EU Privacy Law EU/EEA

Cookie Compliance in 2026: Country-by-Country Requirements Across the EU

How EU cookie consent rules differ by country: CNIL, Spanish AEPD, German TTDSG, Italian Garante and more, with the fines that defined each position.

Regulation

ePrivacy Directive Article 5(3), national implementations

Max Penalty

Set nationally; largest cookie fine to date is EUR 150 million (CNIL)

Enforcing Authority

National authorities (CNIL, AEPD, Garante, BfDI/state DPAs, and others)

Official Source

eur-lex.europa.eu

Executive Summary

  • The consent rule comes from ePrivacy Directive Article 5(3), but each member state implemented it in national law, so requirements and enforcement styles differ meaningfully by country.
  • France's CNIL is the strictest enforcer: reject must be as easy as accept, and its Google (EUR 150M) and Facebook (EUR 60M) fines set the de facto EU standard.
  • Germany's TTDSG (2021, now TDDDG) codified consent for device access; Italy's Garante requires a banner with an X-to-refuse or equivalent; Spain's AEPD updated guidance to require a visible reject option.
  • Consent-free analytics is tolerated only narrowly: the CNIL publishes exemption criteria that most analytics configurations do not meet.
  • A single banner built to the strictest national standard (first-layer reject, no pre-consent firing, granular purposes) satisfies all of them.

EU cookie compliance is one principle applied twenty-seven ways. Article 5(3) of the ePrivacy Directive requires prior consent before storing or accessing anything on a user’s device, but the directive was transposed into national law country by country, each with its own statute, regulator, and guidance. What follows maps the positions that matter most in practice.

Rule sourceePrivacy Directive Art. 5(3), national implementations
Strictest enforcerFrance (CNIL)
Largest cookie fineEUR 150M, Google (CNIL, December 2021)
Official textEUR-Lex CELEX 32002L0058

The countries that set the tone

France. The CNIL enforces its own guidelines under the Loi Informatique et Libertés, outside the GDPR one-stop-shop. Its December 2021 decisions against Google (EUR 150 million) and Facebook (EUR 60 million) established that rejecting cookies must take the same effort as accepting them. The CNIL also publishes the EU’s clearest exemption criteria for consent-free audience measurement, which most analytics tools fail by default. It recommends refreshing consent every 6 to 13 months.

Germany. Consent lives in Section 25 of the TTDSG (since renamed TDDDG), in force December 2021, which ended years of ambiguity in German law. German state DPAs run coordinated website audits, and German courts entertain competitor claims over cookie violations, adding civil exposure on top of regulatory.

Italy. The Garante’s 2021 guidelines require that users be able to refuse via the banner itself, accept scrolling as consent in no case, and re-prompt no sooner than six months after a refusal. The Garante actively fines both banner design and pre-consent firing.

Spain. The AEPD’s cookie guide, updated in 2023 to align with EDPB positions, requires a visible reject option and prohibits making refusal harder than acceptance. The AEPD is among the highest-volume fining authorities in the EU, so smaller sites see enforcement here.

Elsewhere, the pattern repeats with local flavor: the Belgian DPA’s IAB TCF decision reshaped ad-tech consent strings, the Dutch AP has warned that cookie walls invalidate consent, and the EDPB’s 2023 cookie banner task force report pushed national positions toward convergence on first-layer rejection and no pre-ticked purposes.

Build once, to the strictest standard

Maintaining per-country banners is error-prone and buys nothing. A configuration that satisfies the CNIL satisfies everyone: no non-essential cookies before consent, Accept and Reject with equal prominence on the first layer, granular purposes on the second, a persistent preference link, consent records retained, and re-prompt intervals honored. The failure mode is drift: tags added outside the consent platform quietly restore pre-consent firing. Verify empirically and re-verify after marketing changes; a free scan shows exactly which cookies and trackers fire before consent on your site, per page. For the legal architecture behind these rules, see ePrivacy vs. GDPR.

Frequently Asked Questions

Are cookie rules the same in every EU country?

No. The consent principle is EU-wide, but each country transposed the ePrivacy Directive into national law with its own enforcer and nuances. France, Germany, Italy, and Spain each publish their own cookie guidance, and enforcement intensity varies.

Does every EU country require a reject button on the first layer?

The CNIL made first-layer rejection the effective standard in France with its 2021 fines, and Spain, Italy, and others have followed in guidance. Building to that standard everywhere is simpler and safer than maintaining country variants.

Can I use Google Analytics without consent in the EU?

Generally no. Analytics cookies require consent in most member states. The CNIL's audience-measurement exemption requires strict configuration: no cross-site tracking, truncated identifiers, and short retention, which standard Google Analytics setups do not meet.

What is Germany's TTDSG?

The Telecommunications-Telemedia Data Protection Act (2021, renamed TDDDG in 2024), which finally transposed the ePrivacy cookie rule into German statute. Section 25 requires consent for storing or accessing information on end-user devices, mirroring Article 5(3).

Do cookie walls comply with EU rules?

Contested. Several authorities and the EDPB view pure cookie walls as invalidating consent. Pay-or-consent models are under active EDPB and Commission scrutiny after the 2024 opinion on large platforms, so treat them as high-risk.

Regulatory Crosswalk

GDPRUK PECRSwiss FADP

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.