ConsentPixel – Privacy · Verified

GDPR & EU Compliance · Cookie Consent

GDPR Cookie Consent Requirements 2026: What Every Website Serving EU Visitors Must Know

In September 2025, France's CNIL fined Google €325 million and Shein €150 million for cookie violations — in a single day. In 2025 alone, European regulators issued €1.2 billion in GDPR penalties. The rules have not changed dramatically, but the enforcement has. Here is exactly what GDPR cookie consent requires in 2026, where most websites still get it wrong, and what a compliant implementation actually looks like.

By the ConsentPixel — Privacy · Verified team July 2026 14 min read For website owners and agencies serving EU and UK visitors
€1.2B
Total GDPR fines issued in 2025 alone — a 22% year-on-year increase
€325M
CNIL fine against Google in September 2025 — for cookie consent failures
Before
The one word that decides compliance: cookies and pixels must not fire before consent

GDPR cookie consent is one of the most actively enforced areas of European data protection law. The fundamental rules have been in place since 2018, but enforcement has accelerated sharply in 2025 and 2026, and the EDPB has expanded the scope of what counts as a "cookie" well beyond the traditional HTTP cookie. If you operate a website that receives visitors from any EU or EEA country — or the UK — this article gives you the current legal requirements, the enforcement reality, and the technical configuration that actually satisfies both. This is informational, not legal advice; consult qualified counsel for your specific situation.

GDPR cookie compliance is governed by two overlapping instruments, not one. Understanding which does what is essential for understanding why the requirements are what they are:

The ePrivacy Directive (2002/58/EC, amended 2009) — often called the EU Cookie Law — is the specific instrument that created the consent requirement for cookies. Article 5(3) states that any cookie not strictly necessary for a service the user explicitly requested requires prior consent. This applies to analytics cookies, advertising cookies, functional cookies, social media embeds, tracking pixels, device fingerprinting, and URL-based identifiers. Member states implement the Directive through national legislation, which is why enforcement and specific interpretations vary across the EU.

GDPR (General Data Protection Regulation, 2018) defines what valid consent looks like — it must be freely given, specific, informed, and unambiguous. When cookies process personal data (which analytics and advertising cookies always do, since they transmit IP addresses and device identifiers), GDPR's lawful basis requirements apply alongside the ePrivacy Directive's consent requirement. In practice this means every non-essential cookie has two compliance layers: ePrivacy requires consent before it's placed, and GDPR defines the quality of that consent.

The ePrivacy Regulation is dead — and that matters

After eight years of stalled negotiations, the European Commission formally withdrew the proposed ePrivacy Regulation in February 2025. The practical consequence: cookie rules in the EU will continue to be governed by the 2002 ePrivacy Directive, transposed differently by each member state. Harmonisation is not coming. The divergence between national implementations — and national enforcement intensity — will continue to grow. For businesses operating across multiple EU markets, the national differences in enforcement priority are as important as the baseline EU requirements.

The "strictly necessary" exemption is the only category that doesn't require consent. Its definition is narrow — the ICO, CNIL, and EDPB all agree that strictly necessary means the service literally cannot function without it from the user's perspective, not just that it makes the service work better for the business.

GDPR Article 4(11) defines consent as a "freely given, specific, informed and unambiguous indication of the data subject's wishes." All four elements must be present. If any one is missing, the consent is legally invalid. Courts and regulators have tested each element extensively, and the specific requirements are now well established:

Freely given

The visitor must have a genuine choice. Cookie walls — where users must accept cookies to access content — are generally non-compliant. The EDPB has also stated that "consent or pay" models (where users either pay a subscription or accept tracking) do not constitute freely given consent for large platforms in most cases (EDPB Opinion 08/2024). Reject must be as easy as accept — confirmed in the CNIL's €325M Google fine and now actively enforced across most EU member states.

Specific

Consent must be given separately for each purpose. You cannot bundle analytics, advertising, and functional cookies into a single checkbox. A visitor who consents to "analytics to improve site performance" has not consented to advertising tracking and has not consented to data flowing to Meta or Google Ads. Granular category controls are a GDPR requirement, not a design option.

Informed

The visitor must understand what they're consenting to before they consent. This means the consent banner itself — not the linked privacy policy — must identify the specific tools being used (Google Analytics, Meta Pixel, etc.) and explain what they do and who receives the data. Vague references to "third-party cookies" or "advertising partners" have been found insufficient by multiple DPAs including France's CNIL and the Dutch AP.

Unambiguous

Continuing to browse is not consent. Scrolling is not consent. Pre-ticked boxes are not consent (Planet49 ruling, CJEU 2019 — still binding). The visitor must take a positive action — clicking Accept or equivalent. Silence, inactivity, or dismissal of a banner without explicit acceptance does not constitute valid consent under GDPR.

Prior consent — the same requirement as CIPA

GDPR and the ePrivacy Directive require consent to precede cookie placement — the cookie must not fire while the banner is still loading, not fire while the visitor is reading the banner, not fire if the visitor dismisses or ignores the banner. The standard is identical to what US courts require under CIPA for California visitors: prior, affirmative, technically enforced consent before any tracking fires. One compliant CMP configuration satisfies both.

EDPB's expanded scope: pixels, fingerprinting, URL tracking

The European Data Protection Board's Guidelines 2/2023 on technical scope of the ePrivacy Directive, finalised in October 2024, formally expanded the scope of Article 5(3) beyond traditional HTTP cookies. This is the most significant regulatory development for tracking pixel operators in 2025–2026.

The EDPB confirmed that the consent requirement applies to any technology that stores or accesses information on a user's terminal device — not just cookies. Specifically named in the guidelines:

  • Tracking pixels embedded in web pages — any 1x1 pixel or transparent image that triggers a request to a third-party server on page load requires prior consent, because it accesses the user's terminal equipment (the browser initiates the request) and transmits identifying information (IP address, device headers, unique identifiers)
  • URL-based tracking — UTM parameters and link decorators that persist individual user identifiers across sessions fall within scope, particularly where they're used to track individual user journeys
  • Device fingerprinting — collecting combinations of browser characteristics (user agent, screen resolution, installed fonts, timezone) to identify individual users requires prior consent regardless of whether a cookie is set
  • HTML5 local storage and IndexedDB — any storage or access on a user's device for non-essential purposes requires consent, regardless of the technical mechanism used

The practical implication for Meta Pixel, TikTok Pixel, Google Analytics, Microsoft Clarity, and similar tools: they are all explicitly within EDPB's expanded Article 5(3) scope. None of them can fire before consent under EU law.

Recent enforcement: the cases every website owner should know

€325M
Google — CNIL (France) · September 2025
Two violations: displaying advertising inside Gmail without prior consent, and making the cookie rejection process significantly harder than acceptance during account creation. The CNIL found 74 million accounts affected by invalid consent. Reject was buried; accept was prominent. This asymmetry alone generated one of the largest cookie fines ever.
€150M
Shein — CNIL (France) · September 2025
Cookie violations including pre-enabled non-essential cookies and an inadequate rejection mechanism. Both Shein and Google fines were issued on the same day, demonstrating CNIL's capacity for coordinated high-value enforcement actions.
€15M
Swedish pharmacy chains — IMY (Sweden) · August 2025
Multiple pharmacy chains fined for deploying Meta Pixel on healthcare websites without proper user consent, transmitting sensitive health-related browsing data to Meta. The IMY held that liability rested with website operators, not Meta — you are responsible for what your pixels do.
€310M
LinkedIn — Irish DPC · October 2024
Behavioural advertising without valid legal basis. LinkedIn used contract as a legal basis for targeted advertising — the DPC found that consent was the only valid basis for behavioural advertising and that LinkedIn's approach failed to meet the GDPR standard. Microsoft set aside $425M before the decision, signalling that parent companies take these risks seriously.

