
Short answer: GDPR cookie consent is valid when a visitor gives a freely given, specific, informed and unambiguous opt-in before any non-essential cookie or tracker loads. The ePrivacy Directive requires the consent; the GDPR defines its standard. That means no pre-ticked boxes, no consent by scrolling, a reject option as easy as accept, and withdrawal at any time.
Related guides:
- How to make your website GDPR compliant in 8 steps
- Free cookie policy template
- 7 GDPR compliance tools that automate the hard work for you
Key takeaways
- The consent requirement for cookies comes from Article 5(3) of the ePrivacy Directive, not the GDPR. The GDPR supplies the definition of what valid consent looks like.
- It covers any storage of or access to information on a user's device, including local storage, SDKs and tracking pixels, whether or not the data is personal data.
- At EU level, only strictly necessary cookies (and those used purely to transmit a communication) are exempt. Analytics and advertising cookies generally need consent.
- Regulators expect a reject option on the first layer of the banner, no pre-ticked boxes, no deceptive button design, and withdrawal that is as easy as giving consent.
- For HealthTech, third-party pixels on patient-facing pages can create both EU consent problems and, for US HIPAA entities, PHI disclosure problems.
Which law actually requires cookie consent?
The ePrivacy Directive creates the cookie consent rule, and the GDPR sets the standard that consent must meet.
Article 5(3) of Directive 2002/58/EC, as amended by Directive 2009/136/EC, says storing information, or gaining access to information already stored, on a user's terminal equipment is only allowed if the user "has given his or her consent, having been provided with clear and comprehensive information" about the purposes. Each member state implements it in national law, so wording and enforcement vary.
The GDPR then defines consent. Article 4(11) of the GDPR requires "any freely given, specific, informed and unambiguous indication" of the user's wishes, given "by a statement or by a clear affirmative action". Article 7 adds that you must be able to demonstrate consent and that withdrawing it must be as easy as giving it.
- The rule is about the device, not the data. The Court of Justice confirmed in Planet49 (C-673/17), decided on 1 October 2019, that the consent requirement applies whether or not the information stored or accessed is personal data.
- It is not limited to cookies. The EDPB Guidelines 2/2023 on the technical scope of Article 5(3) (version 2, adopted 7 October 2024) explain how tracking pixels, URL-based tracking, local storage and similar techniques can fall in scope.
You also cannot fall back on legitimate interests for non-essential cookies. The EDPB Cookie Banner Taskforce report, published in January 2023, records that supervisory authorities agreed legitimate interest cannot be the legal basis for placing or reading cookies that need consent.
What makes cookie consent valid?
Valid cookie consent is an active, informed, granular opt-in collected before the cookie is set, with a real option to say no.
| GDPR element | What it means for a cookie banner | Primary source |
|---|---|---|
| Freely given | Refusing must not block access to the site. A "cookie wall" that shows content only after "Accept" fails. | EDPB Guidelines 05/2020 on consent |
| Specific | Separate choices per purpose, such as analytics and advertising, not one bundled "Accept". | GDPR Art. 4(11) |
| Informed | Explain purposes, who sets the cookies (including third parties) and how long they last. | Planet49 press release |
| Unambiguous | A clear click. Pre-ticked boxes, silence and inactivity do not count (GDPR Recital 32). | GDPR Recital 32 |
| Demonstrable | You can prove who consented, when, and to what. | GDPR Art. 7(1) |
| Withdrawable | Withdrawal is as easy as giving consent. | GDPR Art. 7(3) |
Three points catch many SaaS teams out, per the EDPB Guidelines 05/2020 on consent (version 1.1, adopted 4 May 2020):
- Scrolling is not consent. The EDPB says scrolling or swiping through a page will not under any circumstances satisfy the requirement for a clear affirmative action.
- Cookie walls are not freely given consent. The guidelines use the example of a site where the only way to see content is to click "Accept cookies".
- Pre-ticked boxes fail. Planet49 dealt with exactly this: a checkbox ticked by default, which the user had to untick to refuse, is not valid consent.
Which cookies are exempt from consent?
At EU level, only cookies used solely to transmit a communication, or that are strictly necessary to provide a service the user explicitly asked for, are exempt.
Both exemptions come from the second sentence of Article 5(3). Typical examples are login session cookies, cart or form state, load balancing and the cookie storing the user's consent choice.
Watch the classification. The Cookie Banner Taskforce report flags "essential" labels that do not hold up, and notes that website owners must be able to show regulators why a cookie is strictly necessary.
What about analytics cookies? The EU-level text has no general analytics exemption, so analytics cookies normally need consent. Some national regulators carve out narrow exceptions. France's CNIL, for example, allows audience measurement trackers without consent only under strict conditions such as a single-publisher purpose, no cross-referencing with other processing, truncated IP addresses and a 13-month tracker lifetime, and notes that most large analytics offerings do not qualify. Check local rules before relying on one.
A brief note on the UK. The UK applies PECR rather than the ePrivacy Directive. Section 112 of the Data (Use and Access) Act 2025, in force in full from 5 February 2026 under S.I. 2026/82, replaced PECR regulation 6. As of October 2026, the ICO's guidance on exceptions lists new exceptions, including statistical purposes and adapting a service's appearance or functionality, which only apply if you give clear and comprehensive information and a simple, free means to object. These are UK rules; they do not relax consent for EU visitors.
Cookie banner requirements EU: a design checklist
A compliant banner gives a real, equally easy choice before anything non-essential loads, and keeps that choice available afterwards.
The checklist below draws on the EDPB Cookie Banner Taskforce report, which reflects a common denominator agreed by EU supervisory authorities rather than a binding standard. National regulators can and do go further.
