Cookie Consent Laws by Country: Complete Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 48 primary sources cited on this page. How we verify our legal content

Cookie Consent Laws by Country: Complete Guide (2026)

Frequently Asked Questions

Which countries require opt-in cookie consent?

All 27 EU member states require opt-in consent under the ePrivacy Directive and GDPR. The UK requires opt-in consent under PECR, with conditional post-DUAA exemptions for statistics cookies and for cookies that adapt how a site appears. Each applies only where the user gets clear and comprehensive information about the purpose and a simple means of objecting, free of charge, and does not object, and the statistics exemption additionally requires that the information not be shared with anyone except a person assisting with improvements to that service or website. South Korea requires consent under PIPA. Brazil, China, Thailand, South Africa, Singapore, and several other countries require consent for cookies that process personal data. No US state requires an EU-style banner covering all cookies, but opt-in consent is required in defined situations: Washington's My Health My Data Act requires consent before consumer health data is collected, and Connecticut requires consent before sensitive data is processed and before personal data is used for targeted advertising or sold where the controller knows the consumer is at least 13 and under 16.

What happened to the proposed EU ePrivacy Regulation?

The European Commission's 2025 Work Programme, published in February 2025, formally withdrew the draft ePrivacy Regulation after years of legislative deadlock. The Commission cited an inability to reach agreement between the Parliament and Council, and the proposal being outdated in light of newer EU digital laws. The current ePrivacy Directive (2002/58/EC) and its national implementing laws remain in force.

What is the EU Digital Omnibus and how does it affect cookies?

The European Commission proposed the Digital Omnibus package on November 19, 2025. For cookies, the key changes would shift personal data processing rules entirely from the ePrivacy Directive to the GDPR, create new exemptions for first-party analytics and functional cookies, and require businesses to respect machine-readable browser consent signals. The package remains in legislative review and is not expected to take effect before 2027 at the earliest.

What did the UK DUAA 2025 change about cookie consent?

The Data (Use and Access) Act 2025 received Royal Assent on June 19, 2025 and key provisions came into force February 5, 2026. It inserted a new Schedule A1 into PECR creating two conditional exemptions: paragraph 5 for statistics cookies and paragraph 6 for cookies that adapt how a site appears or functions. Both apply only where the user is given clear and comprehensive information about the purpose and a simple means of objecting, free of charge, and does not object. The statistics exemption additionally requires that the data not be shared with anyone except a person assisting with improvements to that service or website, and it does not cover information the device emits automatically. Advertising, targeting, and measurement cookies still require consent. The DUAA also raised maximum PECR fines to UK GDPR levels: up to £17.5 million or 4% of global turnover.

Does my US-based website need a cookie banner for EU visitors?

If your website is accessible to EU visitors and processes their personal data, the GDPR and ePrivacy Directive apply. Whether your site specifically targets EU users affects the practical enforcement risk, but the legal obligation exists for any site that processes EU residents' personal data. Displaying an opt-in cookie consent banner for visitors detected in the EU is the standard compliance approach for US-based organizations with meaningful EU traffic.

What is the Global Privacy Control and which US states require honoring it?

The Global Privacy Control is a browser-level signal that communicates a user's opt-out preference to websites. As of September 10, 2026, twelve states require businesses to act on a browser-level opt-out signal such as GPC: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. Ten of those statutes name an opt-out preference signal or universal opt-out mechanism. Nebraska and Texas use identical authorized-agent wording instead, so a browser setting or extension can carry the opt-out, and the controller must honor it where it can verify the consumer's identity and the agent's authority with commercially reasonable effort. The California CPPA conducted coordinated enforcement sweeps targeting GPC non-compliance in September 2025, alongside the attorneys general of Colorado and Connecticut.

Are 'consent or pay' cookie walls legal in the EU?

For large online platforms, the EDPB's Opinion 08/2024 concluded they generally do not produce valid consent under the GDPR. The EDPB found that presenting users with only the choice of consenting to behavioral advertising or paying a fee fails the 'freely given' requirement. Meta's challenge to the opinion was dismissed as inadmissible by order of the EU General Court on April 29, 2025 in Case T-319/24, because the opinion is not a binding act, so there was no ruling on the substance; Meta's appeal in Case C-454/25 P is pending. For smaller websites, the analysis is less settled, but most EU DPAs take a restrictive view. The safest approach is to allow site access regardless of cookie choices.

When will India's DPDPA cookie consent rules take effect?

India's DPDP Rules 2025 were notified in November 2025 and brought the provisions constituting the Data Protection Board of India into force, though as of MeitY's notification of May 6, 2026 the Board still had no Chairperson or Members and applications were being invited. Consent Manager registration opens November 2026. All substantive provisions including consent, privacy notice, and security requirements take effect on May 13, 2027. After that date, organizations using cookies to collect personal data of Indian users will need consent that is specific, unambiguous, and involves a clear affirmative action.