What most websites still get wrong

Based on the enforcement record and DPA audit findings, the most common GDPR cookie consent failures in 2026 are:

FailureWhy it fails GDPRHow common
Pixels fire while the consent banner is loadingPrior consent requires zero tracking before the choice is made — even 50ms of pre-consent pixel activity is non-compliantExtremely common
Reject is harder to find than AcceptFreely given requires equal prominence — the Google €325M fine was partly for this exact asymmetryVery common
Pre-ticked optional cookie categoriesUnambiguous consent requires active action — pre-ticked boxes have been non-compliant since Planet49 (2019)Common
"By using this site you agree to cookies"Continued browsing is not consent — unambiguous requires a positive actionStill common
Cookie wall (must accept to access content)Freely given requires a genuine choice — access cannot be conditioned on tracking acceptanceModerately common
Single checkbox for all cookie purposesSpecific consent requires granular categories — analytics and advertising are separate purposesVery common
Privacy policy disclosure instead of banner disclosureInformed consent requires information before consent is obtained — a linked policy doesn't satisfy thisCommon on smaller sites
No consent records / timestampsGDPR accountability principle requires controllers to demonstrate consent was givenVery common

What a compliant configuration looks like

A GDPR-compliant cookie consent configuration has five non-negotiable technical properties:

  1. All non-essential scripts are blocked before consent. When a visitor lands on your page, zero requests to Google Analytics, Meta Pixel, TikTok, Hotjar, Clarity, or any other non-essential tracking tool should appear in the network tab. The CMP must enforce this blocking — displaying a banner while scripts load in the background is a violation.
  2. Accept and Reject are equally prominent on the first layer. Both options must be visible on the initial banner view without requiring the visitor to click through to a second layer to find Reject. A prominent Accept button with a small "Manage preferences" link that hides Reject is non-compliant.
  3. Granular category controls. At minimum, analytics and advertising must be separate consent categories. The visitor must be able to accept analytics but decline advertising, or decline both independently.
  4. Consent records with timestamps. Every consent event must be logged with: the timestamp when the choice was made, the version of the banner shown, the specific categories accepted or declined, and an identifier that ties the record to the session. These records must be producible within days if a DPA investigation asks for them.
  5. Withdrawal as easy as consent. GDPR Article 7(3) requires that withdrawal of consent must be as easy as giving it. A visible, accessible preference centre that lets visitors change or withdraw consent at any time is mandatory.
GDPR-compliant cookie consent: the required sequence Visitor arrives All scripts blocked Banner shown Accept + Reject equal prominence Visitor chooses Granular per purpose category Consent logged Timestamp + version + categories stored Scripts fire Only accepted categories only Non-compliant: any tracking request before Step 4 = ePrivacy Directive violation This applies to Google Analytics, Meta Pixel, Hotjar, Clarity, LinkedIn Tag — every non-essential script
The GDPR-compliant sequence. Any tracking request appearing before the consent log entry in Step 4 is a violation of the ePrivacy Directive.

Country-level differences that matter

Because the ePrivacy Regulation was withdrawn, the ePrivacy Directive continues to be implemented differently by each EU member state. For businesses operating across multiple EU markets, these differences affect which DPA is most likely to investigate you and what specific requirements apply:

CountryRegulatorKnown enforcement focusNotable requirement
FranceCNILHighest enforcement intensity in EU — cookie fines, email tracking, ad-techReject must be as easy as accept on first layer; formal guidance on email tracking pixels (April 2026)
NetherlandsAP (Autoriteit Persoonsgegevens)Third-party trackers, pre-ticked boxes — issued formal warnings to 200+ websites and fined Kruidvat €600KTechnical script blocking enforcement — Dutch AP reviews actual script behaviour, not just banner design
GermanyDSK (federal coordination) + 16 state DPAsTTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz) implements ePrivacy locally — stricter than many member statesLegitimate interest cannot be used for non-essential cookies; consent required for analytics
ItalyGaranteCookie walls, scroll consent, dark patternsEncourages use of documented CMPs; issued guidance on cookie classification
BelgiumAPDIAB TCF framework — APD's major ruling on TCF created years of litigationIAB TCF compliance is not a GDPR safe harbor; underlying consent obligations still apply
SpainAEPDHighest count of GDPR fines by number in Europe — active enforcement against SMEsGranular cookie categories required; cookie audit tools expected

