European Union
EU cookie consent: an ePrivacy and GDPR implementation checklist
How device-access rules and GDPR consent requirements shape a defensible banner and blocking setup.
8 min read · 1 August 2026
Two legal layers, one user journey
Article 5(3) of the ePrivacy Directive governs storing information on, or accessing information from, a user’s device. Where that activity involves personal data, GDPR obligations also apply.
National laws implement the Directive, so teams need an EU baseline plus a country-level review for their target markets.
What the first layer should do
Before consent, keep optional analytics, advertising and functional technologies inactive. Present accept, reject and settings actions with comparable clarity, and avoid preselected optional purposes.
- Explain purposes in plain language.
- Separate optional purposes so the choice is granular.
- Do not treat scrolling or continued browsing as consent.
- Make withdrawal as easy as giving consent.
Evidence and change management
Record a pseudonymous visitor reference, time, selected purposes, notice version and configuration version. Re-ask when purposes or vendors materially change rather than silently extending an old choice.
Retention should be documented and proportionate. Keep the evidence needed to demonstrate the decision without turning the consent log into an unnecessary identity store.
Release checklist
Test the site in a clean browser before and after each choice. Verify network requests, cookies, local storage, iframes and consent signals, including on translated pages and tag-manager variants.
- No optional storage before an affirmative choice.
- Reject works from the first layer.
- Preference centre reopens from every page.
- Policy links and vendor information match production behaviour.
- Consent Mode defaults and updates match the selected categories.