Does Australia require cookie consent banners?

Australia does not currently require pop-up cookie consent banners. The Privacy Act 1988 requires notification about personal data collection, which can be accomplished through a privacy policy. The Privacy and Other Legislation Amendment Act 2024 (signed December 2024) strengthens consent standards. A second tranche is now in consultation: the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026, released August 31, 2026 with submissions closing September 18, 2026, would define personal information by reference to whether an individual is identified or reasonably identifiable, with notes covering identifiers, location data and behavioural patterns. It is a draft, not law. The trajectory is toward stronger cookie consent requirements.

Is applying EU cookie consent rules globally the safest approach?

Mostly, but not entirely. An EU-standard opt-in banner is the strictest single consent posture and covers the jurisdictions that require opt-in consent. It does not on its own satisfy US state law, which separately requires an opt-out link and recognition of universal opt-out signals whatever the banner does, nor Quebec's rule that identifying, locating and profiling functions be off by default with specific disclosures, nor Washington's separate consents for consumer health data. The primary tradeoff is that opt-in models result in many users declining non-essential cookies, reducing analytics coverage and advertising revenue. Organizations with significant non-EU traffic sometimes implement geolocation-based flows to apply opt-out or notice-only rules for visitors in jurisdictions that do not require opt-in, preserving analytics and ad performance in those markets.

Updates

Corrected the UK DUAA cookie exemptions (they are conditional on giving users information and a free way to object, not automatic), the claim that no US state ever requires opt-in consent (Washington health data and Connecticut sensitive data and known-minor advertising do), Switzerland's inform-and-object regime and Canada's penalty picture including Quebec's Law 25 tracking rule, Spain's LSSI cookie fine band, the current list of states requiring a universal opt-out signal, the non-binding status of the EDPB cookie banner taskforce report, the outcome of Meta's court challenge, and stale entries on France, Vietnam, India, Nigeria, the UAE, Germany, Australia and the EU Digital Omnibus. Corrected the last remaining FAQ answer that described the UK DUAA cookie exemptions as automatic (they apply only where users get clear information and a simple free way to object), put the count of states that require honoring a browser-level opt-out signal on one consistent test and added Nebraska for twelve, corrected the German Federal Court of Justice cookie ruling to 28 May 2020 (I ZR 7/16), corrected Brazil's ANPD position to allow legitimate interest for aggregate audience measurement while treating consent as the appropriate basis for advertising cookies, removed two unsourced claims that the CNIL's September 2025 fines were the largest anywhere, repointed the California Privacy Protection Agency link to the agency's own sweep announcement, cited the Commission annex that contains the ePrivacy withdrawal quotes, qualified the US and India rows of the comparison table, and moved Switzerland out of the Middle East and Africa section.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Major refresh: added ePrivacy Regulation withdrawal (Feb 2025), EU Digital Omnibus cookie proposal (Nov 2025), UK DUAA 2025 PECR changes, EDPB Opinion 08/2024 on consent-or-pay, GPC multi-state mandate, India DPDP Rules 2025, Australia Privacy Act 2024 amendments, expanded country sections and enforcement detail. Expanded from ~2,350 to ~4,500 words.

Reviewed and approved by an editor

Initial publication.

