Cookie Consent Requirements 2026: GDPR & ePrivacy Compliance Guide
If your website uses cookies — and almost every website does — you probably need to get cookie consent from your visitors. This isn’t just a best practice; it’s a legal requirement under EU law. Yet many website owners are unaware of the full scope of cookie consent requirements under the ePrivacy Directive and GDPR.
Here’s what you need to know to stay compliant in 2026.
Types of Cookies and Their Legal Basis
Not all cookies are treated equally under the law. The key question is whether a cookie is strictly necessary for your website to function. If it isn’t, you need consent.
Strictly Necessary Cookies (No Consent Needed)
These cookies are essential for the basic operation of your website. They include:
- Session cookies that keep a user logged in while navigating pages
- Load-balancing cookies that distribute traffic across servers
- Shopping cart cookies that remember items added to a basket
- Security cookies that protect against fraudulent activity
Because these cookies are required for the service the user has explicitly requested, you don’t need to obtain consent — but you must still disclose them in your cookie policy.
Performance and Analytics Cookies (Consent Needed)
Analytics cookies track how users interact with your website — which pages they visit, how long they stay, and where they come from. While these are useful for improving your site, they are not strictly necessary. You need:
- Prior consent before placing these cookies
- A clear explanation of what data is collected and why
Note: Some analytics providers offer “consent-mode” or privacy-preserving configurations that reduce the consent burden, but you should always verify with your legal advisor.
Functional Cookies (Consent Needed)
These cookies enhance user experience by remembering preferences like language selection, font size, or region. Examples include:
- Language preference cookies that remember the user’s chosen language
- Video player cookies that remember playback position
- UI customization cookies that remember layout preferences
Since the user has not explicitly requested these features, consent is required.
Targeting and Advertising Cookies (Consent Needed)
These cookies create user profiles for targeted advertising and marketing. They are the most heavily regulated category. Consent must be:
- Explicit and informed — users must know exactly how their data is used
- Freely given — no forced acceptance as a condition of accessing your site
- Granular — users should be able to choose which categories they accept
What the ePrivacy Directive Requires
The ePrivacy Directive (2002/58/EC), often called the “Cookie Law,” sets the baseline for cookie regulation in the EU. Its requirements are straightforward but strict:
Prior Consent
You must obtain informed consent before storing or accessing any information on a user’s device, unless the cookie is strictly necessary. This means:
- Consent must be obtained before the cookie is placed
- Consent must be specific to the types of cookies being used
- Pre-ticked checkboxes are not valid consent under GDPR
Clear Information
Users must be told, in clear and plain language, what cookies you use and why. This includes:
- The identity of each cookie or cookie category
- The purpose of each cookie
- The duration — how long the cookie remains on the device
- Whether third parties have access to the cookie data
Opt-In Mechanism
Your cookie banner must give users a meaningful choice to accept or reject cookies. Simply continuing to browse the website does not constitute valid consent.
Right to Withdraw
Users must be able to withdraw their consent at any time, and it must be as easy to withdraw consent as it is to give it. This means:
- A persistent cookie settings link in your website footer
- A simple UI to change preferences
- The ability to reject all cookies with a single click
What GDPR Adds
The General Data Protection Regulation (GDPR) builds on the ePrivacy Directive by adding data protection requirements to the cookie consent framework. Here’s what that means in practice:
Lawful Basis Documentation
You need to document your lawful basis for each data processing activity involving cookies. For non-essential cookies, this is typically consent. For essential cookies, it may be legitimate interests. You must:
- Record when and how consent was obtained
- Maintain logs of consent for compliance audits
- Review and refresh consent at appropriate intervals
Data Processing Records
Under Article 30 of GDPR, you must maintain records of all data processing activities, including those involving cookies. This includes:
- What cookies you deploy and what data they collect
- Why you use each cookie
- Where the data is processed (including third-country transfers)
- How long the data is retained
Privacy Policy Must List Cookies
Your privacy policy must be transparent about your use of cookies. This means:
- A dedicated section listing all cookies by name, purpose, duration, and type
- Clear identification of third-party cookies (e.g., Google Analytics, Facebook Pixel)
- Links to your cookie policy for more granular details
Most regulators expect this information to be at least summarized in your privacy policy, with full details available in the cookie policy.
Cookie Consent Requirements Around the World
Cookie regulation is increasingly global. Here’s how different jurisdictions approach it:
European Union: ePrivacy Directive + GDPR
The strictest framework. Requires prior opt-in consent for all non-essential cookies, with detailed record-keeping and full transparency.
United Kingdom: PECR + UK GDPR
Post-Brexit, the UK maintains its own Privacy and Electronic Communications Regulations (PECR) alongside UK GDPR. The requirements are largely aligned with the EU, with the ICO providing its own guidance on cookie compliance.
