TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. EU Cookie Legislation: Complete Compliance Guide for 2026
Legal Compliance

EU Cookie Legislation: Complete Compliance Guide for 2026

Understand EU cookie legislation, from the ePrivacy Directive to GDPR consent rules. Learn what consent requires, what fines apply, and how to comply.

TermsBox Team|July 26, 202615 min read

EU cookie legislation is the set of rules that decide whether you can place a tracking cookie on a European visitor's browser, and almost every website that reaches European users falls under it. The rules are older than the General Data Protection Regulation (GDPR), stricter than most site owners assume, and enforced by 27 different national regulators with their own guidance. This guide explains what the law actually requires, where the common banner mistakes come from, and what compliance looks like in practice. It is educational information rather than legal advice, so consult a qualified attorney for guidance on your specific situation.

What EU Cookie Legislation Actually Is

EU cookie legislation is not a single law. It is a layered framework built from a directive, a regulation, and 27 national implementations that give the rules legal force in each member state.

The three layers that matter:

  • The ePrivacy Directive (2002/58/EC, amended by 2009/136/EC): Article 5(3) is the core cookie rule. It requires that users give informed consent before a website stores information on, or gains access to information already stored on, their terminal equipment.
  • The GDPR (Regulation 2016/679): it does not mention cookies in its articles, but it defines consent in Article 4(11) and sets the conditions for valid consent in Article 7. Since the ePrivacy Directive borrows the GDPR definition of consent, GDPR sets the quality bar.
  • National implementing laws: for example, the UK Privacy and Electronic Communications Regulations 2003 (PECR), Germany's Telecommunications Digital Services Data Protection Act (TDDDG, formerly TTDSG), and France's Loi Informatique et Libertés as applied by the CNIL.

Because the ePrivacy rules sit in a directive rather than a regulation, they are not uniform across the bloc. The consent obligation is the same everywhere. The penalties, the guidance on banner design, and the enforcement appetite are not.

Why the Rules Cover More Than Cookies

Article 5(3) is technology-neutral. It refers to storing or accessing information on a user's device, which covers cookies but also local storage, session storage, IndexedDB, pixels, SDK identifiers, and device fingerprinting scripts.

That matters because many site owners believe they escape the rules by using "cookieless" tracking. They do not. If your analytics vendor reads a canvas fingerprint or writes to localStorage, the same consent obligation applies.

The Consent Standard Under EU Cookie Legislation

The single most important thing to understand about EU cookie legislation is that consent has a legal definition, and most banners in the wild do not meet it. GDPR Article 4(11) defines consent as a freely given, specific, informed, and unambiguous indication of the data subject's wishes, given by a statement or clear affirmative action.

Broken down into the tests regulators apply:

  1. Freely given: the user must have a genuine choice. Access to the site cannot be conditioned on accepting non-essential cookies unless a real alternative exists.
  2. Specific: consent must be granular by purpose. A single "accept all" toggle covering analytics, advertising, and personalization is not specific consent.
  3. Informed: before consenting, users need to know who is setting cookies, for what purposes, how long the cookies last, and whether data goes to third parties.
  4. Unambiguous: a clear affirmative action is required. Silence, inactivity, pre-ticked boxes, and continued scrolling do not qualify.
  5. Withdrawable: Article 7(3) requires that withdrawing consent be as easy as giving it.
  6. Demonstrable: Article 7(1) requires the controller to prove consent was obtained, which means logging consent records.

The Planet49 Ruling Changed the Baseline

In October 2019 the Court of Justice of the European Union decided Case C-673/17 (Planet49 GmbH). The court held that a pre-checked box does not constitute valid consent, and that the consent requirement applies whether or not the information stored is personal data.

The same ruling confirmed that users must be told the duration of the cookies and whether third parties can access them. If your cookie banner does not disclose retention periods, it falls short of what the court described.

Prior Consent Means Before, Not During

Consent must be obtained before non-essential cookies are set. In practice, this is where most implementations fail: the banner appears, but Google Analytics, Meta Pixel, and Hotjar have already fired in the page head.

A compliant setup blocks all non-essential scripts until the user makes a choice. Tag managers that load vendor tags on page load, regardless of consent state, will produce a violation even when the banner design is perfect.

