Last updated: 2026-09-05 · Next review: 2026-12-05 · Scope: EU/EEA · Directive 2002/58/EC Article 5(3) (ePrivacy), consolidated text incorporating Directive 2009/136/EC, and Regulation (EU) 2016/679 Articles 4(11) and 7 (the consent standard), applied through national law
Do I need cookie consent?
Prior consent is required when you store or read non-essential information on a user's device, not because you have a website. The trigger is Article 5(3) of the ePrivacy Directive, and it is technology-neutral. The strictly-necessary exemption is narrow. Where consent is required, the standard is the GDPR standard, not a lighter cookie-specific one. This page walks that screen. It is not legal advice and not a binding determination.
The short version
First ask whether you store information on, or read information from, the user's device at all (cookies, local storage, SDKs, pixels, fingerprinting). If not, Article 5(3) does not engage. If yes, classify what you store: only what is strictly necessary to deliver a service the user explicitly requested is exempt from prior consent. Where personal data are processed, GDPR transparency duties can still apply. Analytics and advertising generally need prior consent before they fire. A few national authorities allow a narrow publisher-scoped measurement exemption under conditions; check yours. Where consent is required it must be freely given, specific, informed, and unambiguous, given by a clear affirmative action (Planet49 on pre-ticked boxes), with refuse as easy as accept as a taskforce-majority view, and as easy to withdraw as to give.
Two instruments, one screen
People collapse “cookie consent” into a single GDPR question. The screen is actually two instruments stacked, and keeping them separate is what keeps the answer accurate.
- The trigger is ePrivacy Article 5(3): storing or accessing information on terminal equipment, whatever the technology. GDPR does not itself create the cookie rule.
- The standard, once consent is the basis, is GDPR Articles 4(11) and 7: freely given, specific, informed, unambiguous, a clear affirmative action, and as easy to withdraw as to give.
- The overlayis national. Article 5(3) applies through each Member State's law, so analytics exemptions and cookie-wall stances differ. Check the authority competent for your processing.
This guide uses provision identifiers, short statutory terms, and original plain-English summaries; it does not reproduce full provisions. It is educational content, not legal advice and not a binding determination. Whether a specific cookie or tracker is strictly necessary is a fact-based judgement against the service the user actually requested.
The category map at a glance
Read this after confirming that something is stored on or read from the device. Each row is a distinct category; pick the highest that applies. The free checker encodes this EU-level split. It does not ask whether a national analytics exemption applies, so an analytics answer there always returns consent-required; use this guide's national overlay for that second question.
| What you store or read | Prior consent? | The key condition |
|---|---|---|
| Nothing stored or read on the device | Article 5(3) does not engage | Unusual for a modern site. Confirm third-party embeds and tags before you treat the rule as off. |
| Strictly necessary only | No prior consent | Session, authentication, security, load-balancing, basic cart, recording the consent choice itself. GDPR Articles 13 and 14 still apply where personal data are processed; national law may add notice duties. The exemption is judged against the service the user explicitly requested. |
| Analytics, measurement, or A/B testing | Prior consent, generally | Not strictly necessary for the requested service. A few national authorities allow a narrow publisher-scoped, privacy-preserving measurement exemption under conditions (CNIL Sheet no. 16 is a French worked example). The free checker does not assess that overlay and treats analytics as consent-required. Check your authority; do not assume a pan-EU exemption. |
| Advertising, retargeting, social, or other third-party tracking | Prior consent | Clearly non-essential. Third-party tags can also act as separate or joint controllers for the data they collect, so settle who is responsible for what before you deploy them. |
| Categories not yet known | Do not pick a path yet | Audit every cookie, local-storage item, SDK, pixel, and tag, including third-party ones, then re-run the classification. The strictly-necessary test is narrow. |
Version and jurisdiction stamp: original plain-English summaries of Article 5(3) of Directive 2002/58/EC as it reads in the consolidated text incorporating Directive 2009/136/EC (EUR-Lex CELEX 02002L0058-20091219), read with GDPR Articles 4(11) and 7 and the EDPB Guidelines 05/2020 on consent. Provision identifiers, short statutory terms, and original plain-English summaries; not full provisions. Applied through national law by each Member State's competent authority. Checked 2026-09-05. Next review 2026-12-05.
