EU Cookie Law (ePrivacy Directive) Explained (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 35 primary sources cited on this page. How we verify our legal content

EU Cookie Law (ePrivacy Directive) Explained (2026)

Frequently Asked Questions

What is the ePrivacy Directive and how does it relate to GDPR?

The ePrivacy Directive (2002/58/EC, amended by 2009/136/EC) is the EU law that governs cookies, tracking technologies, and electronic communications. It operates as a lex specialis alongside the GDPR: the Directive controls the act of placing cookies on a device, while the GDPR governs how the personal data collected through those cookies is processed. Where both laws apply, the ePrivacy Directive's specific rules take precedence. The GDPR sets the consent standard that the ePrivacy Directive's cookie consent requirement must meet.

Was the ePrivacy Regulation withdrawn?

Yes. The European Commission announced the intended withdrawal in Annex IV of its 2025 Work Programme, published on February 11, 2025, approved the withdrawal on July 16, 2025, and the withdrawal took legal effect when the notice appeared in the Official Journal on October 6, 2025 (OJ C, C/2025/5423). The Commission stated that no agreement was expected from the co-legislators and that the proposal was outdated given recent digital legislation. The existing ePrivacy Directive remains fully in force. A new approach to updating cookie rules was introduced through the November 2025 Digital Omnibus, which proposes folding cookie consent rules into the GDPR rather than replacing the Directive with a separate regulation.

What does the November 2025 Digital Omnibus propose for cookies?

The Digital Omnibus, published November 19, 2025, proposes two new GDPR articles. Article 88a would require single-click reject options equal in prominence to accept, prohibit repeat consent requests for six months after a refusal, and preserve the strictly necessary exemption. Article 88b would require websites to honor machine-readable browser-level consent signals, allowing users to set privacy preferences once in their browser rather than clicking through individual cookie banners. The proposal is still subject to European Parliament and Council approval and is not yet law.

Which cookies are exempt from the consent requirement?

Only two categories are exempt under Article 5(3). First, cookies used solely for transmitting a communication over a network (technical routing). Second, cookies strictly necessary for providing a service the user explicitly requested, such as authentication cookies, shopping cart cookies, and security cookies. Analytics, advertising, and most functional cookies all require consent. Some national regulators, notably France's CNIL, allow a narrow exemption for privacy-preserving, first-party-only audience measurement tools under strict conditions.

Are pre-ticked cookie consent checkboxes legal in the EU?

No. The CJEU ruled in Case C-673/17 (Planet49) in October 2019 that pre-ticked checkboxes do not constitute valid consent for cookies. Consent must involve a clear affirmative action. Scrolling or continuing to browse the site also does not count as valid consent. This applies regardless of whether the cookie data constitutes personal data.

Are 'consent or pay' cookie walls legal?

It depends on the context. The EDPB issued Opinion 08/2024 in April 2024 finding that 'in most cases' large online platforms cannot use a consent-or-pay model because users lack a genuine free choice. The European Commission reached the same conclusion regarding Meta on April 23, 2025 and fined it €200 million; in December 2025 Meta undertook to offer EU users a third option using less personal data for less personalised ads, presented from January 2026. However, the opinion primarily targets large platforms, and national authorities have not uniformly prohibited all consent-or-pay models for smaller publishers. The Dutch DPA treats a cookie wall as invalid consent unless the visitor is offered a reasonable alternative to reach the content, holding that a visitor denied access to a site after refusing cookies has not given free consent. The question remains unsettled at the EU-wide level.

What penalties can a website face for cookie law violations?

Penalties vary by country. France has imposed fines of €325 million (Google, 2025) and €150 million (Google, 2021) using GDPR penalty provisions. Spain treats a cookie consent breach (article 22.2 LSSI) as a light infringement fined up to €30,000 under article 39.1(c), rising to €30,001 to €150,000 if it is repeated within three years; the LSSI ceiling, reserved for very serious infringements, is €600,000. GDPR fines apply when personal data is involved. Germany's TDDDG maximum is €300,000, with GDPR fines available for personal-data violations. In practice, most regulators use the GDPR framework of up to €20 million or 4% of global annual turnover when cookies involve personal data processing.

Do analytics cookies like Google Analytics require consent?

Under the ePrivacy Directive, analytics cookies generally require consent. However, some national regulators have softened this for first-party analytics. France's CNIL allows an exemption for first-party audience measurement cookies under strict conditions: the data must be aggregated, not shared with third parties, and limited in retention. Third-party tools like Google Analytics that transfer data externally consistently require consent across all EU jurisdictions.

How often must websites re-request cookie consent?

The ePrivacy Directive does not specify a re-consent interval. National guidance varies. The CNIL treats keeping the user's choice, consent or refusal alike, for six months as good practice, so a site should not re-prompt inside that window. Other authorities suggest 12-month intervals. The Digital Omnibus proposal, if adopted, would prohibit re-requesting consent for a purpose the user already refused for at least six months. Organizations should also re-request consent whenever they add new cookie categories or change processing purposes.

