Cookie Consent Laws by Country: Complete Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 48 primary sources cited on this page. How we verify our legal content

Cookie consent law follows three models worldwide: the EU's opt-in standard under the ePrivacy Directive, the US opt-out approach built on state privacy statutes, and a notice-only model used in countries such as Australia. Applying EU-standard opt-in consent to all visitors is the strictest single posture, but it does not by itself discharge US state obligations such as the opt-out link and the universal opt-out signal.
Cookie consent requirements differ across virtually every major jurisdiction. A website accessible worldwide faces a patchwork of laws ranging from the EU's strict opt-in regime to countries with no cookie-specific rules at all. Enforcement actions and fines have reached hundreds of millions of euros in the EU alone, and the regulatory landscape shifted significantly in 2024-2026 with a wave of new laws and enforcement decisions.
This guide surveys cookie consent rules across more than 30 countries and regions, with particular focus on what changed in 2024-2026 and what to expect next.
Quick Answer: How Cookie Consent Varies by Country
Cookie consent law does not work the same way everywhere. Three distinct models exist:
Opt-in model: Cookies cannot be placed until the user actively agrees. The EU, UK, South Korea, and a growing number of countries in Asia and Africa use this approach.
Opt-out model: Cookies are permitted by default; users must take action to stop them. This is the dominant US state-law model, where the focus is on honoring opt-out signals like the Global Privacy Control rather than requiring upfront consent.
Notice-only model: Organizations must inform users that cookies are used (typically in a privacy policy), but no consent banner is required. Australia has operated under this model, though recent reforms tighten the rules.
The practical implication for global websites: applying EU-standard opt-in consent to all visitors is the safest single consent posture, because it is the strictest. It is not a complete compliance answer. US state law requires an opt-out link and recognition of universal opt-out signals whatever the banner does, Quebec requires profiling functions to be off by default with specific disclosures, and Washington requires separate consents for consumer health data.
Why Cookie Consent Varies by Country
The variation reflects fundamentally different legal traditions and policy priorities. The EU treats privacy as a fundamental right and has historically regulated technology proactively. The United States has historically favored a sectoral and market-based approach, relying on state legislatures and the FTC rather than a comprehensive federal data protection law. Developing economies have often adopted modern data protection frameworks modeled on the EU (or in some cases the APEC Privacy Framework) but with different enforcement capacity and timelines.
The technology also matters. Cookie consent rules generally trace their origins to the EU's ePrivacy Directive, which was a response to specific concerns about tracking in the early 2000s. Countries that adopted data protection frameworks later, such as Brazil, India, and Thailand, typically address cookies through broader personal data processing rules rather than cookie-specific legislation.
The EU/EEA: The Global Standard-Setter
The EU's cookie framework rests on two instruments: the ePrivacy Directive (Directive 2002/58/EC as amended by 2009/136/EC) and the GDPR (Regulation 2016/679). Together they create the world's most demanding cookie consent regime.
How the EU Framework Works
Article 5(3) of the ePrivacy Directive requires prior, informed consent before any non-essential cookie is placed on a user's device. The GDPR's consent standard requires that consent be freely given, specific, informed, and demonstrated through an unambiguous affirmative action.
Pre-ticked checkboxes are illegal following the CJEU's Planet49 ruling (Case C-673/17). Scrolling or continued browsing does not constitute consent. Rejection must be as easy as acceptance, a principle that led to major fines.
Strictly necessary cookies are exempt from consent. These include cookies essential for the service the user explicitly requested, such as session cookies for a shopping cart or security tokens.
The ePrivacy Regulation: Withdrawn February 2025
For years, the EU had been trying to replace the ePrivacy Directive with a new Regulation. The proposed ePrivacy Regulation, introduced in 2017, promised to harmonize rules across member states and address gaps in the Directive.
In February 2025, the European Commission's 2025 Work Programme, published on February 11, 2025, formally withdrew the proposal at item 29 of its Annex IV list of withdrawals. The Commission stated that "no agreement is expected from the colegislators" and that the proposal was "outdated in view of some recent legislation in both the technological and the legislative landscape." The current ePrivacy Directive and its national implementations remain the applicable law.
The Digital Omnibus Proposal: New Cookie Rules on the Horizon
On November 19, 2025, the European Commission proposed the Digital Omnibus package, a broad legislative initiative that would fundamentally reshape how cookie rules work in the EU.
Key proposed changes relevant to cookies:
- The ePrivacy Directive would no longer govern personal data processing. The GDPR alone would apply to cookies that collect personal data, unifying the legal framework.
- New exemptions would be created for security cookies, first-party analytics cookies, and cookies necessary to deliver a user-requested service. These would not require a consent banner.
- Repeated consent requests for the same purpose would be prohibited within a six-month window.
- Businesses would be required to respect machine-readable consent signals (such as browser-level preferences).
These changes would address a long-standing complaint about cookie banner fatigue. However, the Digital Omnibus is still in legislative review, and it has slipped. The Council's negotiating-mandate vote scheduled for June 26, 2026 was cancelled when agreement could not be reached on open issues. In Parliament the co-rapporteurs published a draft report on June 22, 2026, LIBE and ITRE discussed it jointly on July 13, 2026, and more than 1,750 amendments were tabled by the July 15, 2026 deadline. Nothing in the package is law, and adoption during 2026 now looks unlikely.
EU Enforcement Highlights
Each of the EU's 27 member states enforces cookie rules through its national data protection authority (DPA). Several stand out for enforcement intensity.
France (CNIL): On September 1, 2025 the CNIL's restricted committee fined GOOGLE 325 million euros and SHEIN 150 million euros under Article 82 of the French Data Protection Act for placing advertising cookies without valid consent and for defective refusal and withdrawal mechanisms. The decisions were published on September 3, 2025. Part of the GOOGLE penalty rests on a separate finding under Article L. 34-5 of the Postal and Electronic Communications Code, for advertisements displayed as emails in the Gmail Promotions and Social tabs without prior consent, rather than on cookies alone.
The CNIL had already fined Google 150 million euros and Facebook 60 million euros in December 2021 for making cookie rejection too difficult. It requires a visible reject button on the first-layer banner and allows limited first-party analytics exemptions.
Italy (Garante): Issued updated cookie guidelines in 2021 requiring a visible reject button on the initial banner and a separate cookie policy distinct from the general privacy notice.
Germany (Laender DPAs): Section 25 of the TDDDG is the operative German cookie rule. It requires consent on the basis of clear and comprehensive information, with only the narrow exemptions in section 25(2) for transmission and for a service the user explicitly requested. The Federal Court of Justice applied the Planet49 standard in its judgment of May 28, 2020 (I ZR 7/16), following the CJEU's ruling of October 1, 2019.
Supervision is not shared evenly. Under section 29(2) TDDDG the federal BfDI is the competent authority for section 25 only where the storage or access is carried out by telecommunications service providers or federal public bodies. Ordinary commercial websites answer to the 16 Laender data protection authorities. Germany has also built a statutory answer to banner fatigue: section 26 TDDDG and the Einwilligungsverwaltungsverordnung establish recognised consent-management services.
Spain (AEPD): Enforces cookie compliance under the LSSI (Ley 34/2002) alongside GDPR. A cookie breach of article 22.2 is a minor infringement under article 38.4(g), carrying a fine of up to 30,000 euros under article 39.1(c). A repeat within three years becomes a serious infringement under article 38.3(i), in the band of 30,001 to 150,000 euros. GDPR-level fines apply separately where personal data processing is involved.
Belgium (APD): Issued a landmark 2022 decision against IAB Europe's Transparency and Consent Framework, finding the TCF itself violated the GDPR.

EDPB Cookie Banner Taskforce
The European Data Protection Board (EDPB) established a Cookie Banner Taskforce in 2021 to coordinate enforcement across DPAs. Its report, adopted on January 17, 2023, records what the authorities agreed among themselves while handling the NOYB banner complaints: a reject button must be as reachable as the accept button; designs that steer users through confusing colors, misleading wording or pre-selected acceptance are not acceptable; and users must be able to withdraw consent as easily as they gave it.
The report is expressly not binding. Its own disclaimer says these positions "do not constitute stand-alone recommendations or findings to obtain a greenlight from a competent authority" and "do not prejudge the analysis that will have to be made by the authorities of each complaint and each website concerned." It also records that where a complaint concerns the placement or reading of cookies, the applicable framework is only the national law transposing the ePrivacy Directive, with the GDPR governing the processing that follows.
Enforcement itself comes from the national authorities. The CNIL's September 2025 sanctions against GOOGLE (325 million euros) and SHEIN (150 million euros) under Article 82 of the French Data Protection Act show the scale those national decisions now reach.
The UK: PECR and the DUAA 2025 Changes
The UK's cookie rules derive from the Privacy and Electronic Communications Regulations 2003 (PECR), which mirror the EU's ePrivacy framework. Post-Brexit, PECR operates independently alongside UK GDPR, enforced by the Information Commissioner's Office (ICO).
What PECR Requires
Regulation 6 of PECR requires prior consent before placing cookies or similar technologies. Consent must be informed, specific, and involve a clear affirmative action. Strictly necessary cookies are exempt. The consent standard aligns with UK GDPR.
Data (Use and Access) Act 2025: A Significant Shift
The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on June 19, 2025. Key PECR-related provisions came into force on February 5, 2026. The DUAA made two material changes to cookie rules:
New conditional exemptions: The DUAA inserted a new Schedule A1 into PECR, in force from February 5, 2026. Two of its paragraphs matter for most websites, and neither is a free pass.
Paragraph 5 covers statistics. It applies only where the sole purpose is collecting information about how the service or website is used with a view to making improvements, the information is not shared with anyone except a person helping to make those improvements, the user is given clear and comprehensive information about the purpose, and the user is given a simple means of objecting, free of charge, and does not object. Paragraph 5(2) also puts information the device emits automatically outside the exemption.
Paragraph 6 covers cookies whose sole purpose is adapting or enhancing how the site appears or functions, such as a language or theme choice. It carries the same two conditions: clear and comprehensive information, plus a simple and free means of objecting.
So these are opt-out categories, not consent-free ones. A site that drops its analytics banner without providing an objection mechanism, or that sends the data to a third party for anything beyond improving that site, is outside the exemption and back under regulation 6. Strictly necessary cookies remain separately exempt. Advertising cookies, targeting, frequency capping, and ad measurement still require consent.
Significantly higher fines: The maximum PECR penalty rose to UK GDPR levels: up to £17.5 million or 4% of global annual turnover, whichever is higher. Previously the PECR maximum was £500,000. This aligns PECR enforcement power with UK GDPR and signals that ICO enforcement is likely to intensify.

The United States: State-Law Patchwork
The United States has no federal law requiring cookie consent banners. Cookie-related obligations arise from a growing set of state privacy statutes focused on opt-out rights, online tracking, and targeted advertising. See our detailed state-by-state US guide for specifics.
