Key takeaways
The EU has a common cookie baseline, but it does not have one cookie enforcement office. Each country applies the ePrivacy Directive through national law, while GDPR sets the standard for valid consent when personal data is involved.
For an ordinary website, the defensible starting point is simple: block non-essential storage and tracking until the visitor chooses; make refusal as easy as acceptance; explain purposes and third parties plainly; and leave a persistent way to change the choice.
The differences still matter. France permits a narrow audience-measurement exemption under strict conditions. Dutch law has an exemption for analytics with little or no privacy impact. Italy normally prevents you from asking a refuser again for six months. The UK now has specific statistical and service-improvement exceptions, but they come with conditions and an objection mechanism. Switzerland does not copy the EU's prior-consent rule wholesale.
There is no credible public dataset that supports neat country-by-country "acceptance rate" percentages across all banner designs and audiences. Compare country segments only within your own measurement system, using the same definitions, banner design, traffic mix, and period.
The EU and EEA baseline
Article 5(3) of the ePrivacy Directive covers storing information on, or accessing information from, a user's device. Cookies are the obvious example, but the rule is technology-neutral. Pixels, local storage, software-development kits, tracking links, and some forms of fingerprinting do not escape scrutiny because they lack the word "cookie." The European Data Protection Board confirmed that broad technical scope in its final 2024 guidance.
Storage or access is allowed without consent where it is strictly necessary to transmit a communication or provide a service the user explicitly requested. A basket cookie can qualify. An advertising identifier does not become necessary because the marketing team likes it. "Necessary for our business model" is not the legal test.
Where consent is required, GDPR supplies the standard: it must be freely given, specific, informed, and unambiguous. In practice:
- Do not set non-essential cookies before the user acts.
- Do not treat scrolling, silence, or continued browsing as agreement.
- Do not pre-tick optional categories.
- Give people a real refusal route without hiding it behind extra friction.
- Make withdrawal as easy as giving consent.
- Keep a record of the choice and the information shown at the time.
This is why a banner is not the whole compliance job. If an ad tag fires while the banner is still loading, the nicest button design in Europe will not rescue the implementation. Start with what the ePrivacy Directive requires, then check whether your site actually follows it.
GDPR is not your cookie permission slip
Website owners regularly argue that "legitimate interests" lets them set analytics or advertising cookies. That mixes two legal questions. The ePrivacy rule governs access to the device. GDPR governs later processing of personal data. You may need to satisfy both. A GDPR legal basis does not erase an ePrivacy consent requirement.
What happened to the ePrivacy Regulation?
The proposed ePrivacy Regulation was supposed to replace the 2002 directive with a directly applicable EU regulation. It spent years stuck in negotiations.
On 11 February 2025, the European Commission placed the proposal on the withdrawal list in its 2025 work programme, saying that no agreement was foreseeable and that the proposal was outdated in light of later legislation. The withdrawal was formally published in the EU Official Journal on 6 October 2025.
So the promised replacement did not arrive. The directive and national implementing laws remain the working framework. That does not mean cookie law is frozen forever: courts, national guidance, enforcement decisions, and later legislation still change how the rules work. It does mean you should stop planning around a mythical imminent ePrivacy Regulation.
Check the implementation, not just the banner. Run a free cookie scan to see which trackers load before a visitor chooses. Then compare the result with the rules below.
Cookie consent rules by country at a glance
This table is a working compliance map, not a claim that one setting guarantees compliance everywhere.