Which Cookies Are Exempt From Consent

Article 5(3) of the ePrivacy Directive contains two exemptions. A cookie is exempt if it is used for the sole purpose of carrying out the transmission of a communication, or if it is strictly necessary for the provider to deliver a service explicitly requested by the subscriber or user.

The Article 29 Working Party (now the European Data Protection Board) issued Opinion 04/2012 on cookie consent exemptions, which remains the standard reference. Cookies that generally qualify as exempt:

  • User-input cookies that remember form entries during a session
  • Authentication cookies that keep a logged-in user signed in
  • User-centric security cookies, such as those limiting failed login attempts
  • Multimedia player session cookies
  • Load-balancing session cookies
  • User-interface customization cookies, such as a language preference the user selected
  • Shopping cart cookies for e-commerce sessions

Cookies that always require consent:

  • Google Analytics, Matomo (unless self-hosted in a specific anonymized configuration), and every other analytics tool
  • Advertising and retargeting cookies from Google Ads, Meta, LinkedIn, and TikTok
  • Social media share buttons and embedded content that sets identifiers
  • A/B testing and personalization tools
  • Heatmap and session recording tools such as Hotjar and Microsoft Clarity
  • Affiliate tracking cookies

A frequent misconception is that first-party analytics are exempt. They are not exempt under the directive itself. Some regulators, including the CNIL, allow a narrow exemption for strictly configured audience measurement, but the conditions are tight: no cross-site tracking, no data sharing, limited retention, and anonymized reporting.

Cookie Banner Requirements Under EU Cookie Legislation

Regulators have converged on a set of design expectations. The European Data Protection Board's Report of the Cookie Banner Taskforce (January 2023), produced after coordinated complaints across member states, is the clearest statement of what national authorities consider non-compliant.

What a compliant banner must do:

  • Present accept and reject options at the same level, in the first layer, with equal visual prominence
  • Avoid deceptive design, meaning no bright "Accept all" button next to a grey text link for rejection
  • Offer purpose-level granularity, with all non-essential categories off by default
  • Name the third parties setting cookies, or link to a full list
  • Disclose cookie lifespans
  • Provide a persistent way to change or withdraw consent after the initial choice
  • Refrain from blocking access to content while consent is pending, unless a lawful alternative such as a paid, tracking-free option is offered

What regulators have specifically flagged as non-compliant:

  • Banners with only an "Accept" button and a "Settings" link
  • Reject options buried two clicks deep
  • Pre-ticked purpose toggles
  • Consent walls that force acceptance to view content, without an equivalent alternative
  • Banners that reappear aggressively after rejection to pressure the user
  • Cookies set before any interaction with the banner

The Reject Button Question

There is no article of EU cookie legislation that says "you must have a reject button." The requirement follows from the definition of freely given consent: if refusing is significantly harder than accepting, consent is not free.

The CNIL made this explicit in its 2020 cookie guidelines and enforced it in January 2022, when it fined Google 150 million EUR and Facebook 60 million EUR precisely because rejecting cookies took more clicks than accepting them. A same-layer reject button is now the practical standard across the EU.

Enforcement and Penalties Across Member States

Because the ePrivacy Directive is implemented nationally, penalties differ by country. There is no single EU-wide cookie fine ceiling, and this is one of the most misreported aspects of EU cookie legislation.

Regulator Country Legal basis for cookie fines Notable action
CNIL France Loi Informatique et Libertés, up to 2 percent of turnover for ePrivacy breaches 150 million EUR (Google) and 60 million EUR (Facebook), January 2022
ICO UK PECR, up to 500,000 GBP; GDPR fines separate Formal warnings issued to major UK websites in 2023 and 2024
Garante Italy National ePrivacy implementation Google Analytics use ruled unlawful without adequate transfer safeguards, June 2022
DSB Austria National ePrivacy implementation First EU decision against Google Analytics transfers, January 2022
AEPD Spain LSSI, up to 150,000 EUR for serious cookie infringements Repeated fines for banners lacking reject options

Where cookie practices also breach GDPR, for example by processing personal data without a valid legal basis, the GDPR ceiling in Article 83(5) applies: up to 20 million EUR or 4 percent of total worldwide annual turnover, whichever is higher.

Enforcement is also driven by complaints. The advocacy group noyb filed over 700 complaints against non-compliant cookie banners starting in 2021, and many of the resulting decisions shaped current regulator guidance. Small sites are rarely the first target, but complaint-driven enforcement means no site is structurally safe.

