GDPR Cookie Consent: What the Law Requires
Last updated: August 24, 2026
The GDPR itself doesn't regulate cookies directly — that's the ePrivacy Directive's job. But in practice, cookie consent collected on a website has to meet GDPR's consent standard: freely given, specific, informed, and unambiguous. This applies to any site processing EU residents' data, regardless of where the site owner is based.
Core consent requirements
- Opt-in, not opt-out. Non-essential cookies can't be set before explicit consent. Continued browsing is not consent.
- Rejecting must be as easy as accepting. "Accept" and "Reject" buttons at the same visual level — no dark patterns hiding the reject option.
- No pre-ticked boxes. Non-essential categories are off by default.
- Granular consent by category — typically necessary, preferences, statistics, and marketing — not a single all-or-nothing checkbox.
- Withdrawing consent must be as easy as giving it — at any time, without contacting support.
- Provability. You need to be able to show who consented to what, and when — a consent log.
Website checklist
- A banner that blocks third-party scripts (analytics, ads) until consent;
- Separate, toggleable cookie categories;
- "Accept all" / "Reject all" buttons at equal prominence;
- A cookie policy listing every cookie used and its provider;
- A consent log with timestamp, banner version, and selected categories;
- A way to change the decision at any time (e.g. a footer link).
Fines
GDPR uses a two-tier fine structure: up to €10 million or 2% of global annual turnover for less severe violations, and up to €20 million or 4% of global annual turnover for more serious ones — including violations of consent and processing principles (whichever amount is higher applies). EU data protection authorities have already fined sites specifically for cookie banners lacking a reject option or using pre-checked consent.
Getting compliant quickly
Cookiestack automatically scans your site, sorts cookies into categories, blocks third-party scripts until consent, and keeps a consent log — no developers required. GDPR, CCPA, and Russia's 152-FZ are all supported in one widget.
This article is for informational purposes only and is not legal advice. Consult a qualified data protection lawyer for your specific situation.