The Core Model: Opt-Out, Not Opt-In
The general US model is opt-out: cookies are permitted unless a user signals otherwise, and no state requires an EU-style banner covering all cookies. But opt-in consent is required in defined situations, and trackers routinely land inside them.
Washington's My Health My Data Act, RCW 19.373.030(1)(a), has since March 31, 2024 barred a regulated entity from collecting any consumer health data without consent for a specified purpose, unless the collection is necessary to provide something the consumer requested. That reaches pixels and trackers on health-related pages, and the Act is backed by a private right of action.
Connecticut requires consent before sensitive data is processed at all (Conn. Gen. Stat. section 42-520(a)(4)), and before personal data is used for targeted advertising or sold where the controller knows, or wilfully disregards, that the consumer is at least 13 and under 16 (section 42-520(a)(7)). Most of the newer state acts carry equivalent sensitive-data and known-minor consent rules.
Outside those situations, the primary mechanisms are:
"Do Not Sell or Share" links: California's CCPA/CPRA requires a link allowing consumers to opt out of the sale or sharing of personal information, including advertising cookies.
Global Privacy Control (GPC): A browser-level signal that communicates opt-out preferences. Businesses subject to California's CCPA/CPRA must honor GPC as a valid opt-out request.
States Requiring GPC Compliance (current as of September 10, 2026)
Twelve states now require businesses to act on an opt-out sent from the browser, and the list grows as further state privacy acts phase in. The test used here is practical rather than verbal: a statute is counted if it obliges a controller to honor an opt-out that a browser setting or extension sends, whatever the statute calls that signal.
- California: Requires honoring GPC under CCPA/CPRA; the California Privacy Protection Agency announced a joint investigative sweep into businesses that were not honoring GPC opt-outs on September 9, 2025, alongside the Attorneys General of California, Colorado and Connecticut.
- Colorado: The Colorado AG has designated GPC as an acceptable universal opt-out mechanism.
- Connecticut: As of January 1, 2025, businesses must honor universal opt-out signals under the Connecticut Data Privacy Act.
- Montana: Mont. Code Ann. section 30-14-2809(3)(b) has required controllers to accept an opt-out sent through an opt-out preference signal since January 1, 2025.
- Texas: Tex. Bus. and Com. Code section 541.055(e) lets a consumer designate an authorized agent through an internet browser setting or extension or a global device setting, and the controller must comply where it can verify the consumer's identity and the agent's authority with commercially reasonable effort.
- Maryland: The Maryland Online Data Privacy Act (MODPA), effective October 1, 2025, requires honoring opt-out signals.
- New Jersey: Businesses have had to respect GPC since July 15, 2025 under the New Jersey Data Privacy Law.
- New Hampshire: RSA 507-H:6, V(a)(1)(B) has required controllers to accept an opt-out preference signal since January 1, 2025.
- Oregon: Under the Oregon Consumer Privacy Act, businesses have had to honor qualifying opt-out signals since January 1, 2026.
- Delaware: 6 Del. C. section 12D-106(e)(1)a.2 has required recognition of an opt-out preference signal since January 1, 2026.
- Minnesota: The Minnesota Consumer Data Privacy Act, Minn. Stat. section 325M.14, requires controllers to honor an opt-out preference signal.
- Nebraska: Neb. Rev. Stat. section 87-1111(5) carries the same authorized-agent wording as Texas, so a browser setting or extension can carry the opt-out and the controller must honor it on the same verification terms.
Nebraska and Texas are counted here even though neither statute uses the phrase "opt-out preference signal": both require a controller to act on an opt-out that reaches it from a browser setting or extension acting as the consumer's authorized agent. Neither obligation is unconditional. Both let a controller decline where it cannot verify, with commercially reasonable effort, the consumer's identity, the agent's authority, or that the consumer is a resident of the state.
Federal Picture
Congress has repeatedly introduced comprehensive federal privacy bills but none have passed. The FTC exercises limited authority over deceptive cookie practices under Section 5 of the FTC Act.
Canada: PIPEDA and Stalled Reform
Canada regulates cookies through the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL). The Office of the Privacy Commissioner (OPC) provides enforcement and guidance.
Under PIPEDA, organizations must obtain meaningful consent for collecting or using personal information. The OPC interprets analytics and advertising cookies that track identifiable behavior as requiring express consent. Cookies collecting non-identifiable information may rely on implied consent.
The OPC cannot fine anyone for a consent failure. PIPEDA section 28 creates offences only for a closed list of acts, such as destroying requested records or obstructing the Commissioner, punishable by a fine of up to CAD 10,000 on summary conviction and CAD 100,000 on indictment, and those are prosecutions rather than OPC penalties. CASL is the statute with monetary teeth: section 20(4) sets a maximum penalty of CAD 1 million for an individual and CAD 10 million for any other person, and it is enforced by the CRTC.
Quebec is the one Canadian jurisdiction with an express tracking-technology rule. Section 8.1 of the Act respecting the protection of personal information in the private sector requires anyone collecting personal information using technology that includes functions allowing a person to be identified, located or profiled to first inform them of the technology and of the means available to activate those functions, which means those functions must be off by default. Quebec penalties run to CAD 10 million or 2% of worldwide turnover in administrative penalties (section 90.12) and CAD 25 million or 4% of worldwide turnover in penal fines (section 91).
Bill C-27 (the Digital Charter Implementation Act 2022), which would have replaced PIPEDA with stricter rules, died on the Order Paper when Parliament was prorogued on January 6, 2025. No replacement has been enacted since, and PIPEDA remains the governing federal law as of September 10, 2026.
