Organisations should treat consent as the default for storing or reading information from a user’s device, especially for cookies and similar tracking tools. Exceptions are narrow and usually cover only what is necessary and proportionate to deliver the communication service or a service specifically requested by the end-user, such as authentication sessions or shopping baskets.
When is consent the default for cookies and tracking?
Consent is the safer default whenever a technology stores or reads information on a user’s device for tracking, profiling, advertising, analytics beyond strictly necessary operation, or cross-site recognition. The practical test is whether the tool is essential to deliver the service the user asked for, or whether it mainly serves measurement, marketing, or behavioural insight.
For organisations, the key distinction is functional necessity, not convenience. If the browser storage or identifier is only supporting service delivery, it may fit within a narrow exception. If it is helping the organisation understand, follow, or influence the user across sessions or sites, consent is usually required before deployment.
Where communications services are involved, this issue often sits alongside broader lawful processing duties under Identity Data Privacy and Consent Guide, especially when device identifiers, session data, or preference state can be linked back to an identifiable person.
What counts as a narrow exception to consent?
The exception is limited to what is necessary and proportionate for the communication service itself or for a service specifically requested by the end-user. Typical examples include keeping a login session alive, preserving an active shopping basket, routing a message, or supporting a security function that is intrinsic to the service request. The justification must match the user’s request, not the organisation’s broader business goals.
That means the same technology can be lawful in one context and unlawful in another. A session cookie that prevents repeated sign-in prompts may be acceptable, but the same mechanism used to build a marketing profile would move outside the exception. Organisations should document why each cookie or tracker exists and tie that explanation to the service function it supports.
For the underlying legal baseline, organisations should map these decisions against the processing principles in EU General Data Protection Regulation (GDPR), particularly necessity, transparency, purpose limitation, and data minimisation.
How should organisations operationalise lawful processing for tracking tools?
Start by inventorying every cookie, pixel, SDK, tag, and similar technology, then classify each one by purpose, storage duration, and whether it can run before consent. The useful question is not “does it collect data?” but “what service does it enable, and could that service work without it?” That analysis should drive the consent banner, the default state, and the technical blocking logic.
Practically, organisations should separate strictly necessary functions from analytics, advertising, and preference-enhancing functions. Consent should be specific, informed, and revocable, and refusal should not degrade the service beyond what is genuinely necessary. Where a tool supports security or authentication, the organisation should still verify that its scope is limited to the requested function and that retention is proportionate.
Strong governance also requires evidence. Keep records of the cookie inventory, the lawful-basis rationale, consent logs, and the implementation decision that prevents non-essential tools from loading before opt-in. Those artefacts matter when privacy teams, product owners, and auditors need to show that the processing choice was deliberate rather than accidental.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 5 — Principles relating to processing of personal data | Cookies and tracking require purpose, minimisation, and transparency choices. |
| Art. 6 — Lawfulness of processing | The question is about the lawful basis for tracking and consent. | |
| Art. 25 — Data protection by design and by default | Consent and blocking logic must be built into the product, not added later. | |
| Recommendation — Apply purpose limitation and minimisation before loading non-essential tracking. Document the lawful basis for each tracker and default non-essential tools to consent. Build consent gating and pre-consent blocking into the user journey by default. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Session and authentication cookies depend on controlled credential and token handling. |
| Recommendation — Limit session material to the minimum lifetime and rotate or revoke it promptly. | ||
Practitioner Guidance
What to prioritise: Classify each tracker by function before you classify it by vendor or channel. A cookie that is “helpful” but not necessary should default to blocked until consent is captured.
What to verify: Confirm that the code path for denied consent really suppresses the relevant scripts, pixels, and storage writes. A consent banner without enforcement is only a disclosure layer.
Common mistake: Treating analytics, personalisation, or retargeting as if they were part of the requested service. That shortcut usually turns a narrow exception into an overbroad lawful-basis claim.
Practitioner takeaway: The strongest control is a purpose-based design decision made before deployment, because lawful processing for cookies depends on what the tool does, not on how easily it can be enabled.
Related resources from NHI Mgmt Group
- How should organisations handle consent for health data submitted through service portals?
- How should organisations handle local data processing requirements when expanding into MEA markets?
- How should organisations handle cookie consent and tracking controls on security and privacy pages?
- How should healthcare organisations handle tracking pixels in patient portals without exposing protected data?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org