Skip to content
Legiscope
Menu
Data Privacy

Cookie Consent Under GDPR and ePrivacy: Complete Guide

Cookie consent under GDPR and ePrivacy: legal framework, valid consent rules, cookie categories, enforcement fines, and compliance checklist.

Cookie consent remains one of the most visible and most frequently misimplemented obligations in European data protection law. Studies indicate that roughly 90% of cookie banners deployed across the EU still fail to meet the legal standard for valid consent. Supervisory authorities have responded with escalating fines – CNIL imposed EUR 150 million on Google in January 2022, and the Luxembourg CNPD fined Amazon EUR 746 million in a case where consent practices formed part of the complaint.

This guide covers the legal framework governing cookie consent GDPR obligations, technical requirements, and a practical implementation checklist.

Cookie consent in Europe rests on two intersecting instruments: the ePrivacy Directive 2002/58/EC and the GDPR. They govern different aspects of the same user interaction.

The ePrivacy Directive (2002/58/EC)

Article 5(3) of the ePrivacy Directive requires prior informed consent before any information is stored on or accessed from a user’s terminal equipment – regardless of whether it constitutes personal data. Even anonymous analytics cookies require consent under ePrivacy.

The Directive was amended in 2009 by Directive 2009/136/EC, replacing the original opt-out regime with opt-in. Each member state has transposed this into national law, creating local variations.

How Does the GDPR Apply to Cookies?

The GDPR applies whenever cookies involve personal data – which is nearly always. User IDs, IP addresses, and device fingerprints constitute personal data under Article 4(1). The GDPR requirements for consent apply in full: freely given, specific, informed, and unambiguous.

The ePrivacy Directive governs placing or reading the cookie; the GDPR governs processing the personal data collected through it. Cookie consent must satisfy both simultaneously. See our guide to valid GDPR consent.

Article 5(3) includes an exemption for cookies strictly necessary for providing a service explicitly requested by the user.

These cookies are exempt because the service cannot function without them:

  • Session authentication cookies – maintaining a logged-in state
  • Shopping cart cookies – retaining items during a session (a recurring topic in e-commerce GDPR compliance)
  • Load-balancing cookies – distributing traffic across servers
  • Security cookies – CSRF tokens and similar protections

The EDPB and CNIL have confirmed that the exemption is narrow. A cookie is strictly necessary only if the service cannot be provided without it and the user has explicitly requested the service.

Every other category requires prior consent before being placed on the user’s device:

  • Analytics cookies – Google Analytics, Matomo, Hotjar. CNIL has noted a limited exemption may apply under specific conditions (first-party only, aggregated data, limited retention), but the default is that consent is required.
  • Marketing and advertising cookies – retargeting pixels, ad network trackers, cross-site identifiers. These account for the majority of enforcement actions.
  • Social media cookies – embedded content from Facebook, Twitter/X, LinkedIn, YouTube that sets trackers on page load.
  • Functional cookies serving the provider’s interests – A/B testing, recommendation engines, browsing-history personalisation.

For more examples of how consent works across different processing activities, see our practical examples of GDPR consent.

Authorities have converged on a consistent standard. The EDPB Guidelines 05/2020 and CNIL cookie guidelines provide the authoritative references.

No Pre-Ticked Boxes

The CJEU settled this in Planet49 (Case C-673/17, October 2019): pre-ticked checkboxes do not constitute valid consent. The user must take an affirmative action. Continuing to browse, scrolling, or navigating to another page also does not constitute consent.

Equal Prominence for Accept and Refuse

Users must be able to refuse cookies as easily as they accept them. CNIL’s enforcement actions against Google (EUR 150 million) and Facebook (EUR 60 million) in January 2022 centred specifically on this point: the “Accept” button was prominent while refusing required multiple clicks through settings menus. A “Refuse All” button must be presented at the same level and with equivalent visual prominence as “Accept All”.

Granular Choice by Purpose

Consent must be specific to each purpose. A single “Accept All” option without the ability to consent to individual categories does not meet the granularity requirement. Users must be able to accept analytics cookies while refusing marketing cookies, or vice versa.

No consent walls. Making site access conditional on accepting all cookies is generally non-compliant. The EDPB has stated that conditional consent is not freely given. A narrow exception may apply where a genuine equivalent alternative is offered, but this remains contested.

Documented and withdrawable. Organisations must demonstrate that consent was obtained (Article 7(1) GDPR) and provide a mechanism for withdrawal at any time, as easily as it was given (Article 7(3) GDPR). A persistent footer link allowing users to revisit preferences is the standard approach.

Enforcement is accelerating. Cookie consent violations accounted for approximately 18% of all GDPR-related enforcement actions between 2021 and 2025. Key cases include:

Authority Target Fine Key Issue
CNIL (France) Google EUR 150M Refusing cookies required more clicks than accepting
CNIL (France) Facebook EUR 60M Asymmetry in accept/refuse mechanism
CNPD (Luxembourg) Amazon EUR 746M Consent and transparency failures including cookies
CNIL (France) TikTok EUR 5M Cookie deposit without consent, no refuse mechanism
CNIL (France) Microsoft EUR 60M Advertising cookies deposited without consent on Bing

Beyond headline fines, CNIL conducted over 300 targeted cookie audits in 2023, issuing 94 formal notices. Cookie consent GDPR compliance is an active enforcement priority across every major European supervisory authority. For broader context, see our guide to GDPR fines.

Use this checklist to verify that your cookie consent mechanism meets current legal requirements. This should form part of your broader GDPR compliance checklist.

Audit and classification:

  • [ ] Audit all cookies and trackers on your site, including those set by third-party scripts
  • [ ] Classify each cookie: strictly necessary, functional, analytics, or marketing
  • [ ] Verify that “strictly necessary” cookies genuinely meet the legal exemption
  • [ ] Document purpose, provider, retention period, and data collected for each cookie

Consent mechanism design:

  • [ ] Present a consent banner on first visit, before any non-essential cookies fire
  • [ ] Include “Accept All” and “Refuse All” buttons at the same level with equal prominence
  • [ ] Provide granular controls for each cookie category independently
  • [ ] No pre-ticked boxes, implied consent, or scroll-based consent
  • [ ] No cookie walls conditioning site access on acceptance

Ongoing compliance:

  • [ ] Record proof of each consent choice with timestamp and scope
  • [ ] Provide a persistent mechanism (footer link) for withdrawing or modifying consent
  • [ ] Re-audit cookies quarterly – third-party scripts frequently add new trackers
  • [ ] Update your cookie policy whenever new cookies are deployed

The ePrivacy Regulation, intended to replace the 2002 Directive, remains stalled as of early 2026. Meanwhile, Chrome completed its third-party cookie phase-out in 2025, following Safari and Firefox. This does not eliminate consent requirements – first-party cookies, fingerprinting, local storage, and pixels remain in scope – but it shifts the practical focus. The Digital Markets Act adds further consent requirements for gatekeeper platforms. See our guide to GDPR requirements and our analysis of the hidden productivity cost of cookie banners.

Frequently Asked Questions

Yes. The ePrivacy Directive covers any storage or access of information on a user’s terminal equipment, which includes mobile devices. SDKs and tracking libraries in apps are subject to the same consent requirements as cookies on websites.

No. The ePrivacy Directive requires consent for non-essential cookies independently of the GDPR’s legal bases. Legitimate interest under Article 6(1)(f) GDPR cannot override the ePrivacy consent requirement.

No maximum duration is specified in law. CNIL recommends retaining consent choices for a maximum of 13 months. Other authorities suggest 6 to 12 months. Re-prompt at least annually.

Generally no. The EDPB considers conditional access means consent is not freely given. A narrow exception may apply where a genuine equivalent alternative exists (such as a paid subscription), but this remains subject to case-by-case assessment.

Not legally required, but strongly recommended. The information can be included in your privacy policy, but it must cover: cookie types, purposes, retention periods, third parties involved, and how to withdraw consent. A standalone document improves transparency and simplifies audits. If you are choosing a consent platform to run this, compare the options in our guide to Cassie and Syrenis alternatives.

Yes, if your website targets EU users by offering goods or services to them or monitoring their behaviour. Both the GDPR and national ePrivacy transpositions apply regardless of where your servers or company are located.

FAQ

Strictly necessary cookies: no legal basis required — they are exempt from consent under ePrivacy Directive recital 66. All other cookies (analytics, advertising, preference) require prior informed consent under ePrivacy Article 5(3) and GDPR Article 6(1)(a).

Does the ePrivacy Regulation replace the ePrivacy Directive for cookies?

Not yet. The ePrivacy Regulation (ePR) is still being finalised (as of 2026). The current ePrivacy Directive (2002/58/EC, amended 2009) remains the applicable law. Member states have transposed it differently, creating variation across EU jurisdictions.

No, under current interpretations. The CNIL (France), DSB (Austria), DPA (Italy), and others have ruled that standard Google Analytics implementations transfer data to the US unlawfully and require valid consent. Server-side analytics with IP anonymisation before transfer is a compliant alternative.

A CMP manages the technical implementation of cookie consent — capturing, storing, and propagating consent signals. You do not legally need a branded CMP, but a custom implementation that doesn’t properly store and document consent creates accountability risks. TCF-certified CMPs (IAB Europe’s framework) are common in adtech.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

For a regulated-industry DPO, that distinction is the whole decision. Consent is one lawful basis under Art. 6(1)(a) GDPR; a compliance program is everything around it.

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026