Cookie compliance

Cookie compliance that holds up,
in every market you sell to.

What cookies are, what the EU, UK, US and Australian rules ask of them, and how regulators expect a cookie banner to look. Written for teams who run a website in more than one market. A practical guide, not legal advice.

ePrivacy Art. 5(3)GDPR Art. 7UK PECRCCPA and GPCAustralian Privacy Act

Last updated Published by TryTrustableNot legal advice

Short answer

Cookie compliance means setting cookies and similar trackers only in the way the law where your visitors live allows. In the EU and UK that means asking for opt-in consent before any cookie that is not strictly necessary, with rejecting as easy as accepting and no pre-ticked boxes. In California and other US states it means letting people opt out of the sale or sharing of their data, including through Global Privacy Control. In Australia it means treating cookie data that identifies people as personal information under the Privacy Act. Everywhere, it means telling people what you set and why, and being able to prove what they chose.

01

What are cookies?

A cookie is a small text file a website asks the browser to store, then reads back on later requests. Cookies keep you logged in, remember a basket, count visits and, when set by ad networks, follow a browser across sites. The law does not regulate the file format: it regulates storing or reading information on a person's device. So the same rules cover local storage, tracking pixels, fingerprinting and identifiers in mobile SDKs.

Cookies are usually sorted three ways: by purpose, by who sets them, and by how long they last. Purpose is the one that decides whether you need consent.

TypeWhat it isConsent in the EU and UK?
Strictly necessaryNeeded for something the visitor asked for: a login session, a basket, load balancing, the cookie that stores their consent choiceNo
Functional or preferenceRemembers choices such as language or regionUsually yes in the EU; the UK now has an exception if you inform and offer an easy objection
Analytics or statisticsCounts visits and measures how the site is usedYes in the EU; the UK now has an exception for first-party statistics under conditions
Marketing or advertisingTracks visitors across sites to target and measure adsYes, everywhere in Europe
First-partySet by the site the visitor is onDepends on purpose, not on who sets it
Third-partySet by another domain loaded on the page: an ad network, a video embedDepends on purpose; almost always non-essential
Session vs persistentDeleted when the browser closes, or kept until an expiry dateDepends on purpose; lifetime should be proportionate

The same rules cover similar technologies: local storage, pixels, fingerprinting and SDK identifiers in apps.

First-party vs third-party cookies. A first-party cookie is set by the domain in the address bar; a third-party cookie by another domain whose code or iframe is on the page. Browsers increasingly restrict third-party cookies, but that does not remove the legal duty: an analytics cookie set as first-party still needs consent in the EU.

05

Cookies under the Australian Privacy Act

Australia has no cookie-specific consent law. The Privacy Act 1988 and the Australian Privacy Principles apply when information collected through cookies is personal information, meaning it identifies a person or could reasonably identify them. Then your APP privacy policy must say how you collect it (APP 1), you must notify people at collection (APP 5), and use it only for the purposes you collected it for or ones they would reasonably expect (APP 6). Sensitive information, such as health data inferred from browsing, generally needs consent (APP 3). Most businesses with annual turnover of A$3 million or less are exempt from the Act, with exceptions. Many Australian sites use a notice-style banner with an opt-out; sites with EU or UK visitors use regional rules so those visitors get an opt-in banner.

Questions

The things people ask us

What is cookie compliance?

Setting cookies and similar trackers only as the law in each visitor's market allows: opt-in consent in the EU and UK for anything not strictly necessary, opt-outs in US states, and accurate notice everywhere.

Do I need a cookie banner?

If you have EU or UK visitors and set any cookie that is not strictly necessary, yes. If you share data with ad networks and the CCPA applies, you need a Do Not Sell or Share link. Our free cookie consent checker gives an answer from what your site runs.

Why are pre-ticked boxes not allowed?

Consent under the GDPR needs a clear affirmative act. Recital 32 says pre-ticked boxes are not consent, and the Court of Justice confirmed it for cookies in Planet49 (2019).

Does the reject button have to be on the first layer?

EU and UK regulators expect refusing to be as easy as accepting. The EDPB taskforce listed a missing reject button on the first layer as a problem, and the CNIL and ICO say the same.

Do analytics cookies need consent in the UK?

Not always since the Data (Use and Access) Act 2025. First-party statistics to improve your service can use an exception if you inform people, let them object simply and for free, and meet the other conditions. Advertising cookies still need consent.

What is the difference between a cookie notice and a cookie policy?

The notice is the short banner text with the choices. The policy is the full page listing each cookie, its provider, purpose and lifetime.

Does Australia require cookie consent?

There is no cookie-specific consent rule. The Privacy Act applies where cookie data is personal information, so you need notice and a privacy policy that covers it, and consent for sensitive information.

Book a walkthrough

See what your site sets before anyone clicks.

Thirty minutes: we scan your site live, then show the same trackers held behind the banner, with regional rules for the EU, UK and US.