The ePrivacy Directive and GDPR set the rules for EU cookie compliance. Since these laws were introduced, expectations around digital privacy have increased, and enforcement has become stricter.
In September 2025, France’s CNIL fined Google €325 million and Shein €150 million in a single day, both for cookie violations. The Dutch DPA issued formal warnings to over 200 websites and fined Kruidvat €600,000 for pre-ticked consent boxes. One thing is clear: If you run a website that gets any traffic from Europe, cookie compliance is mandatory. This guide covers what the EU cookie law actually requires, how the GDPR and ePrivacy Directive work together, what counts as valid consent, how each cookie category is treated under EU law, and what’s changed for 2026.
Key takeaways
- EU cookie compliance requires meeting both the ePrivacy Directive and GDPR.
- Non-essential cookies, such as analytics, advertising, functional, social embeds, require explicit opt-in before they load.
- Your cookie banner must offer accept and reject with equal visual prominence. A buried or grey-text reject button is non-compliant.
- Enforcement fines reached hundreds of millions in 2025. The CNIL alone fined Google €325M and Shein €150M for cookie violations.
- Country-specific rules may slightly vary across EU member states. Germany, France, Belgium, and Italy have issued DPA-specific guidance that goes beyond the baseline.
What is EU cookie compliance?
EU cookie compliance means meeting the legal requirements set by the ePrivacy Directive (also called the EU Cookie Directive or European Cookie Law) and the General Data Protection Regulation (GDPR) when using cookies on your website.
Together, these laws require websites to:
- tell users what cookies they’re using and why
- obtain opt-in consent before placing non-essential cookies
- give users the ability to change or withdraw consent at any time
- keep records proving that consent was obtained
The ePrivacy Directive has been in effect since 2002, with cookie-specific consent rules added in 2009 and enforced from 2011. It applies to any website that places cookies on EU users’ devices, regardless of where the website is hosted. The GDPR has been in place since May 2018 and governs the processing of personal data, which includes most cookies that can identify a user.

Want to generate a custom cookie banner?
Create your cookie banner with CookieYes CMP- Trusted by 2M+ businesses worldwide
Sign up for free14-day free trialCancel anytime
The two laws behind EU cookie compliance
Understanding how the ePrivacy Directive and GDPR interact is the foundation of EU cookie compliance. Here are the key points to know:
ePrivacy Directive (2002/58/EC)
The ePrivacy Directive, often called the EU Cookie Law or Cookie Law, is the specific law that created the consent obligation for cookies. The relevant provision (Article 5(3)) says: any cookie that isn’t strictly necessary for a service the user explicitly requested requires prior consent.
This covers analytics cookies, advertising cookies, functional cookies, and social media embeds. It also covers technologies beyond cookies, such as tracking pixels, device fingerprinting, and URL-based identifiers, which all fall under the same rule.
Member states implement the Directive through national legislation, which is why enforcement and interpretation may differ across the EU. France’s CNIL, Germany’s DSK, Belgium’s BDPA, and Italy’s Garante have all issued guidance that sometimes diverges on the details. Where national rules differ, follow the strictest interpretation, not the most lenient.
GDPR (Regulation 2016/679)
The GDPR governs how personal data is processed. Because most cookies often identify or can be linked to a person, they fall within GDPR’s scope as personal data (online identifiers). The GDPR defines what valid consent looks like, and it sets the standard that your cookie banner must meet.
First things first, not all cookies require consent. The rule is that strictly necessary cookies are exempt, and everything else needs opt-in. Here’s how the standard GDPR cookie categories break down:
| Cookie category | Examples | Consent required? |
| Strictly necessary | Session cookies, authentication, shopping cart, security | No, but must be disclosed |
| Preferences / functional | Saved language, region, accessibility settings | Yes |
| Analytics / performance | Google Analytics, Matomo, Hotjar | Yes |
| Advertising / marketing | Meta Pixel, Google Ads, retargeting | Yes |
| Social media embeds | YouTube, Twitter/X widgets that track users | Yes |
Strictly necessary cookies
These are the only categories exempt from consent. But strictly necessary has a narrow definition. A cookie qualifies only if the service literally cannot function without it. Authentication tokens, session identifiers, and shopping cart cookies meet this bar. Analytics do not. Personalisation does not.
You still need to disclose strictly necessary cookies in your cookie policy, even though consent isn’t required.
Functional and preference cookies
These remember user choices such as language preference, region, and display settings. They improve the experience but aren’t required for the service to work. Consent is required before placing them.
Analytics and performance cookies
Google Analytics, Matomo, Hotjar, and similar tools all require cookie consent in the EU. The fact that analytics data helps you improve your site doesn’t make it strictly necessary. Germany and France have both confirmed this position explicitly.
First-party analytics don’t get an automatic exemption either. If they track user behaviour across sessions, they require consent.
Advertising and marketing cookies
These track users across websites to serve targeted ads. Tracking cookies consistently require consent and attract the most enforcement attention. The CNIL’s 2025 actions against Google and Shein were both driven by advertising cookie violations — invalid consent mechanisms, pre-set tracking, and banner designs that made rejection harder than acceptance.
Social media cookies
YouTube video players, Twitter/X widgets, and Facebook comment boxes often set tracking cookies independently. If you embed third-party content that loads tracking cookies, that requires consent too. Embedding the player doesn’t transfer your compliance obligations to the third party.
What is valid cookie consent under EU law?
GDPR Article 4(11) defines consent as: freely given, specific, informed, and unambiguous. All four elements must be present. If anyone is missing, the consent is invalid.
Freely given
The user must have a genuine choice. Cookie walls, where users must accept cookies to access content, are generally non-compliant. The EDPB has also stated that a pay or consent model (where users either pay a subscription or accept tracking) doesn’t constitute freely given consent for large platforms in most cases (EDPB Opinion 08/2024).
Specific
Consent must be given separately for each purpose. You can’t bundle analytics, advertising, and functional cookies into a single checkbox. A user must be able to say yes to analytics and no to advertising. And both choices must be respected independently.
Informed
Users need to know what they’re consenting to. That includes what the cookie does, who sets it (first party or named third party), how long it persists, and what data it collects.
Clear affirmative action
The user must actively do something. Click an Accept button, toggle a switch. Pre-ticked boxes, continued browsing or scrolling does not constitute GDPR consent. The Court of Justice of the EU confirmed this in the Planet49 ruling (Case C-673/17, October 2019), which remains the controlling authority on this point.
The Planet49 ruling (CJEU, Case C-673/17, October 2019) established that a pre-ticked checkbox does not constitute valid cookie consent under EU law, because consent requires “an indication of the data subject’s wishes” that points to active, not passive, behaviour. This case law remains the baseline for all EU cookie consent enforcement.
What the cookie banner must do
Your cookie banner must appear before any non-essential cookies load. If your analytics tag fires the moment a user lands on the page before they’ve seen the banner, that counts as non-compliance. Therefore, every analytics, advertising, and functional script must be blocked until the user gives consent.

The banner must present accept and reject options with equal prominence. The CNIL has explicitly fined websites where the reject option required more steps or was harder to find than the accept option. The buttons should be the same size, the same visual weight, and at the same level in the banner hierarchy.

Users must be able to change their cookie consent choices anytime. This is typically handled via a persistent “Manage Cookies” link in the footer or a floating preferences icon.

Link to your full cookie policy, where users can read detailed information about each cookie, its purpose, and its retention period.
Cookie banner issues to avoid
The EDPB’s guidelines and DPA enforcement have identified a clear set of dark patterns that invalidate consent:
- Pre-ticked boxes for non-essential cookies
- Asymmetric button designs, including a large or brightly coloured accept button alongside a small grey reject link.
- Burying Reject All behind a second or third layer while Accept All is on the first screen (hidden reject options)
- Naming the reject button “Accept necessary only” in a way that implies it’s the inferior choice (misleading labels)
- Design suggesting that inactivity from user equals consent
- Lack of specific consent options for each cookie category
The Garante (Italy’s DPA) specifically requires that closing the banner with an “X” button defaults to no consent for optional cookies. The BDPA (Belgium) requires both “Accept all” and “Reject all” on the same first-layer banner.
How to prove EU cookie compliance?
You also need to be able to prove that cookie consent happened. Regulators have asked for this evidence during audits. Your logs should include:
- Timestamp of when consent was given
- Which categories the user accepted or rejected
- The version of the banner they saw
- The user’s IP or session identifier (where legally permissible)

How to implement EU cookie compliance: step by step
- Audit your cookies: Use a cookie scanner tool to find every cookie and tracker on your site, including anything loaded by third-party scripts. Classify each one by purpose.
- Choose a consent management platform (CMP): A CMP handles banner display, blocks scripts until consent is given, and stores consent records.
- Write plain-language descriptions for each cookie category: “Analytics cookies help us understand how visitors use our site, so we can fix broken pages and improve navigation” is better than any technical jargon.
- Write your EU cookie policy: Your cookie policy must include: a list of every cookie you use, its category, its purpose, who sets it (first party or named third party), and how long it lasts. It should be linked from the banner and accessible at all times.
- Design the banner: Equal prominence to accept and reject options. Do not use pre-ticked boxes or dark patterns. Provide a “customise” button for consenting to cookie categories individually.
- Block scripts by default: Configure your tag manager (Google Tag Manager, Tealium, etc.) to fire analytics and advertising tags only after the user consents.
- Set up consent logging: Make sure your CMP is recording consent events with timestamps and banner version numbers, and that you can export these records if a regulator asks.
- Re-scan after changes: Every time you add a new plugin, theme, or third-party integration, scan for new cookies. Schedule quarterly audits at a minimum.
What your EU cookie policy must include
A cookie policy is part of the informed consent requirement and transparency under GDPR. Users must be able to understand what they’re consenting to, and the policy is where that detail lives.
A compliant EU cookie policy must include:
- A list of cookies: every cookie used on the site, not just categories
- Category classification: which GDPR cookie category each cookie falls under
- Purpose : what the cookie does in plain language
- Data collected: what information the cookie captures
- Retention period: how long the cookie persists on the user’s device
- Third-party disclosure: where a third party sets or accesses the cookie, name them and link to their own privacy policy
- How to withdraw consent: practical instructions for users to change their preferences
The policy should be linked from the banner, from your site footer, and from your privacy policy.
Need a cookie policy for your website?
Create your cookie policy with CookieYes CMP- Trusted by 2M+ businesses worldwide
Sign up for free14-day free trialCancel anytime
What happens if I ignore EU cookie compliance?
GDPR fines reach up to €20 million or 4% of global annual turnover. Beyond financial penalties, regulators can issue orders requiring changes within weeks, and non-compliance orders can compound daily.
Country-wise cookie consent requirements
Germany
Germany’s cookie consent requirements is governed by the Telecommunications Telemedia Data Protection Act (TTDSG), specifically Section 25, which implements the EU ePrivacy Directive. When personal data is also involved, GDPR applies alongside it.
Consent must be freely given, informed, specific, and unambiguous. In practice, this means:
- Show the cookie banner before any non-essential cookies load.
- Give equal prominence to accept and reject options — combining “Accept all” with a low-visibility “Settings” link is not valid.
- Scrolling, clicking, or continued browsing does not count as consent.
- Cookie walls are generally not permitted unless users can close the banner in a single step and continue using the site.
- Users must be able to withdraw consent just as easily as they gave it.
Norway
Norway is not an EU member, but as part of the European Economic Area (EEA), it applies GDPR through its Personal Data Act. Norway cookie consent rules are set by the Electronic Communications Act and supervised by Nkom (for electronic communications) and Datatilsynet (the Norwegian DPA).
Nkom’s guidelines recommend GDPR-standard consent even where the law technically permits browser presets as consent. In practice, that means:
- Provide easy consent withdrawal.
- Obtain explicit, specific consent before placing non-essential cookies.
- Inform users what cookies are used, what data they collect, why, and who processes it.
- Make this information readily visible via a cookie pop-up, a footer link, or a front-page text box.
- No pre-checked boxes.
Belgium
Belgium implements GDPR through the Data Privacy Act (2018) and the EU ePrivacy Directive through the Electronic Communications Act (2015). The Belgian Data Protection Authority (BDPA) issued a cookie checklist in October 2023 that sets out concrete expectations.
Belgian cookie consent rules are notably strict on categorization and cookie design. Key requirements:
- Obtain free, specific, informed, and unambiguous consent before placing any non-essential cookies.
- Include both an “Accept all” and a “Reject all non-essential cookies” button in the same banner layer(not buried in a second step).
- No cookie walls, deceptive design, or pre-checked boxes.
- Users must be able to consent by purpose separately; a single cookie cannot serve multiple purposes.
