1. Introduction: why cookie consent matters in 2026
If your website serves users in the European Union (or European Economic Area), cookie consent isn't optional — it's the law. The ePrivacy Directive (often called the "Cookie Law") requires websites to obtain prior informed consent before placing non-essential cookies or trackers on a user's device.
In 2026, enforcement has intensified significantly. EU data protection authorities (DPAs) have issued over €1.2 billion in GDPR fines since 2018, and cookie-related violations account for a growing share. The Belgian DPA alone has issued multiple six-figure fines for cookie consent violations in 2025-2026, targeting both small businesses and large platforms.
This guide covers everything you need to know to get your website's cookie consent compliant — from the legal requirements to choosing a consent platform and testing your setup.
💡 Not sure if your site is compliant? Use our free EU compliance scanner to check your cookie consent setup — takes 10 seconds.
2. Which EU laws govern cookies?
The ePrivacy Directive (2002/58/EC)
The ePrivacy Directive, specifically Article 5(3), is the primary law governing cookies and similar tracking technologies. It requires:
Prior consent: You must obtain consent before storing or accessing information on a user's device
Clear information: Users must be informed about the purpose of cookies in clear, understandable language
Right to withdraw: Users must be able to withdraw consent as easily as they gave it
The ePrivacy Directive was implemented into EU member state law through national legislation, meaning specific requirements vary slightly by country. However, the core consent requirement is uniform across the EU.
The GDPR (2016/679)
The GDPR complements the ePrivacy Directive in several ways:
Consent standard (Art. 4(11), 7): Consent must be freely given, specific, informed, and unambiguous. Silence or pre-ticked boxes do not constitute valid consent
Transparency (Art. 12-14): You must clearly explain what cookies you use and why in your privacy policy
Data protection by design (Art. 25): Privacy-friendly default settings should be the norm
Record-keeping (Art. 30): You must maintain records of processing activities, including cookie consent
The proposed ePrivacy Regulation
The proposed ePrivacy Regulation, intended to replace the existing Directive, has been under negotiation since 2017. As of mid-2026, it has not yet been adopted. The current ePrivacy Directive remains in force, and the general expectation is that the new Regulation will largely codify existing requirements, with potential additions around AI-driven tracking and IoT cookie consent.
⚠️ Important distinction: The ePrivacy Directive covers all cookies placed on a user's device. The GDPR covers the processing of personal data collected through those cookies. Both apply simultaneously.
3. What the law requires in practice
Consent: what valid consent looks like
For cookie consent to be valid under both the ePrivacy Directive and GDPR:
Prior: Consent must be obtained before any non-essential cookies are set (no "consent by scrolling" — the European Court of Justice rejected this in 2019)
Active: A pre-ticked checkbox or an opt-out banner does not constitute valid consent. Users must take a clear affirmative action
Granular: Users must be able to consent to different categories of cookies separately (essential, functional, analytics, marketing)
Easily withdrawn: Withdrawing consent must be as easy as giving it — a "cookie settings" link in the footer is considered best practice
Documented: You must be able to prove that consent was given. Most consent platforms store a timestamped record
Cookie categories you must distinguish
Best practice (and increasingly required by DPAs) is to categorise cookies clearly:
Category
Description
Consent needed?
Strictly necessary
Essential for the website to function (session cookies, authentication, load balancing)
No (legitimate interest)
Functional / Preferences
Remember user preferences, language, region
Yes — implied consent may be acceptable in some interpretations
Analytics / Performance
Track page views, user behaviour, site performance (Google Analytics, Plausible, etc.)
Yes — unless fully anonymised and no data is shared with third parties
Marketing / Advertising
Targeted ads, cross-site tracking, social media pixels (Meta Pixel, Google Ads, LinkedIn Insight)
Yes — explicit, prior consent required
Cookie consent banner: design requirements
EU DPAs have become increasingly specific about cookie banner design:
No dark patterns: Buttons for "Accept all" must not be more prominent than "Reject all" or "Settings". The French CNIL and Belgian DPA have specifically fined companies for making rejection harder than acceptance
Clear purpose: Each cookie category must be explained in plain language — not just "we use cookies to improve your experience"
No cookie walls: Denying access to content because a user refuses non-essential cookies is generally not permitted (with limited exceptions for genuine paywalls)
Mobile-friendly: The banner must work properly on mobile devices without blocking the entire screen
🔍 Scan your cookie consent setup: Our free compliance scanner detects 15+ consent platforms (Cookiebot, OneTrust, CookieYes, Complianz, Klaro, and more) and checks for privacy-policy links.
