GDPR Cookie Requirements: Consent, Disclosure, and Proof

If your website uses cookies or similar tracking on visitors in the EU, GDPR cookie requirements come down to this: block every non-essential cookie until the visitor gives freely given, specific, informed, and unambiguous consent through an interface where refusing is as easy as accepting; tell them clearly what each category does; let them withdraw at any time; and keep records that prove they agreed. Two laws work in tandem. The GDPR governs how personal data is processed, and the ePrivacy Directive (2002/58/EC) governs what gets stored on a person’s device. Getting either wrong exposes you to fines up to €20 million or 4% of worldwide annual revenue, whichever is higher.1General Data Protection Regulation (GDPR). Art. 83 GDPR – General Conditions for Imposing Administrative Fines

Which Cookies and Trackers Need Consent

Article 5(3) of the ePrivacy Directive requires consent before storing information on a user’s device, or reading information already there, with two narrow exemptions: transmission of a communication over a network, and tracking that is strictly necessary to provide a service the user specifically requested.2European Data Protection Board. Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

Session cookies keeping a shopping cart alive, login authentication, and load-balancing cookies fall inside the strictly necessary exemption. Analytics, advertising pixels, social media plugins, and cross-site tracking do not. Those need consent before they fire.

The rules cover more than browser cookies. The European Data Protection Board (EDPB) has confirmed that Article 5(3) reaches any technology that reads or writes information on the device, including device fingerprinting and tracking pixels.2European Data Protection Board. Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive A consent platform that governs cookies but lets fingerprinting scripts run in the background leaves a compliance gap.

One point catches many operators off guard: the ePrivacy Directive offers no “legitimate interest” path for storing or accessing information on a device. Only two options exist — consent, or the strictly necessary exemption.2European Data Protection Board. Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive Listing tracking purposes as legitimate interest does not cure the need for consent.

What Counts as Valid Consent

The GDPR defines consent as a freely given, specific, informed, and unambiguous indication of the person’s wishes, given through a clear affirmative action.3General Data Protection Regulation. Art. 4 GDPR – Definitions Every word does work:

  • Freely given: no penalty for refusing.
  • Specific: cookie consent cannot be bundled with agreeing to terms of service, and each distinct purpose needs its own choice.
  • Informed: the person knew what they were agreeing to.
  • Unambiguous, affirmative action: a deliberate click or check, not passive behavior.

Recital 32 spells out what does not qualify: silence, pre-ticked boxes, and inactivity. In Planet49 (C-673/17) the Court of Justice of the European Union held that a pre-checked box cannot produce valid consent because no one can tell whether a user who left it alone actually intended to agree. Scrolling, continuing to browse, or simply landing on the page fail the same test.

Specificity also means a single “I agree” covering analytics, advertising, and social media at once will not do. The interface has to let visitors accept some categories and reject others.

How the Banner Must Be Built

The EDPB’s Cookie Banner Taskforce has catalogued the design patterns regulators treat as infringements.4European Data Protection Board. Report of the Work Undertaken by the Cookie Banner Taskforce The most common failure is a missing reject button on the first layer. If “Accept All” appears on the initial banner but refusing requires navigating to a second screen, most regulators consider that a violation. A “Reject All” option must sit at the same level and carry equivalent visual weight — same size, similar prominence, no burying it in muted gray while the accept button glows green. France’s data protection authority, the CNIL, fined Google €150 million for exactly this asymmetry: one click to accept, no equally easy way to refuse.

Other flagged practices:

  • Using a small unstyled hyperlink for the refuse option while accept is a prominent button.
  • Manipulative color contrast that makes accept visually dominant and refuse near-invisible.
  • Pre-ticked preference boxes in the settings layer, forcing users to deselect each category.
  • Mislabeling advertising or analytics cookies as “strictly necessary” to avoid the consent requirement.
  • Claiming legitimate interest for tracking purposes that require consent.

Cookie Walls and “Consent or Pay”

A cookie wall that blocks all site content unless the visitor accepts tracking is invalid under the EDPB’s consent guidelines. When access depends on accepting cookies, consent is not freely given.5European Data Protection Board. Guidelines 05/2020 on Consent Under Regulation 2016/679

“Consent or pay” is the newer variant: accept tracking or pay a subscription. In Opinion 08/2024 the EDPB found that for large online platforms, a binary choice between consenting to behavioral advertising and paying a fee will in most cases fail to produce valid consent. The opinion identified problems including a fee that can coerce consent from users who cannot afford it, the power imbalance between a dominant platform and an individual, and bundling all tracking purposes into a single decision. If such a model is used, the EDPB said, the paid alternative must be functionally equivalent to the free version, the fee must be genuinely appropriate rather than punitive, and users must still be able to consent to individual purposes.6European Data Protection Board. Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms

What Your Cookie Notice Must Disclose

Information about data collection must be concise, transparent, and easily accessible, in clear and plain language.7General Data Protection Regulation. Art. 12 GDPR – Transparent Information, Communication and Modalities for the Exercise of the Rights of the Data Subject “We use cookies to improve your experience” falls well short. The CNIL cited exactly that kind of vague disclosure in its Amazon enforcement action.

At the point of collection, the notice must identify the data controller and provide contact details, explain the specific purposes for each cookie category, name recipients or categories of recipients, and state the storage duration for each cookie or the criteria used to determine it.8General Data Protection Regulation. Art. 13 GDPR – Information to Be Provided Where Personal Data Are Collected From the Data Subject Users must also be told they can withdraw consent at any time, and that withdrawal does not affect the lawfulness of processing already carried out.9General Data Protection Regulation. Art. 7 GDPR – Conditions for Consent

In practice, organize cookies into distinct categories (functional, analytics, marketing) with enough detail for a non-technical visitor to understand what each does and who benefits. The full disclosure need not sit on the banner itself. A layered approach works: a first screen offering clear accept and reject choices with a link to the detailed breakdown.

Withdrawal and Preference Management

Withdrawing consent must be as easy as giving it.9General Data Protection Regulation. Art. 7 GDPR – Conditions for Consent If accepting took one click, revoking cannot require five settings pages. The EDPB’s taskforce flagged the absence of a withdraw icon as non-compliant.4European Data Protection Board. Report of the Work Undertaken by the Cookie Banner Taskforce A persistent floating icon, a clearly labeled footer link, or a privacy settings tab available throughout the visit will each work. Visitors should not have to hunt.

Technically, every non-essential script must stay blocked until the user affirmatively clicks accept. This is the prior consent principle. Your tag manager or consent platform needs to gate every analytics and advertising script behind the consent signal. If a visitor loads the page and 40 advertising cookies fire before the banner even renders, the site is already in violation regardless of what the banner then says.

How Long Consent Lasts

The GDPR sets no maximum duration, but regulators treat consent as degrading over time as vendors and policies change. National guidance varies: France and Ireland suggest no longer than six months, Germany recommends six to twelve, and the UK advises considering an automatic refresh every two years. Operating across several EU countries, the safe path is the shortest applicable interval. Any material change to the cookie policy, tracking purposes, or vendor list should trigger a fresh consent request regardless of how recently the user last consented.

Proving Consent

The controller carries the burden of proof. Article 7(1) requires that where processing is based on consent, the controller be able to demonstrate that the person consented.9General Data Protection Regulation. Art. 7 GDPR – Conditions for Consent “We had a banner” is not evidence. Records must tie a specific consent event to a specific version of the cookie policy.

Effective consent logs capture the timestamp of the action, which categories were accepted and rejected, the version of the notice displayed at the time, and a pseudonymous identifier (such as a hashed session ID) linking the record to the browser session without storing personal identity data. Update the log whenever a user modifies preferences, store it securely for as long as the processing that relies on it continues, and treat it as the primary defense when a data protection authority investigates a complaint.

Whether Non-EU Sites Are Covered

The GDPR reaches organizations outside the EU when they process personal data of people located in the EU in connection with offering them goods or services, or monitoring their behavior within the Union.10General Data Protection Regulation. Art. 3 GDPR – Territorial Scope For cookie compliance, the monitoring prong catches most companies. Recital 24 defines monitoring as tracking people online, including subsequent profiling to analyze or predict preferences, behavior, and attitudes. A site that drops analytics or advertising cookies on visitors from EU countries is monitoring their behavior, wherever the servers sit.

Offering goods or services does not require payment. Accepting orders from EU addresses, showing prices in euros, publishing in EU languages, or targeting EU audiences through advertising can each establish the connection. A U.S. e-commerce store shipping to Germany, a SaaS platform with EU subscribers, or a media site running Google Analytics on French visitors all fall inside the scope.

Penalties

Consent violations sit in the top penalty tier: up to €20 million or 4% of worldwide annual revenue for the preceding financial year, whichever is higher.1General Data Protection Regulation (GDPR). Art. 83 GDPR – General Conditions for Imposing Administrative Fines That ceiling covers infringements of the basic principles for processing, including the conditions for valid consent. National authorities set the actual amount based on severity, duration, how many people were affected, and the level of cooperation with the investigation.

The numbers are not theoretical. The CNIL fined Google €150 million and Amazon €35 million for dropping advertising cookies without valid consent and providing inadequate disclosures. In Amazon’s case, investigators found more than 40 advertising cookies were set the moment a visitor reached the homepage, before any consent interaction. The EDPB’s Cookie Banner Taskforce was created to coordinate responses to complaints across member states, treating consent interface violations as a systemic enforcement priority.11European Data Protection Board. EDPB Adopts Guidelines on Right of Access and Letter on Cookie Consent

Regulators can also order the organization to bring its processing into compliance within a set deadline, with daily penalty payments for continued non-compliance. The operational cost of rebuilding a consent infrastructure under regulatory pressure, together with the reputational fallout, tends to run well above the cost of building it correctly at the start.