Skip to content

Cookie Consent in 2026: What's Law and What's Only Proposed

Cookie consent requirements EU 2026: separating what is actually in force from the Digital Omnibus proposals still under negotiation, plus a no-regrets build.

28 Aug 202610 min read
  • Consent

Verified as of August 2026: EU and UK rules are actively changing, and some widely-shared claims are out of date. This is operational orientation, not legal advice; confirm with official sources or your data protection adviser.

A large share of the content currently ranking for European cookie consent describes proposed reforms as though they were settled law. They are not. As of August 2026, cookie rules in the EU are still governed by the ePrivacy Directive as transposed into each member state's national law, with GDPR supplying the standard for what valid consent looks like. The EU's Digital Omnibus package: which proposes moving consent rules into a new GDPR Article 88a, mandating equal prominence for accept and reject, introducing a moratorium on re-asking after refusal, and recognising browser-level signals, remains under negotiation and is not in force. Building today against the proposal rather than the law is how teams end up with a banner that satisfies nobody.

Key Takeaways

  • The legal trigger for cookie consent is national ePrivacy law, not GDPR. GDPR supplies the consent standard. "GDPR requires a cookie banner" is a category error.
  • National regimes genuinely differ. France, Germany, Spain and Italy diverge on banner mechanics and on which analytics configurations can be exempted.
  • The Digital Omnibus data track is proposed, contested, and not law. Council working text has stripped several core provisions.
  • The AI Omnibus is a separate instrument. Do not conflate the two.
  • The UK diverged in 2025–26 via the Data (Use and Access) Act, which created new PECR exemptions for certain analytics and appearance/functionality cookies.
  • A no-regrets build exists: reject-at-first-layer, no pre-ticked non-essential categories, honest granularity, logged consent, and no cookies before a decision.
The banner is the visible layer. What determines legality sits in twenty-seven national transpositions beneath it.

The Structural Point Everyone Gets Backwards

Two instruments, two jobs.

The ePrivacy Directive (2002/58/EC, as amended), Article 5(3), governs storing information on, or accessing information already stored on, a user's terminal equipment. It requires consent unless the storage is strictly necessary for a service the user explicitly requested, or is solely for transmitting a communication. It is a Directive, so it does not apply directly: each member state transposes it into national law, and those transpositions differ.

GDPR does not contain a cookie rule. What it supplies is the definition of consent (Article 4(11)) and the conditions for validity (Article 7). When national ePrivacy law says "consent is required," GDPR tells you what consent must look like.

The practical consequence: your compliance question is always which member states are we in scope for, and what does each of their regulators require. A single "EU cookie banner" is a simplification you accept knowingly, not a legal object.

What Is Actually In Force: The Table

RequirementStatus as of August 2026Source of obligationWhat you must do
Consent before non-essential cookies/storageIn forceePrivacy Art. 5(3) as nationally transposedSet nothing non-essential before an affirmative choice
Consent must be freely given, specific, informed, unambiguousIn forceGDPR Art. 4(11), Recital 32No pre-ticked boxes, no bundled consent, no implied consent from scrolling
Withdrawal as easy as givingIn forceGDPR Art. 7(3)Persistent, reachable settings control
Reject as easy as accept on the first layerIn force in several member states via national guidance (notably France/CNIL); not a uniform EU-wide statutory ruleNational regulator guidanceSafest: provide a first-layer reject
Analytics exemption for certain measurement configsPartial, national, CNIL operates a defined exemption; other states differNational regulator guidanceCheck per market; do not assume portability
Cookie wallsContested and national: some regulators tolerate narrowly, EDPB restrictiveNational + EDPB guidanceTreat as high risk
Consent records retained as proofIn forceGDPR Art. 7(1)Log timestamp, scope, version, signal
UK: exemption for certain analytics/statistical and appearance/functionality cookiesIn force in the UK (DUAA 2025 amendments to PECR, all data protection provisions active 19 June 2026)PECR as amendedVerify exact scope against ICO guidance before relying on it
Moving cookie rules into a new GDPR Article 88aPROPOSED, NOT LAWDigital Omnibus proposalNothing. Monitor.
Mandatory equal prominence accept/reject EU-widePROPOSED, NOT LAWDigital Omnibus proposalBuild it anyway; it's already best practice
Six-month moratorium on re-asking after refusalPROPOSED, NOT LAWDigital Omnibus proposalOptional to adopt voluntarily
Legally recognised browser-level consent signalsPROPOSED, NOT LAW; core provisions reportedly weakened in Council working textDigital Omnibus proposalDo not build a strategy on it
DSA duties on your own small brand siteNot applicable: DSA obligations fall largely on intermediaries, platforms and VLOPsDSANothing directly; you feel it through platform ad policy

The Digital Omnibus: What It Is and What It Isn't

Two Omnibuses, frequently confused

There are two distinct packages in circulation and a great deal of published content merges them:

  • The AI Omnibus, which amended EU AI Act timelines: postponing certain high-risk obligations (standalone Annex III high-risk to December 2027; embedded Annex I to August 2028). It did not delay the Article 50 transparency obligations, which apply from 2 August 2026.
  • The Digital Omnibus (data track), covering GDPR, ePrivacy and related instruments. This is the one containing the cookie proposals. It is still under negotiation.

Writing "the EU delayed everything" or "the EU has fixed cookie banners" collapses two different instruments at two different stages. Both statements are wrong.

What the data-track proposals contain

The published proposals have included: relocating terminal-equipment consent rules into GDPR as a new Article 88a; a requirement for accept and reject to be presented with equal prominence; a moratorium of around six months preventing sites from re-prompting a user who has refused; machine-readable browser-level consent expressions that sites would have to honour; and expanded exemptions for certain low-risk measurement purposes.

Why you must not build to it yet

Legislative texts change in trilogue. Reporting on Council working documents indicates several core provisions have been stripped or materially weakened. Timelines are unsettled. Any post telling you "from 2026 you can rely on browser signals" is describing a possible future, not a legal position.

Enacted on the left, proposed on the right. Most currently-ranking content merges the two piles.

National Divergence: Four Markets Worth Knowing

France

The CNIL has been the most prescriptive regulator in this area and the most active enforcer. Its guidance has consistently required that refusing be as easy as accepting at the first layer, and it operates a defined exemption for audience-measurement configurations that meet strict conditions: including no cross-site tracking, limited retention, and no transfer to third parties for their own purposes.

Germany

Germany transposed Article 5(3) through the TDDDG (formerly TTDSG), giving terminal-equipment consent a distinct statutory home. It also created a framework for recognised consent management services. German enforcement culture, and the competitor-standing tradition in unfair competition law, makes it a market where sloppy banners carry practical risk from more than the regulator.

Spain

The AEPD publishes detailed cookie guidance and has iterated on it, including addressing banner design, cookie walls, and the treatment of continued browsing, which is not consent.

Italy

The Garante has issued its own guidelines on cookies and tracking, addressing scroll-based consent (not valid), banner re-presentation intervals, and the treatment of device fingerprinting as functionally equivalent to cookie storage.

The takeaway is not "learn four regimes." It's that your consent management platform's single "EU" preset is a commercial approximation, and you should know which market's rules it is actually implementing.

The UK Path

The Data (Use and Access) Act 2025 received Royal Assent in 2025 and was phased in, with all data protection provisions active as of 19 June 2026. For cookies it did something the EU has so far only proposed: it created new statutory exemptions under PECR allowing certain cookies to be set without consent, covering defined statistical/analytics purposes and certain appearance-and-functionality purposes.

Two cautions. First, the exemptions are conditional, not blanket: verify the precise scope against current ICO guidance before you disable a consent category. Second, DUAA also raised PECR penalties toward GDPR-level maximums. Lighter consent requirements, heavier consequences for getting them wrong.

The full comparison is in the UK vs EU divergence piece.

The No-Regrets Build

Here is what to implement now. Every item is either already required somewhere, or costs you little and positions you well if the Omnibus lands.

1. Nothing non-essential fires before a decision

The most common technical failure. Tag managers and pixels routinely execute before consent state is resolved. Test with a clean browser profile and a network inspector, not with your CMP's dashboard.

2. Reject on the first layer, equal to accept

Same size, same contrast, same position tier. This is required in some markets today and proposed EU-wide. There is no scenario where building it costs you.

3. Nothing pre-ticked

Only strictly-necessary may be on by default, and it should be presented as non-optional rather than as a ticked box.

4. Real granularity, honestly labelled

Purpose categories users can understand: measurement, personalisation, advertising. Not "performance cookies" and "targeting cookies" with vendor lists nobody reads.

Timestamp, scope granted, banner version, and the signal received. Article 7(1) puts the burden of proof on you.

6. Persistent, easy withdrawal

A footer link or a small floating control. As easy as the original acceptance.

7. Don't nag

Re-prompting a refusing user on every page view is bad practice today and would be prohibited under a proposal that may become law. Pick an interval of at least six months.

8. Scope your banner to your markets

If you serve both UK and EU traffic, you can serve different configurations. Whether you should is a judgment about brand consistency and operational complexity, covered in the divergence piece.

What This Means for Measurement

The honest position: consented analytics in Europe undercounts, and the size of the gap varies by market and audience. Server-side collection does not solve this: Article 5(3) concerns access to and storage on terminal equipment regardless of where processing subsequently happens, and moving the pipeline server-side changes nothing about whether consent was needed.

What actually helps: consent-mode modelling used honestly with its limits stated, cohort-level rather than user-level analysis, and a shift toward measuring what you can measure well: branded search volume, direct traffic, share of voice, and pipeline attribution at the account level rather than the click level.

Frequently Asked Questions

No. National ePrivacy law creates the requirement to obtain consent for storing or accessing information on a device. GDPR defines what valid consent must look like. The distinction matters because it determines which regulator's guidance you follow.

Is the EU Digital Omnibus law yet?

No. As of August 2026 the data track, including the cookie proposals, remains under negotiation, and reporting indicates Council working text has stripped or weakened several core provisions. Treat every element as proposed and contested.

They are a proposal. There is no EU-wide legal obligation to honour a browser signal as of August 2026. Do not restructure your consent architecture around it.

Can I use Google Analytics in the EU in 2026?

It depends on configuration, jurisdiction and your transfer position, not on a yes/no answer. Several regulators found specific historical configurations unlawful. The current framework, contractual safeguards, and your specific setup all matter, get market-specific advice.

In most member states, yes, unless the configuration meets a national exemption such as CNIL's audience-measurement carve-out. In the UK, DUAA created statutory exemptions for certain statistical purposes, verify scope against ICO guidance.

Contested. EDPB guidance is restrictive on making access conditional on consent because it undermines "freely given." Some national positions tolerate narrow implementations with a genuine alternative. High-risk area.

No. DSA obligations fall largely on intermediary services, platforms and very large online platforms: ad repositories, ad transparency, restrictions on targeting using special-category data or targeting minors, and dark-pattern prohibitions on platform interfaces. A small brand's own site feels DSA indirectly through the ad policies platforms adopt.

No. Continued browsing, scrolling, and inactivity have been rejected as valid consent signals by CJEU case law and by multiple national regulators including the Garante and AEPD.

There is no single statutory figure. Regulator guidance in several markets suggests intervals in the range of six to thirteen months. Six months is a defensible floor and aligns with the proposed moratorium.

Do UK and EU visitors need different banners?

They can. Since 19 June 2026 the UK permits certain cookies without consent that the EU does not. Whether to run two configurations is an operational and brand decision, not a compliance requirement.

Further Reading


If you want a growth setup that measures honestly under European consent conditions rather than pretending the gap doesn't exist, that's a large part of what I work on. More at younusfardeen.com.