EU Cookie Law Explained: Requirements, Consent, and Compliance
Learn what the EU cookie law requires from your website. Covers the ePrivacy Directive, GDPR consent rules, exemptions, penalties, and compliance steps.
If your website uses cookies and has visitors from Europe, the EU cookie law applies to you, whether your business is based in Berlin, London, or Boston. The EU cookie law requires websites to obtain informed consent before placing most cookies on a visitor's device, and regulators across Europe have backed that requirement with multi-million euro fines. This guide explains where the law comes from, what it actually requires, which cookies are exempt, and how to bring your website into compliance. It is educational information rather than legal advice, so consult a qualified attorney for guidance specific to your situation.
What Is the EU Cookie Law?
The EU cookie law is not a single statute called the "Cookie Law." It is the common name for Article 5(3) of the ePrivacy Directive (Directive 2002/58/EC), as amended by Directive 2009/136/EC. The 2009 amendment is what introduced the consent requirement that reshaped how websites handle cookies.
Article 5(3) states that storing information, or gaining access to information already stored, on a user's device is only allowed if the user has given consent after receiving clear and comprehensive information about the purpose of the processing. In plain terms: before your website sets a cookie, reads a device fingerprint, or uses local storage for anything beyond delivering the service the visitor asked for, the visitor must agree to it.
Three points about the law's structure matter for compliance:
- It is a directive, not a regulation. Each EU member state implements it through national legislation, such as the UK's Privacy and Electronic Communications Regulations (PECR), which survived Brexit, or France's Loi Informatique et Libertés. Enforcement details and penalties vary by country.
- It covers more than cookies. The rule applies to any technology that stores or reads information on a device: localStorage, pixels, SDKs in mobile apps, and browser fingerprinting techniques.
- It applies regardless of personal data. Unlike the General Data Protection Regulation (GDPR), Article 5(3) protects the device itself. Consent is required even if the cookie contains no personal data at all.
EU Cookie Law and GDPR: How They Work Together
Many site owners assume the GDPR replaced the cookie rules in 2018. It did not. The ePrivacy Directive and the GDPR operate side by side, and understanding the split is essential for cookie law compliance.
The ePrivacy Directive answers the question "may I place this cookie?" The GDPR answers the question "may I process the personal data this cookie collects?" Since most tracking cookies collect identifiers that count as personal data under GDPR Article 4(1), both laws usually apply to the same cookie.
The GDPR changed the cookie landscape in one decisive way: it redefined consent. Article 4(11) of the GDPR requires consent to be a freely given, specific, informed, and unambiguous indication of the user's wishes, expressed through a statement or clear affirmative action. The ePrivacy Directive borrows this definition. That is why the vague "implied consent" banners common before 2018 are no longer defensible.
The Court of Justice of the European Union confirmed this in the Planet49 ruling (Case C-673/17, October 2019). The court held that a pre-ticked checkbox does not constitute valid consent, and that users must receive information about cookie durations and third-party access. Every compliant cookie banner in Europe today is shaped by that decision.
What the EU Cookie Law Requires From Your Website
Compliance comes down to four operational requirements. Regulators such as France's CNIL, Ireland's DPC, and the UK's ICO have published guidance that converges on the same core points.
- Prior consent for non-essential cookies. Analytics, advertising, personalization, and social media cookies must not load until the visitor actively opts in. Firing them on page load and asking afterward is a violation, not a technicality.
- Clear and comprehensive information. Visitors must be told what cookies you use, what each category does, how long cookies persist, and which third parties receive data. This is the job of your cookie policy.
- Granular choice. Visitors must be able to accept some purposes and refuse others. A banner offering only "Accept all" fails this test. CNIL guidance also requires that refusing cookies be as easy as accepting them, which is why a "Reject all" button belongs on the first banner layer.
- Easy withdrawal. Under GDPR Article 7(3), withdrawing consent must be as easy as giving it. A persistent link or icon that reopens the preference center satisfies this.
You also need to keep records. If a regulator asks, you should be able to demonstrate when and how a visitor consented, which consent management platforms log automatically.
Information Your Cookie Policy Must Contain
The "informed" part of informed consent depends on your disclosures. A compliant cookie policy lists:
- Each cookie or cookie category in use, with its purpose
- The duration of each cookie (session or persistent, and for how long)
- Whether the cookie is first-party or third-party, and who the third party is
- How visitors can change or withdraw their consent
- A link to your privacy policy for broader data processing details
Maintaining this list by hand is where most websites drift out of compliance, because tags and third-party scripts change constantly. A cookie policy generator built on an actual scan of your site keeps the disclosures aligned with the cookies you really set.