4. Cookie consent platforms compared
Here are the most popular cookie consent platforms in 2026, with their key features:
Platform
Free tier
Starting price (paid)
Cookie categories
Consent record
Cookiebot (by Usercentrics)
200 URLs, basic scan
€12/mo
✅ Granular
✅ Stored
CookieYes
25 URLs, 5K pageviews
$10/mo
✅ Granular
✅ Stored
Complianz (WordPress)
1 site (limited)
€45/yr
✅ Granular
✅ Stored
OneTrust
Free scan only
$10/mo (Pro)
✅ Granular
✅ Stored
Osano
Basic banner
$199/mo
✅ Granular
✅ Stored
Termly
Basic consent
$23/mo
✅ Granular
✅ Stored
Klaro
Open source
Free / self-hosted
✅ Granular
Manual
Tarteaucitron
Open source
Free / self-hosted
✅ Granular
Manual
Iubenda
Basic banner
€9/mo
✅ Granular
✅ Stored
⚠️ Important: The free scanner detects which consent platform you're using — but having a platform installed doesn't guarantee compliance. The banner must be properly configured (granular categories, no dark patterns, documented consent).
5. Compliance checklist
Use this checklist to verify your cookie consent compliance:
☐ Consent before tracking: All non-essential cookies are blocked until the user gives active consent
☐ Granular categories: Users can accept/reject different categories separately
☐ No dark patterns: "Reject all" is as easy to click as "Accept all"
☐ Clear language: Cookie purposes are explained in plain, non-deceptive language
☐ Privacy policy linked: A link to your full cookie/privacy policy is visible in the banner
☐ Withdraw consent: A "cookie settings" link is permanently available (typically in the footer)
☐ Consent documented: You store consent records with timestamps and details of what was accepted
☐ Mobile friendly: The banner works properly on mobile screens
☐ Cookie policy published: A separate cookie policy page lists all cookies used, their purpose, and retention
☐ No cookie wall: Content is not blocked behind cookie acceptance
☐ Third-party audit: You know what third-party scripts (analytics, ads, social media) your site loads and have accounted for them in your banner
☐ Regular review: Cookies and tracking technologies are reviewed at least annually to ensure accuracy
6. Enforcement and penalties
Cookie consent enforcement has intensified across the EU in 2025-2026. Key trends:
Country
DPA
Notable recent actions
France
CNIL
Multiple €100K+ fines for inadequate cookie consent, including dark pattern violations. CNIL is the most active enforcer.
Belgium
APD/GBA
€250K+ fines for Meta and other platforms for cookie consent violations. Strong focus on documentation.
Italy
Garante
€5M+ total fines for cookie-related GDPR violations in 2025. Active on small and medium businesses.
Spain
AEPD
Systematic sweeps of cookie consent compliance across sectors. Focus on "consent by scrolling" violations.
Germany
Multiple state DPAs
Cookie consent fines under GDPR up to €20M. Increasingly coordinated enforcement across states.
Penalties for cookie consent violations can reach up to €20 million or 4% of annual global turnover (whichever is higher) under Article 83(5) GDPR. The average fine for an SME cookie violation in 2025-2026 ranges from €5,000 to €250,000 depending on severity.
⚠️ Key risk: Many enforcement actions start with a simple user complaint. If a visitor reports your cookie banner, the DPA will investigate — and the cost of non-compliance (fine + legal fees + lost reputation) far exceeds the cost of a consent platform.
7. Free tools to check your cookie consent compliance
You don't need to guess whether your cookie consent setup is compliant. Here are free tools to verify:
EUComply Free Scanner
Our free compliance scanner checks your website for cookie consent platforms, privacy-policy links, legal pages, and security headers. Enter any URL and get results in seconds — no sign-up required.
Scan your site with the free checker to identify gaps
Choose a consent platform from the comparison table above (free options: Klaro, Tarteaucitron if you can self-host; CookieYes if you need hosted)
Configure granular categories — never use binary "accept/reject all" only
Update your privacy policy to include detailed cookie information
Document consent — most paid platforms handle this automatically
Test on mobile and verify the "reject" path is equally easy
📋 Need a complete compliance package? Our Pro tier ($79/yr) generates auditor-ready PDF reports, DPA documents, NIS2 vendor clauses, and EAA accessibility statements — everything you need to prove compliance to clients, auditors, and insurers. See Pro features →