The bottom line

GDPR cookie consent in 2026 is not a banner design question. It is a technical enforcement question. The CNIL's €325M fine against Google was not for having a bad privacy policy — it was for making reject harder than accept and displaying ads without prior consent. The Swedish pharmacy fines were not for having a confusing banner — they were for Meta Pixel firing before consent and transmitting health-related browsing data to Meta. The pattern is the same in every major enforcement action: the tools fired before consent was obtained, or the consent mechanism failed to be technically enforced. A compliant CMP that blocks all non-essential scripts before consent, presents Accept and Reject with equal prominence, logs every choice with a timestamp, and enables withdrawal as easily as consent is not optional in 2026. It is the minimum required by law and the minimum required to avoid joining the enforcement record above. This is informational, not legal advice; consult qualified counsel for specific situations.

See whether your site meets GDPR cookie consent requirements

ConsentPixel — Privacy · Verified scans any website and shows exactly which scripts fire before consent — the same test DPA audit tools run. Free, no card required.

Scan my site free

Frequently asked questions

Does GDPR require a cookie banner?

GDPR itself does not mandate a specific banner format. However, the ePrivacy Directive requires prior consent before any non-essential cookie or tracking technology is placed on a visitor's device — and in practice, a consent management platform displaying a consent banner is the standard and legally accepted mechanism for collecting, recording, and managing this consent. The banner must offer both Accept and Reject with equal visual prominence and must not pre-tick any optional categories. Not legal advice.

Does Google Analytics need consent under GDPR?

Yes. Google Analytics is not strictly necessary for website operation, so it requires prior consent under the ePrivacy Directive and GDPR before placing cookies or transmitting user data. Multiple DPAs — including the Austrian DSB, French CNIL, Italian Garante, and Dutch AP — have ruled that GA transfers user data to the US without adequate safeguards. Even within the EU, GA4 must be blocked until consent is obtained. Not legal advice.

What is the maximum GDPR fine for cookie violations?

Under GDPR, the maximum fine for violations is €20 million or 4% of global annual turnover, whichever is higher. Cookie violations that breach the ePrivacy Directive alone may carry lower national-level fines in some member states, but where GDPR's data protection principles are also violated (which most tracking cookie deployments will trigger), the higher GDPR fine ceiling applies. France's CNIL imposed €325M on Google and €150M on Shein in September 2025 for cookie violations.

Does GDPR cookie consent apply to B2B websites?

Yes. GDPR applies to the processing of personal data of natural persons — B2B website visitors are natural persons whose IP addresses and device identifiers are collected by tracking cookies. There is no B2B exemption from cookie consent requirements. Even if your website targets business clients, if it tracks individual visitors using non-essential cookies, prior consent is required for EU visitors. Not legal advice.

Can legitimate interest be used for analytics cookies instead of consent?

No, not for the ePrivacy Directive layer. The ePrivacy Directive requires consent before placing non-essential cookies — it does not permit legitimate interest as an alternative legal basis. GDPR's legitimate interest provision (Article 6(1)(f)) applies to data processing, but it cannot substitute for the prior consent requirement under ePrivacy Article 5(3). Multiple DPAs and the CJEU have confirmed this: analytics cookies require consent, not legitimate interest. Not legal advice.

ConsentPixel — Privacy · Verified
We build GDPR and CIPA-first consent enforcement for websites and the agencies that manage them. This article is informational and not legal advice. GDPR enforcement evolves rapidly — verify current DPA guidance for your jurisdiction. Consult qualified counsel for specific situations.
Scroll to Top