Consent & Cookies

What is Strictly Necessary Cookies?

Strictly necessary cookies are cookies that are essential for delivering a service the user explicitly requested — such as keeping a login session, holding a shopping cart, or storing a consent choice — and are the only category exempt from cookie consent requirements under EU ePrivacy rules.

The exemption comes from Article 5(3) of the ePrivacy Directive: consent is not required where storage or access is 'strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.' Two words carry the weight — strictly, and requested. The cookie must be essential (not merely useful) to something the user asked for (not something the business wants).

Regulators have kept the category narrow. Recognized examples include session cookies for authentication, shopping-cart cookies, security tokens and fraud-prevention cookies, load-balancing cookies, user-interface preferences within a session (language chosen by the user), and the cookie that records the visitor's own consent choices. The common thread: without the cookie, the thing the user is trying to do breaks.

Consistently outside the category: analytics and audience measurement (useful to the business, not necessary to the user), advertising and retargeting cookies, social media embeds' trackers, A/B-testing tools, and personalization beyond a user-selected preference. Labels do not change the analysis — regulators look at function, and misclassifying marketing cookies as 'necessary' in your banner is itself a compliance failure that scanners and auditors catch quickly.

Strictly necessary cookies still carry obligations: they must be disclosed in the cookie policy with purpose and duration, and any personal data they process remains subject to GDPR. Exempt from consent does not mean exempt from law, and the exemption is assessed per cookie, not per site.

Why it matters for eCommerce

Online stores have a genuinely large strictly-necessary footprint — carts, checkout state, fraud prevention, session management — which is why an eCommerce site works at all before the banner is answered. The temptation is to stretch the label over analytics or personalization 'because the store needs them.' Resist it: the test is what the shopper needs to shop, and mislabeled categories undermine the credibility of your whole consent setup.

Frequently asked questions

Do strictly necessary cookies require consent?
No — they are exempt under ePrivacy Article 5(3) and can be set before and regardless of banner choices. They must still be disclosed in your cookie policy, and personal data they process remains subject to GDPR.
Are analytics cookies strictly necessary?
No. Audience measurement benefits the business rather than being essential to the service the user requested, so it requires consent in the EU. A few regulators tolerate narrowly configured first-party measurement without consent, but standard analytics deployments need opt-in.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Run a free scan

← Back to all glossary terms