Cookies and GDPR – what is actually required?

The General Data Protection Regulation (GDPR) came into force on 25 May 2018 and undoubtedly strengthened the protection of EU citizens' personal data, in a far more evolved and unforgiving form than its original version (Directive 95/46/EC).
Let's be honest: for business owners, administrators and company directors, the first encounter with this regulation must have felt like running into a giant, given its intimidating scale, complexity and — by no means trivial — fines for non-compliance.
The lack of information and training on the subject at the time led, in some cases I witnessed myself, to overzealous measures being put in place, even creating some rather comical awkwardness between companies and their staff. Fortunately, the fog has been lifting, the information is becoming clearer and companies are adopting the procedures that are genuinely appropriate and required by the GDPR.
I have no doubt that the GDPR will bring about a shift in mindset around how we view personal data and, in my opinion, that shift is clearly a positive one, since it reduces to dust the scope for misuse of our data — something we used to react to with indignation, albeit resignation.
One issue I keep coming across (and the reason I'm writing this article) is the uncertainty about what to do with cookies now: do they coexist with the GDPR, or has the GDPR replaced them?
If you haven't got time to read on, I'll say it up front: they coexist and both are mandatory. But if you have the time and you're interested in what each one means, how they relate to each other and what you should do in your case, let me explain:
Cookies and GDPR: what is actually required?

It's fairly common to conflate cookies with privacy policies or data protection law, which leads to the (mistaken) idea that the use of cookies is governed by the General Data Protection Regulation (GDPR), when in fact it isn't: the use of cookies and obtaining consent are not governed by the GDPR, but rather by the ePrivacy Directive.
What are cookies and what are they for?
Cookies are small files of information stored on the user's computer via their web browser, designed to deliver a better, faster experience of a website by storing, for example, a login session or the products we add to a shopping basket, among other features that can improve the way a website is used. Cookies do not store personal data. The obligation for website owners to inform users about their use of cookies came into effect in 2009, with the arrival of European Union Directive 2009/136/EC.
Now that the GDPR is here, is the cookie directive no longer needed?
No, that's not the case. The ePrivacy Directive 2002/58/EC (or the original Cookie Law) was created to establish guidelines and expectations for electronic privacy, including the use of email marketing and cookies. We can think of the ePrivacy Directive as something that “works alongside” the GDPR, rather than being superseded by it.
What's the difference between a “Directive” and a “Regulation”?
Directives set out goals and guidelines agreed between member states, which are then free to adopt and adapt them within their national legislation. Regulations, on the other hand, are legally binding in all member states from the moment they apply, and must be complied with according to the rules established across the Union.
What exactly does the Cookie Law require?
The cookie law requires that, once the user has been informed about the cookies being stored, their informed consent is obtained before any cookies are stored on their device and/or they are tracked. Before consent is given, no cookies — other than exempt cookies — may be installed.
What needs to be done to obtain that consent?
Depending on the local authority, consent can be obtained through continued browsing, clicking, scrolling the page or any other method that requires the user to actively continue. In practice, you need a banner or pop-up with a brief, clear explanation of the purpose of the cookies the website installs. It should include a link to a page detailing the cookies used on the website, including any third-party activity. Where third-party cookies are present, your website is not responsible for them, but you must include a link to the privacy policy of the third party or parties concerned.
Exemptions from the requirement to obtain consent
Technical cookies – essential to delivering the service. These include preference cookies, session cookies, load balancing, and so on.
Statistical cookies – managed directly by the owner (not by third parties), provided the data is not used for profiling.
Third-party statistical cookies (anonymised) – for example, Google Analytics * * This exemption may not apply in all regions and is therefore subject to specific local regulations.
Proof of consent vs record of consent
The Cookie Law does not require you to keep a record of consent, but it does state that you must be able to demonstrate that consent took place (even if that consent has since been withdrawn). Typically, the simplest way to achieve this is with a cookie solution that uses a prior blocking mechanism, since in those circumstances the cookie installation scripts will only run once consent has been obtained. That way, the mere fact that the scripts have run is sufficient proof of consent.
To illustrate the point, let's imagine that the ability to run cookies is a car. The cookie solution is the ignition key, and consent is the act of starting the engine; to start the engine the user had to turn the key in the ignition or press the “Start” button (the act of giving consent), so for them to be driving the car at all, the ignition must have been switched on — and therefore the fact that they are driving the car is sufficient proof of their consent.
JTNDZGl2JTIwY2xhc3MlM0QlMjJmYi1jb21tZW50cyUyMiUyMGRhdGEtaHJlZiUzRCUyMmh0dHBzJTNBJTJGJTJGd3d3LmplbGx5Y29kZS5wdCUyRmNvb2tpZXMtcmdwZC1yZWFsbWVudGUtZXhpZ2lkbyUyRiUyMiUyMGRhdGEtd2lkdGglM0QlMjIxMDAlMjUlMjIlMjBkYXRhLW51bXBvc3RzJTNEJTIyMTAlMjIlM0UlM0MlMkZkaXYlM0U=

Get what we write
No fixed calendar: only when there is something worth your time.

Gonçalo Malho Rodrigues
Fundador & CEO
Fundou a Jelly – Digital Agency em Portugal em 2010 e a Strivesync – AI-Native Systems no Dubai em 2026. Detém outras empresas, noutros setores, como a Stronddo – Online Art Galleryl, a Scallent – Human Talent. Gonçalo, criou a The Change Framework, que apoia líderes a gerar a mudança através da mobilização de equipas em torno de uma causa.