What is consent and when is it required?
Consent is the prior approval a user gives, through an active action, for a website to set cookies or similar non-essential technologies in their browser. Article 5.3 of the ePrivacy Directive (2002/58/EC, amended by Directive 2009/136/EC) requires it, the rule that specifically governs access to and storage of information on a user's terminal equipment.
When those cookies also allow identifying a person, for instance through an identifier tied to their browsing behavior, the GDPR kicks in as the general data protection framework. The relationship between the two laws is straightforward: the ePrivacy Directive decides whether the cookie can be placed on the device at all, and the GDPR governs what happens afterward with the personal data that cookie generates.
Not every cookie needs consent. Cookies strictly necessary to deliver the service the user requested, such as a shopping cart or an active login, are exempt under Article 5.3 itself. Consent is only mandatory for analytics, personalization, or advertising cookies.
