.com and example.com are separate domains, domain field filled with www.example.com
    Adding an external domain. HubSpot checks the tracking code on the homepage before it accepts the domain.
  2. Step 02

    Name the banner and choose where it shows

    Give it an internal name. Leave the URL path empty for the whole domain, or enter a subfolder such as de. Pick the countries; with none selected, every visitor sees it. HubSpot reads the country from the visitor’s IP address, so a VPN can switch the banner off.
    HubSpot, Create consent banner: internal name Opt-in by category, an empty URL path, countries not selected, Global Privacy Control switched on
    The configuration step. Global Privacy Control makes the banner respect the browser signal of visitors who opted out of tracking in general.
    HubSpot country list: the group European Union with Portugal, Austria, Romania and Belgium
    The country list starts with the group European Union. Switzerland isn’t part of it and has to be added on its own.
  3. Step 03

    Leave the advanced switches off

    Deactivate cookies and Allow all cookies both hide the banner on the pages and countries you chose. Use them only for a deliberate exception, such as no tracking at all on a members’ area.
    HubSpot, Advanced cookie banner settings: switches Deactivate cookies and Allow all cookies, both off
    Both advanced switches remove the banner where they apply. Visitors then can’t choose.
  4. Step 04

    Choose the banner type

    Notification only informs, and cookies load straight away. Opt-in loads them after a yes; HubSpot marks it “Suggested for: Europe”. Opt-out loads them and lets visitors say no. Tick Allow opt-in by category if visitors should choose analytics, functionality and advertising separately.
    HubSpot, Select a banner type: Notification, Opt-in suggested for Europe with Allow opt-in by category ticked, and Opt-out
    Opt-in by category: no HubSpot tracking cookies until the visitor accepts, and a choice per category.
  5. Step 05

    Set the language and texts

    Pick the default language and HubSpot fills in its standard text, German included. Rewrite the notification text so it names your tools and links to your privacy policy. Keep the button labels short and plain.
    HubSpot, Consent banner content: notification text, Accept and Decline button texts and the disclaimer text
    The banner texts. The disclaimer shows only on opt-in banners and explains what declining does.
  6. Step 06

    Fill in the categories and add a Decline all button

    Each category gets a label and a description. Name the tools behind each one, for example “Google Analytics, HubSpot analytics”. Then tick Show decline all button, so the category window offers Accept all and Decline all side by side.
    HubSpot, Consent categories content: the analytics category with label Analytics and its description
    One description per category. HubSpot’s standard text is generic; your own tools make it useful.
    HubSpot, Accept all and Save button texts, Show decline all button ticked, button text Decline all
    Show decline all button adds a third button next to Accept all and Save settings.
  7. Step 07

    Publish and switch off any old default banner

    Click Publish. The list shows each banner with its URLs, countries and an Active switch. If you turned on HubSpot’s data privacy settings earlier, HubSpot already created a default opt-in banner called “GDPR Policy” for all URLs and countries. Keep one banner per page and country, and switch the other off.
    HubSpot, Default consent banners: GDPR Policy switched off, Opt-in by category switched on, both for all URLs and all countries
    Two banners on the same pages and countries compete. Here the automatic “GDPR Policy” is off.
  8. Step 08

    Match the style to your site

    Under Global consent banner style and preview, click Customize. Set the position, background, font and buttons, and preview each banner. The style applies to all banners on the domain. Give Accept and Decline the same weight, so neither looks like the default.
    HubSpot, Customize cookie banner: global styles for banner position, background, font and buttons, with a preview of the opt-in banner
    The style editor (Marketing Hub or Content Hub Starter and up). Changes apply to every banner of the domain.
  9. Step 09

    Add a Cookie settings link to the footer

    Copy the code under Cookie Settings Button and put it in your footer, on HubSpot pages and on external pages alike. The link reopens the banner so visitors can change their mind. Only opt-in banners can be reopened this way; a notification banner can’t.
    HubSpot, Cookie Settings Button: embed code for a button that calls showBanner, with a Copy button
    The embed code. Most themes have a footer where you paste it once for all pages.
  10. Step 10

    Test it as a visitor

    Open the site in a private window. The banner should appear before anything else happens. Click Cookies settings, check the categories, decline, and confirm in the developer tools that no __hstc or hubspotutk cookie appears. Visitors who already had HubSpot cookies before the banner went live see it only once those expire.
    An opt-in cookie banner on a demo page of Example GmbH: notification text with Cookies settings, Accept and Decline
    The published banner on a test page. Accept and Decline look the same here, as set in the style editor.
    The cookie category window: Necessary always active, Analytics and Advertisement switched off, buttons Accept all, Decline all and Save settings
    After a click on Cookies settings: one switch per category, and Decline all next to Accept all.

What changes in your HubSpot reports when visitors decline cookies

Your traffic doesn’t drop because of the banner. HubSpot still counts visits and page views, anonymously. What changes is that those visits can’t be tied to a person any more.

  • No page history on the contact. A visitor who declines and then fills in a form becomes a contact with zero page views. Sales sees the form, not the five pages read before it.
  • Sources shift to direct traffic. HubSpot takes the original source from the page the form was sent from. If the visitor came from a LinkedIn ad and submits on that same page, the UTM parameters are still in the address and the source is right. If they clicked to another page first, the contact shows as direct traffic.
  • Google Analytics shows fewer visitors than HubSpot. HubSpot counts declined visits anonymously, Google Analytics without Consent Mode doesn’t count them at all. Pick one tool as the source for traffic numbers.
  • Lead scoring on page views weakens. Points for visited pages only reach contacts who accepted, so build your lead scoring on form answers and email engagement as well.
  1. Step 01

    See a contact’s choice

    Open the contact, go to Activities and include Analytics events in the filter. An accepted banner shows as “accepted cookie tracking on” with the page address.
    HubSpot contact Max Mustermann: timeline with form submission, two page views, and analytics activity accepted cookie tracking on the demo page
    A visitor who accepted: page views, the form and the consent all on one timeline.
    HubSpot contact Erika Mustermann: timeline with form submission and created from Paid Social, no page views
    A visitor who declined: the form and the source from the UTM parameters, but no page views.
  2. Step 02

    Build a segment by consent

    Create a contact segment with the property Privacy consent and the values Approved, Declined or Revoked. With categories switched on, Approved and Declined refer to the analytics cookies. The property holds the cookie choice only; permission to send email is a separate setting, covered in our double opt-in guide.
    HubSpot segment filter: Privacy consent, Contact has completed with value, options Approved, Declined and Revoked
    The filter for consent choices. Revoked means the visitor withdrew consent later.
  3. Step 03

    Report on banner clicks

    In a custom report (Professional or Enterprise), choose Cookie banner as the data source. Then use clicks or views, and fields such as analytics category consent, to see the share of visitors who accept.
    HubSpot custom report builder: choose data sources, search for Cookie shows the source Cookie banner under Marketing
    The data source Cookie banner sits under Marketing.
    HubSpot custom report Cookie banner accepted and declined: analytics category consent yes 2, no 1, report total 3
    Clicks on the banner by analytics consent. The share of yes is the share of visitors you can follow.

Common problems with the HubSpot cookie banner

ProblemUsual causeFix
The banner doesn’t showNo banner published for that exact domain (www or not), the tracking code is missing, or a theme hides it with CSSCheck the domain spelling, the tracking code and the theme’s CSS. Test in a private window without ad blockers
Two banners on the same pageHubSpot’s banner and a consent tool both run, or the default banner covers the WordPress main siteOne banner per domain. Limit HubSpot’s banner to the HubSpot subdomain
The banner comes back on every pageThe browser or an extension deletes cookies, so the choice is lostNothing to fix on your side if it only happens in that browser
The banner shows inside an embedded pageThe embedded page carries the tracking code tooLimit the banner to the right paths, or remove the tracking code from the embedded page
Cookies load before anyone clicksThe banner type is Notification, or the scripts were pasted by handSwitch to Opt-in, and wrap pasted scripts in the consent listener
Old custom CSS no longer worksThe move to v2 changed the banner’s HTML; selectors such as #hs-eu-cookie-confirmation no longer matchUse the style editor instead of custom CSS
The Cookie settings link does nothingThe banner is a notification bannerOnly opt-in banners can be reopened

Cookie banner settings for Germany, Austria and Switzerland

HubSpot gives you the controls. Your data protection officer or lawyer decides which ones your site needs. These are the settings they usually ask about.

  • German texts. Choose German as the default language and HubSpot fills in its German standard texts. For a site in German and English, create one banner per language path, for example de and en.
  • Countries. The group European Union covers Germany and Austria. Switzerland, Liechtenstein and the UK are outside it and need their own selection, or leave the countries empty so every visitor sees the banner.
  • Decline as easy as accept. Show decline all puts Decline all next to Accept all, and the style editor gives both buttons the same look.
  • The privacy policy. Name every tool and cookie the banner covers there, and link it from the banner text. HubSpot’s list of the cookies it sets covers the HubSpot part.
  • Hosting and data processing. Where HubSpot stores the data and how to accept its data processing agreement is a separate question; our guide to the HubSpot EU data centre covers it.

How we set up cookie consent in a HubSpot portal

Most consent problems we see come from tags nobody listed. We start with a list of what loads on the site, and open the banner editor after that.

  1. Step 01

    List what loads

    We open every template of the site in a fresh browser and note each script and cookie, and where it was added: HubSpot integration, header code, Tag Manager or a module.
  2. Step 02

    Decide the banner

    From that list follows HubSpot’s banner or a consent tool, by domain. Your data protection officer signs off the type and the texts.
  3. Step 03

    Wire the tags

    HubSpot’s integrations for Google, the consent listener for pasted tags, or the consent tool’s blocking. Google Consent Mode where ads run.
  4. Step 04

    Fix the reporting

    A segment and a report for consent, sources checked against form pages, and lead scoring that doesn’t rely on page views alone.
  5. Step 05

    Check it twice a year

    New tools arrive with every campaign. A private-window test and a look at the banner report every six months catch them. The same test is one of the checks in our HubSpot portal audit.

Frequently asked questions

Is HubSpot’s cookie banner free?

Yes. The banner works on every HubSpot plan, free included. Changing its colours, position and buttons in the style editor needs Marketing Hub or Content Hub Starter or higher.

Does the HubSpot cookie banner block Google Analytics?

Only if Google Analytics or Tag Manager is connected in HubSpot’s integration settings. Then HubSpot holds it back until consent and passes the choice to Google through Consent Mode. Code you pasted into the header runs regardless.

Does the HubSpot cookie banner block scripts I added myself?

No. HubSpot’s banner holds back only HubSpot’s own cookies and the Google and ad tags connected through HubSpot. A LinkedIn tag, Hotjar or a YouTube video pasted into your site’s code runs before consent unless a developer wraps it in HubSpot’s consent listener or a consent tool blocks it.

Does the HubSpot cookie banner make a website GDPR-compliant?

Not on its own. The banner covers only what HubSpot loads, so tags added by hand still need their own consent handling. Whether your banner type, texts and tools meet the GDPR and local law is for your data protection officer or lawyer to decide.

Does the HubSpot cookie banner support Google Consent Mode v2?

Yes, on pages hosted by HubSpot. Google Analytics 4 connected in HubSpot’s integrations gets advanced Consent Mode, Google Tag Manager gets basic Consent Mode, both with an opt-in banner for EU, EEA and UK visitors. On other sites, or with Google code pasted by hand, a developer sets it up.

Do HubSpot forms work if a visitor declines cookies?

Yes. The form shows and the contact is created. HubSpot just can’t link the visitor’s earlier page views to the contact, and the source may show as direct traffic.

Why did my traffic drop after adding the HubSpot cookie banner?

Not in HubSpot. HubSpot still counts declined visits anonymously. What changes is attribution: declined visits can’t be tied to a contact, and some sources move to direct traffic. Google Analytics without Consent Mode does count fewer visitors.

How long does HubSpot remember a visitor’s cookie choice?

Six months. HubSpot stores the choice in the cookies __hs_opt_out and __hs_cookie_cat_pref, which expire after six months, and then shows the banner again. Visitors who clear their cookies see it sooner.

Can I use Cookiebot or Usercentrics instead of HubSpot’s banner?

Yes. Turn HubSpot’s banner off for that domain and pass the visitor’s choice to HubSpot through its consent API, or use the Cookiebot app from the HubSpot Marketplace. Don’t run both banners.

Why is my HubSpot cookie banner not showing?

Usually the banner isn’t published for that exact domain (with or without www), the tracking code is missing, or the site’s CSS hides it. You also won’t see it again once you’ve clicked it; test in a private window.

What happens to the old HubSpot cookie banner?

HubSpot moves every account from the old editor (v1) to the new one (v2). The automatic move started on 11 May 2026 and runs in batches. Custom CSS written for the old banner may stop working.

Where do I see who accepted or declined cookies in HubSpot?

On the contact’s timeline under analytics activity, in segments with the property Privacy consent, and in custom reports with the data source Cookie banner.

Know what your site tracks before anyone says yes

We check your tags, banner and consent reports live, on your site and in your portal. You keep the findings, whether we work together or not.