Cookie compliance that holds up,
in every market you sell to.
What cookies are, what the EU, UK, US and Australian rules ask of them, and how regulators expect a cookie banner to look. Written for teams who run a website in more than one market. A practical guide, not legal advice.
Last updated Published by TryTrustableNot legal advice
Cookie compliance means setting cookies and similar trackers only in the way the law where your visitors live allows. In the EU and UK that means asking for opt-in consent before any cookie that is not strictly necessary, with rejecting as easy as accepting and no pre-ticked boxes. In California and other US states it means letting people opt out of the sale or sharing of their data, including through Global Privacy Control. In Australia it means treating cookie data that identifies people as personal information under the Privacy Act. Everywhere, it means telling people what you set and why, and being able to prove what they chose.
What are cookies?
A cookie is a small text file a website asks the browser to store, then reads back on later requests. Cookies keep you logged in, remember a basket, count visits and, when set by ad networks, follow a browser across sites. The law does not regulate the file format: it regulates storing or reading information on a person's device. So the same rules cover local storage, tracking pixels, fingerprinting and identifiers in mobile SDKs.
Cookies are usually sorted three ways: by purpose, by who sets them, and by how long they last. Purpose is the one that decides whether you need consent.
| Type | What it is | Consent in the EU and UK? |
|---|---|---|
| Strictly necessary | Needed for something the visitor asked for: a login session, a basket, load balancing, the cookie that stores their consent choice | No |
| Functional or preference | Remembers choices such as language or region | Usually yes in the EU; the UK now has an exception if you inform and offer an easy objection |
| Analytics or statistics | Counts visits and measures how the site is used | Yes in the EU; the UK now has an exception for first-party statistics under conditions |
| Marketing or advertising | Tracks visitors across sites to target and measure ads | Yes, everywhere in Europe |
| First-party | Set by the site the visitor is on | Depends on purpose, not on who sets it |
| Third-party | Set by another domain loaded on the page: an ad network, a video embed | Depends on purpose; almost always non-essential |
| Session vs persistent | Deleted when the browser closes, or kept until an expiry date | Depends on purpose; lifetime should be proportionate |
The same rules cover similar technologies: local storage, pixels, fingerprinting and SDK identifiers in apps.
First-party vs third-party cookies. A first-party cookie is set by the domain in the address bar; a third-party cookie by another domain whose code or iframe is on the page. Browsers increasingly restrict third-party cookies, but that does not remove the legal duty: an analytics cookie set as first-party still needs consent in the EU.
GDPR cookie consent and the ePrivacy rule (EU)
In the EU, cookie consent comes from Article 5(3) of the ePrivacy Directive, implemented in each country's own law. Storing or accessing information on a user's device needs the user's consent, after clear and comprehensive information, unless it is strictly necessary to provide a service the user asked for or only for transmitting a communication. This applies whether or not the cookie holds personal data.
The GDPR supplies the standard that consent must meet: freely given, specific, informed and unambiguous, by a clear affirmative act (Article 4(11)); as easy to withdraw as to give (Article 7(3)); and provable (Article 7(1)). Recital 32 says silence, pre-ticked boxes and inactivity are not consent, and the Court of Justice confirmed in Planet49 (C-673/17, 2019) that a pre-ticked box is not valid cookie consent. Any personal data the cookies then collect also needs a lawful basis under the GDPR.
The European Commission has proposed changes to the cookie rules as part of its digital simplification work. Until a change is adopted and in force, Article 5(3) applies as written.
UK cookie compliance under PECR
In the UK the rule is regulation 6 of the Privacy and Electronic Communications Regulations (PECR), enforced by the ICO, with consent to the UK GDPR standard. The Data (Use and Access) Act 2025 changed it. According to the ICO, its data protection provisions were phased in between June 2025 and June 2026 and are now in force. Alongside the strictly necessary exception, PECR now has exceptions for:
- Statistical purposes: first-party analytics used only to improve your own service, if you give clear information and a simple, free way to object, share data only with processors helping you, and aggregate it.
- Appearance: remembering a visitor's choices about how the site looks or works, on the same conditions.
- Emergency assistance and communication, in narrow cases.
The ICO is explicit that none of these exceptions covers online advertising. Ad and tracking cookies still need opt-in consent, and the ICO's banner expectations (reject as easy as accept, no pre-ticked boxes, no nudging) are unchanged. Many UK sites will still ask for analytics consent because their analytics provider does not meet the processor-only condition.
Cookie compliance under the CCPA and other US laws
US state privacy laws are opt-out, not opt-in. You may set cookies without asking first, but you must tell people what you collect and let them opt out of certain uses.
- Notice at collection: the categories of personal information collected through cookies and the purposes, at or before the point of collection. A link in the footer or banner to that notice is the usual approach.
- Do Not Sell or Share: letting an ad network's cookies collect data for cross-context behavioural advertising is "sharing" under the CCPA. If you do it, you need a clear "Do Not Sell or Share My Personal Information" link, and the opt-out must actually stop those cookies.
- Global Privacy Control: the California Attorney General says businesses must honour GPC as a valid request to opt out of sale or sharing. Several other states also require universal opt-out signals to be honoured.
Not sure whether the CCPA applies to you? Try the CCPA applicability checker.
Cookies under the Australian Privacy Act
Australia has no cookie-specific consent law. The Privacy Act 1988 and the Australian Privacy Principles apply when information collected through cookies is personal information, meaning it identifies a person or could reasonably identify them. Then your APP privacy policy must say how you collect it (APP 1), you must notify people at collection (APP 5), and use it only for the purposes you collected it for or ones they would reasonably expect (APP 6). Sensitive information, such as health data inferred from browsing, generally needs consent (APP 3). Most businesses with annual turnover of A$3 million or less are exempt from the Act, with exceptions. Many Australian sites use a notice-style banner with an opt-out; sites with EU or UK visitors use regional rules so those visitors get an opt-in banner.
Cookie notice vs cookie policy
The two are often confused. A cookie notice is the short message in the banner itself: what you use cookies for, the choices, and a link to more detail. A cookie policy is the full page behind that link: every cookie or tracker by name, the provider, its purpose, its category and how long it lasts, plus how to change consent. Under the GDPR and PECR, consent is only informed if that detail is available at the point of choice, so the notice needs to link to the policy. Some sites put the cookie policy inside their privacy notice; a separate page is easier to keep current.
Our free cookie policy generator builds the table for you, and the cookie scanner finds what your site actually sets.
Cookie banner requirements: design rules from the ICO, CNIL and EDPB
Most cookie enforcement in Europe is about banner design rather than missing banners. In January 2023 the EDPB published the report of its cookie banner taskforce, which brought national regulators to a common view on the practices they see most. Together with ICO and CNIL guidance, these are the rules a banner for EU and UK visitors should meet.
| Rule | What regulators expect | Who says so |
|---|---|---|
| Reject as easy as accept | A reject option on the first layer, as visible and as many clicks as accept | EDPB taskforce, CNIL, ICO |
| Equal prominence | No accept button in bright colour beside a faint reject link | EDPB taskforce (deceptive colours and contrast), ICO (nudging) |
| No pre-ticked boxes | Every non-essential category off until the visitor turns it on | GDPR Recital 32, CJEU Planet49, ICO |
| No consent by scrolling | Continuing to browse is not consent | EDPB Guidelines 05/2020, CNIL |
| Nothing before consent | Non-essential cookies and tags held until the visitor chooses | ePrivacy Art. 5(3), PECR reg. 6 |
| Granular choice | Separate purposes (analytics, marketing) the visitor can choose between | EDPB, ICO |
| Honest classification | Do not label ad or analytics cookies as essential | EDPB taskforce (inaccurately classified essential cookies) |
| No legitimate interest for cookies | Consent, not legitimate interest, for non-essential storage | EDPB taskforce |
| Easy withdrawal | A persistent link or icon to change or withdraw consent at any time | GDPR Art. 7(3), EDPB taskforce |
| Proof | A record of what each visitor was shown and chose, and when | GDPR Art. 7(1), CNIL |
These come from EU and UK regulators. In US opt-out states the banner must instead make opting out easy.
Accessibility counts too: the banner should be readable by screen readers and usable by keyboard, and should not hide content in a way that makes refusing harder than accepting.
Shopify and WordPress cookie banners
Shopify. Shopify offers its own cookie banner through its Privacy and Compliance app, and a Customer Privacy API that applies consent to Shopify-managed pixels, audiences and checkout. If you use another banner, it must call that API (setTrackingConsent) with the visitor's choice for Shopify's four categories: preferences, analytics, marketing and sale of data. Otherwise Shopify's own tracking ignores your banner. Scripts added by apps and in theme.liquid need to be held as well.
WordPress. Plugins inject scripts in many places, often before a banner plugin loads. Check that your banner loads first in the <head>, that it holds scripts added by other plugins and by your theme, and that embeds (YouTube, maps) are blocked until consent. The WP Consent API plugin lets compatible plugins read a banner's choice. After any change, scan the site before and after consent to see what really fires.
Whatever the platform, the test is the same: load the site in a clean browser, and before you click anything, no non-essential cookie should be set and no tracker request should leave the page.
How TryTrustable handles cookie compliance
The TryTrustable consent banner is one script tag at the top of the <head>. What it does:
- Blocks before consent. Non-essential scripts, iframes and pixels that load after it are held until the visitor grants the matching purpose, matched by a tag you add or by known tracker hosts.
- Regional rules. Opt-in for EU and UK visitors; opt-out for US states with Global Privacy Control honoured; DPDP rules for India.
- No pre-ticked categories in opt-in regions, and an equal-prominence setting that gives reject the same styling as accept.
- Google Consent Mode v2 set for you (see our Consent Mode guide).
- Proof. Every choice is written to a tamper-evident consent ledger with the notice version shown; withdrawals are relayed to your processors' webhooks with each delivery logged.
- Rights. A privacy-request link on the banner.
A banner is one part of compliance. It does not make a site compliant on its own: the cookie policy, your privacy notice and the way you use the data all matter.
The things people ask us
What is cookie compliance?
Setting cookies and similar trackers only as the law in each visitor's market allows: opt-in consent in the EU and UK for anything not strictly necessary, opt-outs in US states, and accurate notice everywhere.
Do I need a cookie banner?
If you have EU or UK visitors and set any cookie that is not strictly necessary, yes. If you share data with ad networks and the CCPA applies, you need a Do Not Sell or Share link. Our free cookie consent checker gives an answer from what your site runs.
Why are pre-ticked boxes not allowed?
Consent under the GDPR needs a clear affirmative act. Recital 32 says pre-ticked boxes are not consent, and the Court of Justice confirmed it for cookies in Planet49 (2019).
Does the reject button have to be on the first layer?
EU and UK regulators expect refusing to be as easy as accepting. The EDPB taskforce listed a missing reject button on the first layer as a problem, and the CNIL and ICO say the same.
Do analytics cookies need consent in the UK?
Not always since the Data (Use and Access) Act 2025. First-party statistics to improve your service can use an exception if you inform people, let them object simply and for free, and meet the other conditions. Advertising cookies still need consent.
What is the difference between a cookie notice and a cookie policy?
The notice is the short banner text with the choices. The policy is the full page listing each cookie, its provider, purpose and lifetime.
Does Australia require cookie consent?
There is no cookie-specific consent rule. The Privacy Act applies where cookie data is personal information, so you need notice and a privacy policy that covers it, and consent for sensitive information.
See what your site sets before anyone clicks.
Thirty minutes: we scan your site live, then show the same trackers held behind the banner, with regional rules for the EU, UK and US.