Chapter 1: What the Law Actually Requires
Three pieces of EU law govern cookies and privacy on websites:
GDPR (General Data Protection Regulation)
The GDPR — Regulation (EU) 2016/679 — applies whenever you collect or process personal data from EU residents. Personal data includes IP addresses, which means virtually every website tracking visitor behaviour is affected.
What you need: A lawful basis for processing personal data. For most cookie-related processing, consent is the appropriate basis.
ePrivacy Directive (Cookie Law)
The ePrivacy Directive — Directive 2002/58/EC, amended in 2009 — is the specific law that requires cookie consent. Article 5(3) states that storing or accessing information on a user's device requires their consent, unless it's strictly necessary for the service.
What you need: Active, informed consent before non-essential cookies are set. A "by continuing to use this site you accept cookies" banner is not compliant.
The interplay
The GDPR sets the general data protection framework. The ePrivacy Directive sets the specific rules for electronic communications. Both must be satisfied. In practice: you need GDPR-compliant consent (freely given, specific, informed, unambiguous) for ePrivacy-covered tracking.
National implementations
EU directives are implemented at the member state level, which means minor differences apply:
- Denmark: Cookie Executive Order — first cookie must be declined on landing, explicit consent before analytics
- Germany: TTDSG — strict "only strictly necessary without consent" approach
- France: RGPD + CNIL guidelines — heavily enforced; CNIL actively fines non-compliant sites
- Netherlands: Telecommunicatiewet — similar to Danish approach; consent before analytics
- UK (post-Brexit): PECR (UK) — similar to ePrivacy, enforced by ICO