Brazil: LGPD
Brazil's Lei Geral de Protecao de Dados (LGPD) does not contain a specific cookie provision, but its requirements for a legal basis for processing personal data apply to cookies that collect personal information. The Autoridade Nacional de Protecao de Dados (ANPD) says in its cookie guide that consent is the more appropriate basis for non-necessary cookies, and that legitimate interest will rarely be the right basis where cookie data is used for advertising, especially through third-party cookies, behavioural profiling or tracking across different sites. Analytics sit differently. The guide accepts legitimate interest for audience measurement where the processing is limited to identifying patterns and trends from aggregated data, without combining it with other tracking mechanisms and without building user profiles. It also says consent is not the appropriate basis for strictly necessary cookies, because there the user has no real choice to give. Brazilian websites have widely adopted EU-style cookie banners in practice, partly because many also serve European users and partly because the ANPD's posture favors consent for tracking technologies.
China: PIPL
China's Personal Information Protection Law (PIPL), effective November 2021, regulates cookies as part of its broader personal information framework. The Cyberspace Administration of China (CAC) oversees enforcement.
The PIPL requires consent or another specified legal basis before processing personal information. Advertising cookies that share data with third parties or involve cross-border transfers face additional requirements, including data transfer impact assessments. China's approach is notably strict on third-party data sharing: each overseas transfer of personal information requires a separate legal basis and, in many cases, a security assessment filed with the CAC.
Japan: APPI
Japan's Act on the Protection of Personal Information (APPI), significantly amended in April 2022, addresses cookies through the concept of "individually-referable information." The Personal Information Protection Commission (PPC) enforces the APPI.
When a business provides cookie identifiers to a third party that can combine them with other data to identify individuals, the providing business must confirm that the third party has obtained the individual's consent. Japan does not require EU-style consent banners for first-party cookies. The focus is on third-party data sharing for advertising rather than initial cookie placement.
South Korea: PIPA
South Korea's Personal Information Protection Act (PIPA) is one of Asia's strictest frameworks. The Personal Information Protection Commission (PIPC) enforces it alongside the Network Act, which addresses online tracking specifically.
PIPA requires consent for collecting personal information, which covers cookies that track identifiable users. Korean websites commonly display cookie consent notices. The PIPC has been active in enforcement, with fines reaching billions of Korean won for violations involving personal data collection through tracking technologies.
India: DPDPA and the 2025 Rules
India's Digital Personal Data Protection Act 2023 (DPDPA) was enacted in August 2023. The Ministry of Electronics and Information Technology published the DPDP Rules 2025 on November 13, 2025, activating the framework.
The DPDPA requires consent that is specific, unambiguous, and involves a clear affirmative action, language that closely mirrors the GDPR. Cookies that collect personal data require consent. A new "Consent Manager" framework allows intermediaries registered with the Data Protection Board of India to handle consent on behalf of data principals.
Implementation follows a phased timeline. The Rules brought the Board-constituting provisions into force, but the Board is not yet staffed: MeitY's notification F. No. 2(1)/2026-Pers.I of May 6, 2026 was still inviting applications for one Chairperson and four Members, to be shortlisted by a Search-cum-Selection Committee. India therefore has a data protection law and rules but no sitting adjudicatory body yet.
Consent Manager registration opens November 2026, and the remaining provisions including consent and security requirements take effect in May 2027.
Australia: Privacy Act Amended
Australia regulates online data collection through the Privacy Act 1988 and the Australian Privacy Principles, enforced by the Office of the Australian Information Commissioner (OAIC).
The Privacy and Other Legislation Amendment Act 2024, signed into law in December 2024, is the most significant reform in years. Key changes affecting cookies:
- Consent must be voluntary, informed, current, specific, and unambiguous. Pre-ticked boxes and dark patterns are restricted.
- A second tranche is now out for consultation. The Attorney-General's Department released the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 on August 31, 2026, with submissions closing September 18, 2026. Its new section 6FD would define personal information as information or an opinion that relates to an identified individual, or an individual who is reasonably identifiable, with explanatory notes covering pseudonyms and identifiers, location and geolocation data, and behaviours or patterns of activity. It does not list IP addresses, device IDs and cookie identifiers by name, and it is a draft, not law.
Australia still does not require a pop-up cookie consent banner; notice through a privacy policy generally satisfies the current requirement. But the trajectory is toward stronger cookie-specific obligations.

Region-by-Region Roundup
Latin America
Beyond Brazil, several Latin American countries have strengthened their data protection frameworks. Chile reformed its data protection law in 2024. Colombia applies its Habeas Data Law (Law 1581/2012) to online data collection. Argentina operates under Personal Data Protection Law 25,326 and is developing updated rules. The regional trend is toward stronger consent requirements for tracking, with Brazil's ANPD serving as the regional enforcement reference point.
Asia-Pacific
Singapore: The Personal Data Protection Act (PDPA) requires consent for collecting personal data, which covers cookies that identify individuals. The PDPC has been active in enforcement with fines up to SGD 1 million, increasing to 10% of local turnover for egregious breaches.
Thailand: The Personal Data Protection Act (PDPA), fully effective June 2022, requires consent for collecting personal data through cookies. Consent must be freely given, specific, and informed.
Vietnam: Law No. 91/2025/QH15 on Personal Data Protection, passed on June 26, 2025 and in force since January 1, 2026, replaced the 2023 Personal Data Protection Decree. It requires consent for processing personal data, including cookie-based tracking.
Indonesia: The Personal Data Protection Law (2022) requires lawful basis for processing, with consent as the primary basis for tracking technologies.
New Zealand: The Privacy Act 2020 requires notification about data collection but does not mandate a cookie consent banner. The Office of the Privacy Commissioner provides guidance on cookie best practices.
