Cookies
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Online tracking technologies and consent requirements
Overview
15 sources · Jul 23, 2026Legal Framework
Cookie regulation sits at the intersection of the ePrivacy Directive (2002/58/EC) and the GDPR. Article 5(3) of the ePrivacy Directive requires prior informed consent for storing or accessing information on a user's device — the provision that governs most non-essential cookies and similar tracking technologies. The GDPR supplies the substantive standard for that consent: it must be freely given, specific, informed, and unambiguous under Article 4(11) and Article 7, with Article 6(1)(a) providing the corresponding legal basis. The EDPB has confirmed the linkage between the two instruments:
"The notion of consent in the draft ePrivacy Regulation remains linked to the notion of consent in the GDPR."
— EDPB Guidelines 05/2020 §6
For tracking that serves advertising or analytics rather than strictly necessary functionality, consent under the ePrivacy instrument is required before the cookie is set or read. The GDPR then governs the downstream processing of any personal data collected through that cookie, including questions of controller responsibility and lawful basis.
Key Developments
The CJEU's ruling in Wirtschaftsakademie established that joint controllership can arise even where one party merely embeds a third-party tracking tool. A fan page administrator who integrates Facebook's social plugin becomes a joint controller because the data collection via cookies is carried out for mutual benefit. The Court emphasised that:
"the production of those statistics is based on the prior collection, by means of cookies installed by Facebook on the computers or other devices of visitors to that page, and the processing of the personal data of those visitors for such statistical purposes."
— Wirtschaftsakademie ¶38
The Court further noted that the processing was "intended, in particular, to enable Facebook to improve its system of advertising, in order better to target its communications" — confirming that advertising-driven cookie deployment falls squarely within the GDPR's material scope.
On the consent quality front, the EDPB has addressed cookie walls directly. Where a website blocks all content unless the user clicks "Accept cookies," the consent obtained is not valid:
"Since the data subject is not presented with a genuine choice, its consent is not freely given."
— EDPB Guidelines 05/2020 §40
Enforcement actions reinforce these thresholds. The Italian Garante fined Depac €15,000 for insufficient legal basis for data processing through cookies, and the EDPB's Cookie Banner Taskforce has been coordinating cross-border enforcement against deceptive or manipulative cookie consent interfaces since 2023.
Status of the Debate
This topic is actively contested in court. The core legal framework — ePrivacy Article 5(3) consent plus GDPR consent standards — is well established, but its application to specific tracking technologies, joint controllership allocation, and the permissibility of cookie walls and equivalent mechanisms remains in flux. The pending ePrivacy Regulation could resolve ambiguities around scope and enforcement, but until its adoption, national courts and DPAs are filling gaps with divergent approaches. The central open question is whether consent obtained through "accept or leave" architectures can ever satisfy the "freely given" requirement, and what constitutes a genuinely equivalent "reject all" option. A CJEU referral on cookie wall validity would settle the debate definitively.
Practical Guidance
Obtain prior opt-in consent before setting non-essential cookies. Article 5(3) ePrivacy Directive requires it; pre-ticked boxes or implied consent do not satisfy the GDPR standard under Article 4(11).
Provide a genuine "reject all" option equivalent to "accept all." Following the EDPB's guidance, any mechanism that conditions content access on cookie acceptance renders consent invalid as not freely given.
Identify all controllers involved in cookie-based processing. Wirtschaftsakademie confirms that embedding third-party tracking tools can create joint controllership — assess whether your organisation exercises influence over the purposes and means of processing.
Disclose purposes specifically. Generic "we use cookies to improve our services" statements are insufficient; users must understand what data is collected, by whom, and for what advertising or analytics purpose before consenting.
Audit cookie inventories regularly. Document every cookie set, its provider, its purpose, and its legal basis — and ensure that consent preferences are enforced technically, not merely recorded.