CookieHawkGuides › Cookie consent requirements in the EU and EEA

What is actually required of a cookie consent in the EEA?

The requirement is not about having a banner. It is about having valid consent before your website stores or reads anything on the visitor's device. Here is what that takes, and where most banners actually fail.

Updated 2 September 2026 · 7 minute read

This guide is written to be practically useful, not as legal advice. National implementations differ, so if you are unsure about your specific situation, speak to a lawyer in your jurisdiction.

The main rule

Article 5(3) of the ePrivacy Directive (2002/58/EC) requires information and consent before anyone stores information on, or gains access to information already stored on, a user's terminal equipment. Cookies are the most common example, but the rule is technology-neutral: it also covers local storage in the browser and similar techniques.

Note what the rule attaches to. It concerns storage and access on the device — not whether the data is personal data. A cookie can therefore be covered even if you believe it identifies nobody.

The ePrivacy Directive is a directive, not a regulation. That means each country has implemented it in its own national law, and details such as enforcement and penalties differ. The consent standard itself, however, comes from the GDPR and is the same across the EEA.

The exemptions, and why they are narrower than people think

There are two exemptions from the consent requirement:

The words “sole purpose” and “strictly necessary” are what make the exemptions narrow. A shopping basket that remembers what you put in it is strictly necessary for the shop you asked for. An analytics tool telling you how many people visited is not — however useful it is to you.

The European Data Protection Board has specifically noted that some organisations classify as “essential” or “strictly necessary” things that would not qualify under Article 5(3). In practice, analytics and advertising almost always require consent.

What makes consent valid

The consent standard itself comes from the GDPR, Articles 4(11) and 7. Valid consent must be freely given, specific, informed and unambiguous, and given by a clear affirmative action.

Where banners actually fail

The most common failures are not about the wording in the banner, but about what happens behind it.

1. Tracking loads before the choice

The most common of all. The banner displays neatly, but the measurement tools already sent data as the page loaded. The consent is then practically irrelevant: the processing has already happened.

2. No has no effect

The banner registers the rejection but does not block the scripts. It looks right in the interface and is wrong in the code. Here is how to test it yourself.

3. Rejecting is harder than accepting

“Accept all” as a large coloured button, with rejection hidden behind “Settings” and two more clicks. The consent is then not freely given in practice, even if saying no is formally possible. Both options should be equally available on the first layer.

4. No real way to change your mind

Once a visitor has said yes, they must be able to withdraw it just as easily. A link in the footer or a small always-available icon solves this.

5. The cookie list does not match reality

Many websites have a list of cookies written once and never updated. If a plugin adds a new tracking tool, it appears nowhere. The information is then no longer accurate, and the consent no longer informed.

You must be able to demonstrate consent was given

The GDPR places the burden of demonstrating consent on the controller. If asked, it is not enough to say your website has a banner — you must be able to show that this visitor consented, to what, and when.

In practice that means the choices should be logged: timestamp, what was chosen, and which version of the banner and privacy policy applied at the time. Without that, the consent exists only in the visitor's own browser, and you cannot retrieve it from there.

A practical order of work

  1. Find out what your website actually loads today, before changing anything. Without that baseline you cannot tell whether a change helped.
  2. Sort what you find into necessary, functional, statistics and marketing.
  3. Make sure everything but the necessary is blocked until the visitor says yes.
  4. Give the banner an equivalent no on the first layer, and a way to change one's mind.
  5. Update the cookie list so it describes what is actually set.
  6. Test again, and test after every theme or plugin update.

Common questions

Do I need a cookie banner if I only use Google Analytics?

Yes, as a general rule. Analytics is not strictly necessary to deliver the website the visitor requested, so it falls outside the exemptions and requires consent. That holds even if you have disabled advertising features in Analytics.

Is “by using this site you accept cookies” enough?

No. Consent requires a clear affirmative action. Continuing to use the website, scrolling down or dismissing a notice is not an unambiguous indication of wishes.

Must “Reject all” be as visible as “Accept all”?

The starting point is that consent must be freely given. If declining is noticeably harder than accepting, that undermines the freedom of the choice. A large majority of EEA data protection authorities have taken the view that the absence of a reject option on a layer containing an accept button does not meet the requirements for valid consent.

Does this apply to websites without login or e-commerce?

Yes. The rule attaches to storage and access on the device, not to what kind of website you run. A simple company site with Analytics is covered.

Does the same apply in the UK?

The UK has its own implementation, the Privacy and Electronic Communications Regulations, alongside the UK GDPR. The principles are closely related, but if the UK is your main market you should check the specifics there rather than assume EEA guidance transfers wholesale.

Want to know whether your own setup holds up?

The free check shows what your website does before the visitor has chosen, and what still happens after “Reject all”. It is a technical observation, not a legal assessment — but it gives you the factual basis.

Check your website free

Read next

CookieHawk leveres av Webkompaniet AS · org.nr. 999 529 860 · Oslo · Vilkår · Personvern