GDPR Cookie Consent: The Complete Guide for Ecommerce Brands

RS
River Starnes
Updated
GDPR cookie consent explained for ecommerce: lawful basis, banner rules, prior consent, granular choices, and withdrawal so US brands avoid costly mistakes.

GDPR Cookie Consent: The Complete Guide for Ecommerce Brands

GDPR cookie consent is the legal requirement to get a user's permission before your website sets non-essential cookies or fires the tracking scripts behind them. If your store reaches shoppers in the EU or UK, this applies to you whether or not your company is based there. Under the General Data Protection Regulation, consent must be freely given, specific, informed, and unambiguous, signalled by a clear affirmative action. That rules out pre-ticked boxes, "by continuing to browse you agree" notices, and cookie walls that force acceptance. This guide explains what GDPR cookie consent actually requires, how it interacts with the ePrivacy rules that govern cookies, the banner and granularity rules brands most often get wrong, and how to keep defensible records, so you can comply without gutting your analytics or guessing at the law.

What GDPR Cookie Consent Means

Two regimes work together here, and conflating them is the first mistake brands make. The ePrivacy Directive (the "cookie law") is what actually requires consent before a cookie or similar technology is stored on or read from a user's device. The GDPR then defines what valid consent looks like, that "freely given, specific, informed and unambiguous" standard, and governs any personal data those cookies go on to process.

In practice, this means:

  • Prior consent. Non-essential cookies and tags must not fire until the user opts in. Loading analytics or advertising scripts on page load "and then" showing a banner is non-compliant, because the cookies are already set.
  • A clear affirmative act. Silence, inactivity, pre-checked boxes, or continued browsing do not count as consent.
  • No bundling. Consent for one purpose (say, analytics) cannot be a condition of using the site or bundled with unrelated purposes.
  • As easy to withdraw as to give. Users must be able to change their mind later, typically through a persistent settings link, without jumping through hoops.

Not every cookie needs consent. Cookies that are strictly necessary to deliver a service the user explicitly requested, such as keeping items in a cart, load balancing, or security tokens, are exempt. Analytics, advertising, personalization, and most third-party embeds are not. If you are unsure where a given cookie falls, our breakdown of strictly necessary cookies under the GDPR walks through the exemption in detail.

Why Cookies Trigger GDPR at All

A common objection from ecommerce teams is "cookies aren't personal data, so why does GDPR apply?" The answer is that cookies frequently are treated as personal data, or are the mechanism that collects it. Identifiers stored in cookies, device IDs, and the behavioral profiles built on top of them can single out an individual, which is the GDPR test for personal data. We cover the nuance in are cookies considered personal data under GDPR.

Because the ePrivacy rules require consent for storing or accessing information on a device regardless of whether it is "personal data," consent is the relevant lawful basis for almost all tracking, advertising, and analytics cookies. Legitimate interest is generally not available as a workaround for cookies that the ePrivacy rules say require prior consent. Treating consent as the default for non-essential cookies keeps you on the safe side of both regimes.

First-Party vs. Third-Party Cookies (and Other Trackers)

Not every cookie carries the same consent weight, and the first split that matters is who sets it.

First-party cookies are set by the domain the shopper is actually visiting, your store. They remember the cart, keep someone logged in, or measure how your own site is used, and the data stays under your control. Third-party cookies are set by other domains loaded into your pages, an embedded YouTube video, a Meta or Google Ads pixel, a chat widget. Because those providers can follow a user across many sites, third-party cookies raise the sharpest privacy concerns and almost always require explicit consent.

Third-party cookies also create a shared-responsibility problem: you and the provider both have obligations. You can't realistically audit everything Google or Meta does with the data, so the practical standard is to name the third parties present on your site, link to their policies, and be honest about what you don't control, rather than claim a level of visibility no publisher actually has.

