← All posts
cookie consentSep 30, 20267 min read

Which cookies need consent, and which don't

In the EU and UK, cookies need consent unless strictly necessary for what the visitor asked for. Examples, regulator guidance and where countries differ.

Katla Team

In the EU and the UK, a cookie needs consent unless it is strictly necessary to provide something the visitor explicitly asked for, such as staying logged in, keeping a shopping basket or remembering their cookie choice. Analytics, advertising, A/B testing, most chat widget tracking and the cookies set by embedded video platforms need consent first, with a few national exceptions for privacy-friendly measurement. In the US, state privacy laws such as California's CCPA do not require consent before cookies at all: they require a way to opt out.

The rule: purpose decides

The EU rule is Article 5(3) of the ePrivacy Directive. Storing or reading anything on a visitor's device needs their consent, with two exceptions: when it is for "the sole purpose of carrying out the transmission of a communication", or when it is "strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service". It is not limited to cookies: the EDPB's guidelines on its technical scope apply it to tracking pixels, tracking links and other techniques too.

Two readings of that sentence settle most cases. The Article 29 Working Party, the EDPB's predecessor, wrote in its opinion on the cookie consent exemption that "the purpose of the cookie should always be the basis for evaluating if the exemption can be successfully applied rather than a technical feature of the cookie". And the UK's ICO says necessity is judged from the visitor's side: advertising may fund your site, but "there are no advertising purposes that meet the strictly necessary exception" (ICO).

Cookies that do not need consent

CookieWhat it doesWho says it is exempt
Login sessionKeeps a signed-in visitor recognised from page to pageArticle 29 WP, CNIL, ICO
Load balancingSends a visitor's requests to the same serverArticle 29 WP, CNIL, ICO
Shopping basketRemembers what the visitor has addedArticle 29 WP, CNIL, ICO
Consent cookieRemembers the visitor's cookie choice itselfCNIL, ICO
Language choiceRemembers a language the visitor pickedArticle 29 WP, CNIL
CSRF tokenStops forged submissions of forms the visitor is usingArticle 29 WP, as security for the service the visitor requested

The CNIL's list is in its 2020 guidelines, and it starts with the trackers that store the visitor's own choice about trackers. The ICO gives the example of a consent cookie that remembers preferences "(eg 90 days)" as one that can be exempt, provided it is used for nothing else.

Two conditions come with every exemption. A cookie can only be exempt if every purpose it serves is exempt: the CNIL's example is a login cookie that may be set without consent, but not reused for advertising unless the visitor agreed to that. And its lifetime should match its job: the Article 29 WP says an exempt cookie "must be set to expire once it is not needed".

Cookies that need consent

Analytics. The Article 29 WP was blunt: analytics cookies "are not strictly necessary to provide a functionality explicitly requested by the user", because "the user can access all the functionalities provided by the website when such cookies are disabled". A few countries carve out narrow exceptions, below.

Advertising and retargeting. Third-party advertising cookies "cannot be exempted from consent", and the Article 29 WP extends that to related operational uses such as frequency capping and click fraud detection.

A/B testing. No EU-wide exemption covers it, so by the same reasoning as analytics it needs consent, except where a national regulator says otherwise.

Chat widgets. They are not named in the guidance above, so the general test applies. A cookie that keeps a conversation going once the visitor opens the chat serves something they asked for. Identifiers a widget sets on every page load, before anyone opens it, to count or follow visitors, do not.

Embedded video. The Article 29 WP exempts player session cookies needed to play the video, for the duration of the session. The video platform's own analytics and advertising cookies are another matter. The ICO suggests configuring embeds so they set nothing when the page loads, using a privacy mode where one exists and telling visitors below the player that pressing play will set cookies. Asking for consent, or linking out, are its alternatives.

Tip

Classify a cookie by what it does on your site, not by its name or who wrote it. A session cookie reused to build an advertising profile is an advertising cookie.

Where the answer differs by country

The exemption is interpreted nationally, and analytics is where the differences show.

France. The CNIL exempts audience measurement when its purpose is "strictly limited" to measuring the site's own audience, for the publisher alone, producing anonymous statistics that are not cross-referenced with other data or passed to third parties. Its recommendation adds a tracker lifetime such as 13 months, not extended automatically on each visit, and a maximum of 25 months for the data. Its developer guide lists A/B testing among the allowed purposes, and warns that "most large audience measurement offerings do not fall within the scope of the exemption". More on the French rules.

Italy. The Garante's 2021 cookie guidelines treat analytics cookies like technical cookies when they cannot single out a visitor (for third-party analytics, for example by masking at least the last part of the IP address), are used only for aggregate statistics on a single site, and the provider does not combine the data with anything else.

United Kingdom. Since 5 February 2026, PECR has a statistical purposes exception, added by the Data (Use and Access) Act 2025. The ICO lists page visits, device types, referrers and A/B testing as likely to qualify when the aim is improving your own site, as long as you explain it and offer "a simple means of objecting, free of charge". Tracking individual visitors and anything to do with advertising still need consent. More on the UK rules.

Other countries have their own readings, so check each market you serve rather than assuming one country's exemption travels.

In the US: opt-out, not opt-in

US state privacy laws work the other way round. The CCPA does not require consent before cookies. It gives consumers the right to opt out of the sale or sharing of their personal information, where sharing means "sharing for cross-context behavioral advertising", through a "Do Not Sell or Share My Personal Information" link. Global Privacy Control has to be honoured as that opt-out, and selling the data of consumers known to be under 16 needs opt-in. The details are on our CCPA page.

Finding out what your site sets

You cannot sort cookies you do not know about, and the list changes every time someone adds a tag. Open your site in a private window and look at DevTools before touching the banner, or run our cookie checker on a URL. And a cookie on your own domain is not necessarily yours: many are written by other companies' scripts, which is where first-party and third-party cookies part ways.

Katla does this for you. It crawls your site, records every cookie, and classifies each one with AI into a category with a confidence score you can override, then generates the cookie policy from that list. In GDPR mode, the cookie guard lets only functional cookies through before the visitor chooses and deletes non-functional ones set earlier. In US State Laws (CCPA) mode, it works as an opt-out and honours GPC. Deciding what counts as necessary for your site stays with you.


This post summarises regulator guidance and is not legal advice. The rules differ by country, so check the regulator's own text for the markets you serve.