Verified as of August 2026: EU and UK rules are actively changing, and some widely-shared claims are out of date. This is operational orientation, not legal advice; confirm with official sources or your data protection adviser.
A large share of the content currently ranking for European cookie consent describes proposed reforms as though they were settled law. They are not. As of August 2026, cookie rules in the EU are still governed by the ePrivacy Directive as transposed into each member state's national law, with GDPR supplying the standard for what valid consent looks like. The EU's Digital Omnibus package: which proposes moving consent rules into a new GDPR Article 88a, mandating equal prominence for accept and reject, introducing a moratorium on re-asking after refusal, and recognising browser-level signals, remains under negotiation and is not in force. Building today against the proposal rather than the law is how teams end up with a banner that satisfies nobody.
Key Takeaways
- The legal trigger for cookie consent is national ePrivacy law, not GDPR. GDPR supplies the consent standard. "GDPR requires a cookie banner" is a category error.
- National regimes genuinely differ. France, Germany, Spain and Italy diverge on banner mechanics and on which analytics configurations can be exempted.
- The Digital Omnibus data track is proposed, contested, and not law. Council working text has stripped several core provisions.
- The AI Omnibus is a separate instrument. Do not conflate the two.
- The UK diverged in 2025–26 via the Data (Use and Access) Act, which created new PECR exemptions for certain analytics and appearance/functionality cookies.
- A no-regrets build exists: reject-at-first-layer, no pre-ticked non-essential categories, honest granularity, logged consent, and no cookies before a decision.
The Structural Point Everyone Gets Backwards
Two instruments, two jobs.
The ePrivacy Directive (2002/58/EC, as amended), Article 5(3), governs storing information on, or accessing information already stored on, a user's terminal equipment. It requires consent unless the storage is strictly necessary for a service the user explicitly requested, or is solely for transmitting a communication. It is a Directive, so it does not apply directly: each member state transposes it into national law, and those transpositions differ.
GDPR does not contain a cookie rule. What it supplies is the definition of consent (Article 4(11)) and the conditions for validity (Article 7). When national ePrivacy law says "consent is required," GDPR tells you what consent must look like.
The practical consequence: your compliance question is always which member states are we in scope for, and what does each of their regulators require. A single "EU cookie banner" is a simplification you accept knowingly, not a legal object.
What Is Actually In Force: The Table
| Requirement | Status as of August 2026 | Source of obligation | What you must do |
|---|---|---|---|
| Consent before non-essential cookies/storage | In force | ePrivacy Art. 5(3) as nationally transposed | Set nothing non-essential before an affirmative choice |
| Consent must be freely given, specific, informed, unambiguous | In force | GDPR Art. 4(11), Recital 32 | No pre-ticked boxes, no bundled consent, no implied consent from scrolling |
| Withdrawal as easy as giving | In force | GDPR Art. 7(3) | Persistent, reachable settings control |
| Reject as easy as accept on the first layer | In force in several member states via national guidance (notably France/CNIL); not a uniform EU-wide statutory rule | National regulator guidance | Safest: provide a first-layer reject |
| Analytics exemption for certain measurement configs | Partial, national, CNIL operates a defined exemption; other states differ | National regulator guidance | Check per market; do not assume portability |
| Cookie walls | Contested and national: some regulators tolerate narrowly, EDPB restrictive | National + EDPB guidance | Treat as high risk |
| Consent records retained as proof | In force | GDPR Art. 7(1) | Log timestamp, scope, version, signal |
| UK: exemption for certain analytics/statistical and appearance/functionality cookies | In force in the UK (DUAA 2025 amendments to PECR, all data protection provisions active 19 June 2026) | PECR as amended | Verify exact scope against ICO guidance before relying on it |
| Moving cookie rules into a new GDPR Article 88a | PROPOSED, NOT LAW | Digital Omnibus proposal | Nothing. Monitor. |
| Mandatory equal prominence accept/reject EU-wide | PROPOSED, NOT LAW | Digital Omnibus proposal | Build it anyway; it's already best practice |
| Six-month moratorium on re-asking after refusal | PROPOSED, NOT LAW | Digital Omnibus proposal | Optional to adopt voluntarily |
| Legally recognised browser-level consent signals | PROPOSED, NOT LAW; core provisions reportedly weakened in Council working text | Digital Omnibus proposal | Do not build a strategy on it |
| DSA duties on your own small brand site | Not applicable: DSA obligations fall largely on intermediaries, platforms and VLOPs | DSA | Nothing directly; you feel it through platform ad policy |
The Digital Omnibus: What It Is and What It Isn't
Two Omnibuses, frequently confused
There are two distinct packages in circulation and a great deal of published content merges them:
- The AI Omnibus, which amended EU AI Act timelines: postponing certain high-risk obligations (standalone Annex III high-risk to December 2027; embedded Annex I to August 2028). It did not delay the Article 50 transparency obligations, which apply from 2 August 2026.
- The Digital Omnibus (data track), covering GDPR, ePrivacy and related instruments. This is the one containing the cookie proposals. It is still under negotiation.
Writing "the EU delayed everything" or "the EU has fixed cookie banners" collapses two different instruments at two different stages. Both statements are wrong.
What the data-track proposals contain
The published proposals have included: relocating terminal-equipment consent rules into GDPR as a new Article 88a; a requirement for accept and reject to be presented with equal prominence; a moratorium of around six months preventing sites from re-prompting a user who has refused; machine-readable browser-level consent expressions that sites would have to honour; and expanded exemptions for certain low-risk measurement purposes.
Why you must not build to it yet
Legislative texts change in trilogue. Reporting on Council working documents indicates several core provisions have been stripped or materially weakened. Timelines are unsettled. Any post telling you "from 2026 you can rely on browser signals" is describing a possible future, not a legal position.
National Divergence: Four Markets Worth Knowing
France
The CNIL has been the most prescriptive regulator in this area and the most active enforcer. Its guidance has consistently required that refusing be as easy as accepting at the first layer, and it operates a defined exemption for audience-measurement configurations that meet strict conditions: including no cross-site tracking, limited retention, and no transfer to third parties for their own purposes.
Germany
Germany transposed Article 5(3) through the TDDDG (formerly TTDSG), giving terminal-equipment consent a distinct statutory home. It also created a framework for recognised consent management services. German enforcement culture, and the competitor-standing tradition in unfair competition law, makes it a market where sloppy banners carry practical risk from more than the regulator.
Spain
The AEPD publishes detailed cookie guidance and has iterated on it, including addressing banner design, cookie walls, and the treatment of continued browsing, which is not consent.
Italy
The Garante has issued its own guidelines on cookies and tracking, addressing scroll-based consent (not valid), banner re-presentation intervals, and the treatment of device fingerprinting as functionally equivalent to cookie storage.
The takeaway is not "learn four regimes." It's that your consent management platform's single "EU" preset is a commercial approximation, and you should know which market's rules it is actually implementing.
The UK Path
The Data (Use and Access) Act 2025 received Royal Assent in 2025 and was phased in, with all data protection provisions active as of 19 June 2026. For cookies it did something the EU has so far only proposed: it created new statutory exemptions under PECR allowing certain cookies to be set without consent, covering defined statistical/analytics purposes and certain appearance-and-functionality purposes.
Two cautions. First, the exemptions are conditional, not blanket: verify the precise scope against current ICO guidance before you disable a consent category. Second, DUAA also raised PECR penalties toward GDPR-level maximums. Lighter consent requirements, heavier consequences for getting them wrong.
The full comparison is in the UK vs EU divergence piece.
The No-Regrets Build
Here is what to implement now. Every item is either already required somewhere, or costs you little and positions you well if the Omnibus lands.
1. Nothing non-essential fires before a decision
The most common technical failure. Tag managers and pixels routinely execute before consent state is resolved. Test with a clean browser profile and a network inspector, not with your CMP's dashboard.
2. Reject on the first layer, equal to accept
Same size, same contrast, same position tier. This is required in some markets today and proposed EU-wide. There is no scenario where building it costs you.
3. Nothing pre-ticked
Only strictly-necessary may be on by default, and it should be presented as non-optional rather than as a ticked box.
4. Real granularity, honestly labelled
Purpose categories users can understand: measurement, personalisation, advertising. Not "performance cookies" and "targeting cookies" with vendor lists nobody reads.
5. Log the consent event
Timestamp, scope granted, banner version, and the signal received. Article 7(1) puts the burden of proof on you.
6. Persistent, easy withdrawal
A footer link or a small floating control. As easy as the original acceptance.
7. Don't nag
Re-prompting a refusing user on every page view is bad practice today and would be prohibited under a proposal that may become law. Pick an interval of at least six months.
8. Scope your banner to your markets
If you serve both UK and EU traffic, you can serve different configurations. Whether you should is a judgment about brand consistency and operational complexity, covered in the divergence piece.
What This Means for Measurement
The honest position: consented analytics in Europe undercounts, and the size of the gap varies by market and audience. Server-side collection does not solve this: Article 5(3) concerns access to and storage on terminal equipment regardless of where processing subsequently happens, and moving the pipeline server-side changes nothing about whether consent was needed.
What actually helps: consent-mode modelling used honestly with its limits stated, cohort-level rather than user-level analysis, and a shift toward measuring what you can measure well: branded search volume, direct traffic, share of voice, and pipeline attribution at the account level rather than the click level.
Frequently Asked Questions
Does GDPR require a cookie banner?
No. National ePrivacy law creates the requirement to obtain consent for storing or accessing information on a device. GDPR defines what valid consent must look like. The distinction matters because it determines which regulator's guidance you follow.
Is the EU Digital Omnibus law yet?
No. As of August 2026 the data track, including the cookie proposals, remains under negotiation, and reporting indicates Council working text has stripped or weakened several core provisions. Treat every element as proposed and contested.
Will browser-level consent signals become legally binding?
They are a proposal. There is no EU-wide legal obligation to honour a browser signal as of August 2026. Do not restructure your consent architecture around it.
Can I use Google Analytics in the EU in 2026?
It depends on configuration, jurisdiction and your transfer position, not on a yes/no answer. Several regulators found specific historical configurations unlawful. The current framework, contractual safeguards, and your specific setup all matter, get market-specific advice.
Do I need consent for analytics cookies?
In most member states, yes, unless the configuration meets a national exemption such as CNIL's audience-measurement carve-out. In the UK, DUAA created statutory exemptions for certain statistical purposes, verify scope against ICO guidance.
Are cookie walls legal?
Contested. EDPB guidance is restrictive on making access conditional on consent because it undermines "freely given." Some national positions tolerate narrow implementations with a genuine alternative. High-risk area.
Does the Digital Services Act require anything of my website's cookie banner?
No. DSA obligations fall largely on intermediary services, platforms and very large online platforms: ad repositories, ad transparency, restrictions on targeting using special-category data or targeting minors, and dark-pattern prohibitions on platform interfaces. A small brand's own site feels DSA indirectly through the ad policies platforms adopt.
Is scrolling consent?
No. Continued browsing, scrolling, and inactivity have been rejected as valid consent signals by CJEU case law and by multiple national regulators including the Garante and AEPD.
How long should consent last before I re-ask?
There is no single statutory figure. Regulator guidance in several markets suggests intervals in the range of six to thirteen months. Six months is a defensible floor and aligns with the proposed moratorium.
Do UK and EU visitors need different banners?
They can. Since 19 June 2026 the UK permits certain cookies without consent that the EU does not. Whether to run two configurations is an operational and brand decision, not a compliance requirement.
Further Reading
- European Data Protection Board, guidelines and recommendations
- European Commission, data protection policy
- ICO, guidance on storage and access technologies
- GDPR Article 7, conditions for consent
If you want a growth setup that measures honestly under European consent conditions rather than pretending the gap doesn't exist, that's a large part of what I work on. More at younusfardeen.com.