Strictly Necessary Cookies
Strictly necessary cookies are cookies that a website needs to function properly, and without which the site would either not work at all or not work as intended. They typically support core features such as accessing secure areas of a site. In most EU and UK contexts, these cookies are generally exempt from the requirement to obtain prior consent, though organizations are still expected to identify and document which cookies genuinely qualify.
Strictly necessary (or essential) cookies are those that are essential to provide an information society service explicitly requested by the user, or that are used for the sole purpose of enabling the transmission of a communication over an electronic communications network. Under the ePrivacy Directive as implemented in the EU and under PECR in the UK, such cookies generally fall within the consent exemption for storing or accessing information on a user's device, whereas non-essential cookies such as analytics or advertising cookies typically require prior consent. The exemption is interpreted narrowly and applies to the placing of, and access to, information on the device; it does not by itself resolve any GDPR obligations that may arise if the cookie's operation involves processing personal data, which must be assessed separately. Practitioners should note that whether a specific cookie qualifies as strictly necessary is a fact-specific determination, that data protection authorities apply this category restrictively, and that the same reasoning extends to similar technologies (such as local storage, pixels, or SDKs) even though they are not literally cookies.
Why it matters
The strictly necessary category sits at the heart of every cookie compliance program because it defines the boundary of the consent exemption. In most EU and UK contexts, cookies that genuinely qualify as strictly necessary are generally exempt from the requirement to obtain prior consent under the ePrivacy Directive as implemented across the EU and under PECR in the UK. Everything that falls outside this narrow category, analytics, advertising, and many functional cookies, typically requires prior consent before it is placed on or read from a user's device. Misclassifying a non-essential cookie as strictly necessary can therefore expose an organization to the risk that it is deploying tracking technologies without a valid legal basis for their placement.
Data protection authorities generally interpret this exemption restrictively, and the burden falls on the organization to identify and document which cookies genuinely qualify. Guidance from the UK's Information Commissioner's Office, for example, frames this as an expectation that organizations have identified those cookies that are strictly necessary and those that are not. Because the determination is fact-specific rather than automatic, it is not enough to label a cookie essential because it is convenient or commercially useful; it must be essential to deliver a service the user has explicitly requested.
It is also important not to treat the exemption as resolving all compliance questions. The consent exemption addresses only the placing of, and access to, information on a device. If the operation of a strictly necessary cookie involves the processing of personal data, any GDPR obligations that arise must be assessed separately and are not automatically satisfied by the fact that the cookie is exempt from consent. Organizations that overlook this distinction may satisfy the ePrivacy analysis while leaving GDPR questions unaddressed.
Who it's relevant to
Inside Strictly Necessary Cookies
Common questions
Answers to the questions practitioners most commonly ask about Strictly Necessary Cookies.