How to decide, step by step
- 1
Check whether Article 5(3) engages at all
“Do I need cookie consent?” is not the same question as “do I have a website.” The rule that decides it is Article 5(3) of the ePrivacy Directive 2002/58/EC, as amended by Directive 2009/136/EC. It engages when you store information on, or gain access to information already stored on, a user's terminal equipment. Cookies, local storage, SDKs, pixels, and fingerprinting can fall within that trigger when they actually store information on the device or gain access to information from it; the technology's label is not decisive. If you place or read nothing on the device at all, the cookie rule does not engage and no cookie consent is required on that basis. That outcome is unusual for a modern site or app, so confirm it covers third-party embeds (maps, video, fonts, social widgets) and analytics tags, which often set or read device data without being obvious. Re-check the moment you add any.
- 2
Classify what you store against the strictly-necessary exemption
Once the rule engages, the path splits on what you store or read. Article 5(3) exempts from prior consent only what is strictly necessary to deliver a service the user has explicitly requested, or what is solely needed to carry out a transmission. Typical examples are a session or authentication cookie, a security or load-balancing cookie, a shopping-cart cookie, and the cookie that records the user's own consent choice. Two cautions sit on that exemption. First, it is narrow and is judged against the specific service the user asked for, not against what is convenient for measurement, marketing, or product analytics. Second, exemption from consent does not automatically remove every notice duty. Where personal data are processed, GDPR Articles 13 and 14 still apply; national implementing law may add more. A cookie notice is prudent, but it is not a separate universal Article 5(3) requirement. If the categories in use are not yet known, that is itself the finding: audit every cookie, local-storage item, SDK, pixel, and tag, including third-party ones, classify each against the requested service, and only then continue.
- 3
If anything is non-essential, hold it until prior consent
Analytics, measurement, A/B-testing, advertising, retargeting, social-media tags, and other third-party tracking are generally not strictly necessary, so Article 5(3) requires the user's prior consentbefore they fire. Prior means what it says: non-essential scripts and tags may be set or read only once the user has agreed. Loading them on the first page view, before any choice is made, means they ran without consent. Strictly necessary items may still load in the meantime. One hedge belongs here and nowhere else: a few national authorities allow a narrow exemption for certain privacy-preserving, first-party audience measurement under strict conditions. The CNIL's Sheet no. 16 is a current worked example under French law (inform users, offer an objection, limit the tracer to a single site or application publisher with no cross-checking, truncated IP, limited lifetime; a third-party processor may serve several publishers only if each publisher's data and trackers stay independent). Most large analytics offerings still fall outside it. That is a national overlay, not a general EU rule, so check your competent authority's current guidance before you treat analytics as exempt rather than assuming the exemption travels.
- 4
Apply the GDPR consent standard, not a lighter cookie standard
Where Article 5(3) requires consent, the standard of that consent is the GDPR standard, not a lighter cookie-specific one. Articles 4(11) and 7 require consent to be freely given, specific, informed, and unambiguous, given by a clear affirmative action. The Court of Justice confirmed the pre-ticked-checkbox point for cookies in Planet49 (Case C-673/17, judgment of 1 October 2019): a pre-ticked box the user must deselect is not valid consent. EDPB Guidelines 05/2020 add that inactivity, silence, and continued browsing are not valid consent either. An accept-only banner is a different problem (whether refusing is as easy as accepting), not the Planet49 holding. Information has to come first. Tell the user what you store or read, why, how long cookies last, and whether third parties may access them, in plain language, before any non-essential cookie is set. Where GDPR Article 13 applies, identify the recipients or categories of recipients (Article 5(3) read with Articles 4(11) and 13).