Middle East and Africa
United Arab Emirates: Federal Decree-Law No. 45 of 2021 on personal data protection requires data subject consent for processing personal data, including cookies. No fine amount appears anywhere in the Decree-Law. Article 26 leaves the list of violations and the administrative penalties to a Council of Ministers decision, and Article 28 required Executive Regulations to fill in the detail, so the penalty machinery is still pending and no statutory maximum exists to quote.
Saudi Arabia: The Personal Data Protection Law (PDPL), effective September 2023, requires consent for personal data processing that is not otherwise authorized by law.
South Africa: POPIA (Protection of Personal Information Act) requires consent for processing personal information, which the Information Regulator has interpreted to include behavioral tracking cookies.
Nigeria: The Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act 2023 require consent for personal data collection. The Act, signed on June 12, 2023, established the Nigeria Data Protection Commission as the enforcement authority, replacing NITDA in that role.
Kenya: The Data Protection Act 2019 requires consent for processing personal data, including cookie-based tracking.
Israel: The Privacy Protection Law requires notice about data collection. Israel operates closer to the notice model but is modernizing its framework.
Turkey: The KVKK (Law No. 6698) requires explicit consent for processing sensitive data and informed consent for general personal data, including cookies.
Europe Outside the EU and EEA
Switzerland: Switzerland is an inform-and-object regime, not a consent regime. Article 45c of the Telecommunications Act permits processing of data stored on a user's device only if users are informed of the processing and its purpose and are advised that they may object to it. The revised Federal Act on Data Protection (revFADP), effective September 2023, governs the personal data that cookies collect.
The FDPIC's cookie factsheet of March 31, 2026 puts it plainly: European law requires explicit prior consent, while Swiss law emphasises transparent information and the right to object, with users able to opt out in principle before non-essential cookies are activated. Explicit prior consent is required only where the processing is unexpected, high risk, or involves sensitive data.
Global Comparison Table
| Country/Region | Consent Model | Legal Basis | Enforcement Authority | Max Penalty |
|---|---|---|---|---|
| EU (27 states) | Opt-in | ePrivacy Directive + GDPR | National DPAs | 20M euros / 4% turnover |
| UK | Opt-in; statistics and site-appearance cookies conditionally exempt post-DUAA (information plus a free way to object) | PECR + UK GDPR | ICO | 17.5M GBP / 4% turnover |
| USA | Opt-out (state level); opt-in for consumer health data and other sensitive data in some states | State privacy laws | State AGs, FTC | Varies by state |
| Canada | Meaningful consent; Quebec requires tracking functions off by default | PIPEDA, CASL, Quebec Law 25 | OPC (no fining power), CRTC, Quebec CAI | 10M CAD / 2% turnover (Quebec administrative); 25M CAD / 4% (Quebec penal) |
| Brazil | Consent preferred | LGPD | ANPD | 2% revenue, 50M BRL cap |
| China | Consent | PIPL | CAC | 50M CNY / 5% revenue |
| Japan | Third-party consent | APPI | PPC | 100M JPY |
| South Korea | Opt-in | PIPA + Network Act | PIPC | 3% revenue |
| India | Consent (enforcement from May 2027) | DPDPA + DPDP Rules 2025 | DPBI (not yet staffed) | 250 crore INR |
| Australia | Notice (tightening) | Privacy Act 1988 (amended 2024) | OAIC | 50M AUD |
| Singapore | Consent | PDPA | PDPC | 10% local turnover |
| Thailand | Consent | PDPA | PDPC Thailand | 5M THB |
| South Africa | Consent | POPIA | Information Regulator | 10M ZAR |
| Nigeria | Consent | NDPR / NDP Act 2023 | NDPC | 2% turnover |
| UAE | Consent | Federal Decree-Law 45/2021 | UAE Data Office | Not set in law (Art. 26 leaves penalties to a Cabinet decision) |
| Turkey | Consent | KVKK | KVKK Board | Administrative fines |
| Switzerland | Inform plus right to object (consent for unexpected, high-risk or sensitive processing) | TCA Art. 45c + revFADP | FDPIC investigates and orders measures; it cannot fine | 250K CHF criminal fine on individuals, imposed by cantonal prosecutors |
| Israel | Notice | Privacy Protection Law | PPA | Administrative fines |
| New Zealand | Notice | Privacy Act 2020 | OPC NZ | Modest fines |
Cookie Banner Enforcement and "Consent or Pay"
How Banner Design Is Actually Policed
The taskforce positions described earlier are a common denominator among supervisory authorities, not an enforceable standard in themselves. Enforcement runs through each member state's ePrivacy transposition, applied by its own authority, and fines for deceptive cookie banners continue to be issued across member states.
In practice authorities look for the same things: a reject option as easy to reach as the accept option, interface designs that do not use color, sizing or wording to steer users toward acceptance, and consent that is granular by purpose rather than bundled.
"Consent or Pay" Models
A "consent or pay" model presents users with a binary choice: consent to behavioral advertising or pay a subscription fee to access the service. Meta introduced such a model for Facebook and Instagram in the EU in 2023.
In April 2024, the EDPB's Opinion 08/2024 concluded that consent or pay models generally do not result in valid, freely given consent for large online platforms. The EDPB found that presenting users with no genuine alternative to consenting fails the "freely given" standard. The EDPB recommended that large platforms offer an equivalent alternative without behavioral advertising and without a paywall.
