Back to the blog
Guide

EU cookie law: what the ePrivacy Directive and GDPR require

There is no single act called the EU cookie law. The term covers one article of the ePrivacy Directive and the GDPR's rules on consent, as interpreted by the EU's highest court and national regulators. This guide goes through what they say and what they mean for your website.

Article 5(3) of the ePrivacy Directive

The core of the cookie law is one paragraph of Directive 2002/58/EC, as amended by Directive 2009/136/EC:

"Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information [...] about the purposes of the processing."

Three things follow from the wording:

  • It is not only about cookies: it covers any information stored on, or read from, the visitor's device, including local storage and similar techniques.
  • Consent comes first: the storing or reading is only allowed once the visitor has consented.
  • There are two exceptions: storage needed to transmit a communication, and storage that is strictly necessary for a service the visitor explicitly asked for, such as a shopping basket or a login session.

Where the GDPR comes in

The ePrivacy Directive does not define consent itself. It refers to the EU data protection rules, which now means the GDPR. The EU data protection authorities read this as a reference both to the GDPR's definition of consent and to its conditions:

Article 4(11): the definition

Consent is "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement".

Article 7: the conditions

You must be able to demonstrate consent (7(1)). The visitor can withdraw it at any time, and it must be as easy to withdraw as to give (7(3)). When judging whether consent is freely given, utmost account is taken of whether a service is made conditional on consent to processing it does not need (7(4)).

Recital 32: what is not consent

"Silence, pre-ticked boxes or inactivity should not therefore constitute consent."

Whatever you do with the data after the cookie is set, such as analysing it or sharing it with an ad platform, falls under the GDPR whenever it is personal data, including its rules on legal basis, transparency and data subjects' rights.

The Planet49 ruling

On 1 October 2019 the Court of Justice of the EU (Grand Chamber) ruled in Planet49 (C-673/17), a case referred by the German Federal Court of Justice. It held that:

  1. consent is not valid if it is given through a pre-ticked checkbox that the user has to untick to refuse;
  2. the consent requirement applies whether or not the information stored or accessed is personal data;
  3. the information you give visitors must include how long the cookies will operate and whether third parties can access them.

What the regulators expect from a cookie banner

In January 2023 the European Data Protection Board published the report of its cookie banner taskforce. It records the positions the national authorities agreed on as a minimum when handling complaints about cookie banners:

  • No reject button: a vast majority of the authorities consider a banner with an accept button but no reject option on the same layer an infringement.
  • Pre-ticked boxes: do not lead to valid consent, including on the second layer of a banner.
  • Deceptive design: a reject option offered only as a link in the body text, without visual emphasis, does not lead to valid consent, and a reject button with unreadable contrast can be manifestly misleading.
  • Legitimate interest: cannot be the legal basis for placing or reading cookies.
  • "Essential" cookies: some sites label cookies as essential that are not strictly necessary. The authorities discussed website owners' responsibility to keep a list of their cookies and to demonstrate that those they call essential really are.
  • Withdrawal: visitors need an easily accessible way to withdraw consent at any time, such as a small permanent icon or a link in a visible, standard place.

The EDPB's consent guidelines add that scrolling or swiping through a page is never a clear affirmative action, and that consent is not freely given when access to the website depends on accepting cookies (a cookie wall). National regulators can add their own guidance on top.

National laws, fines and the UK

Because Article 5(3) is in a directive, each EU country has its own implementing law, for example the TDDDG in Germany and the cookie order (cookiebekendtgørelsen) in Denmark. The national regulator enforces it, and penalties for cookie breaches depend on that national law.

Where the GDPR applies to the data you collect, breaching its consent conditions can lead to fines of up to 20 million euros or 4% of worldwide annual turnover, whichever is higher (Article 83(5)).

The UK has its own rules in the Privacy and Electronic Communications Regulations (PECR), enforced by the ICO. Following the Data (Use and Access) Act 2025, PECR contains further exceptions to the consent requirement, for example for some statistical and appearance cookies, each with conditions such as clear information and a simple, free way to object. If you have UK visitors, read the ICO's guidance on storage and access technologies.

Checklist for your website

Use this list to check your cookie set-up:

  • Cookies and scripts that need consent are blocked until the visitor has given it
  • The banner offers a reject option on the same layer as the accept button
  • Rejecting is as clear as accepting: no hidden links, no unreadable buttons
  • Visitors can choose per purpose (analytics, marketing, preferences)
  • No boxes are ticked in advance
  • The banner explains what the cookies are for, how long they last and whether third parties can access them
  • Visitors can change or withdraw their choice at any time, as easily as they gave it
  • Every decision is recorded, so you can demonstrate consent
  • Your site stays usable for visitors who refuse (no cookie wall)
  • You scan your website regularly, because new plugins and embeds add new cookies

Note: this guide is general information, not legal advice. For questions about your own situation, talk to a lawyer who specialises in data protection.

Frequently asked questions

Is there an official law called the EU cookie law?

No. "EU cookie law" is shorthand for Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended in 2009), read together with the GDPR's rules on consent. Each EU country has written Article 5(3) into its own law.

Does it apply to businesses outside the EU?

The GDPR applies to businesses outside the EU when they offer goods or services to people in the EU or monitor their behaviour there (Article 3(2)). The national laws implementing Article 5(3) set their own scope, so if you target visitors in the EU, plan on following the consent rules.

Do analytics cookies need consent?

Analytics cookies are not strictly necessary for the service a visitor asked for, so the starting point under Article 5(3) is that they need consent. In the UK, PECR now has a conditional exception for some statistical cookies. In an EU country, check your national regulator's guidance before assuming any exception applies.

Are cookie walls allowed?

The European Data Protection Board's consent guidelines say that for consent to be freely given, access to a service must not depend on accepting cookies, and that consent obtained through a cookie wall is not valid.

What happened to the ePrivacy Regulation?

It was proposed in 2017 to replace the ePrivacy Directive, but the European Commission withdrew the proposal in 2025 after years without agreement. The ePrivacy Directive and the national laws based on it remain in force.

Meet the cookie rules in five minutes

Consentaur scans your site, blocks scripts until visitors consent, sends Google Consent Mode v2 signals and records every decision.

Start your free trial

14-day free trial. No credit card required.