The legal framework
Which Cookies Need Consent?
The requirement to obtain consent for cookies does not come from the GDPR alone. It originates in the ePrivacy Directive (Directive 2002/58/EC, as amended by Directive 2009/136/EC), commonly known as the "Cookie Law." The ePrivacy Directive specifically addresses the storage of information on, and access to information from, a user's terminal equipment — which includes cookies, local storage, device fingerprinting, and similar tracking technologies. The GDPR then sets the standard for what valid consent looks like.
Under Article 5(3) of the ePrivacy Directive, storing or accessing information on a user's device requires the user's prior consent, except when the storage is strictly necessary for providing a service explicitly requested by the user. This means every cookie that is not strictly necessary for the website to function as the visitor expects requires informed, freely given consent before it can be set. Not after. Not during. Before.
This is a critical distinction that many websites get wrong. The default state of a new visitor's browser must be free from non-essential cookies until that visitor has made an affirmative choice to accept them. Loading Google Analytics on page load and then showing a consent banner is a violation. The analytics script — and the cookies it sets — must wait until the visitor has actively consented to the analytics category.
In practice, cookies fall into four categories, each with different consent requirements. Understanding these categories is the foundation of any compliant cookie implementation.
Strictly Necessary
Cookies essential for the basic functioning of the website. These enable core features that the visitor has explicitly requested, such as logging in, maintaining a shopping cart, or processing a payment. Examples include session cookies that keep a user logged in, CSRF tokens that protect form submissions, load balancer cookies that route traffic to the correct server, and shopping cart cookies that remember items between pages. These cookies do not require consent because without them the service the visitor requested would not work. However, you must still disclose their existence in your cookie policy.
Analytics & Performance
Cookies used to collect information about how visitors use your website. This category includes tools like Google Analytics, Adobe Analytics, Hotjar, Matomo, Mixpanel, Heap, and similar services that measure page views, session duration, bounce rates, scroll depth, click patterns, and conversion funnels. Even though these cookies may seem harmless from the website owner's perspective, they collect personal data — including IP addresses, device identifiers, and behavioral profiles — and therefore require explicit consent before being set.
Functional & Preferences
Cookies that remember choices the visitor has made to enhance their experience beyond basic functionality. Examples include remembering a visitor's language preference, storing their preferred font size or display theme, remembering a username for faster login (without actually authenticating), or saving regional settings like currency or time zone. While these cookies improve user experience, they are not strictly necessary for the website to function. The visitor can use the site without them, even if the experience is less convenient. Therefore, consent is required before setting them.
Marketing & Advertising
Cookies used to track visitors across websites, build advertising profiles, and serve targeted advertisements. This category includes Google Ads remarketing cookies, the Meta (Facebook) Pixel, LinkedIn Insight Tag, TikTok Pixel, Twitter conversion tracking, programmatic advertising cookies from demand-side platforms, and retargeting cookies from networks like Criteo and AdRoll. These cookies are the most privacy-invasive category and are subject to the strictest scrutiny from data protection authorities. Consent is absolutely mandatory, and many enforcement actions have specifically targeted the unauthorized use of marketing cookies.
An important nuance: the "strictly necessary" exemption is narrow and must be interpreted restrictively. A cookie is only exempt if it is genuinely essential for a service the user has actively requested. A website owner cannot simply relabel analytics or marketing cookies as "strictly necessary" to avoid the consent requirement. Data protection authorities, particularly the French CNIL and the Austrian DSB, have issued guidance making clear that analytics cookies — even first-party analytics — are not strictly necessary and do require consent, unless configured in a way that is both anonymous and purely statistical with no cross-site tracking capability.