Cookies That Are Exempt From Consent
The EU cookie law contains a narrow but important exemption. Article 5(3) does not require consent for cookies that are strictly necessary to provide an information society service explicitly requested by the user, or that are used solely to carry out the transmission of a communication.
Cookies generally accepted as exempt include:
- Session and login cookies that keep a user authenticated during a visit
- Shopping cart cookies that remember items during checkout
- Consent preference cookies that record the visitor's own cookie choices
- Load balancing cookies that route traffic for the duration of a session
- Security cookies used for fraud prevention or to detect repeated failed logins
- User interface customization cookies with short lifespans, such as language selection
Cookies that are never exempt, no matter how routine they feel:
- Analytics cookies, including Google Analytics. Regulators treat audience measurement as non-essential, with only narrow national carve-outs for privacy-limited first-party analytics (France's CNIL exempts certain configurations, for example).
- Advertising and retargeting cookies, including Google Ads, Meta Pixel, and every programmatic vendor.
- Social media cookies set by embedded share buttons, like buttons, or video players.
- A/B testing and personalization cookies that profile visitor behavior.
The test is user-centric: strictly necessary means necessary for the service the visitor asked for, not necessary for your business model. "We need ad revenue" does not make advertising cookies essential.
Valid Consent Under the EU Cookie Law
Because consent is the legal centerpiece, regulators scrutinize how banners collect it. Measured against GDPR Article 4(11) and the European Data Protection Board's Guidelines 05/2020 on consent, a compliant banner meets all of the following:
- Active opt-in. Consent requires an affirmative action, such as clicking "Accept." Scrolling, continued browsing, and pre-ticked boxes are invalid.
- No cookie walls. Consent is not freely given if the visitor cannot access the site without accepting tracking. The EDPB considers blanket cookie walls non-compliant.
- Equal prominence for refusal. Hiding "Reject" behind a second layer while "Accept all" sits on the first layer has drawn direct fines. CNIL fined Google 150 million EUR and Facebook 60 million EUR in January 2022 for exactly this asymmetry.
- No dark patterns. Color tricks, guilt-laden wording, and buttons designed to steer visitors toward acceptance undermine the validity of the consent collected.
- Specific per purpose. Bundling analytics, advertising, and personalization into one all-or-nothing toggle does not meet the specificity requirement.
One more detail that surprises many site owners: consent expires in practice. CNIL recommends renewing consent at least every 13 months, and the Danish and Irish authorities give similar guidance. A consent management platform should re-prompt visitors on that cycle.
Penalties and Enforcement Across Member States
Because the ePrivacy Directive is implemented nationally, penalties vary by member state rather than following a single EU-wide figure. That decentralization has not made enforcement soft. National authorities can fine under their ePrivacy implementations without the cross-border cooperation the GDPR requires, which makes cookie cases faster to bring.
Notable enforcement actions show the pattern:
Cookie Policy Generator
Create a cookie policy for GDPR compliance. Create yours in minutes with TermsBox.
Generate Now| Authority | Company | Fine | Core violation |
|---|---|---|---|
| CNIL (France) | 150 million EUR (2022) | Rejecting cookies harder than accepting | |
| CNIL (France) | 60 million EUR (2022) | Rejecting cookies harder than accepting | |
| CNIL (France) | Amazon | 35 million EUR (2020) | Cookies set without prior consent |
| Garante (Italy) | Multiple publishers | Ongoing sweeps | Non-compliant banners and cookie walls |
| ICO (UK) | Major UK websites | Warning campaign (2023-2024) | Missing "Reject all" options |
Where cookies process personal data, GDPR penalties stack on top: up to 20 million EUR or 4% of global annual turnover, whichever is higher, under Article 83. Enforcement also reaches small businesses. CNIL has run sweep campaigns issuing formal notices to hundreds of ordinary websites, not just tech giants.
How to Comply With the EU Cookie Law: Step by Step
Bringing a website into compliance is a concrete, finite project. Work through these steps in order:
- Audit your cookies. Scan your site to inventory every cookie, script, and pixel, including those set by third-party tags you forgot were installed. An automated scanner such as the one in TermsBox detects cookies and trackers you cannot see in your own source code.
