European Cookie Law Explained: ePrivacy, GDPR, and Consent
Understand the European cookie law: how the ePrivacy Directive and GDPR regulate cookies, what valid consent requires, and how to make your site compliant.
If your website has visitors from the EU, the European cookie law determines what you must do before setting a single tracking cookie. The rules behind the European cookie law come from two separate pieces of legislation, the ePrivacy Directive and the General Data Protection Regulation (GDPR), and misunderstanding how they interact is the most common reason websites end up with non-compliant cookie banners. This guide explains where the rules come from, which cookies need consent, what valid consent looks like, and how to bring your website into compliance. It is educational content rather than legal advice, so consult a qualified attorney for guidance specific to your situation.
What Is the European Cookie Law?
The European cookie law is not a single statute. It is the common name for Article 5(3) of the ePrivacy Directive (Directive 2002/58/EC), as amended in 2009 by Directive 2009/136/EC. That provision requires anyone storing information on a user's device, or accessing information already stored there, to obtain the user's informed consent first.
A cookie, in this context, is a small text file a website places in your browser to remember information between page loads. The law's language is deliberately broader than cookies alone. It covers any storage or access technology, including:
- HTTP cookies (first-party and third-party)
- localStorage and sessionStorage
- Tracking pixels and web beacons
- Browser fingerprinting scripts
- Mobile SDK identifiers
Because the ePrivacy Directive is a directive rather than a regulation, it does not apply directly. Each EU member state transposed it into national law, such as the UK's Privacy and Electronic Communications Regulations (PECR) or France's Loi Informatique et Libertés. That is why enforcement details and penalty amounts differ from country to country even though the core rule is the same everywhere.
The Two Laws Behind European Cookie Rules
Cookie compliance in Europe rests on the interaction between two laws, and you need both to get the full picture.
The ePrivacy Directive Sets the Rule
Article 5(3) of the ePrivacy Directive establishes the core obligation: no storing or reading of information on a user's device without informed consent, unless an exemption applies. The directive covers the act of placing the cookie itself, regardless of whether the cookie contains personal data.
The GDPR Defines Valid Consent
The ePrivacy Directive requires consent but points to data protection law for its definition. Since May 2018, that definition comes from Article 4(11) of the GDPR: consent must be a freely given, specific, informed, and unambiguous indication of the user's wishes, expressed through a statement or clear affirmative action. Article 7 of the GDPR adds conditions, including that withdrawing consent must be as easy as giving it.
The GDPR also applies directly whenever cookies process personal data. Online identifiers, including cookie IDs and IP addresses, count as personal data under Article 4(1) and Recital 30. In practice, almost every advertising or analytics cookie triggers both laws at once: the ePrivacy Directive for setting the cookie, and the GDPR for processing the data it collects.
The Court of Justice of the EU confirmed the strict reading in the Planet49 judgment (Case C-673/17, October 2019): pre-ticked checkboxes do not constitute valid consent, and consent requirements apply whether or not the cookie contains personal data.
Which Cookies Require Consent Under European Cookie Law
Not every cookie needs a consent banner. The ePrivacy Directive contains two exemptions in Article 5(3): cookies used solely to transmit a communication, and cookies strictly necessary to provide a service the user explicitly requested.
Exempt: Strictly Necessary Cookies
These can be set without consent because the service the visitor asked for cannot work without them:
- Session cookies that keep a shopping cart filled during checkout
- Authentication cookies that keep a user logged in
- Security cookies that detect fraud or repeated failed logins
- Load-balancing cookies that route traffic across servers
- Consent-preference cookies that remember the visitor's own cookie choices
Not Exempt: Everything Else
The following categories require prior opt-in consent for EU visitors:
- Analytics cookies (Google Analytics, Matomo in default configuration, Hotjar)
- Advertising and retargeting cookies (Google Ads, Meta Pixel, programmatic ad tech)
- Social media cookies (embedded share buttons, YouTube embeds, social login widgets)
- Personalization cookies that are not essential to a requested service
- A/B testing and session recording tools
A frequent misconception is that first-party analytics are exempt because they feel harmless. They are not. Regulators including France's CNIL and Spain's AEPD have stated that audience measurement cookies need consent unless they meet narrow conditions, such as producing only aggregated statistics with no cross-site tracking. Standard Google Analytics does not meet those conditions.
