Legal & Compliance

EU Cookie Consent: Prior Consent, Equal Choices, and Withdrawal

Cookie banners are only the visible control. The underlying question is whether a website stores or accesses information on a visitor's device, or begins related personal-data processing, before it has a valid basis to do so.

What the rules require

For Germany, § 25 TDDDG requires clear, comprehensive information and consent before storage or access on an end user's device, subject to narrow exceptions for communications transmission and operations strictly necessary for a service the user expressly requested. Elsewhere in the EU/EEA, national laws implement the ePrivacy framework, so wording and enforcement can differ even when the core principle is similar.

Where processing relies on consent, GDPR Article 7(3) says withdrawal must be as easy as giving consent. The European Data Protection Board's cookie-banner taskforce also reported that most authorities considered a banner with an accept control but no refusal option incompatible with valid consent.

What AllyProof checks

The browser captures observable facts rather than labelling every cookie in advance:

  • cookies, local storage, and requests before any choice;
  • whether accept and reject choices are available at comparable prominence;
  • whether refusing actually stops new optional tracking activity;
  • whether a visitor can reopen privacy choices later; and
  • whether the banner blocks access to a required legal link.

A finding can still need human review. A cookie name alone does not prove its purpose, and a network request may be necessary in one implementation but optional in another.

How to review a finding

Inventory every pre-choice cookie, storage key, and third-party request. Record its purpose, provider, lifetime, and necessity. Block optional tags until the relevant consent category is granted, make refusal work without extra pressure, and provide a persistent privacy-settings control. Then test a fresh browser session and a refusal path—not only the happy path after acceptance.

Official sources

This is general information, not legal advice. Cookie and device-storage rules depend on purpose, necessity, the applicable national law, and the complete consent flow.

Common questions

Must every cookie wait for consent?
No. Storage or access strictly necessary to transmit a communication or provide a service explicitly requested by the user may be exempt. Analytics, advertising, and similar optional purposes usually need a valid legal basis and often prior consent.
Does EU law require an identical Reject button?
The EDPB taskforce considered the absence of a refusal option wherever an accept button is shown incompatible with valid consent in the cases it reviewed. Exact national enforcement and interface details can still vary.
What does AllyProof test?
It records cookies, browser storage, and network requests before interaction; compares first-layer accept and reject controls; attempts refusal; observes later tracking; and looks for a way to revisit or withdraw the choice.

Want to review these signals on your own website?

Run a free compliance check