GDPR and ePrivacy

Do Analytics Cookies Need Consent? EU Rules and Exceptions

Learn when analytics cookies need consent, what cookieless tracking changes, and how to assess national exemptions, vendor claims and your configuration.

Published
Reading time
6 min

Analytics cookies generally need prior consent under applicable EU device-storage rules unless a specific exemption covers the configured use. The answer depends on the operations, purposes and national rules. Calling a tool first-party, cookieless or privacy-friendly does not establish an exemption.

This guide provides a decision process for website owners and privacy teams. France is used as a clearly identified national example. It does not create a permission that can automatically be applied throughout Europe, and UK PECR requires a separate assessment.

Separate device access from personal-data processing

There are two questions to answer:

QuestionWhat to examine
Does the implementation store or access information on a device?Cookies, browser storage, identifiers and other relevant technical operations
Does it process personal data?Identifiability, purposes, recipients, lawful basis, retention and other GDPR requirements

Article 5(3) of the ePrivacy Directive governs the first question through national implementing rules. Its consent requirement has exceptions for transmission and what is strictly necessary for a service explicitly requested by the user. GDPR legitimate interests cannot substitute for consent where that device operation requires it. ePrivacy Directive, Article 5(3)

An exemption for device access does not settle the lawful basis for personal-data processing. Conversely, an argument about anonymised reports does not establish that the preceding collection was exempt. Our GDPR and ePrivacy overview explains the wider framework.

A decision process for an analytics deployment

Use the following sequence before deciding whether to load analytics without a banner choice. It is a review method, not an automated legal determination.

  1. Describe the exact implementation. Record the product version, enabled features, browser code, identifiers, server processing and recipients.
  2. Identify device storage and access. Inspect what happens on a fresh visit, including requests that do not create cookies.
  3. Identify the applicable national rules. Do not select a favourable country's guidance merely because the provider is based there.
  4. Test a specific exemption against the configuration. If a required condition is not established, do not rely on that exemption. Obtain consent or redesign and reassess.
  5. Assess personal-data processing separately. Resolve lawful basis, transparency, retention, recipient roles and transfers where relevant.
  6. Verify the deployed behaviour. A configuration document is not evidence that the production tags follow it.

Keep the decision attached to the configuration version. A later change that links analytics to advertising or adds a cross-site identifier can change the assessment.

France: what CNIL's audience-measurement exemption covers

CNIL describes an exemption for restricted audience measurement performed exclusively for the publisher, producing anonymous statistics. Its conditions exclude combining the data with other processing, passing non-anonymous data to third parties and tracking people across different sites or applications.

CNIL also recommends informing users, limiting tracker duration, avoiding automatic renewal on each visit and periodically reviewing retention. Its guidance gives thirteen months as an example tracker lifetime and recommends a maximum twenty-five months for collected information. These are France-specific recommendations, not EU-wide defaults.

CNIL provides a self-assessment process. A provider must not market a qualifying configuration as CNIL-certified or validated, and a self-assessment does not bind the regulator. CNIL's audience-measurement guidance

Ask the provider for the documented configuration and check your own deployment against it. The name of a product, a previous listing or an exemption claim on a sales page is insufficient evidence.

Two illustrative implementation decisions

A publisher measuring navigation problems: its team proposes a narrowly configured audience tool and documents purpose restrictions, fields, recipients and retention against the applicable national guidance. The next step is to verify every condition and inspect the deployed requests. The example does not itself establish eligibility.

A shop linking analytics to advertising audiences: its team enables user matching and sends events to advertising destinations. It should not carry over an earlier assessment for restricted audience measurement. The additional purposes and disclosures need review before activation.

The useful difference is the processing, not whether both products have an “analytics” label.

Not necessarily. The EDPB's technical-scope guidance examines operations including pixels, URL tracking and certain IP-based techniques. It interprets the scope of Article 5(3); it does not decide every consent exemption or declare every server request subject to consent. EDPB Guidelines 2/2023

Ask what “cookieless” means in the proposed implementation. It might mean no persistent browser cookie, while the system still reads device information, receives identifiers or combines events. Alternatively, a narrowly scoped backend statistic may involve different operations. Assess what occurs rather than treating the label as either an automatic exemption or an automatic violation.

Similarly, server-side collection changes the route. It does not by itself answer whether the initial device access or subsequent forwarding is permitted. See server-side tracking: benefits and limits.

Do not treat GA4 as exempt merely because you disabled an advertising setting or because its cookies are first-party. Review the complete collection and processing configuration against the rules you intend to rely on.

Google Consent Mode controls supported tag behaviour; it does not provide legal permission. In advanced mode, denied storage consent can still result in cookieless requests. Those requests need their own assessment. The choice between basic blocking and advanced measurement should follow the approved processing decision. Google's Consent Mode overview

Use our basic vs advanced Consent Mode guide for the technical comparison. Where consent is required, use a clear choice interface and verify what rejection and withdrawal actually do.

Questions to ask an analytics provider

Use these questions to request concrete evidence rather than a general compliance statement:

Ask the providerEvidence to request
What does the browser read, store and send?Field list, cookie/storage inventory and example request payloads
Which exemption do you rely on?Named jurisdiction, current authority guidance and a condition-by-condition assessment
Which settings are required?Versioned configuration instructions and a list of incompatible features
Who uses the data and for what?Recipient roles, contracts, reuse terms and subprocessor information
Can data be linked across visits or sites?Identifier design, matching functions and isolation controls
What is retained and where?Retention settings for events, identifiers, reports, logs and backups
What happens when the configuration changes?Change notification and a process to reassess the deployment

Review both default and optional features. A tool can have an eligible restricted configuration and a different deployment that does not meet the same conditions.

Validate the decision with technical checks

Create expected results before opening the browser. Use test data and keep sensitive identifiers out of shared request exports.

  • Fresh visit: record scripts, storage and requests before any choice.
  • Rejection: verify that consent-dependent analytics remains restricted through navigation.
  • Analytics only: ensure advertising features do not become enabled through a shared flag.
  • Withdrawal: inspect later browser events, queued work and server forwarding.
  • Returning visit: verify saved preferences and any configuration changes.
  • Exemption-based deployment: inspect the restrictions that support the exemption, not just the absence of a banner.

Compare evidence with the provider's documentation. Investigate discrepancies such as an unlisted identifier, a second destination or logs retaining fields that the event filter removes. Route unresolved questions to the privacy and implementation owners before relying on the exemption.

FAQ

Not where the device-storage or access operation requires consent. The separate GDPR lawful-basis assessment does not remove that requirement.

No. Assess the specific configuration and applicable national conditions. Product names and self-hosting do not establish eligibility, and CNIL's process is not product certification.

Does anonymising reports remove the need to assess collection?

No. Examine the data before aggregation, the device operations and intermediate storage. A report can omit identifiers even when earlier processing used them.

Is an analytics exemption valid across the whole EU?

Do not assume so. Review relevant national rules and guidance. A configuration justified for one jurisdiction needs a separate applicability assessment elsewhere.

Potentially, if all relevant operations are outside the consent requirement or properly exempt and other obligations are met. That conclusion requires an assessment of the whole site, including advertising, embeds and other tracking tools.

Choose the implementation after the assessment

If analytics needs consent, our cookie banner examples show how to explain the choice. For a wider review, use the GDPR readiness assessment, explore cookie consent implementation or request a free consent audit.

Portrait of Doğancan Doğan
Written bySolution Engineer, Privacy Engineering

Solution engineer who has implemented consent management on 200+ corporate websites globally. Specialises in CCPA and GDPR operational compliance.

Keep reading

Related guides.

All of GDPR and ePrivacy →
  1. 01GDPR Cookie Consent in 2026: ePrivacy Rules and ChecksGDPR and ePrivacy · Apr 2026
  2. 02GDPR Cookie Banner Examples: Accept, Reject and SettingsGDPR and ePrivacy · Sept 2026
  3. 03First-Party vs Third-Party Cookies: Examples and ConsentCookies and tracking · Sept 2026

See what fires before consent on your own site.

A free audit of your current banner and tags across regions, with the findings in writing and a 30-minute call to go through them.