| Market | Main authority | Default position for non-essential tracking | Analytics without consent? | Detail that changes implementation |
|---|---|---|---|---|
| France | CNIL | Prior consent | Sometimes, under CNIL's narrow audience-measurement conditions | Refusing must be as easy as accepting |
| Germany | State data protection authorities; other competent bodies under national law | Prior consent under TDDDG | No broad analytics exemption | Private litigation can add risk beyond regulator action |
| Netherlands | AP; ACM has telecom-law responsibilities | Prior consent | Yes, for analytics with little or no privacy impact | Configuration and third-party use matter |
| Belgium | GBA/APD | Prior consent | No broad exemption to assume | Consent must be demonstrable and free |
| Spain | AEPD | Prior consent | No broad exemption to assume | Accept and reject should be offered at the same level |
| Italy | Garante | Prior consent | Technical analytics may qualify only in constrained cases | After refusal, do not re-prompt for at least six months unless an exception applies |
| Austria | DSB | Prior consent | No broad exemption to assume | Cookie consent does not cure separate data-transfer problems |
| Ireland | DPC | Prior consent | No broad exemption to assume | DPC guidance applies the same affirmative-consent model |
| Poland | UODO; national telecom framework | Prior consent | No broad exemption to assume | Use Polish-language information for a Polish audience |
| Denmark, Sweden, Finland | National telecom/data protection authorities | Prior consent | Do not assume one regional exemption | National guidance and enforcement channels differ |
| Norway | Datatilsynet and Nkom | GDPR-standard consent under the Electronic Communications Act | Strictly necessary exception; do not assume a general analytics carve-out | New cookie rules took effect on 1 January 2025 |
| United Kingdom | ICO | Consent unless a PECR exception fits | A conditional statistical-purpose exception now exists | Give clear information and a simple way to object where the exception requires it |
| Switzerland | FDPIC | Case-specific under the FADP and telecom rules | No EU-style blanket answer | High-risk profiling and third-party ad tracking can require consent |
| Brazil | ANPD | Depends on the LGPD legal basis and context | No universal cookie-specific answer | ANPD expects transparent, granular controls and rejects pre-selected consent |
Consent models, at a glance
Prior consent
Non-essential storage waits for a choice.
Conditional exceptions
Some limited purposes may qualify under PECR.
Information-led
Local rules follow a different legal route.
Purpose-led assessment
Confirm the applicable legal basis and notice.
Do not reduce this table to "pick the strictest row and forget the rest." That is a useful design heuristic, not legal analysis. Italy's re-prompt timing and the UK's statutory exceptions are different kinds of rule.
France: CNIL sets a hard practical standard
Law: Article 82 of the French Data Protection Act.
Regulator: Commission nationale de l'informatique et des libertés (CNIL).
The CNIL expects users to be able to refuse cookies as easily as they can accept them. If "Accept all" is on the first layer while rejection requires a tour through a settings panel, the design starts on the wrong foot. Continued browsing is not consent.
France also has a real, but narrow, audience-measurement exemption. CNIL's conditions include limiting measurement to the publisher's needs, avoiding cross-site tracking, constraining data sharing, shortening the life of trackers, and giving users information and an objection route. CNIL publishes a programme for evaluating analytics tools, but a vendor name alone is not a magic exemption. Your purpose and configuration still count.
What to do: put refusal beside acceptance, block advertising and non-exempt analytics before consent, and document why any audience-measurement setup qualifies for exemption.
CNIL's large cases against Google, Microsoft, and Amazon explain why France gets so much attention. For the decisions and amounts, see our cookie consent fine examples.
Germany: TDDDG plus GDPR
Law: Telecommunications Digital Services Data Protection Act (TDDDG), section 25.
Regulators: A mix of state data protection authorities and authorities competent for the TDDDG.
The law was called TTDSG until May 2024, when it was renamed TDDDG. The core device-access rule did not vanish with the acronym change. Consent is required unless storage or access is strictly necessary for transmission or for a telemedia service expressly requested by the user.
Germany also produced the Planet49 case. The Court of Justice of the EU held in 2019 that a pre-ticked checkbox did not produce valid cookie consent and that users must receive information about cookie duration and third-party access.
What to do: use affirmative choices, list meaningful purposes, disclose durations and relevant third parties, and do not assume analytics is necessary. German unfair-competition disputes can create a route to trouble besides a regulator complaint.
If measurement loss is the concern, read how Google Consent Mode v2 works. Consent Mode changes tag behaviour; it does not manufacture consent.
The Netherlands: a narrow analytics exemption
Law: Telecommunications Act, Article 11.7a.
