Non-Essential Cookies
Non-essential cookies are cookies that are not strictly required for a website to work, and instead support things like analytics, marketing, or extra features. Because they go beyond what is needed to deliver the service a user asks for, in the EU and UK they generally cannot be set until the user has given consent. This is different from essential (strictly necessary) cookies, which are typically exempt from the consent requirement.
Non-essential cookies are any cookies (and functionally equivalent technologies such as pixels, local storage, SDKs, or fingerprinting) that fall outside the narrow category of strictly necessary/essential cookies, typically covering analytics, advertising, and non-essential functional purposes. Under the ePrivacy Directive as implemented across EU member states and in the UK under PECR, the storage of, or access to, information on a user's device for non-essential purposes generally requires prior consent, and such cookies should not be set before that consent is obtained. It is important to separate two distinct layers: the ePrivacy consent requirement governs the act of storing or accessing information on the device, while any subsequent processing of personal data derived from those cookies is governed by the GDPR, which may in principle rely on lawful bases other than consent (for example, legitimate interests) for that downstream processing, even though ePrivacy consent is still required for the storage/access step. Consent under the GDPR must be freely given, specific, informed, and unambiguous through a clear affirmative action, so pre-ticked boxes and implied consent are widely regarded as insufficient in the EU. This entry describes the general EU/UK position; requirements differ under other regimes (for example, several US state privacy laws rely on opt-out rather than opt-in), and the precise classification of a given cookie as non-essential depends on its specific purpose and factual context.
Why it matters
Non-essential cookies sit at the centre of most cookie compliance work because they are the cookies that generally cannot be set until a user has given valid consent. In the EU, the ePrivacy Directive is implemented across all member states, and in the UK the equivalent rule sits in PECR; under both, storing or accessing information on a user's device for non-essential purposes such as analytics, advertising, or non-essential functionality generally requires prior consent. Regulators including the UK ICO have made clear that non-essential cookies should not be set before that consent is obtained, including on a website's homepage, which is why the timing of cookie deployment, not just the presence of a banner, matters for compliance.
A recurring source of confusion is the relationship between the two legal layers involved. The ePrivacy consent requirement governs the act of storing or accessing information on the device, while any subsequent processing of personal data derived from those cookies is governed by the GDPR. Regulators often highlight that the GDPR may in principle allow that downstream processing to rely on lawful bases other than consent, such as legitimate interests, yet ePrivacy consent is still required for the storage and access step itself. Treating a legitimate interests basis for downstream processing as if it removed the need for consent to set the cookie is a common misunderstanding that can lead to non-compliant implementations.
Because valid consent under the GDPR must be freely given, specific, informed, and unambiguous through a clear affirmative action, practices such as pre-ticked boxes and implied consent from continued browsing are widely regarded as insufficient in the EU. The correct classification of a specific cookie as essential or non-essential is fact-specific and depends on its actual purpose, so borderline cases, particularly some functional cookies, can require careful case-by-case assessment rather than a blanket label.
Who it's relevant to
Inside Non-Essential Cookies
Common questions
Answers to the questions practitioners most commonly ask about Non-Essential Cookies.