If your website serves users in the European Union (or European Economic Area), cookie consent isn't optional — it's the law. The ePrivacy Directive (often called the "Cookie Law") requires websites to obtain prior informed consent before placing non-essential cookies or trackers on a user's device.
In 2026, enforcement has intensified significantly. EU data protection authorities (DPAs) have issued over €1.2 billion in GDPR fines since 2018, and cookie-related violations account for a growing share. The Belgian DPA alone has issued multiple six-figure fines for cookie consent violations in 2025-2026, targeting both small businesses and large platforms.
This guide covers everything you need to know to get your website's cookie consent compliant — from the legal requirements to choosing a consent platform and testing your setup.
The ePrivacy Directive, specifically Article 5(3), is the primary law governing cookies and similar tracking technologies. It requires:
The ePrivacy Directive was implemented into EU member state law through national legislation, meaning specific requirements vary slightly by country. However, the core consent requirement is uniform across the EU.
The GDPR complements the ePrivacy Directive in several ways:
The proposed ePrivacy Regulation, intended to replace the existing Directive, has been under negotiation since 2017. As of mid-2026, it has not yet been adopted. The current ePrivacy Directive remains in force, and the general expectation is that the new Regulation will largely codify existing requirements, with potential additions around AI-driven tracking and IoT cookie consent.
For cookie consent to be valid under both the ePrivacy Directive and GDPR:
Best practice (and increasingly required by DPAs) is to categorise cookies clearly:
| Category | Description | Consent needed? |
|---|---|---|
| Strictly necessary | Essential for the website to function (session cookies, authentication, load balancing) | No (legitimate interest) |
| Functional / Preferences | Remember user preferences, language, region | Yes — implied consent may be acceptable in some interpretations |
| Analytics / Performance | Track page views, user behaviour, site performance (Google Analytics, Plausible, etc.) | Yes — unless fully anonymised and no data is shared with third parties |
| Marketing / Advertising | Targeted ads, cross-site tracking, social media pixels (Meta Pixel, Google Ads, LinkedIn Insight) | Yes — explicit, prior consent required |
EU DPAs have become increasingly specific about cookie banner design:
Here are the most popular cookie consent platforms in 2026, with their key features:
| Platform | Free tier | Starting price (paid) | Cookie categories | Consent record |
|---|---|---|---|---|
| Cookiebot (by Usercentrics) | 200 URLs, basic scan | €12/mo | Granular | Stored |
| CookieYes | 25 URLs, 5K pageviews | $10/mo | Granular | Stored |
| Complianz (WordPress) | 1 site (limited) | €45/yr | Granular | Stored |
| OneTrust | Free scan only | $10/mo (Pro) | Granular | Stored |
| Osano | Basic banner | $199/mo | Granular | Stored |
| Termly | Basic consent | $23/mo | Granular | Stored |
| Klaro | Open source | Free / self-hosted | Granular | Manual |
| Tarteaucitron | Open source | Free / self-hosted | Granular | Manual |
| Iubenda | Basic banner | €9/mo | Granular | Stored |
Use this checklist to verify your cookie consent compliance:
Cookie consent enforcement has intensified across the EU in 2025-2026. Recent decisions, each verified against the authority's own announcement:
| When | Who | Fine / action | What went wrong |
|---|---|---|---|
| Sep 2025 | Google (France, CNIL) | €325M | Ads in Gmail without valid consent; coercive cookie practices. Third CNIL fine for Google's cookies (€100M in 2020, €150M in 2021). |
| Sep 2025 | SHEIN (France, CNIL) | €150M | Advertising cookies placed before any user choice; ineffective reject/withdrawal mechanisms. |
| Dec 2025 | UK top-1,000 sites (ICO) | Enforcement sweep | 564 of the UK's biggest websites failed initial cookie checks; 17 preliminary enforcement notices; 21 still non-compliant. |
| 2024 | Kruidvat / AS Watson (Netherlands) | €600,000 | Tracking cookies without valid consent. |
Sources: CNIL press releases (cnil.fr, Sep 2025), EDPB case register, ICO news release (4 Dec 2025), Dutch DPA decision on AS Watson.
Beyond the headline cases:
| Country | DPA | Notable recent actions |
|---|---|---|
| France | CNIL | The EU's most active enforcer — multiple €100K+ fines for inadequate cookie consent and dark patterns. |
| Belgium | APD/GBA | €250K+ fines for Meta and other platforms for cookie consent violations. Strong focus on documentation. |
| Italy | Garante | €5M+ total fines for cookie-related GDPR violations in 2025. Active on small and medium businesses. |
| Spain | AEPD | Systematic sweeps of cookie consent compliance across sectors. Focus on "consent by scrolling" violations. |
| Sweden | IMY | Formal warnings to Warner Music Sweden, Aller Media et al. (Apr 2025) for banners favouring "Accept" over "Reject". |
| Germany | Multiple state DPAs | Cookie consent fines under GDPR up to €20M. Increasingly coordinated enforcement across states. |
Penalties for cookie consent violations can reach up to €20 million or 4% of annual global turnover (whichever is higher) under Article 83(5) GDPR. The average fine for an SME cookie violation in 2025-2026 ranges from €5,000 to €250,000 depending on severity.
You don't need to guess whether your cookie consent setup is compliant. Here are free tools to verify:
Our free compliance scanner checks your website for cookie consent platforms, privacy-policy links, legal pages, and security headers. Enter any URL and get results in seconds — no sign-up required.
Passed? Add a free compliance badge to your site — client trust plus a dofollow backlink.
Use our compliance checklist to create a privacy policy that includes your cookie consent practices — instantly, no sign-up.