Meta challenged the opinion and lost, but not on the substance. By order of April 29, 2025 in Case T-319/24 the General Court dismissed the annulment action as inadmissible, holding that the opinion produces no binding legal effects and so is not a challengeable act, and rejected the damages claim as manifestly unfounded. The court did not rule on whether consent-or-pay produces valid consent. Meta appealed to the Court of Justice on July 10, 2025 in Case C-454/25 P, and no ruling on that appeal has been published.
For smaller websites, the picture is less settled. Most EU DPAs take a restrictive view of cookie walls. The safest approach for EU-facing websites is to allow access regardless of cookie choices.
Browser-Level Consent Signals: Global Privacy Control
The Global Privacy Control (GPC) is a browser or browser-extension signal that communicates a user's opt-out preference to every website they visit. It is supported natively in Firefox and Brave, and via extensions for Chrome and Safari.
In the US, compliance with GPC is now legally required in an expanding list of states. The California CPPA launched coordinated enforcement sweeps targeting GPC non-compliance in September 2025 alongside the AGs of Colorado and Connecticut. As of September 10, 2026, twelve states require businesses to act on a browser-level opt-out signal such as GPC, and more join as further state privacy acts phase in. Ten of those statutes name an opt-out preference signal or universal opt-out mechanism; Nebraska and Texas instead require a controller to honor an opt-out sent through a browser setting acting as the consumer's authorized agent.
In the EU, the Digital Omnibus proposal would require data controllers to respect machine-readable consent signals, which would give GPC-like signals legal weight for the first time in European law.
The practical implication: websites that do not yet listen for the GPC signal are falling behind the legal curve in the US and may need to comply with signal-based consent in the EU by 2027.
Practical Multi-Country Compliance Guidance
Geolocation-Based Consent
Most compliance platforms use IP geolocation to determine which consent rules apply to each visitor. An EU visitor sees a full opt-in banner. A US visitor from a GPC-mandatory state sees opt-out options and GPC honored. An Australian visitor sees a privacy policy notice. Geolocation-based routing is the standard approach for large multi-national publishers.
The Global Floor Strategy
For organizations that cannot implement jurisdiction-specific flows, applying EU-standard opt-in consent to all visitors is the safest and simplest baseline, because the EU standard is the strictest consent standard. The tradeoff is that consent rates for non-essential cookies are often significantly lower when opt-in is required, which affects advertising revenue and analytics coverage.
A banner alone is not the whole job, though. Three obligations sit outside it and still apply: a "Do Not Sell or Share" link and honoring the GPC signal under US state law, deactivation by default plus specific disclosures for identifying, locating or profiling technology under Quebec's section 8.1, and separate consents for the collection and the sharing of consumer health data under Washington's My Health My Data Act.
Consent Management Platforms
Dedicated consent management platforms (CMPs) automate cookie scanning, banner display, consent recording, and cookie blocking based on consent status. When choosing a CMP for multi-country compliance, verify support for the specific jurisdictions your site serves, that it can honor the GPC signal, and that consent records are stored in a format that satisfies GDPR audit requirements (Article 7(1)).
This is general legal information, not legal advice. Cookie compliance depends on the specific jurisdictions your website targets, the types of cookies used, and your organization's activities. Consult a qualified attorney in each relevant jurisdiction for advice specific to your situation.
Frequently Asked Questions
Which countries require opt-in cookie consent?
All 27 EU member states require opt-in consent under the ePrivacy Directive and GDPR. The UK requires opt-in consent under PECR, with conditional post-DUAA exemptions for statistics cookies and for cookies that adapt how a site appears. Each applies only where the user gets clear and comprehensive information about the purpose and a simple means of objecting, free of charge, and does not object, and the statistics exemption additionally requires that the information not be shared with anyone except a person assisting with improvements to that service or website. South Korea requires consent under PIPA. Brazil, China, Thailand, South Africa, Singapore, and several other countries require consent for cookies that process personal data. No US state requires an EU-style banner covering all cookies, but opt-in consent is required in defined situations: Washington's My Health My Data Act requires consent before consumer health data is collected, and Connecticut requires consent before sensitive data is processed and before personal data is used for targeted advertising or sold where the controller knows the consumer is at least 13 and under 16.
What happened to the proposed EU ePrivacy Regulation?
The European Commission's 2025 Work Programme, published in February 2025, formally withdrew the draft ePrivacy Regulation after years of legislative deadlock. The Commission cited an inability to reach agreement between the Parliament and Council, and the proposal being outdated in light of newer EU digital laws. The current ePrivacy Directive (2002/58/EC) and its national implementing laws remain in force.
What is the EU Digital Omnibus and how does it affect cookies?
The European Commission proposed the Digital Omnibus package on November 19, 2025. For cookies, the key changes would shift personal data processing rules entirely from the ePrivacy Directive to the GDPR, create new exemptions for first-party analytics and functional cookies, and require businesses to respect machine-readable browser consent signals. The package remains in legislative review and is not expected to take effect before 2027 at the earliest.
What did the UK DUAA 2025 change about cookie consent?
The Data (Use and Access) Act 2025 received Royal Assent on June 19, 2025 and key provisions came into force February 5, 2026. It inserted a new Schedule A1 into PECR creating two conditional exemptions: paragraph 5 for statistics cookies and paragraph 6 for cookies that adapt how a site appears or functions. Both apply only where the user is given clear and comprehensive information about the purpose and a simple means of objecting, free of charge, and does not object. The statistics exemption additionally requires that the data not be shared with anyone except a person assisting with improvements to that service or website, and it does not cover information the device emits automatically. Advertising, targeting, and measurement cookies still require consent. The DUAA also raised maximum PECR fines to UK GDPR levels: up to £17.5 million or 4% of global turnover.
