Skip to main content
Category: Consent Requirements

Necessary Cookies

Also known as: Strictly Necessary Cookies, Essential Cookies
Simply put

Necessary cookies are small text files a website stores on your device that are essential for the site to work and to deliver a service you have asked for, such as accessing secure areas of a site. Because they are strictly necessary for a service you requested, they are generally treated differently from cookies used for analytics or advertising. The precise boundary of what counts as 'necessary' can be uncertain in individual cases and should be assessed against the specific function of each cookie.

Formal definition

In the context of EU/UK ePrivacy rules, 'necessary' (or 'strictly necessary') cookies are those that are strictly necessary to provide an information society service explicitly requested by the subscriber or user. Under the ICO's guidance on the Privacy and Electronic Communications Regulations (PECR), such cookies typically fall within the consent exemption applicable to storage or access that is strictly necessary for a service requested by the user, meaning prior consent is generally not required for these specific cookies (though transparency obligations may still apply). The classification is narrow and function-specific: cookies used for analytics, advertising, or personalization generally do not qualify, and the assessment must be made per cookie against the requested service. Note that the exact scope of 'strictly necessary' is subject to regulator interpretation and can be unclear in practice, and the interaction between ePrivacy rules and the GDPR (including any legal basis for associated personal data processing) should be assessed separately. Practitioners should verify the current position against the applicable ePrivacy Directive, national implementing law such as PECR, and up-to-date regulator guidance.

Why it matters

The classification of a cookie as 'necessary' or 'strictly necessary' carries significant legal consequences under EU and UK ePrivacy rules. Cookies that are strictly necessary to provide an information society service explicitly requested by the user generally fall within the consent exemption, meaning prior consent is typically not required before they are set. By contrast, cookies used for analytics, advertising, or personalization generally do not qualify and normally require consent. Misclassifying a non-essential cookie as 'necessary' to avoid a consent prompt is a common compliance risk, because the exemption is narrow and function-specific.

Getting this boundary right matters because organizations frequently over-populate the 'necessary' category in their cookie banners, treating cookies that support desirable but non-essential functions as essential. Regulators, including the ICO under PECR, interpret 'strictly necessary' narrowly and assess it per cookie against the specific service the user has requested. The exact scope remains subject to regulator interpretation and can be genuinely unclear in individual cases, so the classification should be documented and defensible rather than assumed.

It is also important to remember that the consent exemption under ePrivacy rules addresses only the setting of, or access to, information on the user's device. Where a necessary cookie involves processing of personal data, a separate GDPR analysis of the appropriate legal basis and of transparency obligations should be carried out. Transparency duties may still apply even where consent is not required for a strictly necessary cookie.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy leads need to review how cookies are categorized in consent management tools to ensure that only genuinely strictly necessary cookies are placed in the exempt category. Because the exemption is narrow and assessed per cookie, they should maintain a documented, defensible rationale for each classification and revisit it as regulator guidance evolves.
Engineers and web developers
Those implementing websites and cookie banners are responsible for ensuring that non-essential cookies do not load before consent is obtained, while strictly necessary cookies support core functions such as accessing secure areas. They should be able to map each cookie to the specific requested service it enables so that classification decisions can be verified.
Compliance and legal teams
Compliance and legal teams assess whether a cookie meets the 'strictly necessary' threshold under the applicable ePrivacy rules and national implementing law such as PECR, and separately whether any associated personal data processing has a valid GDPR legal basis. Given the genuine uncertainty around the boundary, they should treat borderline cookies cautiously and verify positions against current official texts and regulator guidance.

Inside Necessary Cookies

Strictly Necessary Function
Cookies that are essential to provide a service explicitly requested by the user, such as those enabling security, load balancing, session management, or remembering items in a shopping basket. The necessity is assessed by reference to the service the user actually asked for, not the interests of the operator.
Consent Exemption
Under the ePrivacy Directive as implemented in national law, strictly necessary cookies generally fall within the exemption from the prior consent requirement that otherwise applies to storing or accessing information on a user's device. The exemption is narrow and is interpreted restrictively by regulators.
Relationship to GDPR
Placing a cookie may still involve processing of personal data, which typically requires an Article 6 lawful basis under the GDPR separate from the ePrivacy question of whether consent is needed to store or access the cookie. The two regimes operate together and should not be conflated.
Transparency Obligation
Even where consent is not required, users generally must still be informed about the cookies in use, for example through a cookie notice or privacy information, in line with transparency expectations under applicable law and guidance.