It's also a mistake to think this is only about cookies. The ePrivacy rules are deliberately technology-neutral: they cover anything that stores or reads information on a user's device. That sweeps in pixel tags and web beacons, device fingerprinting, and local or session storage, and it applies beyond the browser, to mobile apps, smart TVs, and other connected devices. If a tracking SDK in your app writes an identifier to a phone, the same consent logic applies as a marketing pixel on your website.

GDPR Cookie Consent Banner Requirements

The banner is where compliance succeeds or fails, and it is the part regulators and private complainants look at first. A compliant consent experience generally needs to:

  1. Block non-essential tags until consent. The banner has to actually gate the scripts, not just record a preference while tags fire anyway. A surprising number of banners log "rejected" while the tracker still runs, which is worse than no banner at all. If you want to confirm yours behaves, see how to audit whether your cookie banner is actually blocking tags.
  2. Offer reject as prominently as accept. Regulators have consistently criticized designs where "Accept All" is a bright button and rejecting takes extra clicks. Reject should be available at the same layer, with comparable prominence.
  3. Provide granular choices. Users should be able to consent by purpose or category, analytics, marketing, personalization, rather than facing an all-or-nothing switch.
  4. Avoid dark patterns. Misleading colors, hidden options, confusing toggles, and nudges that steer toward acceptance undermine the "freely given" requirement.
  5. Link to a clear cookie policy. Plain-language detail on what each cookie does, who the third parties are, and how long data is retained.
  6. Let users change their mind. A persistent control, often a footer link or floating button, to revisit and withdraw consent at any time.

For a deeper, design-level treatment of layouts and copy, our guide to cookie consent banner requirements for your ecommerce store is a useful companion.

Does GDPR Cookie Consent Apply to US Brands?

Yes, more often than US merchants expect. GDPR has extraterritorial reach: it can apply to a US-based store that offers goods or services to people in the EU or that monitors their behavior, for example through tracking and remarketing pixels. You do not need an EU entity, EU servers, or EU employees for it to reach you. We unpack the triggers in when does GDPR apply to US ecommerce stores.

The practical takeaway: if you ship internationally, run ads that can reach EU users, or simply have EU traffic landing on your store, you should treat GDPR cookie consent as in scope rather than assuming a US base exempts you.

Connecting Consent to Your Tag Stack

Collecting consent is only half the job; your tags actually have to honor it. For brands running Google's ecosystem, this is where Google Consent Mode v2 comes in, it passes the user's consent state to Google tags so analytics and ads adjust their behavior accordingly. Consent Mode alone is not a complete compliance solution, but wiring your banner to your tag manager and to Consent Mode is what turns a recorded preference into an enforced one.

The failure mode to avoid is a "consent theater" setup: a polished banner on the front end with tags that fire regardless on the back end. Enforcement and complaints increasingly target exactly this gap between what the banner claims and what the network requests show.

Keeping Defensible Consent Records

GDPR puts the burden of proof on you: if challenged, you must be able to demonstrate that valid consent was obtained. That means logging, for each consent event, what the user agreed to, when, the version of the banner and policy shown, and the choices they made. Records should be retained so you can produce them in an audit or complaint.

Equally important is honoring withdrawal. When a user revokes consent, the corresponding cookies should stop being set and, where appropriate, existing ones cleared. A consent record that never updates after withdrawal is a liability, not a defense.

How Long Cookie Consent Lasts (and When to Re-Ask)

Consent is not "collect once and forget." The GDPR doesn't set a hard expiry, but European regulators have filled the gap, and France's CNIL is the most-cited: it treats roughly six months as a best-practice window for refreshing consent and expects you to justify any longer period. (Separately, it caps consent-exempt analytics cookies at a 13-month lifespan.) A sensible default is to re-ask returning visitors at least every six to twelve months.

Beyond the clock, several events should trigger a fresh prompt regardless of how recently someone consented:

  • You add a new tracker or third party. The original consent only covered the cookies and parties the user was told about. Dropping in a new analytics or advertising tool means asking again.
  • Your purposes or policy change. Using the data for something new, or materially revising your cookie policy, restarts the clock.
  • The user clears cookies or switches device. With no stored record of their choice, you can't assume prior consent, so the banner should reappear.

The flip side of re-asking is making it effortless for users to revisit their choice on their own terms, which is why a persistent settings link matters as much as the initial banner.

Common GDPR Cookie Consent Mistakes

  • Firing tags before consent. The single most common and most consequential error.
  • Implied or assumed consent. "By using this site you agree" banners are not valid.
  • All-or-nothing choices. No granularity means consent is not "specific."
  • Reject buried or missing. Asymmetry between accept and reject undermines "freely given."
  • No withdrawal path. Users must be able to change their mind easily and later.
  • Stale cookie policies. Listing cookies and third parties you no longer use, or omitting ones you do.
  • Set-and-forget banners. Your tag stack changes; your consent setup has to be re-audited as it does.

How PieEye Helps

PieEye's cookie compliance tooling is built to close the gap between a banner that looks compliant and one that actually is, scanning your site to discover the cookies and trackers in use, blocking non-essential tags until consent, capturing granular per-category choices, and logging consent events so you can prove compliance. Because it enforces consent at the tag level rather than just recording a preference, it addresses the "consent theater" problem that catches so many ecommerce brands.

Frequently Asked Questions

Are cookie walls allowed under the GDPR?

Generally no. A cookie wall blocks access unless the visitor accepts cookies, and the European Data Protection Board has said that conditioning access on acceptance means consent isn't "freely given," so it isn't valid. A few national regulators (Italy's Garante, for example) allow a narrow exception only when users are offered a genuinely equivalent way to reach the same content without consenting, assessed case by case. The safe default is not to gate your store behind cookie acceptance.

Do analytics cookies always need consent?

It depends on where your users are. Authorities in the UK, Belgium, and Ireland treat analytics cookies as non-essential, so they require consent. Others, including France, Germany, the Netherlands, and Italy, allow a narrow exemption for strictly first-party, anonymized audience measurement that doesn't track users across sites, and even then only under specific conditions. If you serve multiple EU countries, the cautious approach is to seek consent for analytics rather than rely on a patchwork of exemptions.

Do I have to list every cookie in my policy?

No. Regulators like the UK's ICO advise describing the categories of cookies you use (essential, analytics, marketing, functional), the purpose of each, and any third parties involved, with links to their policies, rather than maintaining a line-by-line inventory. A cookie-by-cookie list is impractical because third-party tools change their cookies without notice, and it's less useful to shoppers than a clear, plain-language summary.

Is the ePrivacy "Cookie Law" being replaced by the ePrivacy Regulation?

Not anymore. For years the ePrivacy Directive was expected to give way to a new ePrivacy Regulation, but the European Commission withdrew that proposal in 2025 after years without agreement, and the Directive, as implemented in each member state's national law, remains in force. In its place the Commission's late-2025 "Digital Omnibus" package proposes folding cookie-consent rules into the GDPR itself, but that's a proposal, not yet law, so today's requirements are unchanged.

Conclusion and Next Steps

GDPR cookie consent comes down to a few durable principles: get a clear, affirmative opt-in before non-essential cookies fire, make rejecting as easy as accepting, offer granular choices, let users withdraw at any time, and keep records that prove you did. Brands that treat the banner as a front-end formality, while tags fire underneath, carry the most risk; brands that wire consent through to their actual tag stack are the ones that hold up under scrutiny.

If you are reviewing your setup, start by auditing which cookies and trackers your store actually loads, confirm your banner blocks the non-essential ones until consent, and make sure your records and withdrawal flow work end to end. From there, the rest of GDPR cookie consent is mostly maintenance, keeping the policy, the banner, and the tag stack in sync as your store evolves.

For a walkthrough of how PieEye handles GDPR compliance, book a demo.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.