All articles

European Union

EU cookie consent: an ePrivacy and GDPR implementation checklist

How device-access rules and GDPR consent requirements shape a defensible banner and blocking setup.

8 min read · 1 August 2026

Two legal layers, one user journey

Article 5(3) of the ePrivacy Directive governs storing information on, or accessing information from, a user’s device. Where that activity involves personal data, GDPR obligations also apply.

National laws implement the Directive, so teams need an EU baseline plus a country-level review for their target markets.

What the first layer should do

Before consent, keep optional analytics, advertising and functional technologies inactive. Present accept, reject and settings actions with comparable clarity, and avoid preselected optional purposes.

  • Explain purposes in plain language.
  • Separate optional purposes so the choice is granular.
  • Do not treat scrolling or continued browsing as consent.
  • Make withdrawal as easy as giving consent.

Evidence and change management

Record a pseudonymous visitor reference, time, selected purposes, notice version and configuration version. Re-ask when purposes or vendors materially change rather than silently extending an old choice.

Retention should be documented and proportionate. Keep the evidence needed to demonstrate the decision without turning the consent log into an unnecessary identity store.

Release checklist

Test the site in a clean browser before and after each choice. Verify network requests, cookies, local storage, iframes and consent signals, including on translated pages and tag-manager variants.

  • No optional storage before an affirmative choice.
  • Reject works from the first layer.
  • Preference centre reopens from every page.
  • Policy links and vendor information match production behaviour.
  • Consent Mode defaults and updates match the selected categories.