Cookie Policy Generator

Create a cookie policy for GDPR compliance. Create yours in minutes with TermsBox.

Generate Now

The ePrivacy Regulation and What Replaced It

For years, guidance about EU cookie legislation came with a caveat: the ePrivacy Regulation would soon replace the directive and harmonize the rules. That is no longer the expectation.

The European Commission formally withdrew the ePrivacy Regulation proposal in February 2025, after roughly eight years of failed trilogue negotiations. The 2002 directive, as amended in 2009, remains in force.

What that means for your compliance planning:

  • The current consent standard is stable. Build for the ePrivacy Directive plus GDPR, not for a pending replacement.
  • National divergence persists. If you operate across several member states, check local regulator guidance for banner specifics.
  • Related EU legislation still applies alongside it. The Digital Services Act restricts profiling-based advertising to minors and bars advertising based on special category data, while the Digital Markets Act imposes separate consent obligations on designated gatekeeper platforms.

If you want the background on how the directive and the newer proposals relate, our explainer on the ePrivacy Directive covers the legislative history in more detail.

What Your Cookie Policy Must Disclose

EU cookie legislation requires informed consent, and the information duty is usually satisfied through a cookie policy linked from the banner. GDPR Articles 13 and 14 add transparency obligations where cookies process personal data.

A cookie policy that meets the informed consent standard should include:

  • A plain-language explanation of what cookies and similar technologies are
  • A full inventory of the cookies your site sets, broken down by name, provider, purpose, type, and expiry
  • The categories used in your banner, matching the categories exactly
  • Named third parties receiving data, with links to their privacy policies
  • Whether any data is transferred outside the European Economic Area, and the safeguard used, such as standard contractual clauses under GDPR Article 46
  • How users can withdraw consent or change preferences
  • How users can manage cookies through browser settings
  • The date the policy was last updated

Accuracy is the part most sites get wrong. A cookie table copied from a template, listing cookies you no longer use and omitting the three tools your marketing team added last quarter, is not informed consent. You can build an accurate document with a cookie policy generator and keep it aligned with your live site through regular scanning. TermsBox pairs a scanner that inventories the cookies actually present on your pages with a consent banner that blocks non-essential scripts until the user chooses.

Practical Steps to Comply With EU Cookie Legislation

Compliance is an audit problem before it is a banner problem. You cannot obtain informed consent for cookies you have not identified.

  1. Run a full cookie audit. Scan every template on your site, not just the homepage: checkout, blog, landing pages, and any page with embedded video or maps. Record cookie names, domains, purposes, and expiry.
  2. Classify each cookie. Sort them into strictly necessary versus consent-requiring, and document your reasoning for anything you classify as exempt.
  3. Map third-party data flows. Identify which vendors receive data, where they process it, and whether an international transfer mechanism is in place.
  4. Implement prior blocking. Configure your consent management platform so no non-essential script executes before consent. Verify with browser developer tools on a fresh session.
  5. Design the banner for symmetry. Accept and reject on the first layer, equal prominence, granular purposes off by default.
  6. Log consent records. Store the choice, the timestamp, the consent string or category state, and the policy version, so you can meet the Article 7(1) accountability requirement.
  7. Publish a matching cookie policy. The categories, vendor names, and durations in the policy must match what the banner actually controls.
  8. Set a re-consent interval. Most regulators, including the CNIL, treat 6 to 13 months as a reasonable maximum before asking again.
  9. Rescan on a schedule. New marketing tags appear without warning. Monthly scanning catches drift before a complaint does.

Common Compliance Failures to Check For

  • Google Tag Manager firing tags on page load regardless of the consent signal
  • Embedded YouTube videos setting cookies before consent, when youtube-nocookie.com would defer them
  • Consent stored only client-side, with no server-side record for accountability
  • A cookie policy listing four cookies when the site sets 40
  • A "reject all" button that clears the banner without actually deleting previously set cookies
  • Consent Mode configured in basic mode while marketing assumes advanced behavior

Sites using Google's advertising stack should also review how Google Consent Mode v2 interacts with their banner, since the consent signal must reflect the user's real choice rather than a default grant.

How EU Cookie Legislation Compares to Other Regimes

If you operate globally, EU cookie legislation sits at the strict end of the spectrum, and building to it usually covers weaker regimes.

