How should analytics and evidence records be handled?
Do not classify analytics cookies as strictly necessary under the general Article 5(3) exemptions merely because the site operator needs measurement. WP29 states that first-party analytics are often useful but are not strictly necessary for a user-requested website feature because the user can still access the site when those cookies are disabled.
Some national implementations or regulator guidance may create narrower analytics approaches or safeguards, but this page does not state country-specific exemptions. Before relying on analytics without consent, check the Member State law and competent authority guidance that applies to the website, the user group, and the deployment.
- Keep a cookie inventory with name, provider, domain, first-party or third-party status, purpose, duration, storage/access method, and data sent from the terminal equipment.
- For each claimed exemption, record the requested user action, the exact service feature, why the feature fails without the cookie, and why the duration is no longer than needed.
- Separate essential purposes from analytics, ads, social plug-ins, A/B testing, personalization, attribution, fraud measurement for advertising, and product-improvement purposes.
- Keep evidence of banner behavior for non-essential cookies: no consent-required cookies before consent, no pre-ticked boxes, a real reject path, and consent withdrawal that is as easy as giving consent.
- Refresh the assessment when cookie features, vendors, retention periods, domains, user journeys, Member State coverage, or terminal-equipment access techniques change.
Supports the analytics caveat and the principle that doubts should be resolved by seeking consent rather than stretching an exemption.
Grounds the quality standard for consent where a cookie does not fit an Article 5(3) exemption.
Grounds evidence expectations for essentiality, banner behavior, reject options, legitimate-interest confusion, withdrawal, and national-law caveats.
Commission context for the ePrivacy framework and protection of privacy in electronic communications.