Skip to content
CookieTosser

What counts as valid cookie consent in the EU

Published September 27, 2026

This is a plain-language explanation of publicly available rules and rulings, not legal advice. Cookie law is implemented country by country and enforced by national regulators, so specifics vary across the EU and change over time. If a real compliance decision rides on this, check current guidance from the relevant regulator or a lawyer.

Cookie banners are everywhere, but most people have never seen the rule they're supposed to satisfy. It isn't the GDPR, exactly — it's an older, narrower law that the GDPR later gave teeth to.

The actual rule: ePrivacy Directive, Article 5(3)

The requirement to ask before setting cookies comes from the ePrivacy Directive (2002/58/EC), as amended in 2009 (2009/136/EC) — the amendment people nicknamed the "cookie law" at the time. Article 5(3) says that storing information on a user's device, or accessing information already stored there, requires that the user has given consent, after being provided with clear and comprehensive information. This covers essentially any cookie, local storage entry, or similar identifier — not just ones that carry personal data.

There's a built-in exemption: consent isn't required for storage or access that is strictly necessary to provide a service the user explicitly requested. The classic examples are a shopping-cart cookie, a load-balancing cookie, or a security cookie that detects fraudulent login attempts. Analytics cookies are generally treated as falling outside this exemption by most EU regulators, because measuring traffic is useful to the site, not something the visitor asked for — though the exact line is one of the more contested parts of the rule, and a few regulators have floated narrow carve-outs for privacy-preserving, first-party analytics used only in aggregate. Advertising and social-media cookies are not treated as necessary by any regulator's guidance.

Because a directive doesn't apply directly — each EU member state has to transpose it into national law — the fine print differs by country. Germany's implementation is the Telecommunications Digital Services Data Protection Act (TDDDG; it took effect in December 2021 as the TTDSG and was renamed in May 2024); other member states have their own statutes and their own data protection authority interpreting them. The direction is consistent across the EU; the details and enforcement style are not identical.

Why the GDPR matters here too

The ePrivacy Directive says consent is required, but it doesn't fully define what "consent" means — for that, EU regulators and courts point to the GDPR (Regulation (EU) 2016/679), wherever the cookie in question involves personal data (which, given IP addresses and device identifiers, is most of them in practice). GDPR Article 4(11) defines consent as freely given, specific, informed and unambiguous, indicated by a clear affirmative act. Article 7(3) adds that withdrawing consent must be as easy as giving it.

That last point is doing a lot of work in current enforcement. A banner with a one-click "Accept all" button and a "Reject" option buried three menus deep, in a different color, or worded to sound like a loss ("Continue with limited experience") does not satisfy this standard in the view of most EU data protection authorities, including France's CNIL, which has been explicit that accepting and rejecting must take the same number of clicks. The EU-wide Cookie Banner Taskforce, convened by the European Data Protection Board after a wave of coordinated complaints, reported similar findings across member states in 2023: pre-selected toggles, missing reject buttons, and "cookie walls" that block the page entirely unless you accept were the most common problems it found.

Planet49: no pre-ticked boxes

The clearest binding precedent is the Court of Justice of the European Union's ruling in Planet49 (Case C-673/17, decided 1 October 2019). A German company running an online promotional lottery had a pre-ticked checkbox consenting to cookies for advertising purposes, which users had to actively un-tick to opt out. The CJEU held that this does not amount to valid consent under EU law: consent requires active, unambiguous behavior from the user — checking a box yourself, not un-checking one someone else checked for you. The same judgment confirmed that Article 5(3)'s "clear and comprehensive information" duty includes telling the user how long the cookie will last and whether third parties can access it — not just that cookies exist.

Planet49 is why "implied consent" banners — a bar that says "By continuing to browse, you agree to cookies" with no actual choice — dropped out of use across the EU after 2019. They hadn't matched the standard even before the ruling, but the judgment removed any doubt.

What this means in practice

Put together, current EU guidance points to a consistent checklist for a compliant banner, even though no single document lists it exactly this way:

  • Nothing except strictly necessary cookies loads before a choice is made.
  • Accepting requires an affirmative action — no pre-ticked boxes, no "continuing to browse."
  • Rejecting is offered with the same prominence and the same number of clicks as accepting.
  • The banner says, in plain terms, what categories of cookies are involved and (per Planet49) roughly how long they last.
  • Consent can be withdrawn later at least as easily as it was given.

None of this tells you whether a specific site you're looking at is compliant — that depends on facts a scan alone can't fully establish, like where the visitor is, what they clicked, and how a regulator in that country currently reads the rule. What a scan like this site's can show is a narrower, factual thing: what loaded on a fresh visit, before any interaction with the banner at all. If that includes third-party advertising or analytics cookies, per the rule above, that's the specific problem Article 5(3) exists to prevent — see how to check what a site loads yourself, or look up a site's report to see what our monthly scan from Germany found. For what a consent banner is actually supposed to do under the hood, see how consent management platforms work; for the site-owner side of fixing it, see how to stop loading trackers before consent.

Related guides