- 5
Check the mechanism: refuse, granularity, withdrawal, records
Four mechanism tests sit on top of the standard. First, refusing must be as easy as accepting. A vast majority of Cookie Banner Taskforce authorities (report adopted 18 January 2023) consider that a reject option should appear on every layer that contains an accept button. Design is assessed case by case; the report does not impose a single colour standard, and a few authorities on the taskforce disagreed. Second, consent must stay specific and granular, so users can agree to some purposes (for example analytics) and not others (for example advertising) rather than a single all-or-nothing choice (Article 4(11)). Third, users can withdraw consent at any time, as easily as they gave it (Article 7(3)), which in practice means a persistent way to reopen the cookie settings and change or revoke the choice. Fourth, you must be able to demonstrate consent (Article 7(1)): who consented, when, to what information, and to which purposes. A fifth, separate question is the cookie wall, which the next section isolates because the EU position is not uniform.
- 6
Check the national overlay, record the reasoning, and re-check
Article 5(3) applies through national law. Each Member State's competent authority (the data-protection supervisory authority or, in some States, another national regulator) publishes detailed guidance, and two overlays move the most: whether a narrow first-party analytics exemption exists, and whether a cookie wall or “consent or pay” model is permitted under conditions. Check the authority competent for your processing, not a pan-EU blog summary. Keep the assessment and its reasoning with your records, even where the result is that only strictly necessary items are in use, because that conclusion is fragile. The answer is not permanent: adding an analytics tag, a marketing pixel, a third-party embed, or a new SDK can move you from exempt to consent-required on the next deploy. When the position is unclear, document your reasoning and take advice.
Cookie walls and “consent or pay,” in one place
This is the overlay that most pan-EU cookie explainers get wrong, so it is worth isolating. Two different questions get mixed: how easy it is to refuse on the banner, and whether access to the service can be conditioned on consent.
Refuse as easy as accept
For consent to be freely given (Article 7), a vast majority of Cookie Banner Taskforce authorities consider that a reject option should appear on every layer that contains an accept button. The report does not impose a single colour or contrast standard; design is assessed case by case, but it must not clearly push or mislead users toward acceptance. An Accept button next to a buried “manage preferences” link is the design most of those authorities were targeting. This is about the banner, not about whether the rest of the site loads. A few authorities on the taskforce disagreed, so check your own.
Cookie walls / consent or pay
Conditioning access to the service on consent to non-necessary cookies (a cookie wall) can undermine free consent. The EDPB Cookie Banner Taskforce and Guidelines 05/2020 treat a strict wall as usually not freely given. EDPB Opinion 08/2024 then addresses “consent or pay” models implemented by large online platforms: for those platforms using behavioural advertising, a binary pay-or-consent choice will not produce valid consent in most cases, and the opinion is scoped to that class of platforms, not a general permission for every site. Some national authorities have issued criteria for assessing such models. Check your competent authority's current guidance rather than copying another Member State's model or reading Opinion 08/2024 as a green light.
If you are unsure which model you run, that is itself the finding: settle whether users can refuse on the first layer, and whether the rest of the service is withheld until they accept, before you treat consent as freely given.
Run the same screen as a free interactive check
The free GDPR cookie consent checker asks six questions (whether you store or read device data, which category, prior to placing, clear affirmative action, refuse as easy as accept, easy withdrawal), then returns a structured assessment, with the reasons. Use this guide for the method; use the checker to run it. Both are starting points, not legal advice: whether a specific cookie is strictly necessary is a fact-based judgement, and Article 5(3) applies through national law. The checker runs in your browser and stores nothing.
Six mistakes that produce the wrong answer
Treating a banner as the rule
The rule is storage or access on the device, not the existence of a banner. A site that uses only strictly necessary cookies does not need a consent banner for those items. A site that fires analytics on page load has already failed the prior-consent test, banner or not.
Calling analytics strictly necessary
Audience measurement is useful to you. That does not make it essential to the service the user asked for. Treat analytics as consent-required unless your competent authority has published a narrow, conditional first-party exemption that your implementation actually meets.
Counting only HTTP cookies
Article 5(3) is technology-neutral, but the trigger is still actual storage or access on the device. Local storage, SDKs, pixels, and fingerprinting can fall within it when they store or read information there. A cookieless fingerprinting script does not escape the rule merely by avoiding a Set-Cookie header, if it still accesses information on the terminal equipment.