Regulators: Autoriteit Persoonsgegevens (AP) and Autoriteit Consument & Markt (ACM).
Dutch law exempts cookies used to obtain information about the quality or effectiveness of an information-society service where they have little or no effect on the user's privacy. This is often summarized as "analytics cookies do not need consent." That summary is too loose.
The exemption depends on what the analytics setup actually does. Sharing data for a provider's own purposes, building profiles, combining activity across services, or retaining more data than needed works against the low-impact test. Default settings should never be assumed to qualify.
What to do: record the configuration behind any exemption claim. If you cannot explain data recipients, retention, identifiers, and reuse in plain English, consent-gate the tool.
The AP's €600,000 Kruidvat decision concerned unlawful online tracking and an invalid consent flow. It is a useful warning against treating a banner click as proof that the underlying setup is sound.
Belgium: no patience for manufactured consent
Law: Electronic Communications Act and GDPR.
Regulator: Gegevensbeschermingsautoriteit/Autorité de protection des données (GBA/APD).
Belgium follows the EU prior-consent baseline. Its authority also led the cross-border case concerning IAB Europe's Transparency and Consent Framework. The litigation has been long and technical, but the operational lesson is ordinary: an industry framework does not transfer accountability away from the organisations using it.
What to do: make the first choice honest, retain evidence of consent, and map every vendor rather than trusting a framework label.
Spain: equal choices and careful cookie walls
Law: Law 34/2002 on information-society services (LSSI).
Regulator: Agencia Española de Protección de Datos (AEPD).
The AEPD's cookie guide requires actions for accepting and rejecting cookies to appear in a similarly visible format. Scrolling or continuing to browse is not enough.
Spain's guidance allows some "pay or consent" models where the non-consenting alternative is genuine, but this is not permission to lock every visitor into tracking or payment. The EDPB has separately warned that large online platforms will usually be unable to meet valid-consent requirements by offering only behavioural advertising or a fee. Context matters.
What to do: present equal first-layer controls and have counsel assess any pay-or-consent model. Do not borrow one from a newspaper and assume it fits a small ecommerce site.
Italy: the six-month re-prompt rule
Law: Italian Privacy Code, including section 122.
Regulator: Garante per la protezione dei dati personali.
Italy's 2021 guidelines reject scrolling as consent and say closing the banner with an "X" should preserve default settings, meaning no non-technical cookies. The memorable local rule concerns repeat requests: if a user refuses, the banner should not return for at least six months.
There are exceptions. You may ask again when processing conditions materially change, when it is impossible to know whether a cookie remains on the device, or when six months have passed. "We would like another chance tomorrow" is not one of them.
What to do: store refusal status, suppress repeat prompts for six months, and document the event that justifies any earlier request.
Austria: consent does not solve unlawful transfers
Law: Telecommunications Act 2021, section 165.
Regulator: Datenschutzbehörde (DSB).
Austria applies the EU consent baseline. Its better-known analytics decisions dealt with international data transfers after Schrems II. Those cases expose a mistake worth avoiding: cookie consent and lawful data transfers are separate controls. A valid "Accept analytics" click does not automatically make a vendor's overseas transfer lawful.
What to do: check consent, vendor roles, transfer mechanisms, and actual technical safeguards separately.
Ireland and Poland: the same baseline, different enforcers
Ireland's Data Protection Commission says consent is normally required for cookies and similar technologies unless the strictly necessary exemption applies. It also expects consent records and an easy withdrawal route. Ireland matters because many technology companies have their EU headquarters there, but a local establishment does not turn the DPC into Europe's only cookie authority.
Poland applies the ePrivacy rule through its electronic communications legislation, with UODO responsible for personal-data questions. For a site aimed at Polish users, provide clear information in Polish and use affirmative consent for non-essential access.
What to do: do not wait for a famous local fine. Apply the baseline, localize the notice, and know which entity answers complaints.
Denmark, Sweden, Finland, and Norway
Denmark, Sweden, and Finland are EU members. Norway is not, but it belongs to the EEA and applies GDPR. All four require a serious consent implementation; "enforcement seems quieter here" is not an exemption.
Norway deserves a date note. Amendments to its Electronic Communications Act took effect on 1 January 2025 and tied cookie consent to GDPR's standard. Datatilsynet's current guidance says consent must be voluntary, specific, informed, unambiguous, demonstrable, and easy to withdraw. Necessary storage remains exempt.
The national authority split is not identical across the Nordics, so direct complaints may involve a telecom authority, a data protection authority, or both.
What to do: use the EU/EEA baseline, translate the first and second layers for the audience, and verify national guidance before claiming an analytics exemption.
United Kingdom: PECR has changed, not disappeared
Law: Privacy and Electronic Communications Regulations (PECR), as amended, plus UK GDPR.
Regulator: Information Commissioner's Office (ICO).
Brexit did not repeal PECR. The Data (Use and Access) Act 2025 did, however, add exceptions. The ICO's guidance, finalized on 29 April 2026, describes five exceptions, including strictly necessary storage, statistical purposes, and improving a service's appearance or functionality.
The statistical exception is conditional. The processing must be solely statistical, must not be used to make decisions about a person, and must include safeguards. Users need clear information and a simple, free way to object. If the same technology also supports advertising or profiling, you cannot stretch the exception over those extra purposes.
What to do: separate purposes technically, honor objections, and use consent where every condition is not met. A generic "analytics" category tells you too little.
Switzerland: similar result, different legal route
Law: Federal Act on Data Protection (FADP), in force since 1 September 2023, and telecommunications rules.
Regulator: Federal Data Protection and Information Commissioner (FDPIC).
Switzerland is neither an EU nor an EEA member. It would be wrong to say its law copies the ePrivacy prior-consent rule for every non-essential cookie.
Swiss law focuses on transparent, proportionate processing and the rules for personal data. The FDPIC's cookie guidance, first issued in January 2025 and updated in October 2025, explains that consent may be required for personalised advertising where third-party trackers enable high-risk profiling. Consent must also be informed and voluntary when the FADP requires it.
The FADP's criminal fines can target responsible individuals and reach CHF 250,000 for intentional offences. That unusual enforcement structure is not a reason to use a weaker banner.
What to do: identify whether trackers process personal data, support high-risk profiling, or disclose data to third parties. An EU-style opt-in configuration is often the cleaner operational choice, but describe it as a risk-control decision, not a universal statement of Swiss law.
Beyond Europe: Brazil
Law: Lei Geral de Proteção de Dados Pessoais (LGPD).
Regulator: Autoridade Nacional de Proteção de Dados (ANPD).
Brazil does not have an ePrivacy-style cookie statute with one consent rule for every non-essential cookie. Cookies that process personal data fall under the LGPD, and the controller needs an appropriate legal basis.
ANPD's 2022 cookie guide recommends a visible second-level cookie banner, category controls, cookies disabled by default when consent is used, and an easy route to withdraw consent. It also warns against pre-selected options and says legitimate interests require a concrete assessment; they are not a shortcut for any advertising purpose.
What to do: map cookie purposes to LGPD legal bases, provide Portuguese information to Brazilian users, and use granular controls. Do not relabel an EU banner "LGPD" without checking the processing behind it.
We have kept this beyond-Europe section short on purpose. South Korea and Thailand have broad personal-data laws, but reducing either to a one-line "cookie consent rule" would mislead readers. International compliance starts with actual data flows, audience, sector, and local advice, not a flag icon.
What to do on an international website
Start with the implementation that travels well:
| Job | Practical test |
|---|---|
| Inventory | List cookies and similar technologies, their purposes, providers, duration, and data recipients |
| Prior blocking | Confirm non-essential requests do not fire before a choice |
| First-layer design | Put accept and reject controls where users can find them with comparable effort |
| Granularity | Separate necessary, measurement, personalisation, and advertising purposes where relevant |
| Localization | Translate the interface and policy; do not translate only the buttons |
| Proof | Save the consent state, notice version, timestamp, and relevant configuration |
| Withdrawal | Keep a visible privacy or cookie-settings control |
| Re-prompting | Respect Italy's six-month rule and avoid nagging elsewhere |
| Exceptions | Document the exact legal conditions and technical configuration |
| Review | Re-scan after tag-manager, plugin, and vendor changes |
Geo-targeting can reduce needless friction, but it also creates another system to test. IP detection can be wrong. Travellers exist. VPNs exist. Give users a way to reach privacy controls regardless of the region you infer.
Country-level consent performance can help diagnose bad design, but only if the comparison controls for traffic source, device, language, banner layout, and purpose mix. Use it as a diagnostic within your own data, not as a universal country league table.
For the underlying decision, read Do I need cookie consent?. If you operate in the United States too, our CCPA vs GDPR comparison explains why an opt-out link and an EU opt-in banner solve different legal problems.
Check your site before the next visitor does
Run the free ConsentEase cookie scan to catch trackers that load before consent. If you are comparing implementation options, review ConsentEase pricing and choose the setup that fits your sites. No scanner or consent platform guarantees legal compliance; the point is to find and fix what your current setup is actually doing.
Sources
Primary and regulator sources checked for this update:
- European Union, ePrivacy Directive 2002/58/EC: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32002L0058
- EDPB, Guidelines 2/2023 on the technical scope of Article 5(3), final version adopted October 2024: https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_202302_technical_scope_art_53_eprivacydirective_v2_en_0.pdf
- EDPB, Guidelines 05/2020 on consent: https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en
- European Commission, 2025 work programme and withdrawal annex, 11 February 2025: https://commission.europa.eu/document/download/7617998c-86e6-4a74-b33c-249e8a7938cd_en?filename=COM_2025_45_1_annexes_EN.pdf
- Official Journal of the EU, formal withdrawal notice, 6 October 2025: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A52025XC05423
- CNIL, cookies and other trackers guidance: https://www.cnil.fr/en/cookies-and-other-tracking-devices-cnil-publishes-new-guidelines
- CNIL, audience-measurement analytics: https://cnil.fr/en/sheet-ndeg16-use-analytics-your-websites-and-applications
- CJEU, Planet49, 1 October 2019: https://curia.europa.eu/juris/document/document.jsf?docid=218462&doclang=EN
- Autoriteit Persoonsgegevens, cookies guidance: https://www.autoriteitpersoonsgegevens.nl/en/themes/internet-and-smart-devices/cookies
- Belgian GBA/APD, IAB Europe decision: https://www.dataprotectionauthority.be/citizen/iab-europe-held-responsible-for-a-mechanism-that-infringes-the-gdpr
- AEPD, Guide on the use of cookies: https://www.aepd.es/guides/guide-on-use-of-cookies.pdf
- Garante, Guidelines on cookies and other tracking tools, 10 June 2021: https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/9677876
- Irish DPC, cookies guidance: https://www.dataprotection.ie/en/dpc-guidance/guidance-cookies-and-other-tracking-technologies
- Norway Datatilsynet, consent for cookies and tracking technologies: https://www.datatilsynet.no/personvern-pa-ulike-omrader/internett-og-apper/bruk-av-informasjonskapsler-og-andre-sporingsteknologier/
- ICO, guidance on storage and access technologies, updated 29 April 2026: https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/
- UK Data (Use and Access) Act 2025: https://www.legislation.gov.uk/ukpga/2025/18/enacted
- FDPIC, updated cookie guidelines, 7 October 2025: https://www.edoeb.admin.ch/en/cookie-guidelines-updated-version
- Swiss Federal Act on Data Protection: https://www.fedlex.admin.ch/eli/cc/2022/491/en
- Brazil ANPD, Cookies and Personal Data Protection guide: https://www.gov.br/anpd/pt-br/centrais-de-conteudo/materiais-educativos-e-publicacoes/guia-orientativo-cookies-e-protecao-de-dados-pessoais.pdf
This article provides general information, not legal advice. Rules and regulator guidance change; check the current primary source for every market you target.

