Guide

Do I Need Consent for Every Cookie on My Website?

No, but the exemption is narrower than most sites assume. Here's exactly which cookies need consent, which don't, and where the line actually sits.

Published September 1, 2026·Last updated September 1, 2026

No, not every cookie requires consent, but the exemption is narrower than most site owners assume, and it’s easy to misclassify a cookie as “necessary” when it isn’t. Here’s exactly where the line sits.

The exemption: strictly necessary cookies

Both the ePrivacy Directive and GDPR carve out cookies that are strictly necessary to provide a service the user has actively requested. The test isn’t “is this cookie useful” or “does this cookie improve the experience,” it’s whether the specific feature the user asked for cannot function without it. Examples that typically qualify:

  • Session cookies that keep a user logged in during their visit
  • Shopping cart cookies that remember items a user added
  • Load-balancing cookies that route traffic across servers
  • Security cookies like CSRF tokens that prevent attacks
  • A cookie that stores the user’s own consent preference (this one’s necessary almost by definition, you need somewhere to record that they said no)

What does NOT qualify, even though it feels useful

  • Analytics cookies, including Google Analytics, even in “anonymized” or aggregated configurations, are not considered strictly necessary under most EU data protection authority guidance. The service the user requested (viewing your page) works fine without you measuring it.
  • Advertising and remarketing cookies, unambiguously non-essential, always require consent.
  • Personalization cookies that remember preferences for a better experience but aren’t required for the core function (e.g., remembering a dismissed banner across sessions for convenience) fall into a gray area regulators generally treat as requiring consent, not exemption.
  • Social media embed cookies (share buttons, embedded video players) that set third-party cookies, these almost always require consent since the third party’s purposes go beyond your site’s core function.

The most common misclassification

The single most common mistake: labeling analytics cookies as “necessary” in a cookie banner’s category list because the business feels like it needs analytics to run its operations. Business necessity and legal necessity are different tests. GDPR/ePrivacy’s “strictly necessary” exemption is about what the user’s requested service requires, not what the business finds useful or important. Wanting the data isn’t the same as the visitor’s request requiring it.

What this means for your banner design

Because only a narrow slice of cookies qualify for the exemption, most sites need a banner with:

  • A “necessary” category that’s genuinely minimal, and not pre-checked-and-locked as a way to smuggle in analytics or advertising cookies
  • Separate, unchecked-by-default categories for analytics, advertising, and personalization
  • Equal prominence for accept and reject, covered in detail in our compliant banner requirements guide
Our recommendation

CookieYes

Getting the necessary-vs-non-essential classification right, and keeping non-essential cookies off by default, is exactly the kind of granular category setup CookieYes handles out of the box rather than requiring you to hand-classify every script on your site.

Try CookieYes

What about the “legitimate interest” argument for analytics?

Some businesses try to justify skipping consent for analytics by relying on GDPR’s “legitimate interest” lawful basis instead of consent. This generally doesn’t work for cookies specifically, ePrivacy’s cookie-consent requirement is separate from and sits alongside GDPR’s lawful-basis framework, so even a valid legitimate interest under GDPR doesn’t override the ePrivacy consent requirement for setting a non-essential cookie in the first place. We cover this distinction in our legitimate interest vs. consent guide.

This guide is educational and not legal advice. Whether a specific cookie on your site qualifies as strictly necessary depends on how it functions; consult a privacy attorney or technical auditor for your specific cookie inventory.