What Valid Cookie Consent Looks Like
This is where most websites fail. European regulators have published detailed guidance, most notably the European Data Protection Board's Guidelines 05/2020 on consent, and the requirements are specific.
Valid consent under the European cookie law must be:
- Prior. Non-essential cookies must not fire until the visitor consents. Setting cookies on page load and asking afterward is a violation.
- Freely given. The visitor must have a real choice. Rejecting cookies must be as easy as accepting them, which regulators interpret as a reject option on the first banner layer.
- Specific and granular. Visitors must be able to consent per purpose (analytics, advertising, personalization) rather than facing an all-or-nothing choice.
- Informed. The banner must identify who sets cookies, for what purposes, and link to a detailed cookie policy listing each cookie, its duration, and third-party recipients.
- Unambiguous and affirmative. Scrolling, continued browsing, and pre-ticked boxes do not count. The Planet49 ruling settled this.
- Withdrawable. Article 7(3) of the GDPR requires that withdrawing consent be as easy as giving it. A persistent settings link or floating icon lets visitors change their mind at any time.
- Documented. Article 7(1) of the GDPR requires you to be able to demonstrate that consent was given. Your consent tool should keep timestamped records.
Common Banner Mistakes That Regulators Have Fined
- An "Accept" button on the first layer with rejection buried behind "Manage settings." CNIL fined Google 150 million EUR and Facebook 60 million EUR in January 2022 for exactly this asymmetry.
- Interface design that nudges acceptance, such as a bright accept button next to a gray, low-contrast reject link.
- Loading Google Analytics or the Meta Pixel before any interaction with the banner.
- Treating banner dismissal (clicking the X) as consent.
- No way to withdraw consent after the initial choice.
How EU Member States Enforce the Cookie Law
Because each country implements the ePrivacy Directive nationally, enforcement runs through national authorities rather than the GDPR's one-stop-shop mechanism. That means a regulator in any EU country where you have users can act against you directly.
Key enforcement bodies and actions include:
| Regulator | Country | Notable Cookie Enforcement |
|---|---|---|
| CNIL | France | 150 million EUR against Google and 60 million EUR against Facebook (2022) for asymmetric consent; 100 million EUR against Google and 35 million EUR against Amazon (2020) for cookies set without consent |
| AEPD | Spain | Regular fines against websites lacking reject options, typically in the tens of thousands of EUR |
| Garante | Italy | Cookie guidelines enforcement, including action on scrolling-as-consent |
| ICO | United Kingdom | PECR enforcement; 2023-2024 campaign warning top UK websites to fix non-compliant banners |
| Data Protection Commission | Ireland | Lead authority for many US tech firms' EU operations |
Penalty ceilings under national ePrivacy laws vary by member state, so there is no single maximum fine. Where cookie data processing also violates the GDPR, Article 83 applies: up to 20 million EUR or 4% of global annual turnover, whichever is higher. CNIL's cookie fines demonstrate that nine-figure penalties are realistic for large companies, and small-business fines in Spain and Germany show that enforcement is not limited to Big Tech.
Does the European Cookie Law Apply to Your Website?
The rules apply based on where your visitors are, not where your business is registered. You are in scope if:
- Your business is established in an EU or EEA member state, or
- Your website offers goods or services to people in the EU, or monitors their behavior, which brings the GDPR's extraterritorial scope under Article 3(2) into play
For example, a US-based SaaS company with a marketing site that attracts EU signups needs compliant cookie consent for those visitors. So does an Australian e-commerce store shipping to Germany, and a Canadian blog running EU-targeted ads.
Cookie Policy Generator
Create a cookie policy for GDPR compliance. Create yours in minutes with TermsBox.
Generate NowThe UK retained near-identical rules after Brexit through PECR and the UK GDPR, enforced by the Information Commissioner's Office (ICO), so UK traffic requires the same treatment. Switzerland and other EEA-adjacent countries have their own similar frameworks.
If most of your audience is outside Europe, you do not need to show a consent banner to everyone. Geo-targeted consent applies opt-in banners to EU, EEA, and UK visitors while showing lighter notices elsewhere, which preserves analytics data from regions that do not require prior consent. If you also serve California users, note that the CCPA takes an opt-out approach instead; the differences are covered in this GDPR vs CCPA comparison.
How to Comply With the European Cookie Law
Working through compliance in order prevents the most common gaps.