Updates

Corrected the Dutch regulator's position on cookie walls (the AP treats them as unlawful and has been enforcing against misleading banners since April 2025), replaced the wrong Spanish LSSI penalty with the actual article 39 bands, re-dated the ePrivacy Regulation withdrawal to its 6 October 2025 Official Journal notice, re-dated the CJEU IAB Europe judgment to 7 March 2024 and added the Market Court's 14 May 2025 confirmation of the EUR 250,000 fine, named the Land data protection authorities rather than the BfDI as the German enforcer for website cookies, corrected the BGH date, added EDPB Guidelines 2/2023 on tracking beyond cookies, corrected the Digital Omnibus browser-signal timelines and the status of the EDPB taskforce report, and replaced two dead source links.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Major refresh: added the ePrivacy Regulation withdrawal, the Digital Omnibus cookie proposals, the cookie banner taskforce findings, the consent-or-pay opinion, CNIL fines and expanded country sections. Several statements in that revision were found to be inaccurate and were corrected on 10 September 2026; see the later entries in this log.

Reviewed and approved by an editor

Sources and References

  1. Directive 2002/58/EC on Privacy and Electronic Communications (ePrivacy Directive)(eur-lex.europa.eu).gov
  2. Directive 2009/136/EC Amending the ePrivacy Directive (Cookie Amendment)(eur-lex.europa.eu).gov
  3. CJEU Case C-673/17 (Planet49) — Cookie Consent Standard(curia.europa.eu).gov
  4. Article 29 Working Party Opinion 04/2012 on Cookie Consent Exemptions(ec.europa.eu).gov
  5. EDPB Guidelines 05/2020 on Consent under Regulation 2016/679(edpb.europa.eu).gov
  6. Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)(eur-lex.europa.eu).gov
  7. European Commission Work Programme 2025 — ePrivacy Regulation Withdrawal(commission.europa.eu).gov
  8. EU Digital Package — European Commission (Digital Omnibus)(digital-strategy.ec.europa.eu).gov
  9. EDPB Report of the Cookie Banner Taskforce (January 2023)(edpb.europa.eu).gov
  10. EDPB and EDPS Statement on the Digital Omnibus (2026)(edpb.europa.eu).gov
  11. CNIL - Cookies and other trackers: amending guidelines and recommendation (deliberations 2020-091 and 2020-092)(cnil.fr).gov
  12. Italy Garante Cookie Guidelines (2021)(garanteprivacy.it).gov
  13. Spain LSSI (Ley 34/2002) — Law on Information Society Services(boe.es).gov
  14. Germany TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz), official consolidated text, sections 25, 26, 28 and 29(gesetze-im-internet.de).gov
  15. Ireland S.I. No. 336/2011 — Electronic Communications Regulations(irishstatutebook.ie).gov
  16. Netherlands Telecommunicatiewet, consolidated text in force from 15 August 2026(wetten.overheid.nl).gov
  17. France Loi Informatique et Libertes — Article 82(legifrance.gouv.fr).gov
  18. Autoriteit Persoonsgegevens - Tracking cookies: a cookie wall denying access after refusal is not valid consent(autoriteitpersoonsgegevens.nl).gov
  19. Autoriteit Persoonsgegevens, 11 November 2025 - more than 200 websites warned, about three quarters fixed, investigations opened(autoriteitpersoonsgegevens.nl).gov
  20. Autoriteit Persoonsgegevens, 15 April 2025 - 50 warning letters, the first of 500 planned each year(autoriteitpersoonsgegevens.nl).gov
  21. Withdrawal of Commission proposals, OJ C, C/2025/5423, 6 October 2025 (includes COM(2017) 10 final, 2017/0003 (COD), the ePrivacy Regulation)(eur-lex.europa.eu).gov
  22. CJEU Case C-604/22 IAB Europe, judgment of 7 March 2024 (ECLI:EU:C:2024:214)(eur-lex.europa.eu).gov
  23. Belgian Data Protection Authority - The Market Court rules in the IAB Europe case, 14 May 2025 (EUR 250,000 fine confirmed)(dataprotectionauthority.be).gov
  24. EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive, version 2.0 adopted 7 October 2024(edpb.europa.eu).gov
  25. Digital Omnibus proposal COM(2025) 837 final, procedure 2025/0360 (COD) - proposed GDPR Articles 88a and 88b(eur-lex.europa.eu).gov
  26. European Parliament Legislative Train - Digital package: state of play of the Digital Omnibus(europarl.europa.eu).gov
  27. Einwilligungsverwaltungsverordnung (EinwV) of 6 February 2025, BGBl. 2025 I Nr. 32, in force 1 April 2025(gesetze-im-internet.de).gov
  28. Bundesgerichtshof - judgment of 28 May 2020, I ZR 7/16 (Cookie-Einwilligung II)(bundesgerichtshof.de).gov
  29. CNIL, 1 September 2025 - Google fined EUR 325 million for Gmail advertising and cookie consent breaches (SAN-2025-004)(cnil.fr).gov
  30. CNIL cookie recommendation, consolidated version published 16 January 2026 (deliberations 2020-092 and 2025-131)(cnil.fr).gov
  31. CNIL recommendation on tracking pixels in emails, adopted 12 March 2026(cnil.fr).gov
  32. AEPD PS/00300/2019 (Vueling Airlines) - art. 22.2 LSSI, EUR 30,000 reduced to EUR 18,000 on voluntary payment(aepd.es).gov
  33. AEPD PS/00032/2020 (Iberia) - EUR 30,000 for breach of art. 22.2 LSSI over a cookie banner with no reject option(aepd.es).gov
  34. European Commission, 23 April 2025 - Apple and Meta found in breach of the DMA (Meta fined EUR 200 million)(ec.europa.eu).gov
  35. European Commission, 8 December 2025 - Meta commits to give EU users a choice on personalised ads(digital-markets-act.ec.europa.eu).gov
Share: