Essential Cookies
Essential cookies are cookies a website needs in order to work properly for something the user has asked it to do, such as keeping a user logged in or remembering items during a task. Without them, the requested part of the website would not function. Because they are necessary to deliver what the user requested, they are generally not treated the same as cookies used for convenience, analytics, or advertising.
Essential cookies, commonly referred to as strictly necessary cookies, are cookies required for a website to function and to provide a service explicitly requested by the user, for example storing a login session. Under UK guidance from the ICO, the relevant test is that the cookie must be essential to fulfil the user's request; cookies that are merely helpful or convenient, or that are essential only for the website operator's own purposes rather than the user's requested service, do not meet this threshold. In most EU and UK contexts, cookies that satisfy this strict necessity test may fall within an exemption from prior consent under the ePrivacy rules, but the exemption is applied narrowly, and whether a given cookie qualifies depends on its specific purpose and factual context; this definition does not resolve borderline classification questions or the separate question of whether any personal data processed via such cookies triggers additional obligations under the GDPR.
Why it matters
The classification of a cookie as essential carries significant compliance consequences because, in most EU and UK contexts, cookies that satisfy the strict necessity test may fall within an exemption from the prior consent requirement under the ePrivacy rules. This means organizations do not generally need to obtain consent before setting these cookies, provided they genuinely meet the threshold. Misclassifying a convenience, analytics, or advertising cookie as essential in order to avoid seeking consent is a common source of compliance risk, because the exemption is applied narrowly and regulators scrutinize such claims.
The key test, as reflected in UK guidance from the ICO, is that a cookie must be essential to fulfil something the user has actually requested. Cookies that are merely helpful or convenient, or that are essential only for the website operator's own purposes rather than for delivering the service the user asked for, do not qualify. Because this distinction turns on the specific purpose and factual context of each cookie, borderline cases are frequent and cannot be resolved by labeling alone.
It is also important to note that the ePrivacy consent exemption for essential cookies is a separate question from the GDPR. Even where a cookie is exempt from prior consent because it is strictly necessary, any personal data processed through that cookie may still trigger additional obligations under the GDPR, such as identifying a lawful basis and meeting transparency requirements. Organizations should not assume that qualifying as essential resolves all compliance questions.
Who it's relevant to
Inside Essential Cookies
Common questions
Answers to the questions practitioners most commonly ask about Essential Cookies.