- Classify each cookie. Sort the inventory into strictly necessary, functional, analytics, and advertising categories. Only the first category may load without consent.
- Deploy a consent banner that blocks first. The consent management platform must prevent non-essential scripts from firing until opt-in, offer "Accept" and "Reject" with equal prominence, and provide granular category toggles.
- Publish a cookie policy. Document every cookie, its purpose, its duration, and its provider, and link the policy from your banner and site footer.
- Wire up consent signals. Pass the visitor's choice to your tags, for example through Google Consent Mode v2, so that analytics and advertising tools respect refusals.
- Enable withdrawal. Add a persistent "Cookie settings" link in your footer that reopens the preference center.
- Re-scan on a schedule. Every new marketing tool, plugin, or embedded widget can add cookies. Monthly or weekly re-scans keep your banner and policy synchronized with reality, and platforms with living documents update the policy automatically when a scan detects changes.
Common Mistakes That Fail Audits
Even sites with banners fail regulatory sweeps on predictable details. Check your site against this list:
- Non-essential cookies fire before the visitor interacts with the banner
- The first banner layer has "Accept" but no "Reject" of equal prominence
- The cookie policy lists categories but not actual cookies, durations, or vendors
- Embedded YouTube videos or social widgets set cookies outside the consent tool
- Consent is never refreshed, so choices made years ago are still relied on
- The banner appears for EU visitors but the site has no record proving consent
Does the EU Cookie Law Apply to Non-EU Websites?
If your website is based outside the EU but serves European visitors, the practical answer is yes. Two mechanisms create that reach.
First, national implementations of the ePrivacy Directive protect users on the territory of each member state. A US e-commerce store setting advertising cookies on a French visitor's browser falls within CNIL's view of its jurisdiction. Second, GDPR Article 3(2) explicitly extends to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior. Tracking cookies are monitoring, so the GDPR consent standard follows your EU traffic wherever your servers sit.
Many non-EU businesses respond with geo-targeted consent: showing the strict opt-in banner to visitors from the EU, the European Economic Area, and the UK, while showing a lighter notice or opt-out banner elsewhere, such as a "Do Not Sell or Share" link for California visitors under the California Consumer Privacy Act (CCPA). That approach is legitimate as long as geolocation is accurate and EU visitors always get the compliant experience. If you would rather not manage regional variants, applying the EU standard globally is the simplest defensible position.
Also plan for change. The proposed ePrivacy Regulation, intended to replace the 2002 directive, has been stalled in Brussels for years, but national regulators are actively updating guidance on fingerprinting, server-side tracking, and consent-or-pay models. Compliance is a practice, not a one-time checkbox.
Frequently Asked Questions
What is the EU cookie law?
The EU cookie law is the common name for Article 5(3) of the ePrivacy Directive (2002/58/EC, amended by 2009/136/EC). It requires websites to obtain informed consent before storing or accessing cookies and similar technologies on a visitor's device, except for cookies that are strictly necessary for the service the user requested.
Does the EU cookie law apply to websites outside the EU?
Yes, in practice. If your website serves visitors located in the EU, national data protection authorities consider the consent rules to apply regardless of where your business is based. The GDPR's extraterritorial scope under Article 3(2) reinforces this, since most cookies process personal data.
Which cookies do not require consent under EU law?
Cookies that are strictly necessary to deliver a service the user explicitly requested are exempt. Examples include shopping cart cookies, session login cookies, load balancing cookies, and consent preference cookies. Analytics, advertising, and social media cookies all require prior opt-in consent.
Is a cookie banner that only says 'by using this site you accept cookies' compliant?
No. The Court of Justice of the EU confirmed in the Planet49 ruling (C-673/17) that consent must be an active, unambiguous action. Implied consent, pre-ticked boxes, and continued browsing do not qualify. Non-essential cookies must stay blocked until the visitor actively opts in.
What are the penalties for violating the EU cookie law?
Penalties vary by member state because the ePrivacy Directive is implemented through national laws. France's CNIL has issued some of the largest fines, including 150 million EUR against Google and 60 million EUR against Facebook in 2022. Where cookies process personal data, GDPR fines of up to 20 million EUR or 4% of global annual turnover can also apply.
Do I need both a cookie banner and a cookie policy?
Yes. The banner collects consent before non-essential cookies load, while the cookie policy provides the detailed disclosures required for that consent to be informed: which cookies you use, their purposes, durations, and any third parties involved. The two work together, and neither alone is sufficient.