Skip to main content
Category: Cookie Types

User-Input Cookies

Simply put

User-input cookies are small files a website stores on your device to remember information you actively provide during a single visit, such as items in a shopping basket or details entered into a form. They are typically first-party session cookies that expire once you close your browser or your session ends. Because they help deliver the service you asked for, they are generally treated as essential and usually do not require prior consent under EU and UK rules.

Formal definition

User-input cookies are first-party cookies used to store information a user actively enters or selects during a browsing session, for example form-field contents, shopping-cart items, or session state carried across pages. They are most commonly session cookies that expire at the end of the user's session rather than persistent cookies. In most EU jurisdictions and the UK, such cookies are generally regarded as strictly necessary to provide a service explicitly requested by the user and therefore may be exempt from the prior-consent requirement under the ePrivacy Directive as implemented nationally (and PECR in the UK); however, the exemption depends on the specific purpose and whether the cookie is limited to delivering the requested functionality. This categorization concerns the ePrivacy/PECR consent obligation for storing or accessing information on the device; any personal data processed via these cookies remains subject to the GDPR, which is a separate legal analysis. The precise boundary of the exemption is fact-dependent and subject to evolving guidance from data protection authorities, and this definition does not resolve borderline cases where a cookie serves purposes beyond the user's explicit request.

Why it matters

User-input cookies illustrate a category that most organizations can rely on without a consent banner, but only within clearly defined limits. Because these cookies remember information the user has actively provided, such as basket contents or form entries, they are generally treated as strictly necessary to deliver a service the user explicitly requested. In most EU jurisdictions and the UK, that categorization means they may fall within the exemption from the prior-consent requirement under the ePrivacy Directive (as implemented nationally) and PECR. For compliance teams, correctly identifying which cookies genuinely qualify avoids both unnecessary consent friction and the opposite risk of wrongly exempting a cookie that serves broader purposes.

Who it's relevant to

Web developers and engineers
Developers implementing shopping carts, multi-step forms, or session state need to understand which cookies they set qualify as user-input cookies. Keeping such cookies first-party and session-scoped, and limited strictly to delivering the requested functionality, supports reliance on the strictly necessary exemption in most EU jurisdictions and the UK. Where a cookie begins serving additional purposes beyond the user's explicit request, that exemption may no longer apply.
Privacy officers and data protection professionals
Those maintaining cookie inventories and consent configurations should assess each user-input cookie against the specific-purpose test rather than assuming a blanket exemption. The boundary of the strictly necessary exemption is fact-dependent and subject to evolving guidance from data protection authorities, so borderline cases warrant documented reasoning. Note also that any personal data processed via these cookies remains subject to a separate GDPR analysis.
Legal and compliance counsel
Counsel advising on cookie compliance should keep the ePrivacy/PECR consent question distinct from the GDPR processing question, since exemption from prior consent does not resolve GDPR obligations. They should also flag that consent rules and exemption interpretations differ across the EU, the UK, and US state frameworks, so a categorization valid in one regime should not be presented as universal.

Inside User-Input Cookies

Session-based scope
User-input cookies are typically limited to the duration of a browsing session or a short period, storing information the user actively entered rather than persistent tracking identifiers.
User-provided data
These cookies retain input supplied directly by the user, such as text typed into a form, items placed in a shopping basket, or selections made during a transaction as the user moves between pages.
Consent-exemption basis
In most EU jurisdictions, user-input cookies are generally treated as strictly necessary and fall within the ePrivacy consent exemption, because they are essential to provide a service the user has explicitly requested.
Functional purpose limitation
The exemption typically applies only where the cookie's purpose is limited to carrying out or facilitating the transmission of the user's input; using the same data for analytics, profiling, or advertising would generally fall outside the exemption and may require consent.
Interaction with the GDPR
Even where placing a user-input cookie is exempt from ePrivacy consent, any personal data processed through it remains subject to the GDPR, which requires a lawful basis, transparency, and appropriate safeguards. The exemption from consent to store the cookie does not remove GDPR obligations.

Common questions

Answers to the questions practitioners most commonly ask about User-Input Cookies.

Are user-input cookies exempt from consent because they are set in response to something the user typed?
Not automatically. The exemption from consent under the ePrivacy rules in most EU jurisdictions applies to cookies that are strictly necessary to provide a service the user has explicitly requested, and user-input cookies commonly fall within this category (for example, remembering form entries, shopping cart contents, or multi-step input across pages). However, the exemption is tied to necessity, not to the mere fact that the user provided input. If the cookie is used for additional purposes such as analytics, personalization, or advertising, those purposes generally require consent even though the same interaction involved user input. Assess the purpose, not just the origin of the data.
Does a user-input cookie being exempt from ePrivacy consent mean I have no GDPR obligations for it?
No. The ePrivacy consent exemption governs whether you may place or read the cookie without consent, but the GDPR still governs any processing of personal data that follows. If a user-input cookie stores or relates to personal data, you generally still need a lawful basis under the GDPR, and transparency, data minimization, retention limits, and data subject rights obligations continue to apply. The two regimes operate in parallel, so an ePrivacy exemption does not remove GDPR responsibilities.
How long should a user-input cookie persist to stay within the strictly necessary category?
There is no single fixed duration set across jurisdictions. As a general principle, a user-input cookie should typically last only as long as needed to fulfill the requested functionality, which for session-based inputs often means it expires at the end of the session or shortly after. Persistence significantly beyond the functional need may weaken the argument that the cookie remains strictly necessary and could move it outside the exemption. The appropriate duration depends on the specific function and should be documented; guidance from data protection authorities may vary.
How should user-input cookies be documented in a cookie audit or register?
Record each cookie's name, purpose, the specific user-requested function it supports, its duration, and whether it stores personal data. Documenting the necessity rationale is useful because it supports the claim that the cookie qualifies for the consent exemption. Distinguishing user-input cookies from non-essential cookies in your register also helps ensure they are not inadvertently placed behind a consent banner or blocked before consent, and supports accountability if a regulator queries your categorization.
Should a consent management platform block user-input cookies before consent is given?
Generally, cookies that are genuinely strictly necessary, including qualifying user-input cookies, should not be blocked pending consent, because doing so could impair the functionality the user requested. Most CMPs allow you to categorize cookies as strictly necessary so they load without requiring prior consent. The key implementation step is correct classification: a CMP applies the categories you configure and does not itself determine whether a cookie is truly exempt, so the categorization decision requires your own legal judgment.
Do user-input cookies still need to be disclosed to users even if consent is not required?
Yes, transparency obligations generally still apply. Even where a user-input cookie is exempt from consent, users typically should be informed about it, for example in a cookie notice or policy that describes its purpose and duration. Providing this information supports the informed nature of your overall disclosures and is consistent with GDPR transparency requirements where personal data is involved. Disclosure and consent are distinct: an exemption relieves you of obtaining consent, not of being transparent.

Common misconceptions

Because user-input cookies are exempt from consent, they are exempt from all data protection law.
The ePrivacy consent exemption concerns only the placing of and access to the cookie on the device. Any personal data processed through the cookie is still governed by the GDPR, which requires a lawful basis, transparency, and other safeguards. The two regimes apply separately.
Any cookie storing information the user typed automatically qualifies for the strictly necessary exemption.
The exemption generally applies only where the cookie is genuinely essential to deliver a service the user has requested and is limited to that purpose. If the stored input is also reused for analytics, personalization, or advertising, that additional processing typically falls outside the exemption and may require prior consent in the EU.
The exemption for user-input cookies is the same in every jurisdiction.
The strictly necessary or essential-cookie exemption derives from the EU ePrivacy framework and its national implementations, and the UK applies a comparable approach. US state privacy laws such as the CCPA and CPRA operate on different principles, often opt-out based, so the scope and treatment of such cookies can differ and should be assessed per jurisdiction.

Best practices

Confirm that each user-input cookie is genuinely essential to a service the user has requested and document why it qualifies as strictly necessary before relying on the ePrivacy consent exemption.
Limit the cookie strictly to its input-related purpose; if you intend to reuse the stored data for analytics, personalization, or advertising, treat that additional processing separately and obtain consent where required in the EU.
Even where consent to store the cookie is exempt, identify and record an appropriate GDPR lawful basis and provide clear information about the associated processing in your privacy notice.
Set an appropriate, limited lifespan for user-input cookies aligned with the session or task, and avoid retaining the data longer than necessary.
Review the treatment of these cookies against the specific jurisdictions you operate in, since EU, UK, and individual US state rules differ, and do not assume a single approach applies everywhere.
Periodically audit which cookies you classify as user-input or strictly necessary, and reassess the classification as functionality, data uses, and regulatory guidance evolve rather than treating it as a one-time determination.