- Browser presets do not count as valid consent.
- Limit essential cookies (like consent preference storage) to no more than 6 months.
- Consent cannot be bundled with acceptance of a privacy policy or terms of service.
Italy
Italy’s cookie consent rules are set by the Garante (Italy’s Data Protection Authority) and draw on GDPR Articles 4(11), 7, 12, 13, and 25, as well as Section 122 of the Italian data protection code.
The Garante places particular emphasis on banner design, analytics cookie handling, and ongoing consent management:
- Display a prominent cookie banner when any user first arrives and before any optional cookies load.
- Consent must be freely given, informed, specific, and unambiguous. Scrolling and inactivity are not valid.
- Cookie walls are non-compliant unless the site offers genuinely equivalent content without cookies.
- Users must be able to update their choices at any time, ideally via a persistent icon or footer link on every page.
- When users close the banner with the “X” button, the default must stay as no consent for optional cookies.
- Re-prompting consent is acceptable after approximately 6 months, or if there are significant changes to how data is used.
- Provide granular consent. Users should be able to accept individual cookie categories, not just “accept all.”
Poland
Poland implements the ePrivacy Directive through the Electronic Communications Law, alongside the GDPR. The Polish DPA (UODO — Urząd Ochrony Danych Osobowych) supervises enforcement.
For many years, Polish enforcement lagged behind the rest of the EU. That changed after the Planet49 ruling and subsequent CJEU case law. The UODO has issued decisions confirming that:
- Browser settings do not constitute valid consent under GDPR — active, explicit opt-in is required
- Scrolling or continued browsing is invalid consent
- Consent must be specific, informed, and freely given
- IP address sharing with third parties via cookies requires a valid legal basis; sharing it without consent violates Article 6(1) GDPR
In practice, Polish websites now follow the same opt-in model as the rest of the EU. Multinational businesses operating in Poland should apply the same GDPR-standard consent mechanism they use across the EU.
- Complete your cookie audit and classify all cookies by purpose
- Document strictly necessary cookies in the privacy/cookie policy
- Place a CMP with a third-party script blocking configured
- The banner shows accept and reject with equal visual prominence
- Toggle off non-essential cookies by default in the banner
- The preference centre allows granular consent
- Log consent records with timestamps
- Link the cookie policy from the banner
- Schedule a quarterly re-audit
- Review compliance after adding any new third-party scripts
Meet EU cookie consent requirements
with one tool
Create your cookie banner with CookieYes CMP- Trusted by 2M+ businesses worldwide
Sign up for free14-day free trialCancel anytime
FAQs on EU cookie compliance
No consent is required for strictly necessary cookies, but you do need to disclose them, usually in a cookie policy. If your site genuinely uses no non-essential cookies, you don’t need a consent banner, but you should document this in case you’re ever asked to prove it.
No. Analytics cookies are classified as performance or measurement cookies and require consent in the EU. The fact that you want the data doesn’t make the service unable to function without it.
For cookies that involve processing personal data, the CJEU’s Planet49 ruling and subsequent guidance from DPAs make clear that consent is required. Legitimate interest is not a valid basis for non-essential cookies under the ePrivacy Directive.
Consent has a shelf life. Twelve months is the norm, and once that’s up, you need to re-obtain it. If you deploy a new advertising platform or analytics tool, update your banner and recollect consent.
The EU Cookie Directive is another name for the ePrivacy Directive (2002/58/EC, amended 2009). It’s the EU law that created the consent requirement for cookies. It says any cookie that isn’t strictly necessary for a service the user explicitly requested needs prior consent. It’s sometimes called the European Cookie Law or EU Cookie Law. The ePrivacy Directive works alongside the GDPR and says when consent is needed; the GDPR defines what valid consent looks like.
Yes, if you target EU residents or process their personal data. GDPR Article 3(2) applies to any organisation that offers goods or services to people in the EU or monitors their behaviour, regardless of where the organisation is based. A US or UK website accessible in Europe that collects any data about visitors almost certainly falls within scope.
You need the information either in a separate cookie policy page or as a detailed section within your privacy policy. It must include the name of each cookie, its purpose, its retention period, and who sets it. Belgium’s BDPA specifically requires that cookie consent not be bundled with privacy policy acceptance, so keeping them separate is the safer approach.