California: CCPA (Opt-Out Model)
The CCPA takes a different approach. Instead of opt-in consent, it gives consumers the right to opt out of the “sale” or “sharing” of their personal information. Cookies used for cross-context behavioral advertising fall under this requirement. The CPRA amendments expanded this to include “sharing” of data for cross-context behavioral advertising.
Brazil: LGPD
Brazil’s LGPD (Lei Geral de Proteção de Dados) follows the GDPR’s opt-in consent model. Websites serving Brazilian users must obtain consent before placing non-essential cookies and provide clear information about data processing practices.
Building a Compliant Cookie Banner
Your cookie banner is the first thing users see about your data practices. Getting it right is crucial for compliance and user trust.
What Good Consent Looks Like
A compliant cookie banner should include:
- Granular options — users can accept or reject by category, not all-or-nothing
- A reject-all button — equally visible and accessible as the accept button
- Clear language — no legal jargon, just straightforward explanation
- No pre-ticked boxes — consent must be active, not passive
- A cookie policy link — to a page with full details on each cookie
- A consistent UI — works on mobile, tablet, and desktop
Common Pitfalls to Avoid
- Cookie walls that block access unless users accept cookies
- Implied consent through scroll, navigation, or button click
- Burying the reject button in a sub-menu while accept is prominently displayed
- Changing cookie settings without re-obtaining consent
Cookie Policy vs Privacy Policy
Many website owners confuse these two documents, but they serve distinct purposes:
Cookie Policy
A focused document that should list:
- Each cookie by name, type, and category
- Purpose for each cookie
- Duration (session or persistent) and expiry
- Third-party cookies with links to their privacy policies
- How to manage or withdraw consent
Your cookie policy is the operational companion to your cookie banner. It provides the detailed information users need to make informed decisions.
Privacy Policy
A broader document that covers:
- What personal data your website collects overall
- Legal basis for each type of data processing
- User rights and how to exercise them
- Data retention and security practices
- Third-party sharing beyond cookies (e.g., payment processors, email services)
The cookie policy lives within or alongside the privacy policy. For best compliance, link to your cookie policy from your privacy policy’s cookie section.
How PrivacyPolGen Can Help
Navigating GDPR cookie consent requirements can feel overwhelming, but you don’t have to do it alone. PrivacyPolGen helps you create both a comprehensive cookie policy and a fully compliant privacy policy in minutes.
Generate your cookie policy: Answer a few questions about the cookies your website uses, and our cookie policy generator will create a customized document listing each cookie by type, purpose, and duration — ready to comply with the ePrivacy Directive and GDPR.
Generate your privacy policy: Your privacy policy generator creates a complete policy that covers lawful basis, data subject rights, third-party disclosures, and cookie-related data practices — all tailored to your business.
Both policies work together seamlessly, ensuring your website meets cookie consent requirements across jurisdictions while maintaining clear, user-friendly language.
Ready to get compliant? Generate your free cookie policy →
Related articles
Best Free Privacy Policy Generators Compared 2026: Honest, Evidence-Based Review
We compared 7 privacy policy generators — PrivacyPolGen, Termly, TermsFeed, PrivacyPolicies.com, FreePrivacyPolicy and more — on free-tier reality, signup, export formats, languages, and quality. See the table.
GDPR Privacy Policy Template: Free Guide + Generator Tips
Complete GDPR privacy policy template with generator tips. Learn how to create compliant policies that protect users while being user-friendly.
GDPR vs CCPA: Key Differences Every Website Owner Should Know
Understand the key differences between GDPR and CCPA — scope, user rights, penalties, and compliance requirements for your website or business.
On this page
- Types of Cookies and Their Legal Basis
- Strictly Necessary Cookies (No Consent Needed)
- Performance and Analytics Cookies (Consent Needed)
- Functional Cookies (Consent Needed)
- Targeting and Advertising Cookies (Consent Needed)
- What the ePrivacy Directive Requires
- Prior Consent
- Clear Information
- Opt-In Mechanism
- Right to Withdraw
- What GDPR Adds
- Lawful Basis Documentation
- Data Processing Records
- Privacy Policy Must List Cookies
- Cookie Consent Requirements Around the World
- European Union: ePrivacy Directive + GDPR
- United Kingdom: PECR + UK GDPR
- California: CCPA (Opt-Out Model)
- Brazil: LGPD
- Building a Compliant Cookie Banner
- What Good Consent Looks Like
- Common Pitfalls to Avoid
- Cookie Policy vs Privacy Policy
- Cookie Policy
- Privacy Policy
- How PrivacyPolGen Can Help