Consent-Exempt Cookies
Consent-exempt cookies are a limited group of cookies that a website can use without first asking the user for permission, because they are essential to providing a service the user has asked for. A common example is a cookie that remembers the items a user has added to an online shopping basket. Most other cookies, such as those used for analytics or advertising, generally do require consent in the EU and UK.
Consent-exempt cookies are cookies (and functionally similar technologies) whose placement or access falls outside the prior-consent requirement of the ePrivacy Directive as implemented in national law, including the UK's PECR. Under guidance such as the Article 29 Working Party's 2012 opinion, a cookie is only fully exempt where all of its distinct purposes are individually exempt; the recognised exemptions are narrow and typically limited to cookies strictly necessary to provide a service explicitly requested by the user (for example, maintaining the contents of a shopping basket) or used solely to transmit a communication. This exemption addresses only the ePrivacy/PECR consent obligation for storing or accessing information on a device; where such cookies process personal data, the GDPR continues to apply and requires a lawful basis, which may or may not be consent. The scope of these exemptions is defined by EU and UK law and associated regulator guidance; other jurisdictions, such as US state privacy regimes, treat cookies under different (often opt-out) frameworks, so what qualifies as exempt varies by jurisdiction and remains subject to evolving regulatory interpretation.
Why it matters
The scope of the consent exemption is one of the most consequential and most frequently misapplied concepts in cookie compliance. Because a truly consent-exempt cookie can be placed without a prior opt-in, organisations have a strong incentive to classify cookies as "strictly necessary" or "essential." Under the ePrivacy Directive and the UK's PECR, however, the recognised exemptions are narrow, and regulators such as the UK's ICO and Ireland's Data Protection Commission have emphasised that the exemption is limited to a small set of purposes, such as remembering the contents of an online shopping basket. Mislabelling analytics or advertising cookies as essential is a common source of non-compliance and a recurring theme in regulator guidance.
Who it's relevant to
Inside Consent-Exempt Cookies
Common questions
Answers to the questions practitioners most commonly ask about Consent-Exempt Cookies.