FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
20of20items
Across 6 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Strictly Necessary Cookies under the EU ePrivacy Directive

How should analytics and evidence records be handled?

Do not classify analytics cookies as strictly necessary under the general Article 5(3) exemptions merely because the site operator needs measurement. WP29 states that first-party analytics are often useful but are not strictly necessary for a user-requested website feature because the user can still access the site when those cookies are disabled.

Some national implementations or regulator guidance may create narrower analytics approaches or safeguards, but this page does not state country-specific exemptions. Before relying on analytics without consent, check the Member State law and competent authority guidance that applies to the website, the user group, and the deployment.

  • Keep a cookie inventory with name, provider, domain, first-party or third-party status, purpose, duration, storage/access method, and data sent from the terminal equipment.
  • For each claimed exemption, record the requested user action, the exact service feature, why the feature fails without the cookie, and why the duration is no longer than needed.
  • Separate essential purposes from analytics, ads, social plug-ins, A/B testing, personalization, attribution, fraud measurement for advertising, and product-improvement purposes.
  • Keep evidence of banner behavior for non-essential cookies: no consent-required cookies before consent, no pre-ticked boxes, a real reject path, and consent withdrawal that is as easy as giving consent.
  • Refresh the assessment when cookie features, vendors, retention periods, domains, user journeys, Member State coverage, or terminal-equipment access techniques change.
Citations
EDPB Cookie Banner Taskforce report

Grounds evidence expectations for essentiality, banner behavior, reject options, legitimate-interest confusion, withdrawal, and national-law caveats.

What should CMP consent logs retain under the EU ePrivacy Directive?

What should CMP consent logs retain?

Retain the consent event, refusal event, and withdrawal event at purpose level, tied to the exact banner or preference-centre version shown to the user. Article 5(3) is triggered by storing information on, or gaining access to information in, terminal equipment; the log therefore needs to connect the user's choice to the cookies, pixels, SDKs, local storage, identifiers, or similar technologies deployed at that time.

Neither Article 5(3) nor the EDPB consent guidance prescribes a fixed CMP log schema. A practical record normally includes a timestamp; the site or app and market; a pseudonymous user, device, or session key only where needed; the choice and affected purposes; vendor and tracker-inventory versions; banner language and version; the preference payload; and the resulting tag state. Collect only what is needed to demonstrate the choice and its implementation.

  • Keep affirmative consent, refusal, no-choice/default state, later preference changes, and withdrawal as separate states or events so the record does not turn silence into consent.
  • Store the banner and preference-centre version that presented the choice, including the accept, reject, settings, and withdrawal routes available at that time.
  • Link each consent purpose to the live vendor, cookie, pixel, SDK, local-storage, or identifier inventory used by the site or app.
  • Record whether strictly necessary items were separated from analytics, advertising, personalisation, and other optional purposes.
  • Retain only the proof needed to demonstrate the consent workflow; avoid expanding the consent log into a separate behavioural tracking dataset.

What should CMP consent logs retain under the EU ePrivacy Directive?

CMP consent logs should retain a replayable record of the user's consent, refusal, withdrawal, and preference changes, linked to the exact banner version, purposes, vendors, cookie or tracker inventory, and information shown at the time. The log should show that optional Article 5(3) storage or access was not activated before valid consent, that rejection was possible where consent was requested, and that withdrawal was available as easily as consent was given. It is supporting evidence only: it does not cure a misleading banner, an inaccurate vendor inventory, pre-ticked choices, a missing reject route, or a national-law rule that requires something more specific.

Citations
What should CMP consent logs retain under the EU ePrivacy Directive?

Which validity signals should the log preserve?

A log is useful only if it captures consent quality, not just a positive flag. Preserve signals showing that the user saw clear purpose information, made a granular affirmative choice, could refuse optional cookies or trackers, and could later withdraw without undue effort.

For review, keep the evidence that the CMP did not rely on silence, pre-ticked boxes, scrolling, inactivity, or a design that made acceptance look mandatory. If the banner changed, keep the old versioned proof because later screenshots do not prove what a user saw earlier.

  • Consent was recorded by a clear affirmative action for named purposes rather than by inactivity or a preselected default.
  • Purpose-level and vendor-level choices match the CMP configuration and the cookie or tracker inventory active at the timestamp.
  • Reject, continue-without-consenting, or equivalent refusal handling was available where the banner requested consent.
  • Withdrawal was available through a visible, accessible route and was not materially harder than the original consent action.
  • The CMP blocked or suppressed optional tags, pixels, SDK calls, and storage until the relevant consent state allowed them.
Citations
CJEU Planet49 judgment

Supports treating pre-ticked cookie consent as insufficient and preserving the information provided to users for cookie consent.

What should CMP consent logs retain under the EU ePrivacy Directive?

How should consent logs connect to vendor and cookie inventories?

The CMP log should not stand alone. It should point to the inventory that explains which cookies, pixels, SDKs, local-storage entries, tags, or identifiers were present, which were strictly necessary, which required consent, and which vendor or controller received resulting data.

When vendors, purposes, cookies, scripts, consent strings, or banner text change, version the inventory and the CMP configuration together. That versioning lets reviewers distinguish a historical valid choice from a later deployment that needs fresh consent or a new assessment.

  • Keep inventory version, CMP configuration version, tag-manager container version, and banner text version in the same evidence trail.
  • Map each optional vendor or tracker to purpose, category, storage/access type, data recipient, and consent dependency.
  • Document why each strictly necessary item fits the narrow exemption instead of placing it in the consented-purpose bucket.
  • Run periodic scans or deployment checks, but require owner documentation for purposes because scanner output alone cannot prove essentiality.
  • Trigger review when a vendor, purpose, country rollout, cookie lifetime, SDK behaviour, or withdrawal flow changes.
Citations
What should CMP consent logs retain under the EU ePrivacy Directive?

What are the limits of CMP consent-log proof?

A CMP log proves that the system recorded a stated choice under a particular configuration. It does not by itself prove that consent was valid, that the banner was lawful, that all trackers were disclosed, that optional tags were actually blocked, or that the right national authority would accept the implementation.

Use the log with screenshots or rendered banner copies, CMP settings, tag-manager release records, cookie scans, vendor lists, policy text, and withdrawal test results. Keep the national-law caveat explicit: cookie placement or reading is governed by Member State laws transposing the ePrivacy Directive, while subsequent personal-data processing may also be assessed under the GDPR.

  • Do not treat a consent string as proof that the banner was clear, balanced, or granular.
  • Do not use consent logs to justify setting optional cookies before the user chooses.
  • Do not infer country-specific penalties or regulator positions from the EU-level sources alone.
  • Escalate for national-law review when deploying in a new Member State, changing refusal or withdrawal design, or relying on an exemption.
  • Set and document a retention period based on the need to demonstrate consent and handle disputes, then delete or aggregate records when that need ends. The EU-level sources cited here do not prescribe one universal CMP-log retention period.
Citations
Page 2 of 2