Mahope tools: EUComply Clean Copy DeskUptime Transmute BugBottle All tools
FREE PREVIEW · E-BOOK

Cookie Consent & Privacy Compliance for Small Websites

What the Law Actually Requires, How to Audit Your Site, and Building a Compliant Consent Banner

Cookie Consent & Privacy Compliance for Small Websites — book cover

About the book, chapter list and the free EPUB download →

Chapter 1: What the Law Actually Requires

Three pieces of EU law govern cookies and privacy on websites:

GDPR (General Data Protection Regulation)

The GDPR — Regulation (EU) 2016/679 — applies whenever you collect or process personal data from EU residents. Personal data includes IP addresses, which means virtually every website tracking visitor behaviour is affected.

What you need: A lawful basis for processing personal data. For most cookie-related processing, consent is the appropriate basis.

ePrivacy Directive (Cookie Law)

The ePrivacy Directive — Directive 2002/58/EC, amended in 2009 — is the specific law that requires cookie consent. Article 5(3) states that storing or accessing information on a user's device requires their consent, unless it's strictly necessary for the service.

What you need: Active, informed consent before non-essential cookies are set. A "by continuing to use this site you accept cookies" banner is not compliant.

The interplay

The GDPR sets the general data protection framework. The ePrivacy Directive sets the specific rules for electronic communications. Both must be satisfied. In practice: you need GDPR-compliant consent (freely given, specific, informed, unambiguous) for ePrivacy-covered tracking.

National implementations

EU directives are implemented at the member state level, which means minor differences apply:

  • Denmark: Cookie Executive Order — first cookie must be declined on landing, explicit consent before analytics
  • Germany: TTDSG — strict "only strictly necessary without consent" approach
  • France: RGPD + CNIL guidelines — heavily enforced; CNIL actively fines non-compliant sites
  • Netherlands: Telecommunicatiewet — similar to Danish approach; consent before analytics
  • UK (post-Brexit): PECR (UK) — similar to ePrivacy, enforced by ICO

That was the beginning

The complete book continues with eight chapters and two appendices: how to audit your site for cookies and tracking, building a compliant consent banner, consent record-keeping, privacy policy structure under Articles 13–14, and analytics without consent violations.

Download the full EPUB — free

Auditing a site for cookies and trackers by hand takes an afternoon. EUComply Pro runs the scan and writes the report — useful when you do it for a client, $79 per website per year.

No account, no email, no payment. See all six free e-books.