EU

ePrivacy: Cookie Consent Requirements

Rule: Storing or accessing information on a user’s device requires prior informed consent, unless strictly necessary for the service requested.

Article 5(3) states:

Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information.

  1. Prior — Consent must be obtained BEFORE cookies are set
  2. Informed — User must understand what they’re consenting to
  3. Freely given — No “cookie walls” blocking access without consent (per EDPB guidance)
  4. Specific — Separate consent for different purposes
  5. Unambiguous — Clear affirmative action required (no pre-ticked boxes)

Strictly Necessary Exception

Consent is NOT required for cookies that are:

Exempt CategoryExamples
Technical transmissionLoad balancing, network routing
Strictly necessary for service explicitly requestedShopping cart, login session, security tokens
User preference cookiesLanguage, accessibility settings
Cookie TypeConsent Required?
Analytics (Google Analytics, etc.)Yes
Advertising / targetingYes
Social media widgetsYes
A/B testingYes
Session cookies for loginNo (strictly necessary)
Shopping cartNo (strictly necessary)
CSRF tokensNo (security)
Cookie consent preferencesNo (strictly necessary)

Valid:

  • Cookie banner with Accept/Reject buttons
  • Granular controls for different cookie categories
  • Settings page with clear choices

Invalid:

  • Pre-ticked boxes
  • “By continuing to browse you consent”
  • Cookie walls (blocking access without consent)
  • Only “Accept” button with no easy reject option

Practical Guidance

  • First-party analytics may qualify for legitimate interest under GDPR, but ePrivacy still requires consent for storage
  • Consent must be as easy to withdraw as to give
  • Record consent — keep evidence of when and how consent was obtained
  • Refresh consent periodically (every 6-12 months recommended)

Citation

Article 5(3), ePrivacy Directive

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt