Key takeaways

The EU has a common cookie baseline, but it does not have one cookie enforcement office. Each country applies the ePrivacy Directive through national law, while GDPR sets the standard for valid consent when personal data is involved.

For an ordinary website, the defensible starting point is simple: block non-essential storage and tracking until the visitor chooses; make refusal as easy as acceptance; explain purposes and third parties plainly; and leave a persistent way to change the choice.

The differences still matter. France permits a narrow audience-measurement exemption under strict conditions. Dutch law has an exemption for analytics with little or no privacy impact. Italy normally prevents you from asking a refuser again for six months. The UK now has specific statistical and service-improvement exceptions, but they come with conditions and an objection mechanism. Switzerland does not copy the EU's prior-consent rule wholesale.

There is no credible public dataset that supports neat country-by-country "acceptance rate" percentages across all banner designs and audiences. Compare country segments only within your own measurement system, using the same definitions, banner design, traffic mix, and period.

The EU and EEA baseline

Article 5(3) of the ePrivacy Directive covers storing information on, or accessing information from, a user's device. Cookies are the obvious example, but the rule is technology-neutral. Pixels, local storage, software-development kits, tracking links, and some forms of fingerprinting do not escape scrutiny because they lack the word "cookie." The European Data Protection Board confirmed that broad technical scope in its final 2024 guidance.

Storage or access is allowed without consent where it is strictly necessary to transmit a communication or provide a service the user explicitly requested. A basket cookie can qualify. An advertising identifier does not become necessary because the marketing team likes it. "Necessary for our business model" is not the legal test.

Where consent is required, GDPR supplies the standard: it must be freely given, specific, informed, and unambiguous. In practice:

  1. Do not set non-essential cookies before the user acts.
  2. Do not treat scrolling, silence, or continued browsing as agreement.
  3. Do not pre-tick optional categories.
  4. Give people a real refusal route without hiding it behind extra friction.
  5. Make withdrawal as easy as giving consent.
  6. Keep a record of the choice and the information shown at the time.

This is why a banner is not the whole compliance job. If an ad tag fires while the banner is still loading, the nicest button design in Europe will not rescue the implementation. Start with what the ePrivacy Directive requires, then check whether your site actually follows it.

Website owners regularly argue that "legitimate interests" lets them set analytics or advertising cookies. That mixes two legal questions. The ePrivacy rule governs access to the device. GDPR governs later processing of personal data. You may need to satisfy both. A GDPR legal basis does not erase an ePrivacy consent requirement.

What happened to the ePrivacy Regulation?

The proposed ePrivacy Regulation was supposed to replace the 2002 directive with a directly applicable EU regulation. It spent years stuck in negotiations.

On 11 February 2025, the European Commission placed the proposal on the withdrawal list in its 2025 work programme, saying that no agreement was foreseeable and that the proposal was outdated in light of later legislation. The withdrawal was formally published in the EU Official Journal on 6 October 2025.

So the promised replacement did not arrive. The directive and national implementing laws remain the working framework. That does not mean cookie law is frozen forever: courts, national guidance, enforcement decisions, and later legislation still change how the rules work. It does mean you should stop planning around a mythical imminent ePrivacy Regulation.

Check the implementation, not just the banner. Run a free cookie scan to see which trackers load before a visitor chooses. Then compare the result with the rules below.

This table is a working compliance map, not a claim that one setting guarantees compliance everywhere.

Market Main authority Default position for non-essential tracking Analytics without consent? Detail that changes implementation
France CNIL Prior consent Sometimes, under CNIL's narrow audience-measurement conditions Refusing must be as easy as accepting
Germany State data protection authorities; other competent bodies under national law Prior consent under TDDDG No broad analytics exemption Private litigation can add risk beyond regulator action
Netherlands AP; ACM has telecom-law responsibilities Prior consent Yes, for analytics with little or no privacy impact Configuration and third-party use matter
Belgium GBA/APD Prior consent No broad exemption to assume Consent must be demonstrable and free
Spain AEPD Prior consent No broad exemption to assume Accept and reject should be offered at the same level
Italy Garante Prior consent Technical analytics may qualify only in constrained cases After refusal, do not re-prompt for at least six months unless an exception applies
Austria DSB Prior consent No broad exemption to assume Cookie consent does not cure separate data-transfer problems
Ireland DPC Prior consent No broad exemption to assume DPC guidance applies the same affirmative-consent model
Poland UODO; national telecom framework Prior consent No broad exemption to assume Use Polish-language information for a Polish audience
Denmark, Sweden, Finland National telecom/data protection authorities Prior consent Do not assume one regional exemption National guidance and enforcement channels differ
Norway Datatilsynet and Nkom GDPR-standard consent under the Electronic Communications Act Strictly necessary exception; do not assume a general analytics carve-out New cookie rules took effect on 1 January 2025
United Kingdom ICO Consent unless a PECR exception fits A conditional statistical-purpose exception now exists Give clear information and a simple way to object where the exception requires it
Switzerland FDPIC Case-specific under the FADP and telecom rules No EU-style blanket answer High-risk profiling and third-party ad tracking can require consent
Brazil ANPD Depends on the LGPD legal basis and context No universal cookie-specific answer ANPD expects transparent, granular controls and rejects pre-selected consent
EU / EEA

Prior consent

Non-essential storage waits for a choice.

United Kingdom

Conditional exceptions

Some limited purposes may qualify under PECR.

Switzerland

Information-led

Local rules follow a different legal route.

Brazil

Purpose-led assessment

Confirm the applicable legal basis and notice.

A qualitative comparison for orientation only. Apply the local rule to your actual tools, purposes, and audience.

Do not reduce this table to "pick the strictest row and forget the rest." That is a useful design heuristic, not legal analysis. Italy's re-prompt timing and the UK's statutory exceptions are different kinds of rule.

France: CNIL sets a hard practical standard

Law: Article 82 of the French Data Protection Act.
Regulator: Commission nationale de l'informatique et des libertés (CNIL).

The CNIL expects users to be able to refuse cookies as easily as they can accept them. If "Accept all" is on the first layer while rejection requires a tour through a settings panel, the design starts on the wrong foot. Continued browsing is not consent.

France also has a real, but narrow, audience-measurement exemption. CNIL's conditions include limiting measurement to the publisher's needs, avoiding cross-site tracking, constraining data sharing, shortening the life of trackers, and giving users information and an objection route. CNIL publishes a programme for evaluating analytics tools, but a vendor name alone is not a magic exemption. Your purpose and configuration still count.

What to do: put refusal beside acceptance, block advertising and non-exempt analytics before consent, and document why any audience-measurement setup qualifies for exemption.

CNIL's large cases against Google, Microsoft, and Amazon explain why France gets so much attention. For the decisions and amounts, see our cookie consent fine examples.

Germany: TDDDG plus GDPR

Law: Telecommunications Digital Services Data Protection Act (TDDDG), section 25.
Regulators: A mix of state data protection authorities and authorities competent for the TDDDG.

The law was called TTDSG until May 2024, when it was renamed TDDDG. The core device-access rule did not vanish with the acronym change. Consent is required unless storage or access is strictly necessary for transmission or for a telemedia service expressly requested by the user.

Germany also produced the Planet49 case. The Court of Justice of the EU held in 2019 that a pre-ticked checkbox did not produce valid cookie consent and that users must receive information about cookie duration and third-party access.

What to do: use affirmative choices, list meaningful purposes, disclose durations and relevant third parties, and do not assume analytics is necessary. German unfair-competition disputes can create a route to trouble besides a regulator complaint.

If measurement loss is the concern, read how Google Consent Mode v2 works. Consent Mode changes tag behaviour; it does not manufacture consent.

The Netherlands: a narrow analytics exemption

Law: Telecommunications Act, Article 11.7a.
Regulators: Autoriteit Persoonsgegevens (AP) and Autoriteit Consument & Markt (ACM).

Dutch law exempts cookies used to obtain information about the quality or effectiveness of an information-society service where they have little or no effect on the user's privacy. This is often summarized as "analytics cookies do not need consent." That summary is too loose.

The exemption depends on what the analytics setup actually does. Sharing data for a provider's own purposes, building profiles, combining activity across services, or retaining more data than needed works against the low-impact test. Default settings should never be assumed to qualify.

What to do: record the configuration behind any exemption claim. If you cannot explain data recipients, retention, identifiers, and reuse in plain English, consent-gate the tool.

The AP's €600,000 Kruidvat decision concerned unlawful online tracking and an invalid consent flow. It is a useful warning against treating a banner click as proof that the underlying setup is sound.

Law: Electronic Communications Act and GDPR.
Regulator: Gegevensbeschermingsautoriteit/Autorité de protection des données (GBA/APD).

Belgium follows the EU prior-consent baseline. Its authority also led the cross-border case concerning IAB Europe's Transparency and Consent Framework. The litigation has been long and technical, but the operational lesson is ordinary: an industry framework does not transfer accountability away from the organisations using it.

What to do: make the first choice honest, retain evidence of consent, and map every vendor rather than trusting a framework label.

Law: Law 34/2002 on information-society services (LSSI).
Regulator: Agencia Española de Protección de Datos (AEPD).

The AEPD's cookie guide requires actions for accepting and rejecting cookies to appear in a similarly visible format. Scrolling or continuing to browse is not enough.

Spain's guidance allows some "pay or consent" models where the non-consenting alternative is genuine, but this is not permission to lock every visitor into tracking or payment. The EDPB has separately warned that large online platforms will usually be unable to meet valid-consent requirements by offering only behavioural advertising or a fee. Context matters.

What to do: present equal first-layer controls and have counsel assess any pay-or-consent model. Do not borrow one from a newspaper and assume it fits a small ecommerce site.

Italy: the six-month re-prompt rule

Law: Italian Privacy Code, including section 122.
Regulator: Garante per la protezione dei dati personali.

Italy's 2021 guidelines reject scrolling as consent and say closing the banner with an "X" should preserve default settings, meaning no non-technical cookies. The memorable local rule concerns repeat requests: if a user refuses, the banner should not return for at least six months.

There are exceptions. You may ask again when processing conditions materially change, when it is impossible to know whether a cookie remains on the device, or when six months have passed. "We would like another chance tomorrow" is not one of them.

What to do: store refusal status, suppress repeat prompts for six months, and document the event that justifies any earlier request.

Law: Telecommunications Act 2021, section 165.
Regulator: Datenschutzbehörde (DSB).

Austria applies the EU consent baseline. Its better-known analytics decisions dealt with international data transfers after Schrems II. Those cases expose a mistake worth avoiding: cookie consent and lawful data transfers are separate controls. A valid "Accept analytics" click does not automatically make a vendor's overseas transfer lawful.

What to do: check consent, vendor roles, transfer mechanisms, and actual technical safeguards separately.

Ireland and Poland: the same baseline, different enforcers

Ireland's Data Protection Commission says consent is normally required for cookies and similar technologies unless the strictly necessary exemption applies. It also expects consent records and an easy withdrawal route. Ireland matters because many technology companies have their EU headquarters there, but a local establishment does not turn the DPC into Europe's only cookie authority.

Poland applies the ePrivacy rule through its electronic communications legislation, with UODO responsible for personal-data questions. For a site aimed at Polish users, provide clear information in Polish and use affirmative consent for non-essential access.

What to do: do not wait for a famous local fine. Apply the baseline, localize the notice, and know which entity answers complaints.

Denmark, Sweden, Finland, and Norway

Denmark, Sweden, and Finland are EU members. Norway is not, but it belongs to the EEA and applies GDPR. All four require a serious consent implementation; "enforcement seems quieter here" is not an exemption.

Norway deserves a date note. Amendments to its Electronic Communications Act took effect on 1 January 2025 and tied cookie consent to GDPR's standard. Datatilsynet's current guidance says consent must be voluntary, specific, informed, unambiguous, demonstrable, and easy to withdraw. Necessary storage remains exempt.

The national authority split is not identical across the Nordics, so direct complaints may involve a telecom authority, a data protection authority, or both.

What to do: use the EU/EEA baseline, translate the first and second layers for the audience, and verify national guidance before claiming an analytics exemption.

United Kingdom: PECR has changed, not disappeared

Law: Privacy and Electronic Communications Regulations (PECR), as amended, plus UK GDPR.
Regulator: Information Commissioner's Office (ICO).

Brexit did not repeal PECR. The Data (Use and Access) Act 2025 did, however, add exceptions. The ICO's guidance, finalized on 29 April 2026, describes five exceptions, including strictly necessary storage, statistical purposes, and improving a service's appearance or functionality.

The statistical exception is conditional. The processing must be solely statistical, must not be used to make decisions about a person, and must include safeguards. Users need clear information and a simple, free way to object. If the same technology also supports advertising or profiling, you cannot stretch the exception over those extra purposes.

What to do: separate purposes technically, honor objections, and use consent where every condition is not met. A generic "analytics" category tells you too little.

Law: Federal Act on Data Protection (FADP), in force since 1 September 2023, and telecommunications rules.
Regulator: Federal Data Protection and Information Commissioner (FDPIC).

Switzerland is neither an EU nor an EEA member. It would be wrong to say its law copies the ePrivacy prior-consent rule for every non-essential cookie.

Swiss law focuses on transparent, proportionate processing and the rules for personal data. The FDPIC's cookie guidance, first issued in January 2025 and updated in October 2025, explains that consent may be required for personalised advertising where third-party trackers enable high-risk profiling. Consent must also be informed and voluntary when the FADP requires it.

The FADP's criminal fines can target responsible individuals and reach CHF 250,000 for intentional offences. That unusual enforcement structure is not a reason to use a weaker banner.

What to do: identify whether trackers process personal data, support high-risk profiling, or disclose data to third parties. An EU-style opt-in configuration is often the cleaner operational choice, but describe it as a risk-control decision, not a universal statement of Swiss law.

Beyond Europe: Brazil

Law: Lei Geral de Proteção de Dados Pessoais (LGPD).
Regulator: Autoridade Nacional de Proteção de Dados (ANPD).

Brazil does not have an ePrivacy-style cookie statute with one consent rule for every non-essential cookie. Cookies that process personal data fall under the LGPD, and the controller needs an appropriate legal basis.

ANPD's 2022 cookie guide recommends a visible second-level cookie banner, category controls, cookies disabled by default when consent is used, and an easy route to withdraw consent. It also warns against pre-selected options and says legitimate interests require a concrete assessment; they are not a shortcut for any advertising purpose.

What to do: map cookie purposes to LGPD legal bases, provide Portuguese information to Brazilian users, and use granular controls. Do not relabel an EU banner "LGPD" without checking the processing behind it.

We have kept this beyond-Europe section short on purpose. South Korea and Thailand have broad personal-data laws, but reducing either to a one-line "cookie consent rule" would mislead readers. International compliance starts with actual data flows, audience, sector, and local advice, not a flag icon.

What to do on an international website

Start with the implementation that travels well:

Job Practical test
Inventory List cookies and similar technologies, their purposes, providers, duration, and data recipients
Prior blocking Confirm non-essential requests do not fire before a choice
First-layer design Put accept and reject controls where users can find them with comparable effort
Granularity Separate necessary, measurement, personalisation, and advertising purposes where relevant
Localization Translate the interface and policy; do not translate only the buttons
Proof Save the consent state, notice version, timestamp, and relevant configuration
Withdrawal Keep a visible privacy or cookie-settings control
Re-prompting Respect Italy's six-month rule and avoid nagging elsewhere
Exceptions Document the exact legal conditions and technical configuration
Review Re-scan after tag-manager, plugin, and vendor changes

Geo-targeting can reduce needless friction, but it also creates another system to test. IP detection can be wrong. Travellers exist. VPNs exist. Give users a way to reach privacy controls regardless of the region you infer.

Country-level consent performance can help diagnose bad design, but only if the comparison controls for traffic source, device, language, banner layout, and purpose mix. Use it as a diagnostic within your own data, not as a universal country league table.

For the underlying decision, read Do I need cookie consent?. If you operate in the United States too, our CCPA vs GDPR comparison explains why an opt-out link and an EU opt-in banner solve different legal problems.

Check your site before the next visitor does

Run the free ConsentEase cookie scan to catch trackers that load before consent. If you are comparing implementation options, review ConsentEase pricing and choose the setup that fits your sites. No scanner or consent platform guarantees legal compliance; the point is to find and fix what your current setup is actually doing.

Sources

Primary and regulator sources checked for this update:

This article provides general information, not legal advice. Rules and regulator guidance change; check the current primary source for every market you target.