Sources and References

  1. ePrivacy Directive 2002/58/EC(eur-lex.europa.eu).gov
  2. CJEU Case C-673/17 (Planet49)(curia.europa.eu).gov
  3. EDPB Cookie Banner Taskforce Report(edpb.europa.eu).gov
  4. EDPB Opinion 08/2024 on Consent or Pay(edpb.europa.eu).gov
  5. CNIL - Cookies et autres traceurs(cnil.fr).gov
  6. Italy Garante Cookie Guidelines(garanteprivacy.it).gov
  7. UK PECR 2003(legislation.gov.uk).gov
  8. ICO - Data Use and Access Act 2025(ico.org.uk).gov
  9. ICO Cookie Guide(ico.org.uk).gov
  10. California CCPA(oag.ca.gov).gov
  11. Global Privacy Control W3C Specification(w3.org)
  12. Canada PIPEDA(laws-lois.justice.gc.ca).gov
  13. Canada CASL(laws-lois.justice.gc.ca).gov
  14. OPC Canada(priv.gc.ca).gov
  15. Brazil LGPD(planalto.gov.br).gov
  16. Brazil ANPD(gov.br).gov
  17. China PIPL(npc.gov.cn).gov
  18. Japan PPC APPI(ppc.go.jp).gov
  19. South Korea PIPC PIPA(pipc.go.kr).gov
  20. India DPDP Rules 2025(meity.gov.in).gov
  21. Australia Privacy Act 1988(legislation.gov.au).gov
  22. OAIC Australia(oaic.gov.au).gov
  23. Spain LSSI Ley 34/2002(boe.es).gov
  24. PECR 2003, Schedule A1 paras 5 and 6 (statistics and website appearance exemptions inserted by the Data (Use and Access) Act 2025, in force 5 February 2026)(legislation.gov.uk).gov
  25. Washington My Health My Data Act, RCW 19.373.030 (consent required before collecting consumer health data)(app.leg.wa.gov).gov
  26. Connecticut Data Privacy Act, Conn. Gen. Stat. Sec. 42-520 (consent for sensitive data; targeted advertising and sale where the consumer is known to be 13 to 15)(cga.ct.gov).gov
  27. Quebec Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, ss. 8.1, 90.12 and 91(legisquebec.gouv.qc.ca).gov
  28. FDPIC factsheet, Use of cookies and other similar technologies in the context of online tracking (31 March 2026)(edoeb.admin.ch).gov
  29. Swiss Telecommunications Act, Art. 45c (processing of data on external equipment)(fedlex.admin.ch).gov
  30. CNIL sanctions of 1 September 2025 against GOOGLE (EUR 325 million) and SHEIN (EUR 150 million)(cnil.fr).gov
  31. MeitY notification F. No. 2(1)/2026-Pers.I of 6 May 2026 inviting applications for Chairperson and Members of the Data Protection Board of India(meity.gov.in).gov
  32. UAE Federal Decree-Law No. 45 of 2021, Arts. 26 and 28 (penalties left to a Cabinet decision; Executive Regulations)(uaelegislation.gov.ae).gov
  33. Vietnam Law No. 91/2025/QH15 on Personal Data Protection (passed 26 June 2025, in force 1 January 2026)(congbao.chinhphu.vn).gov
  34. New Hampshire RSA 507-H:6, V(a)(1)(B) (opt-out preference signal from 1 January 2025)(gc.nh.gov).gov
  35. Delaware Personal Data Privacy Act, 6 Del. C. Sec. 12D-106(e) (opt-out preference signal from 1 January 2026)(delcode.delaware.gov).gov
  36. Minnesota Consumer Data Privacy Act, Minn. Stat. Sec. 325M.14 (opt-out preference signal)(revisor.mn.gov).gov
  37. TDDDG Sec. 29(2) (BfDI competent for Sec. 25 only for telecommunications providers and federal public bodies)(gesetze-im-internet.de).gov
  38. EDPB Report of the work undertaken by the Cookie Banner Taskforce, adopted 17 January 2023 (see the Disclaimer)(edpb.europa.eu).gov
  39. General Court order of 29 April 2025, Case T-319/24 Meta Platforms Ireland v EDPB (action dismissed as inadmissible)(eur-lex.europa.eu).gov
  40. Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 (released 31 August 2026)(consultations.ag.gov.au).gov
  41. European Parliament Legislative Train, Digital Omnibus package (status as at 2026)(europarl.europa.eu).gov
  42. Nigeria Data Protection Commission, About Us (established under the Nigeria Data Protection Act 2023)(ndpc.gov.ng).gov
  43. ANPD, Guia Orientativo: Cookies e protecao de dados pessoais (v1.0, October 2022), legitimate interest for audience measurement and consent for non-necessary cookies(gov.br).gov
  44. BGH press release 067/2020, judgment of 28 May 2020 in I ZR 7/16 (Cookie-Einwilligung II)(bundesgerichtshof.de).gov
  45. California Privacy Protection Agency, Joint Investigative Privacy Sweep with the Attorneys General of California, Colorado and Connecticut (9 September 2025)(cppa.ca.gov).gov
  46. European Commission Work Programme 2025, COM(2025) 45 final, Annex IV: Withdrawals, item 29 (ePrivacy Regulation proposal COM(2017)10 final)(commission.europa.eu).gov
  47. Montana Consumer Data Privacy Act, Mont. Code Ann. Sec. 30-14-2809(3)(b) (opt-out preference signal from 1 January 2025)(archive.legmt.gov).gov
  48. Nebraska Data Privacy Act, Neb. Rev. Stat. Sec. 87-1111(5)-(6) (opt-out through an authorized agent designated by a browser setting or extension)(nebraskalegislature.gov).gov
  49. Texas Data Privacy and Security Act as enrolled, HB 4 (88R), Tex. Bus. and Com. Code Sec. 541.055(e)-(f) (authorized agent designated by a browser setting, extension or global device setting)(capitol.texas.gov).gov
Share: