Back to the hub

Do I need a cookie consent banner in the EU?

In the EU you need a user's consent before placing non-essential cookies or similar trackers on their device, unless they are strictly necessary for a service the user asked for. Consent must be freely given, specific, informed, and unambiguous, so pre-ticked boxes and continued browsing do not count.

Applies to: Websites and apps that set cookies or similar technologies on the devices of users in the EU or EEA.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

The cookie banner is the most visible piece of privacy compliance a website has, and also the one most often done wrong. The rule is not that every site needs a banner for its own sake. It is that you need valid consent before setting non-essential cookies on a visitor's device, and a banner is simply the practical way to collect it. Get the consent mechanics wrong and the banner gives you no protection at all.

What the law actually requires

Two instruments work together. Article 5(3) of the ePrivacy Directive says that storing information on, or reading information from, a user's device is allowed only with the user's consent, after they have been given clear and comprehensive information, unless the storage or access is strictly necessary to provide a service the user has explicitly requested. The GDPR then sets what "consent" has to look like: under Article 4(11) it must be freely given, specific, informed, and unambiguous, given by a clear affirmative action. The Court of Justice confirmed in Planet49 that pre-ticked boxes do not meet that bar, and regulators treat "continue browsing" the same way.

Which cookies are exempt

Strictly necessary cookies do not need consent. These are cookies required to carry out or facilitate a communication, or that are essential to provide a service the user actually asked for, such as keeping items in a basket, holding a login session, or a security token. Analytics, advertising, and personalisation cookies are not strictly necessary, so they need consent before they load. A useful discipline is to list every cookie in your record of processing activities and mark which category it falls into, so the banner reflects reality.

What is changing

This area is moving. The proposed ePrivacy Regulation that would have replaced the Directive was formally withdrawn in early 2025, so the Directive above remains the governing EU rule. A later EU proposal has floated moving cookie rules into the GDPR itself, but that is a draft and not law, so you comply with the current framework and watch for change. Note that this page covers the EU. The UK has taken a different path under its own 2025 reform, so a UK site should check the separate UK rules rather than assume the EU position. For the wider set of duties, start at the GDPR compliance hub.

Next step

If you are not sure whether your current banner collects consent the right way, run the free 2-minute Obligation Scan. It checks how your site handles non-essential cookies against the consent standard, so you can fix a banner that looks compliant but is not.

Compliance checklist

  • Audit the cookies and trackers your site sets, and sort them into strictly necessary and non-essential.
  • Block non-essential cookies until the user gives consent (ePrivacy Directive Article 5(3)).
  • Give clear, per-purpose information before asking for consent, and make refusing as easy as accepting.
  • Do not use pre-ticked boxes, and do not treat continued browsing as consent.
  • Store proof of consent and let users withdraw it as easily as they gave it (GDPR Article 7(3)).

Sources

Last verified: 2026-07-17

Informational, not legal advice.