An accept-only banner, or consent from scrolling
GDPR consent needs a clear affirmative action (Article 4(11)). Planet49 rejected pre-ticked boxes for cookies. Inactivity, silence, and continued browsing are invalid under EDPB Guidelines 05/2020. An accept-only banner is a refuse-as-easy problem (Cookie Banner Taskforce, majority view), not the Planet49 holding.
Hiding reject behind extra clicks
A vast majority of Cookie Banner Taskforce authorities consider that a reject option should appear on every layer that contains an accept button. Design is assessed case by case and the report does not impose a single colour standard, but it must not clearly push users toward acceptance. A bright Accept next to a buried 'manage preferences' path is the design most of those authorities were targeting.
Copying another Member State's analytics exemption or cookie-wall stance
Article 5(3) bites through national law. A publisher-scoped measurement exemption, or assessment criteria for a consent-or-pay model, that one authority has issued is not a general EU rule. Check the authority competent for your processing.
Where this page sits in the GDPR cluster
| Surface | Job | Format |
|---|---|---|
| This guide | Explain the Article 5(3) screen so a person (or an AI answer) can follow whether prior consent is required | Long-form guide |
| Cookie consent checker | Run the same ePrivacy Article 5(3) + GDPR consent test as a six-question questionnaire | Free tool |
| Do I need a DPIA? | The Article 35 necessity screen, a different GDPR question from cookies | Long-form guide |
| DPA necessity checker | Whether an Article 28 contract is required between the parties | Free tool |
| Free compliance tools hub | The rest of the GDPR toolkit (ROPA, EU representative, DPIA checker) and the other free checkers | Tools index |
Frequently asked questions
Do I need cookie consent?
You need prior consent when you store or read non-essential information on a user's device. The trigger is Article 5(3) of the ePrivacy Directive: cookies, local storage, SDKs, pixels, and fingerprinting can fall within it when they actually store or access information on the device. If you use only what is strictly necessary to deliver a service the user explicitly requested (session, security, load-balancing, basic cart, remembering the consent choice itself), you do not need prior consent for those items. Where personal data are processed, GDPR transparency duties can still apply. Analytics and advertising generally need consent. A few national authorities allow a narrow publisher-scoped exemption for privacy-preserving audience measurement under strict conditions, so check your competent authority before relying on one. If you store or read nothing on the device at all, Article 5(3) does not engage.
Do I always need a cookie banner?
Not always. You need prior consent, commonly collected through a banner, whenever you set or read non-essential cookies or trackers. If you use only strictly necessary items, you do not need consent for them and a consent banner is not required on that basis. A cookie notice is still prudent, and GDPR Articles 13 and 14 apply where personal data are processed, but that notice is not a separate universal Article 5(3) duty. The trigger is non-essential storage or access, not the existence of a banner.
Which cookies count as strictly necessary?
Only those essential to deliver a service the user explicitly requested, or solely needed to carry out a transmission. Common examples are session and authentication cookies, security and load-balancing cookies, a shopping-cart cookie, and the cookie that stores the user's own consent choice. The test is judged against the requested service and is narrow: analytics, advertising, and most third-party trackers generally do not qualify. Adding a convenience feature you find useful does not make it strictly necessary.
Do analytics cookies need consent?
Generally yes. Analytics and measurement are not strictly necessary to deliver the service the user asked for, so they generally need prior consent under Article 5(3). A few national authorities allow a narrow exemption for certain privacy-preserving audience-measurement analytics under strict conditions. The CNIL's Sheet no. 16 is a current French worked example (inform, offer an objection, limit the tracer to a single publisher with no cross-checking, truncated IP, limited lifetime; a processor may serve several publishers only if each publisher's data stay independent). Most large analytics offerings still fall outside it. That exemption is not a general EU rule, and the free checker does not assess it: an analytics answer there returns consent-required. Check your national authority's current guidance before treating analytics as exempt.
Are pre-ticked boxes or 'by continuing you accept' valid consent?
No. GDPR consent must be unambiguous and given by a clear affirmative action (Article 4(11)). The Court of Justice held in Planet49 (Case C-673/17, judgment of 1 October 2019) that a pre-ticked checkbox the user must deselect is not valid consent for cookies. EDPB Guidelines 05/2020 add that inactivity, silence, and continued browsing are not valid consent. An accept-only banner is a refuse-as-easy question (Cookie Banner Taskforce, majority view), not the Planet49 holding.
Are cookie walls allowed?
It depends and is contested. The EDPB Cookie Banner Taskforce and Guidelines 05/2020 treat conditioning access to a service on consent to non-necessary cookies as generally not freely given, so a strict cookie wall usually undermines valid consent. EDPB Opinion 08/2024 (17 April 2024) then addresses consent-or-pay models implemented by large online platforms: for those platforms using behavioural advertising, a binary pay-or-consent choice will not produce valid consent in most cases, and the opinion is scoped to that class of platforms, not a general permission. Some national authorities have issued criteria for assessing such models. Check your own competent authority's current guidance rather than treating either extreme as settled EU-wide law. Separately, a vast majority of Cookie Banner Taskforce authorities consider that a reject option should appear on every layer that contains an accept button (report of 18 January 2023).
How is this different from the free cookie consent checker?
This page is the long-form method: whether Article 5(3) engages, the strictly-necessary classification, prior consent for non-essential items, the GDPR consent standard, the banner mechanism, and the national overlay, with the primary sources. The free GDPR cookie consent checker at /resources/gdpr-cookie-consent-checker runs the same test as a six-question questionnaire and returns a structured assessment (consent-required, exempt, review, or not-applicable). Use the guide to understand the test; use the checker to run it. Neither is legal advice or a binding determination: whether a specific cookie is strictly necessary is a fact-based judgement, and Article 5(3) applies through national law.
Primary sources
- Directive 2002/58/EC (ePrivacy Directive), Article 5(3), consolidated text incorporating Directive 2009/136/EC (EUR-Lex CELEX 02002L0058-20091219). The original 2002 Official Journal text used a right-to-refuse formulation; the prior-consent rule this page applies is the 2009 amendment, which is what the consolidated text carries. eur-lex.europa.eu (checked 2026-09-05).
- Regulation (EU) 2016/679 (GDPR), Articles 4(11), 7, and 13, for the standard of consent (EUR-Lex). eur-lex.europa.eu (checked 2026-09-05).
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, adopted 4 May 2020. www.edpb.europa.eu (checked 2026-09-05).
- EDPB Report of the work undertaken by the Cookie Banner Taskforce, adopted 18 January 2023 (reject controls and banner design). www.edpb.europa.eu (checked 2026-09-05).
- CJEU, Planet49 (Case C-673/17), judgment of 1 October 2019 (pre-ticked boxes are not valid cookie consent). eur-lex.europa.eu (checked 2026-09-05).
- EDPB Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms, adopted 17 April 2024 (the model is not treated as freely given by default; scoped to large online platforms, not a general permission). www.edpb.europa.eu (checked 2026-09-05).
- CNIL, Sheet no. 16: Use analytics on your websites and applications (a national worked example of a conditional publisher-scoped audience-measurement exemption under French law; not a general EU rule). www.cnil.fr (checked 2026-09-05).
Written and maintained by the ISMS Copilot team. Last reviewed 2026-09-05. Next review 2026-12-05.
This page summarises, in original wording, Article 5(3) of Directive 2002/58/EC as it reads in the consolidated text incorporating Directive 2009/136/EC (EUR-Lex CELEX 02002L0058-20091219), the GDPR consent standard in Articles 4(11) and 7 of Regulation (EU) 2016/679, the EDPB Guidelines 05/2020 on consent, the EDPB Cookie Banner Taskforce report of 18 January 2023, the Court of Justice judgment in Planet49 (Case C-673/17, 1 October 2019), EDPB Opinion 08/2024 on consent-or-pay models implemented by large online platforms, and CNIL Sheet no. 16 as a national worked example of a conditional analytics exemption. This guide uses provision identifiers, short statutory terms, and original plain-English summaries; it does not reproduce full provisions. It is educational content, not legal advice and not a binding determination. Whether a specific cookie or tracker is strictly necessary is a fact-based judgement, and Article 5(3) applies through national law, so the guidance of the competent authority in your country governs the detail (including analytics exemptions and cookie walls).
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
