Artifact GuideEU

EU ePrivacy Analytics Cookies

Decide whether analytics cookies need consent, whether a limited analytics exemption can be supported, and what evidence must prove the configuration.

Built for privacy, product analytics, web engineering, consent-platform, legal, and regional operations teams that need cited cookie decisions without inventing country rules.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

are not automatically exempt from EU ePrivacy consent rules. The starting point is Article 5(3): storing information on, or accessing information from, a user's terminal equipment generally requires clear information and consent unless a narrow exemption applies. For analytics, teams need a documented technical classification, consent or exemption rationale, live banner behavior, and country-specific checks where national implementation or regulator guidance controls the final answer.

Section 1

When analytics cookies fall within Article 5(3)

Treat analytics as an whenever the website or app stores identifiers, reads cookies or local storage, sends client-side analytics events, uses tracking pixels or tracked URLs, or instructs browser code to send device-derived information to an analytics endpoint.

The technical scope is broader than classic browser cookies. EDPB guidance covers storage and access separately, client-side JavaScript calls, tracking pixels, tracked links, local processing that sends results back over the network, IP-based tracking in some circumstances, and unique identifiers in websites or mobile apps.

  • Inventory cookies, SDKs, pixels, local storage, ETags, tracked URLs, IP-only analytics, and unique identifiers used for measurement.
  • Record whether the site or a supplier instructs the browser, app, or device to send analytics information back over a public communications network.
  • Do not treat server logs, IP addresses, or first-party tooling as automatically outside Article 5(3); document why the information does or does not originate from terminal equipment.
  • Separate from authentication, security, shopping-cart, user-input, and preference cookies because purpose and implementation drive the exemption analysis.
Section 3

When limited analytics may be exempt or lower-risk

A limited analytics exemption is not a generic ePrivacy safe harbor. WP29 explains that Article 5(3) exemptions are narrow: the cookie must be for network transmission, or strictly necessary for a service or functionality explicitly requested by the user. For analytics, CNIL describes a more specific national-regulator path where audience-measurement cookies may move from opt-in to opt-out only if listed conditions are met.

Use the conditions in CNIL's 11 June 2020 sheet as a historical French regulator example, not as a current EU-wide safe harbor. CNIL's current material, published on 4 July 2025, focuses the French exemption on audience measurement for the publisher's exclusive account, anonymous statistics, no cross-checking with other processing, no non-anonymous data transmission to third parties, and no tracking across sites or apps. It recommends user information, a tracer lifetime no longer than needed for meaningful comparison, 13 months as an example, no automatic extension on repeat visits, a maximum 25-month retention period for collected information, and periodic review. Before relying on the exemption, document the live configuration against the current French material or the applicable authority's current rule for another Member State.

  • Limit the analytics purpose to audience measurement or A/B testing and prohibit advertising, CRM enrichment, cross-site statistics, or other secondary use.
  • Inform users and give them an effective ability to object when relying on the CNIL-described opt-out model.
  • Keep the tracer limited to one site or application editor and prevent cross-checking with other processing.
  • Treat last-byte IP truncation as a condition stated in the 2020 CNIL sheet, not as a complete current test. Current CNIL material requires anonymous statistics and recommends a tracer lifetime limited to what meaningful comparison needs, using 13 months as an example rather than an automatic entitlement.
  • For a third-party processor providing comparative analytics to several publishers, document that data and trackers are collected, processed, stored, and separated independently for each publisher.
  • Ask the provider for its current self-assessment and configuration evidence. CNIL states that self-assessment does not amount to certification or validation, and the publisher remains responsible for checking the deployed configuration.
Section 4

Configuration and evidence requirements

The analytics decision should be reproducible from evidence, not from vendor labels. Keep the scanned cookie list, tag-manager rules, consent-management-platform configuration, event taxonomy, data-sharing settings, IP handling, retention settings, processor terms, and tests showing what fires before accept, after reject, after withdrawal, and after opt-out.

Consent logs matter when analytics is consent-based, but they are not the whole record. The team also needs proof that non-essential analytics is blocked until consent, reject and withdrawal choices are honored, and exempt or opt-out analytics remains within the exact configuration justified in the decision.

  • Save a cookie and tracer inventory with names, domains, purposes, lifetimes, first-party or third-party status, provider, data recipient, and trigger condition.
  • Capture CMP screenshots or configuration exports for the first layer, settings layer, analytics purpose text, accept control, reject control, save choices control, and withdrawal path.
  • Retain consent logs with timestamp, region, banner version, purpose version, user choice, withdrawal events, and a link to the policy text shown at the time.
  • Run evidence tests in at least four states: fresh visitor before choice, accepted analytics, rejected analytics, and withdrawn analytics.
  • For exemption claims, keep an engineering attestation that analytics is limited to measurement or A/B testing, separated per publisher, not cross-checked with other processing, IP-truncated where required, and subject to the documented lifetime.
  • Refresh the record when analytics vendors, tag-manager containers, SDK versions, purposes, countries, user journeys, retention, or banner design change.
Section 5

What EU-wide sources cannot conclude alone

EU-level materials do not give a single operational answer for every analytics setup in every Member State. The ePrivacy Directive is implemented through national laws, national data protection authorities publish different levels of cookie guidance, and CNIL's analytics sheet itself warns that ePrivacy analytics guidance may be subject to national variation.

Do not state that a vendor, tag template, consent mode, or first-party analytics product is exempt across the EU merely because it can be configured with privacy controls. The final conclusion needs the actual configuration, the Member State position, and the evidence record.

Do always need consent under the EU ePrivacy Directive?

No, but consent is the default starting point unless a narrow exemption is supported. CNIL describes limited audience-measurement conditions that may allow an opt-out model, while WP29 and EDPB sources require a purpose-and-implementation analysis.

Can a team rely on CNIL analytics guidance for all EU countries?

No. CNIL is the French regulator, and the cited sheet is dated 11 June 2020 and flags national variation. Treat its conditions as a dated French example, then verify the current law and regulator guidance for every Member State relevant to the site or app.

What should consent logs prove for ?

They should prove the banner and purpose version shown, the user's affirmative choice or rejection, the timestamp and region, later withdrawal, and that analytics tags respected the choice in live tests.

  • Do not invent Member State analytics exemptions or retention limits where the cited sources do not contain that country rule.
  • Do not infer that all first-party analytics is strictly necessary; WP29 says purpose and implementation decide the answer.
  • Do not infer that opt-out analytics is lawful EU-wide from CNIL guidance alone.
  • Do not treat a vendor's privacy-preserving mode as evidence unless technical settings and live network behavior prove the claim.
  • Escalate when the site uses analytics for logged-in users, sensitive journeys, children, employee portals, health or financial services, cross-device measurement, or multi-controller data sharing.
Primary sources

References and citations

cnil.fr
Referenced sections
  • Supports the current French exemption criteria, recommended tracer and data-retention limits, publisher and processor evidence duties, and the warning that provider self-assessment is not CNIL certification or validation.
eur-lex.europa.eu
Referenced sections
  • Provides the baseline ePrivacy Directive framework for terminal-equipment consent and narrow exceptions, as implemented through Member State law.
"terminal equipment"
edpb.europa.eu
Referenced sections
  • Supports maintaining cookie lists, documenting purposes, demonstrating essentiality, and checking accessible withdrawal routes.
"maintain such lists"
edpb.europa.eu
Referenced sections
  • Supports keeping evidence that consent was obtained validly and can be withdrawn as easily as it was given.
"Demonstrate consent"
Related guides

Explore more topics

Are cookie walls allowed under the EU ePrivacy Directive?
FAQ answer on cookie walls under the EU ePrivacy Directive, covering freely given consent, refusal and withdrawal paths, banner evidence, and national-law caveats.
Do Analytics Cookies Require Consent under the EU ePrivacy Directive?
FAQ answer on analytics cookies under Article 5(3) ePrivacy, limited analytics exemptions, configuration evidence, consent logs, and national-law caveats.
ePrivacy cookie consent vs DSA advertising rules
Compare ePrivacy rules for device storage and access with DSA ad labels, advertiser disclosures, targeting information, profiling limits, and VLOP/VLOSE ad repositories.
ePrivacy Directive vs GDPR: cookies, communications, consent, and evidence
Compare the EU ePrivacy Directive and GDPR across subject matter, lex specialis overlap, terminal equipment, communications confidentiality, marketing, consent, enforcement, and evidence.
EU cookie banner requirements under the ePrivacy Directive
EU ePrivacy cookie banner requirements for non-exempt cookies and trackers: prior consent, reject choices, no pre-ticked boxes, withdrawal, analytics limits, cookie walls, and evidence logs.
EU ePrivacy Applicability Test for Cookies, SDKs, Pixels, Communications, and Marketing
A concrete EU ePrivacy Directive applicability test for electronic communications services, terminal-equipment storage or access, cookies, SDKs, pixels, local storage, direct marketing, GDPR overlap, and evidence.
EU ePrivacy Article 5(3) terminal equipment test
A cited Article 5(3) test for cookies, pixels, local identifiers, device APIs, strictly necessary exceptions, and consent evidence.
EU ePrivacy Confidentiality of Communications: Article 5 controls
Article 5 confidentiality guide for EU ePrivacy communications, traffic data, metadata, terminal-equipment access, consent limits, and GDPR interplay.
EU ePrivacy consent-log evidence workflow for cookies and trackers
Build evidence that links each cookie or tracker decision to the banner shown, the user's signal, the live technical behavior, withdrawal, and later changes.
EU ePrivacy cookie banner UX test cases
Source-backed cookie banner UX tests for Article 5(3) ePrivacy consent: reject all, pre-ticked boxes, withdrawal, cookie walls, analytics toggles, and consent evidence.
EU ePrivacy Cookie Scope Classifier Workflow
Decide whether cookies, pixels, SDKs, local storage, identifiers, and analytics fall within Article 5(3), then document consent, an exemption, or escalation.
EU ePrivacy direct-marketing consent checklist
Checklist for ePrivacy Directive direct-marketing messages: consent, soft opt-in, sender identity, opt-out handling, proof records, suppression, and national-law caveats.
EU ePrivacy Directive compliance calendar for cookies, consent, and marketing
Source-backed ePrivacy calendar covering Directive milestones, Article 5(3) cookie reviews, consent evidence, direct marketing checks, and national-law follow-up.
EU ePrivacy Directive Compliance Checklist
A concrete ePrivacy checklist for terminal equipment access, cookie consent, exemptions, banner UX, direct marketing, confidentiality, GDPR interplay, and evidence records.
EU ePrivacy Directive Compliance Guide for Cookies, Marketing, and Communications
Practical ePrivacy Directive compliance checks for terminal equipment, communications confidentiality, cookie consent, exemptions, direct marketing, evidence, and national-law caveats.
EU ePrivacy Directive Cookies and Consent: Article 5(3), exemptions, and banner evidence
Cookie consent guide for the EU ePrivacy Directive: Article 5(3) scope, strictly necessary and transmission exemptions, consent UX, withdrawal, logs, analytics caveats, and GDPR interplay.
EU ePrivacy Directive direct marketing rules for electronic mail
Source-backed guide to Article 13 ePrivacy Directive rules for electronic mail marketing, prior consent, customer soft opt-in, opt-out handling, sender identity, and Member State caveats.
EU ePrivacy Directive Enforcement and Fines
Source-backed guide to ePrivacy Directive enforcement, national penalties, competent authorities, GDPR interplay, cookie-banner risk, and evidence limits.
EU ePrivacy Directive FAQ: cookies, consent, marketing, GDPR interplay
Answers to recurring EU ePrivacy Directive questions on Article 5(3), terminal-equipment access, cookie consent, exemptions, analytics, direct marketing, GDPR interplay, national enforcement, and evidence.
EU ePrivacy Directive Member State Cookie Rules
How to evidence EU ePrivacy cookie compliance when Article 5(3) is implemented through Member State law and national authority practice.
EU ePrivacy Directive Metadata and Location Data Guide
Source-backed guide to EU ePrivacy Directive rules for traffic data, location data, anonymisation, consent, value-added services, Article 5(3) overlap, and national-law limits.
EU ePrivacy Directive penalties and fines: national enforcement caveats
Source-backed guide to ePrivacy Directive penalty exposure, national transposition caveats, cookie enforcement evidence, consent defects, and GDPR overlap limits.
EU ePrivacy Directive Requirements: cookies, communications and marketing
Source-backed map of EU ePrivacy Directive requirements for communications confidentiality, terminal-equipment access, consent, traffic and location data, and direct marketing.
EU ePrivacy Directive vs GDPR: cookies, communications, marketing, and evidence
Compare the EU ePrivacy Directive and GDPR by trigger, consent standard, lex specialis overlap, enforcement caveats, and evidence outputs for cookies, device access, communications, and marketing.
EU ePrivacy Directive vs UK PECR: cookies and direct marketing
Compare the EU ePrivacy Directive with current UK PECR rules for device storage and access, statutory exceptions, consent, electronic-mail marketing, soft opt-ins, and enforcement.
EU ePrivacy soft opt-in FAQ for email marketing
When Article 13(2) soft opt-in can support EU customer email marketing, including existing-customer, similar-offer, opt-out, sender-identity, suppression-list, and national-law checks.
EU ePrivacy soft opt-in marketing checklist
Source-backed checklist for using the EU ePrivacy Directive soft opt-in exception for customer email marketing, opt-outs, sender identity, suppression records, and national-law caveats.
EU ePrivacy soft opt-in marketing review workflow
Decide whether an electronic-mail marketing audience meets every Article 13 soft opt-in condition, or must be suppressed or supported by valid prior consent.
EU ePrivacy Strictly Necessary Cookie Exemptions
Source-backed guide to the Article 5(3) ePrivacy exemptions for transmission cookies, requested-service cookies, analytics caveats, evidence, and national-law checks.
Is a reject-all button required for EU ePrivacy cookie consent?
Standalone FAQ answer on EU ePrivacy reject-all and refuse options for cookie banners, including equal prominence, deceptive UX, consent evidence, withdrawal, and national-law caveats.
Strictly Necessary Cookies under the EU ePrivacy Directive
FAQ answer on when EU ePrivacy Article 5(3) allows cookies without consent, with cited examples, analytics caveats, evidence records, and national-law cautions.
What should CMP consent logs retain under the EU ePrivacy Directive?
FAQ answer on CMP consent logs for EU ePrivacy cookie consent: retained fields, consent validity signals, banner versioning, refusal and withdrawal events, proof limits, and national-law caveats.