Regime Consent model Trigger
EU (ePrivacy plus GDPR) Opt-in before any non-essential cookie Any storage or access on the device
UK (PECR plus UK GDPR) Opt-in, aligned with EU standard Same as EU, enforced by the ICO
California (CCPA/CPRA) Opt-out of sale or sharing Business meets revenue or volume thresholds
Brazil (LGPD) Legal basis required, consent one option Processing personal data of Brazilian residents
Canada (PIPEDA) Meaningful consent, express for sensitive data Commercial activity involving personal data

The practical implication: an opt-in banner built for the EU satisfies UK requirements almost exactly, but it does not automatically satisfy the CPRA, which requires a distinct "Do Not Sell or Share My Personal Information" mechanism and recognition of the Global Privacy Control signal. Multi-region sites typically geo-target the consent experience rather than serving one banner worldwide. For the wider comparison, see our breakdown of GDPR vs CCPA.

Frequently Asked Questions

What is EU cookie legislation?

EU cookie legislation refers primarily to Article 5(3) of the ePrivacy Directive (2002/58/EC as amended by 2009/136/EC), which requires informed consent before storing or accessing information on a user's device. The GDPR (Regulation 2016/679) then defines what valid consent means, and each EU member state implements both through national law.

Do I need consent for all cookies under EU law?

No. Article 5(3) of the ePrivacy Directive exempts cookies that are strictly necessary to deliver a service the user explicitly requested, such as shopping cart cookies, login session cookies, and load-balancing cookies. Analytics, advertising, personalization, and social media cookies all require prior opt-in consent.

Does EU cookie legislation apply to companies outside the EU?

Yes. If your website is accessible to and targets users in the EU, national ePrivacy rules apply to the cookies you set on their devices, and GDPR Article 3(2) extends to organizations outside the EU offering goods or services to EU residents. A US-based e-commerce store shipping to Germany must comply.

What are the fines for cookie consent violations in the EU?

Penalties vary by member state because the ePrivacy Directive is implemented through national law. France's CNIL fined Google 150 million EUR and Facebook 60 million EUR in January 2022 over non-compliant cookie banners, and where GDPR consent rules are breached, fines can reach 20 million EUR or 4 percent of global annual turnover under Article 83.

Is a cookie banner that only says 'by using this site you accept cookies' legal?

No. Implied consent through continued browsing has not been valid since the Court of Justice of the European Union ruled in Planet49 (C-673/17, October 2019). Consent must be a freely given, specific, informed, and unambiguous affirmative action, so pre-ticked boxes and scroll-to-accept mechanisms fail.

Has the ePrivacy Regulation replaced the ePrivacy Directive?

No. The proposed ePrivacy Regulation was formally withdrawn by the European Commission in February 2025 after years of stalled negotiations. The 2002 ePrivacy Directive, as amended in 2009 and implemented in national law, remains the governing EU cookie legislation.

Related Tools

Cookie Policy Generator

Create a cookie policy for GDPR compliance

Related Articles

Legal Compliance

What a Data Subject Is: GDPR Definition, Rights, and Examples

Learn what a data subject is under GDPR, who qualifies, the rights they hold, and what your business must do to handle data subject requests correctly.

July 27, 202614 min read
Legal Compliance

Cybersecurity Data: What It Is and How to Protect It

Learn what cybersecurity data is, the types your business handles, and the legal requirements for protecting it under GDPR, CCPA, and other privacy laws.

July 27, 202611 min read
Legal Compliance

Data Breach in Cyber Security: Causes, Laws, and Response

Understand what a data breach in cyber security is, how breaches happen, which notification laws apply, and how to prevent and respond to an incident.

July 27, 202613 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What EU Cookie Legislation Actually Is
  • Why the Rules Cover More Than Cookies
  • The Consent Standard Under EU Cookie Legislation
  • The Planet49 Ruling Changed the Baseline
  • Prior Consent Means Before, Not During
  • Which Cookies Are Exempt From Consent
  • Cookie Banner Requirements Under EU Cookie Legislation
  • The Reject Button Question
  • Enforcement and Penalties Across Member States
  • The ePrivacy Regulation and What Replaced It
  • What Your Cookie Policy Must Disclose
  • Practical Steps to Comply With EU Cookie Legislation
  • Common Compliance Failures to Check For
  • How EU Cookie Legislation Compares to Other Regimes
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.