Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Cookie Types

Strictly Necessary Cookies

Also known as: Essential Cookies
Simply put

Strictly necessary cookies are cookies that a website needs to function properly, and without which the site would either not work at all or not work as intended. They typically support core features such as accessing secure areas of a site. In most EU and UK contexts, these cookies are generally exempt from the requirement to obtain prior consent, though organizations are still expected to identify and document which cookies genuinely qualify.

Formal definition

Strictly necessary (or essential) cookies are those that are essential to provide an information society service explicitly requested by the user, or that are used for the sole purpose of enabling the transmission of a communication over an electronic communications network. Under the ePrivacy Directive as implemented in the EU and under PECR in the UK, such cookies generally fall within the consent exemption for storing or accessing information on a user's device, whereas non-essential cookies such as analytics or advertising cookies typically require prior consent. The exemption is interpreted narrowly and applies to the placing of, and access to, information on the device; it does not by itself resolve any GDPR obligations that may arise if the cookie's operation involves processing personal data, which must be assessed separately. Practitioners should note that whether a specific cookie qualifies as strictly necessary is a fact-specific determination, that data protection authorities apply this category restrictively, and that the same reasoning extends to similar technologies (such as local storage, pixels, or SDKs) even though they are not literally cookies.

Why it matters

The strictly necessary category sits at the heart of every cookie compliance program because it defines the boundary of the consent exemption. In most EU and UK contexts, cookies that genuinely qualify as strictly necessary are generally exempt from the requirement to obtain prior consent under the ePrivacy Directive as implemented across the EU and under PECR in the UK. Everything that falls outside this narrow category, analytics, advertising, and many functional cookies, typically requires prior consent before it is placed on or read from a user's device. Misclassifying a non-essential cookie as strictly necessary can therefore expose an organization to the risk that it is deploying tracking technologies without a valid legal basis for their placement.

Data protection authorities generally interpret this exemption restrictively, and the burden falls on the organization to identify and document which cookies genuinely qualify. Guidance from the UK's Information Commissioner's Office, for example, frames this as an expectation that organizations have identified those cookies that are strictly necessary and those that are not. Because the determination is fact-specific rather than automatic, it is not enough to label a cookie essential because it is convenient or commercially useful; it must be essential to deliver a service the user has explicitly requested.

It is also important not to treat the exemption as resolving all compliance questions. The consent exemption addresses only the placing of, and access to, information on a device. If the operation of a strictly necessary cookie involves the processing of personal data, any GDPR obligations that arise must be assessed separately and are not automatically satisfied by the fact that the cookie is exempt from consent. Organizations that overlook this distinction may satisfy the ePrivacy analysis while leaving GDPR questions unaddressed.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for cookie compliance need to identify and document which cookies genuinely qualify as strictly necessary and which do not, applying the exemption narrowly as data protection authorities generally expect. They should also assess separately whether the operation of any such cookie triggers GDPR obligations, since the consent exemption does not resolve those questions.
Legal counsel and compliance teams
Legal advisors evaluate whether a particular cookie meets the fact-specific test for being essential to a service the user has explicitly requested, and advise on the difference between the ePrivacy/PECR analysis governing placement on a device and any GDPR analysis governing personal data. Because whether a cookie qualifies is a fact-specific determination, they help organizations record defensible reasoning rather than rely on labels.
Web developers and engineers
Developers implement the mechanisms that place cookies and similar technologies, including local storage, pixels, and SDKs. Understanding which functions are genuinely essential to core site operation, such as accessing secure areas, helps them ensure that non-essential technologies are gated behind consent rather than being deployed by default.
Marketing compliance teams
Marketing teams often work with analytics and advertising cookies, which typically fall outside the strictly necessary category and generally require prior consent in EU and UK contexts. Recognizing that convenience or commercial value does not make a cookie essential helps these teams avoid misclassifying tracking technologies as exempt.

Inside Strictly Necessary Cookies

Consent exemption basis
Strictly necessary cookies are those generally exempt from the prior consent requirement under the ePrivacy Directive and its national implementations, because they are essential to provide a service explicitly requested by the user. The exemption concerns the placing of and access to information on the user's device; any personal data processing that follows is still governed by the GDPR.
Functional necessity criterion
To qualify, a cookie must be essential for a service the user has actively requested, such that the service could not function without it. Cookies that merely enhance or improve a service, but are not indispensable to it, typically fall outside this category and generally require consent in most EU jurisdictions.
Common examples
Cookies that are frequently treated as strictly necessary include those supporting user authentication and session management, load balancing, security features, and remembering the contents of a shopping cart during a session. Whether a given cookie qualifies depends on the specific facts and the service in question.
Scope of the concept beyond cookies
The same reasoning applies to similar technologies, such as local storage, pixels, and SDKs, where they are strictly necessary to deliver a requested service. The exemption is defined by the function performed rather than by the literal use of a cookie.
Jurisdictional variation
The strictly necessary concept derives primarily from EU and UK frameworks. US state privacy laws such as the CCPA and CPRA use different structures, often relying on opt-out rights rather than an opt-in consent exemption, so the category does not map identically across regimes. The geographic scope should always be stated when classifying a cookie.

Common questions

Answers to the questions practitioners most commonly ask about Strictly Necessary Cookies.

Does labeling a cookie as 'strictly necessary' automatically exempt it from consent requirements?
No. The exemption depends on the actual function of the cookie, not on how it is labeled. Under the ePrivacy Directive and its national implementations, the consent exemption generally applies only where a cookie is strictly necessary to provide a service explicitly requested by the user, or is used solely to carry out the transmission of a communication. A cookie that a provider merely finds convenient, or that serves purposes such as analytics or advertising, does not qualify simply because it is described as necessary. Data protection authorities have generally taken the view that this category should be interpreted narrowly, and the classification should be assessed against the specific purpose of each cookie.
If a cookie is strictly necessary and exempt from consent, does that mean the GDPR does not apply to it?
Not necessarily. The consent exemption under the ePrivacy rules concerns the placing of and access to information on a user's device. It does not by itself address the separate question of whether any personal data processed through that cookie is governed by the GDPR. Where a strictly necessary cookie involves processing of personal data, that processing still needs a lawful basis under the GDPR and remains subject to transparency, purpose limitation, and other GDPR obligations. In practice this often means the processing may rely on a basis other than consent, but the applicability of the GDPR should be assessed independently of the ePrivacy exemption.
How do we decide whether a particular cookie qualifies as strictly necessary?
The assessment is function-based and typically done cookie by cookie. A common approach is to ask whether the service the user explicitly requested could be delivered without that cookie. Cookies commonly considered within scope in many EU jurisdictions include those supporting user-input persistence during a session, authentication and security for a requested service, load balancing, and remembering consent choices. Purposes such as analytics, personalization, and advertising generally fall outside the exemption. Because interpretations can vary and regulatory guidance evolves, borderline cases may warrant legal review rather than a purely technical judgment, and the classification should be documented.
Should strictly necessary cookies appear in our cookie banner and consent management platform?
Even where these cookies do not require prior consent, transparency obligations generally still apply, so users are typically informed about them. In practice many organizations list strictly necessary cookies within their cookie notice or CMP interface as an informational, non-toggleable category, distinguishing them from categories that require consent. A CMP can support this presentation, but it does not determine the legal classification; the underlying assessment of whether each cookie truly qualifies remains a separate matter of judgment. Requirements around how information is presented may differ across the EU, the UK, and other regimes.
Do the same principles apply to non-cookie technologies used for essential functions?
Generally yes. The ePrivacy rules on storing and accessing information on a user's device are technology-neutral, so similar technologies such as local storage, SDKs, pixels, and comparable mechanisms fall within the same framework even though they are not literally cookies. Where such a technology is strictly necessary to provide a service the user explicitly requested, the same narrow exemption reasoning generally applies, and where it is not, consent may be required. The classification should be based on the technology's actual purpose rather than its technical form.
Do we need to keep records for cookies we treat as strictly necessary?
Because these cookies typically do not rely on consent, there is generally no consent record to log for them in the way there would be for consent-based cookies. However, maintaining internal documentation of why each cookie was classified as strictly necessary can support accountability and help demonstrate the basis for the classification if questioned. Any personal data processing carried out through these cookies may still be subject to GDPR record-keeping and accountability obligations. Record-keeping expectations can vary by jurisdiction and by the nature of the processing, so the specific requirements should be assessed in context.

Common misconceptions

If a cookie is labelled strictly necessary, no privacy obligations apply at all.
The exemption relates only to the consent requirement for storing or accessing information on the device under the ePrivacy rules. Where the cookie involves personal data, the GDPR (and equivalent laws) still applies, including obligations around transparency, lawful basis for processing, and information provided to users.
Analytics and functionality cookies count as strictly necessary because the site owner considers them important to operations.
Importance to the operator is not the test. A cookie generally qualifies only if the requested service cannot function without it. Analytics, advertising, and many functional cookies typically enhance rather than enable the service and, in most EU jurisdictions, require prior consent.
The strictly necessary category works the same way in every jurisdiction.
The concept is rooted in EU and UK law. Other regimes, including US state privacy laws, structure their obligations differently and may not recognise an identical exemption, so classification should always be assessed against the applicable legal framework.

Best practices

Assess each cookie against the functional necessity test individually, asking whether the specific service the user requested could operate without it, rather than applying the label broadly across a category.
Document the justification for treating each cookie as strictly necessary, so the classification can be explained and defended if questioned by a data protection authority.
Apply the same analysis to non-cookie technologies such as local storage, pixels, and SDKs, since the exemption follows the function performed rather than the technical mechanism.
Keep the strictly necessary set as narrow as possible and route analytics, advertising, and non-essential functional technologies through a consent mechanism instead.
Address any personal data processing carried out by strictly necessary cookies under the GDPR, including transparency notices and an appropriate lawful basis, rather than assuming the consent exemption removes all obligations.
Confirm the classification separately for each jurisdiction in which the service operates, since the strictly necessary exemption is an EU and UK concept and other regimes may treat the same cookie differently.
Review classifications periodically, because regulatory guidance and enforcement positions on what qualifies as strictly necessary continue to evolve.
Application Security Isn’t Optional Anymore.