Consent & Cookies
What is Cookie Consent?
Cookie consent is the permission a website obtains from a visitor before placing non-essential cookies or similar trackers on their device, required as prior opt-in consent under EU ePrivacy rules and delivered as an opt-out right under most US state privacy laws.
The legal root is Article 5(3) of the EU's ePrivacy Directive, which requires consent before storing or accessing information on a user's device unless doing so is strictly necessary for a service the user requested. Because 'information on a device' covers cookies, localStorage, pixels, and fingerprinting alike, the rule applies to essentially all tracking technology, and the GDPR supplies the definition of what valid consent means.
That definition has teeth: consent must be freely given, specific, informed, and unambiguous, expressed through a clear affirmative action. The Court of Justice of the EU held in Planet49 (2019) that pre-ticked boxes are invalid, and European regulators have added that browsing on ('implied consent') does not qualify, that refusing must be as easy as accepting, and that consent must be granular by purpose — analytics, personalization, and advertising each stand on their own.
Valid consent also has a lifecycle. It must be recorded (who consented, when, to what, via which banner version) because the burden of proof sits with the website; it must be withdrawable at any time as easily as it was given; and it must actually control script behavior — a banner that logs choices while trackers fire regardless is worse than no banner, because it documents the violation.
In the US the model inverts: most state laws allow cookies by default but grant an opt-out from sale, sharing, and targeted advertising, with California additionally requiring recognition of the Global Privacy Control signal. Multinational sites therefore run geolocation-based consent: opt-in banners for the EU/UK, opt-out mechanics for US states.
Why it matters for eCommerce
For an online store, cookie consent determines which shoppers can lawfully enter your marketing audiences and analytics. Getting it right is partly UX (a clear banner that does not tank conversion) and partly engineering (trackers genuinely held until consent, choices recorded as proof). The stores that get sued are rarely the ones without banners — they are the ones whose banners do not do anything.
Frequently asked questions
- Is a cookie banner legally required?
- If you serve EU or UK visitors and use non-essential cookies, you need a mechanism for prior opt-in consent — in practice, a banner. US state laws do not mandate a banner but require opt-out mechanisms like a Do Not Sell or Share link and GPC support, which many sites also surface through a banner.
- What makes cookie consent valid under GDPR?
- It must be freely given, specific, informed, and unambiguous, given by affirmative action before the cookies fire, as easy to refuse as to accept, granular by purpose, withdrawable, and provable with records. Pre-ticked boxes and continued-browsing consent are invalid.
- Do I need consent for analytics cookies?
- In the EU, generally yes — analytics is not 'strictly necessary,' so consent is required (a handful of regulators tolerate narrowly configured, first-party audience measurement). In US states, analytics alone typically does not require opt-in, but sharing analytics data for advertising triggers opt-out rights.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
See PieEye Cookie Compliance