Necessary Cookies
Necessary cookies are small text files a website stores on your device that are essential for the site to work and to deliver a service you have asked for, such as accessing secure areas of a site. Because they are strictly necessary for a service you requested, they are generally treated differently from cookies used for analytics or advertising. The precise boundary of what counts as 'necessary' can be uncertain in individual cases and should be assessed against the specific function of each cookie.
In the context of EU/UK ePrivacy rules, 'necessary' (or 'strictly necessary') cookies are those that are strictly necessary to provide an information society service explicitly requested by the subscriber or user. Under the ICO's guidance on the Privacy and Electronic Communications Regulations (PECR), such cookies typically fall within the consent exemption applicable to storage or access that is strictly necessary for a service requested by the user, meaning prior consent is generally not required for these specific cookies (though transparency obligations may still apply). The classification is narrow and function-specific: cookies used for analytics, advertising, or personalization generally do not qualify, and the assessment must be made per cookie against the requested service. Note that the exact scope of 'strictly necessary' is subject to regulator interpretation and can be unclear in practice, and the interaction between ePrivacy rules and the GDPR (including any legal basis for associated personal data processing) should be assessed separately. Practitioners should verify the current position against the applicable ePrivacy Directive, national implementing law such as PECR, and up-to-date regulator guidance.
Why it matters
The classification of a cookie as 'necessary' or 'strictly necessary' carries significant legal consequences under EU and UK ePrivacy rules. Cookies that are strictly necessary to provide an information society service explicitly requested by the user generally fall within the consent exemption, meaning prior consent is typically not required before they are set. By contrast, cookies used for analytics, advertising, or personalization generally do not qualify and normally require consent. Misclassifying a non-essential cookie as 'necessary' to avoid a consent prompt is a common compliance risk, because the exemption is narrow and function-specific.
Getting this boundary right matters because organizations frequently over-populate the 'necessary' category in their cookie banners, treating cookies that support desirable but non-essential functions as essential. Regulators, including the ICO under PECR, interpret 'strictly necessary' narrowly and assess it per cookie against the specific service the user has requested. The exact scope remains subject to regulator interpretation and can be genuinely unclear in individual cases, so the classification should be documented and defensible rather than assumed.
It is also important to remember that the consent exemption under ePrivacy rules addresses only the setting of, or access to, information on the user's device. Where a necessary cookie involves processing of personal data, a separate GDPR analysis of the appropriate legal basis and of transparency obligations should be carried out. Transparency duties may still apply even where consent is not required for a strictly necessary cookie.
Who it's relevant to
Inside Necessary Cookies
Common questions
Answers to the questions practitioners most commonly ask about Necessary Cookies.