Does my US-based website need a cookie banner for EU visitors?
If your website is accessible to EU visitors and processes their personal data, the GDPR and ePrivacy Directive apply. Whether your site specifically targets EU users affects the practical enforcement risk, but the legal obligation exists for any site that processes EU residents' personal data. Displaying an opt-in cookie consent banner for visitors detected in the EU is the standard compliance approach for US-based organizations with meaningful EU traffic.
What is the Global Privacy Control and which US states require honoring it?
The Global Privacy Control is a browser-level signal that communicates a user's opt-out preference to websites. As of September 10, 2026, twelve states require businesses to act on a browser-level opt-out signal such as GPC: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. Ten of those statutes name an opt-out preference signal or universal opt-out mechanism. Nebraska and Texas use identical authorized-agent wording instead, so a browser setting or extension can carry the opt-out, and the controller must honor it where it can verify the consumer's identity and the agent's authority with commercially reasonable effort. The California CPPA conducted coordinated enforcement sweeps targeting GPC non-compliance in September 2025, alongside the attorneys general of Colorado and Connecticut.
Are 'consent or pay' cookie walls legal in the EU?
For large online platforms, the EDPB's Opinion 08/2024 concluded they generally do not produce valid consent under the GDPR. The EDPB found that presenting users with only the choice of consenting to behavioral advertising or paying a fee fails the 'freely given' requirement. Meta's challenge to the opinion was dismissed as inadmissible by order of the EU General Court on April 29, 2025 in Case T-319/24, because the opinion is not a binding act, so there was no ruling on the substance; Meta's appeal in Case C-454/25 P is pending. For smaller websites, the analysis is less settled, but most EU DPAs take a restrictive view. The safest approach is to allow site access regardless of cookie choices.
When will India's DPDPA cookie consent rules take effect?
India's DPDP Rules 2025 were notified in November 2025 and brought the provisions constituting the Data Protection Board of India into force, though as of MeitY's notification of May 6, 2026 the Board still had no Chairperson or Members and applications were being invited. Consent Manager registration opens November 2026. All substantive provisions including consent, privacy notice, and security requirements take effect on May 13, 2027. After that date, organizations using cookies to collect personal data of Indian users will need consent that is specific, unambiguous, and involves a clear affirmative action.
Does Australia require cookie consent banners?
Australia does not currently require pop-up cookie consent banners. The Privacy Act 1988 requires notification about personal data collection, which can be accomplished through a privacy policy. The Privacy and Other Legislation Amendment Act 2024 (signed December 2024) strengthens consent standards. A second tranche is now in consultation: the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026, released August 31, 2026 with submissions closing September 18, 2026, would define personal information by reference to whether an individual is identified or reasonably identifiable, with notes covering identifiers, location data and behavioural patterns. It is a draft, not law. The trajectory is toward stronger cookie consent requirements.
Is applying EU cookie consent rules globally the safest approach?
Mostly, but not entirely. An EU-standard opt-in banner is the strictest single consent posture and covers the jurisdictions that require opt-in consent. It does not on its own satisfy US state law, which separately requires an opt-out link and recognition of universal opt-out signals whatever the banner does, nor Quebec's rule that identifying, locating and profiling functions be off by default with specific disclosures, nor Washington's separate consents for consumer health data. The primary tradeoff is that opt-in models result in many users declining non-essential cookies, reducing analytics coverage and advertising revenue. Organizations with significant non-EU traffic sometimes implement geolocation-based flows to apply opt-out or notice-only rules for visitors in jurisdictions that do not require opt-in, preserving analytics and ad performance in those markets.
Updates
Corrected the UK DUAA cookie exemptions (they are conditional on giving users information and a free way to object, not automatic), the claim that no US state ever requires opt-in consent (Washington health data and Connecticut sensitive data and known-minor advertising do), Switzerland's inform-and-object regime and Canada's penalty picture including Quebec's Law 25 tracking rule, Spain's LSSI cookie fine band, the current list of states requiring a universal opt-out signal, the non-binding status of the EDPB cookie banner taskforce report, the outcome of Meta's court challenge, and stale entries on France, Vietnam, India, Nigeria, the UAE, Germany, Australia and the EU Digital Omnibus. Corrected the last remaining FAQ answer that described the UK DUAA cookie exemptions as automatic (they apply only where users get clear information and a simple free way to object), put the count of states that require honoring a browser-level opt-out signal on one consistent test and added Nebraska for twelve, corrected the German Federal Court of Justice cookie ruling to 28 May 2020 (I ZR 7/16), corrected Brazil's ANPD position to allow legitimate interest for aggregate audience measurement while treating consent as the appropriate basis for advertising cookies, removed two unsourced claims that the CNIL's September 2025 fines were the largest anywhere, repointed the California Privacy Protection Agency link to the agency's own sweep announcement, cited the Commission annex that contains the ePrivacy withdrawal quotes, qualified the US and India rows of the comparison table, and moved Switzerland out of the Middle East and Africa section.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Major refresh: added ePrivacy Regulation withdrawal (Feb 2025), EU Digital Omnibus cookie proposal (Nov 2025), UK DUAA 2025 PECR changes, EDPB Opinion 08/2024 on consent-or-pay, GPC multi-state mandate, India DPDP Rules 2025, Australia Privacy Act 2024 amendments, expanded country sections and enforcement detail. Expanded from ~2,350 to ~4,500 words.
Reviewed and approved by an editor
Initial publication.
