EU cookie compliance is one principle applied twenty-seven ways. Article 5(3) of the ePrivacy Directive requires prior consent before storing or accessing anything on a user’s device, but the directive was transposed into national law country by country, each with its own statute, regulator, and guidance. What follows maps the positions that matter most in practice.
| Rule source | ePrivacy Directive Art. 5(3), national implementations |
|---|---|
| Strictest enforcer | France (CNIL) |
| Largest cookie fine | EUR 150M, Google (CNIL, December 2021) |
| Official text | EUR-Lex CELEX 32002L0058 |
The countries that set the tone
France. The CNIL enforces its own guidelines under the Loi Informatique et Libertés, outside the GDPR one-stop-shop. Its December 2021 decisions against Google (EUR 150 million) and Facebook (EUR 60 million) established that rejecting cookies must take the same effort as accepting them. The CNIL also publishes the EU’s clearest exemption criteria for consent-free audience measurement, which most analytics tools fail by default. It recommends refreshing consent every 6 to 13 months.
Germany. Consent lives in Section 25 of the TTDSG (since renamed TDDDG), in force December 2021, which ended years of ambiguity in German law. German state DPAs run coordinated website audits, and German courts entertain competitor claims over cookie violations, adding civil exposure on top of regulatory.
Italy. The Garante’s 2021 guidelines require that users be able to refuse via the banner itself, accept scrolling as consent in no case, and re-prompt no sooner than six months after a refusal. The Garante actively fines both banner design and pre-consent firing.
Spain. The AEPD’s cookie guide, updated in 2023 to align with EDPB positions, requires a visible reject option and prohibits making refusal harder than acceptance. The AEPD is among the highest-volume fining authorities in the EU, so smaller sites see enforcement here.
Elsewhere, the pattern repeats with local flavor: the Belgian DPA’s IAB TCF decision reshaped ad-tech consent strings, the Dutch AP has warned that cookie walls invalidate consent, and the EDPB’s 2023 cookie banner task force report pushed national positions toward convergence on first-layer rejection and no pre-ticked purposes.
Build once, to the strictest standard
Maintaining per-country banners is error-prone and buys nothing. A configuration that satisfies the CNIL satisfies everyone: no non-essential cookies before consent, Accept and Reject with equal prominence on the first layer, granular purposes on the second, a persistent preference link, consent records retained, and re-prompt intervals honored. The failure mode is drift: tags added outside the consent platform quietly restore pre-consent firing. Verify empirically and re-verify after marketing changes; a free scan shows exactly which cookies and trackers fire before consent on your site, per page. For the legal architecture behind these rules, see ePrivacy vs. GDPR.