- Audit your cookies. Scan your website to inventory every cookie and tracking technology, including those set by embedded third parties like YouTube or chat widgets. Third-party scripts change over time, so a one-time manual check goes stale quickly.
- Classify each cookie. Sort them into strictly necessary, analytics, advertising, and personalization. Only the first category is exempt from consent.
- Publish a cookie policy. Document each cookie's name, provider, purpose, duration, and category. A cookie policy generator can build this from your actual cookie list, and your privacy policy should reference it.
- Deploy a compliant consent banner. Equal-prominence accept and reject buttons on the first layer, granular category toggles, and no non-essential cookies before consent.
- Block cookies until consent. The banner must actually control script execution. A banner that displays while Google Analytics loads underneath is a violation, not a technicality.
- Record and honor choices. Store timestamped consent records, respect rejections across sessions, and provide a persistent way to withdraw or change consent.
- Re-scan regularly. Every new marketing tool, plugin, or embed can introduce cookies your policy does not cover. Periodic scans keep your disclosures accurate.
Steps 1, 5, and 7 are where manual approaches break down, which is why most sites use a Consent Management Platform (CMP). TermsBox combines these steps: its scanner detects the cookies and trackers actually running on your site, the consent banner blocks them until visitors opt in, and for subscribers the hosted cookie policy updates automatically when scans detect changes.
The Future: From Directive to ePrivacy Regulation
The EU has been working to replace the 2002 directive with an ePrivacy Regulation since January 2017. A regulation would apply uniformly across all member states without national transposition, ending the current patchwork. The proposal stalled for years in trilogue negotiations, and in February 2025 the European Commission formally withdrew it, citing no foreseeable agreement.
That leaves the ePrivacy Directive and national implementations as the governing framework for the foreseeable future. Meanwhile, the direction of travel is visible in current initiatives:
- Regulators continue tightening guidance on dark patterns in consent interfaces, including the EDPB's 2023 cookie banner taskforce report.
- Browser-level and signal-based consent mechanisms keep being discussed as a remedy for consent fatigue, though no EU-wide standard has been adopted.
- "Consent or pay" models are under active regulatory scrutiny, with the EDPB's 2024 opinion setting a skeptical baseline for large platforms.
For website owners, the practical takeaway is stability: the consent requirements described in this guide have been settled law since the Planet49 ruling and the GDPR's arrival, and enforcement is increasing rather than loosening. Building proper consent infrastructure now is not a bet on pending legislation. It is compliance with rules that are already enforced.
Frequently Asked Questions
What is the European cookie law?
The European cookie law is the common name for Article 5(3) of the ePrivacy Directive (2002/58/EC), which requires websites to obtain informed consent before storing or accessing non-essential cookies on a visitor's device. Since 2018, the GDPR defines what counts as valid consent, meaning it must be freely given, specific, informed, and unambiguous.
Does the European cookie law apply to websites outside the EU?
Yes, if your website serves visitors in the EU or European Economic Area, the cookie rules apply regardless of where your business is based. A US company with EU visitors must obtain consent before setting non-essential cookies for those visitors, and many sites use geo-targeted banners to apply the rules only where required.
Which cookies are exempt from consent under EU law?
Strictly necessary cookies are exempt: those required to deliver a service the user explicitly requested, such as session cookies for shopping carts, authentication cookies, and security cookies. Analytics, advertising, and social media cookies are not exempt and require prior opt-in consent.
Are cookie walls legal in Europe?
Blanket cookie walls that block all access unless the visitor accepts tracking are generally considered non-compliant, because consent given under that pressure is not freely given. However, some regulators, including CNIL in France, have accepted 'consent or pay' models where users can choose between accepting cookies or paying for an ad-free version, subject to conditions.
What are the penalties for violating the European cookie law?
Penalties vary by EU member state because each country implements the ePrivacy Directive in national law. Enforcement has been substantial: France's CNIL fined Google 150 million EUR and Facebook 60 million EUR in 2022 for making cookie refusal harder than acceptance. Where the GDPR applies, fines can reach 20 million EUR or 4% of global annual turnover.
Do I need both a cookie banner and a cookie policy?
Yes. The banner collects and records consent before non-essential cookies are set, while the cookie policy provides the detailed disclosure: which cookies you use, their purposes, durations, and third parties involved. The two work together, and the banner should link directly to the policy.