Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› EU Cookie Law
Governance, Ownership & Risk

EU Cookie Law

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Governance, Ownership & Risk

The EU Cookie Law is the common name for the ePrivacy Directive rules that govern how websites use cookies and similar tracking technologies. It requires clear notice, informed consent, and the ability for users to reject or withdraw non-essential cookies before a site stores or accesses personal information.

The EU Cookie Law is not a standalone statute so much as a common label for the ePrivacy rules that govern when websites may store or read information on a user’s device. Its core concern is consent, notice, and control before non-essential tracking begins.

In practice, the law reaches beyond traditional cookies to similar identifiers and tracking technologies, including technologies that can profile behaviour across sessions or devices. The key compliance question is whether the storage or access is strictly necessary for the service the user requested, or whether it requires informed consent first.

The law is built around the idea that users should understand what tracking is happening and be able to make a real choice. A valid notice needs to be clear enough to explain the purpose of the cookie or tracker, who is setting it, and whether third parties are involved.

Consent is not meant to be implied by silence or by continuing to browse after being confronted with a banner. The user must be able to reject non-essential cookies as easily as accept them, and a prior choice should be respected unless the user changes it later.

What Counts as Essential or Non-Essential

Not every cookie requires the same treatment. Strictly necessary cookies are generally those needed to deliver a requested service, such as maintaining a shopping basket, preserving a login session, or supporting a security function that the user explicitly initiated.

Analytics, advertising, retargeting, social media embeds, and many cross-site tracking technologies are usually non-essential because they serve measurement or marketing rather than the immediate service the visitor asked for. That distinction is often the centre of the compliance analysis, especially when a site uses multiple tags, pixels, or third-party scripts.

For organisations, cookie compliance is not just a legal banner issue, it is part of data governance and web architecture. The website must know what is deployed, when it loads, what data it touches, and whether the consent state actually gates the relevant storage or access.

That makes implementation detail important: if a script fires before consent is recorded, the site may already have collected or shared data in a way that undermines the legal basis. Teams often need to coordinate legal, product, privacy, security, and engineering decisions to keep consent signals, tag managers, and embedded services aligned.

Risk and Threat Considerations

Cookie mechanisms create privacy, compliance, and trust risk when they are used to track users before a valid choice is made, when consent is bundled or obscured, or when third-party tags collect more data than the notice describes. Because cookies and similar identifiers can support profiling, violations can turn a routine web feature into a material exposure issue.

Failure mechanism: A site loads analytics, advertising, or embedded third-party code before consent is captured, or it presents a consent banner that nudges users toward acceptance without a genuine refusal path.

Impact: The organisation may collect personal data without a valid basis, create unnecessary third-party disclosure risk, and lose user trust while also exposing itself to regulatory scrutiny and remediation costs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 5 — Principles Relating to Processing of Personal DataCookie tracking often processes personal data and must follow lawful, transparent processing principles.
Art. 6 — Lawfulness of ProcessingCookie consent is a legal-basis question when trackers are not strictly necessary.
Art. 25 — Data Protection by Design and by DefaultCookie choice and tracker minimisation are design controls that should be built into the site.
Recommendation — Apply Article 5 principles to limit tracking to what is transparent, necessary, and purpose-bound. Map each non-essential cookie purpose to a valid lawful basis before deployment. Build consent gating and tracker minimisation into default site behaviour.
NIST CSF 2.0PR.DS-01 — Data-at-Rest is ProtectedCookies and similar trackers can store or expose sensitive data that should be protected.
Recommendation — Protect stored tracking data and limit what is retained on the client or server.

Practitioner Guidance

What to watch for: The most common failure is not the banner itself, but the gap between the banner and the actual page behaviour. Teams should treat the consent state as a control input for tags, pixels, and embedded services so that non-essential tracking stays blocked until choice is recorded.

Governance implication: Ownership should extend across privacy, web development, and marketing operations, because cookie compliance breaks when a business can describe consent correctly but cannot enforce it technically. That means the inventory of trackers, their purposes, and their loading behaviour should be kept current as the site changes.

Practitioner takeaway: If users cannot refuse non-essential tracking as easily as they accept it, the implementation is usually weaker than the policy wording suggests.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org