Sources and References
- ePrivacy Directive 2002/58/EC(eur-lex.europa.eu).gov
- CJEU Case C-673/17 (Planet49)(curia.europa.eu).gov
- EDPB Cookie Banner Taskforce Report(edpb.europa.eu).gov
- EDPB Opinion 08/2024 on Consent or Pay(edpb.europa.eu).gov
- CNIL - Cookies et autres traceurs(cnil.fr).gov
- Italy Garante Cookie Guidelines(garanteprivacy.it).gov
- UK PECR 2003(legislation.gov.uk).gov
- ICO - Data Use and Access Act 2025(ico.org.uk).gov
- ICO Cookie Guide(ico.org.uk).gov
- California CCPA(oag.ca.gov).gov
- Global Privacy Control W3C Specification(w3.org)
- Canada PIPEDA(laws-lois.justice.gc.ca).gov
- Canada CASL(laws-lois.justice.gc.ca).gov
- OPC Canada(priv.gc.ca).gov
- Brazil LGPD(planalto.gov.br).gov
- Brazil ANPD(gov.br).gov
- China PIPL(npc.gov.cn).gov
- Japan PPC APPI(ppc.go.jp).gov
- South Korea PIPC PIPA(pipc.go.kr).gov
- India DPDP Rules 2025(meity.gov.in).gov
- Australia Privacy Act 1988(legislation.gov.au).gov
- OAIC Australia(oaic.gov.au).gov
- Spain LSSI Ley 34/2002(boe.es).gov
- PECR 2003, Schedule A1 paras 5 and 6 (statistics and website appearance exemptions inserted by the Data (Use and Access) Act 2025, in force 5 February 2026)(legislation.gov.uk).gov
- Washington My Health My Data Act, RCW 19.373.030 (consent required before collecting consumer health data)(app.leg.wa.gov).gov
- Connecticut Data Privacy Act, Conn. Gen. Stat. Sec. 42-520 (consent for sensitive data; targeted advertising and sale where the consumer is known to be 13 to 15)(cga.ct.gov).gov
- Quebec Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, ss. 8.1, 90.12 and 91(legisquebec.gouv.qc.ca).gov
- FDPIC factsheet, Use of cookies and other similar technologies in the context of online tracking (31 March 2026)(edoeb.admin.ch).gov
- Swiss Telecommunications Act, Art. 45c (processing of data on external equipment)(fedlex.admin.ch).gov
- CNIL sanctions of 1 September 2025 against GOOGLE (EUR 325 million) and SHEIN (EUR 150 million)(cnil.fr).gov
- MeitY notification F. No. 2(1)/2026-Pers.I of 6 May 2026 inviting applications for Chairperson and Members of the Data Protection Board of India(meity.gov.in).gov
- UAE Federal Decree-Law No. 45 of 2021, Arts. 26 and 28 (penalties left to a Cabinet decision; Executive Regulations)(uaelegislation.gov.ae).gov
- Vietnam Law No. 91/2025/QH15 on Personal Data Protection (passed 26 June 2025, in force 1 January 2026)(congbao.chinhphu.vn).gov
- New Hampshire RSA 507-H:6, V(a)(1)(B) (opt-out preference signal from 1 January 2025)(gc.nh.gov).gov
- Delaware Personal Data Privacy Act, 6 Del. C. Sec. 12D-106(e) (opt-out preference signal from 1 January 2026)(delcode.delaware.gov).gov
- Minnesota Consumer Data Privacy Act, Minn. Stat. Sec. 325M.14 (opt-out preference signal)(revisor.mn.gov).gov
- TDDDG Sec. 29(2) (BfDI competent for Sec. 25 only for telecommunications providers and federal public bodies)(gesetze-im-internet.de).gov
- EDPB Report of the work undertaken by the Cookie Banner Taskforce, adopted 17 January 2023 (see the Disclaimer)(edpb.europa.eu).gov
- General Court order of 29 April 2025, Case T-319/24 Meta Platforms Ireland v EDPB (action dismissed as inadmissible)(eur-lex.europa.eu).gov
- Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 (released 31 August 2026)(consultations.ag.gov.au).gov
- European Parliament Legislative Train, Digital Omnibus package (status as at 2026)(europarl.europa.eu).gov
- Nigeria Data Protection Commission, About Us (established under the Nigeria Data Protection Act 2023)(ndpc.gov.ng).gov
- ANPD, Guia Orientativo: Cookies e protecao de dados pessoais (v1.0, October 2022), legitimate interest for audience measurement and consent for non-necessary cookies(gov.br).gov
- BGH press release 067/2020, judgment of 28 May 2020 in I ZR 7/16 (Cookie-Einwilligung II)(bundesgerichtshof.de).gov
- California Privacy Protection Agency, Joint Investigative Privacy Sweep with the Attorneys General of California, Colorado and Connecticut (9 September 2025)(cppa.ca.gov).gov
- European Commission Work Programme 2025, COM(2025) 45 final, Annex IV: Withdrawals, item 29 (ePrivacy Regulation proposal COM(2017)10 final)(commission.europa.eu).gov
- Montana Consumer Data Privacy Act, Mont. Code Ann. Sec. 30-14-2809(3)(b) (opt-out preference signal from 1 January 2025)(archive.legmt.gov).gov
- Nebraska Data Privacy Act, Neb. Rev. Stat. Sec. 87-1111(5)-(6) (opt-out through an authorized agent designated by a browser setting or extension)(nebraskalegislature.gov).gov
- Texas Data Privacy and Security Act as enrolled, HB 4 (88R), Tex. Bus. and Com. Code Sec. 541.055(e)-(f) (authorized agent designated by a browser setting, extension or global device setting)(capitol.texas.gov).gov