Common questions

Answers to the questions practitioners most commonly ask about Necessary Cookies.

Do necessary cookies require user consent under EU rules?
Generally, cookies that are strictly necessary to provide a service explicitly requested by the user are exempt from the consent requirement under the ePrivacy framework as implemented in national law. However, the exemption is narrow and applies only to what is genuinely essential to deliver the requested functionality. Cookies used for analytics, personalisation, or advertising typically fall outside this exemption and usually require consent. The precise boundary can vary between member state implementations and regulator guidance, so you should assess each cookie against the current applicable rules.
Does labelling a cookie as necessary mean it falls outside data protection law entirely?
No. The consent exemption for strictly necessary cookies concerns the ePrivacy rules on storing or accessing information on a user's device. It does not remove any personal data processed via those cookies from the scope of the GDPR. Where a necessary cookie processes personal data, you still need an appropriate Article 6 legal basis, and you must meet transparency, security, and other GDPR obligations. The label 'necessary' addresses the consent question, not the wider data protection position.
How should we decide whether a specific cookie qualifies as strictly necessary?
In most cases the test focuses on whether the cookie is essential to deliver a service the user has actively requested, rather than merely useful to the operator. Reviewing each cookie's purpose, and documenting why it is essential, generally supports a defensible position. Where a cookie serves the operator's own analytics or commercial aims rather than the user's requested functionality, it typically will not qualify. Because regulator guidance on borderline cases can diverge, you should record your reasoning and verify it against the current applicable guidance.
Do we still need to tell users about necessary cookies even if consent is not required?
Yes, typically. Even where the consent exemption applies, transparency obligations generally still apply where personal data is involved. Providing clear information about the cookies you use, their purposes, and their duration, usually in a cookie notice or policy, is generally expected. The exemption removes the need to obtain consent, but it does not remove the need to inform users.
How should necessary cookies be presented in a consent management interface?
In common practice, cookies relied on as strictly necessary are typically presented separately from cookies that require consent, and are not made subject to an opt-in toggle. It is generally advisable to categorise cookies accurately, to avoid classifying non-essential cookies as necessary, and to keep the categorisation aligned with the actual purpose of each cookie. Because interface expectations can reflect evolving regulator guidance, you should review the categorisation against the current applicable position.
How often should the classification of necessary cookies be reviewed?
Periodic review is generally advisable, because the cookies deployed on a site can change as functionality, third-party tools, and configurations evolve. A cookie that was essential for one feature may no longer be necessary, and new cookies may be introduced that were not previously assessed. Maintaining an up-to-date inventory and revisiting the classification, particularly after site changes, helps keep the categorisation accurate against current guidance.

Common misconceptions

Any cookie the website operator considers useful or important qualifies as necessary and is exempt from consent.
The exemption is generally interpreted narrowly and is judged by reference to the service the user explicitly requested, not by the commercial usefulness to the operator. Cookies used for analytics, advertising, or personalisation typically fall outside the strictly necessary category and usually require consent, subject to assessment under applicable national implementing law.
Because necessary cookies are exempt from consent, no legal obligations apply to them at all.
Transparency obligations generally still apply, and where personal data is processed a lawful basis under Article 6 GDPR is typically needed. The ePrivacy consent exemption addresses only whether prior consent is required to store or access the information, not the wider data protection position.
The rules on necessary cookies are uniform across the EU and the UK.
The cookie consent requirement derives from the ePrivacy Directive, which is implemented through national law, so the precise position can vary between member states and under the UK regime. Regulator guidance on borderline categories can also diverge, so the classification of a given cookie should be verified against the applicable local rules.

Best practices

Assess each cookie against whether it is strictly necessary to deliver the service the user explicitly requested, rather than classifying by convenience, and document the reasoning for each classification.
Do not default analytics, advertising, or personalisation cookies into the necessary category; treat these as generally requiring consent unless an assessment under applicable national law supports otherwise.
Maintain a cookie inventory or audit that records each cookie's purpose, duration, provider, and classification, and review it periodically as the site changes.
Provide clear transparency information about all cookies in use, including necessary ones, even where consent is not required for them.
Separately consider the GDPR position: where a cookie involves processing of personal data, identify and record an appropriate Article 6 lawful basis distinct from the ePrivacy consent analysis.
Verify classifications and consent requirements against the current implementing law and regulator guidance in each relevant jurisdiction, since the position can vary and evolve.