Back|
C
Cookiestack
Sign inGet started

GDPR Cookie Consent: What the Law Requires

Last updated: August 24, 2026

The GDPR itself doesn't regulate cookies directly — that's the ePrivacy Directive's job. But in practice, cookie consent collected on a website has to meet GDPR's consent standard: freely given, specific, informed, and unambiguous. This applies to any site processing EU residents' data, regardless of where the site owner is based.

Core consent requirements

  • Opt-in, not opt-out. Non-essential cookies can't be set before explicit consent. Continued browsing is not consent.
  • Rejecting must be as easy as accepting. "Accept" and "Reject" buttons at the same visual level — no dark patterns hiding the reject option.
  • No pre-ticked boxes. Non-essential categories are off by default.
  • Granular consent by category — typically necessary, preferences, statistics, and marketing — not a single all-or-nothing checkbox.
  • Withdrawing consent must be as easy as giving it — at any time, without contacting support.
  • Provability. You need to be able to show who consented to what, and when — a consent log.

Website checklist

  • A banner that blocks third-party scripts (analytics, ads) until consent;
  • Separate, toggleable cookie categories;
  • "Accept all" / "Reject all" buttons at equal prominence;
  • A cookie policy listing every cookie used and its provider;
  • A consent log with timestamp, banner version, and selected categories;
  • A way to change the decision at any time (e.g. a footer link).

Fines

GDPR uses a two-tier fine structure: up to €10 million or 2% of global annual turnover for less severe violations, and up to €20 million or 4% of global annual turnover for more serious ones — including violations of consent and processing principles (whichever amount is higher applies). EU data protection authorities have already fined sites specifically for cookie banners lacking a reject option or using pre-checked consent.

Getting compliant quickly

Cookiestack automatically scans your site, sorts cookies into categories, blocks third-party scripts until consent, and keeps a consent log — no developers required. GDPR, CCPA, and Russia's 152-FZ are all supported in one widget.

Start for free →

This article is for informational purposes only and is not legal advice. Consult a qualified data protection lawyer for your specific situation.

GDPR Cookie Consent Requirements & Fines