- Nothing non-essential fires before a choice. Tag managers, pixels and SDKs are blocked until the user opts in.
- Reject on the first layer. A vast majority of authorities in the taskforce considered a missing reject or refuse option on the first layer a breach.
- No deceptive link design. "Reject" is not hidden as a text link inside a paragraph or placed outside the banner.
- No deceptive colours or contrast. Accept and Reject are equally readable; low-contrast reject text is a red flag in the report.
- No pre-ticked purpose toggles in the second layer.
- Granular purposes. Analytics, advertising and personalisation can be accepted or refused separately.
- Plain-language information on purposes, third parties and cookie duration, with a link to your cookie policy.
- No cookie wall for general access to content.
- Persistent way to change your mind, such as a footer link or floating icon on every page.
- Choice actually enforced. Rejecting must stop tags, not just hide the banner.
- No "legitimate interest" toggles for cookies that need consent.
How do you record consent and handle withdrawal?
Keep a timestamped record of each consent decision and the exact banner version shown, and let users withdraw through the same interface in one step.
Article 7(1) puts the burden of proof on you. The EDPB consent guidelines suggest keeping a record of consent statements received, when consent was obtained and the information provided at the time. A practical consent log captures:
- A pseudonymous consent ID (not a name or email).
- Timestamp and the purposes accepted or refused.
- Banner and cookie policy version shown.
- How the choice was made (first-layer button, settings panel).
- Any later change or withdrawal.
On withdrawal, the EDPB states a user must be able to withdraw consent via the same electronic interface used to give it. If consent took one click, withdrawal should too. After withdrawal, stop the related tags and, where feasible, delete the cookies you set. The GDPR sets no fixed expiry for consent but the EDPB recommends refreshing it at appropriate intervals as good practice.
How do you run a cookie audit?
Scan every page template and user journey, list each cookie and tracker, assign a purpose and owner, and confirm what loads before and after consent.
Use a clean browser profile, then repeat after rejecting and after accepting. Include logged-in areas, sign-up flows and landing pages, which often carry extra pixels. Example audit table:
| Cookie / tracker | Set by | Purpose | Category | Duration | Consent needed (EU)? | Loads before consent? | Owner |
|---|---|---|---|---|---|---|---|
session_id |
First party | Keeps user logged in | Strictly necessary | Session | No | Yes (allowed) | Engineering |
consent_state |
First party | Stores banner choice | Strictly necessary | 6 months | No | Yes (allowed) | Engineering |
| Product analytics cookie | First party script | Usage statistics | Analytics | 13 months | Usually yes | Must be No | Product |
| Ad platform pixel | Third party | Conversion tracking, retargeting | Advertising | 90 days | Yes | Must be No | Marketing |
| Embedded video player | Third party | Video playback, viewing stats | Functional / advertising | Varies | Usually yes | Must be No | Marketing |
Rows are illustrative; replace them with your scan results. Re-run the audit whenever a new tool is added and keep the results as evidence. The cookie policy template is a good place to publish the final list.
Why are tracking pixels riskier on patient-facing sites?
On HealthTech sites, a pixel does not just need consent: the data it sends can reveal health information, which raises the stakes under both EU and US rules.
In the EU, a pixel on a symptom checker or booking page may reveal health conditions. That is special category data, which brings stricter GDPR conditions on top of ePrivacy consent. In our experience, many HealthTech teams keep advertising pixels off clinical, booking and logged-in pages entirely.
In the US, HHS OCR's guidance on use of online tracking technologies by HIPAA covered entities and business associates still applies, with one important change. As the page itself notes, on 20 June 2024 the U.S. District Court for the Northern District of Texas declared unlawful and vacated the portion stating that HIPAA obligations are triggered when tracking connects an IP address with a visit to an unauthenticated public page addressing health topics. As of October 2026, the remaining guidance says trackers on user-authenticated pages generally have access to PHI, and that regulated entities need a business associate agreement with a tracking vendor that meets the business associate definition, or must use a different vendor or approach. This is a HIPAA point for US regulated entities, not an EU consent rule.
How SecureSlate helps
SecureSlate lets SMB and HealthTech teams run GDPR alongside SOC 2, ISO 27001 and HIPAA. GDPR is a built-in framework with multi-framework control mapping. ePrivacy-specific requirements and your internal consent standard can be set up as a custom framework with custom controls.
Use vendor risk management to review analytics, advertising and pixel vendors before they reach your site, risk management to track high-risk trackers on patient-facing pages, and audit management to store cookie audit results and consent log samples as evidence. Security questionnaire automation helps answer the tracking questions that appear in healthcare procurement.
Start your free SecureSlate trial
FAQ
Is cookie consent required by the GDPR or the ePrivacy Directive?
The requirement to get consent before storing or reading cookies comes from Article 5(3) of the ePrivacy Directive, implemented in each EU member state's national law. The GDPR defines what counts as valid consent and governs any personal data you process using those cookies.
Do I need consent for Google Analytics or other analytics cookies?
In most EU countries, yes. There is no general EU-level analytics exemption. A few regulators, such as France's CNIL, allow narrowly configured audience measurement without consent, but most mainstream analytics setups do not meet those conditions.
Does a cookie banner need a "Reject all" button?
EU regulators expect refusing to be as easy as accepting. In the EDPB Cookie Banner Taskforce report, a vast majority of authorities considered a banner with no reject option on the first layer to breach consent requirements.
How long should I keep cookie consent records?
The GDPR sets no fixed retention period. Keep records long enough to demonstrate consent for as long as you rely on it, plus a reasonable period for handling complaints or regulator inquiries, and document that retention decision.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds