GDPR

Knowledge Base | GDPR | Which cookies are strictly necessary under GDPR?

Which cookies are strictly necessary under GDPR?

Strictly necessary cookies are essential to provide a service explicitly requested by the user. Their exemption from prior consent requirements comes from applicable ePrivacy rules, while GDPR requirements still apply when personal data is processed. Examples that can qualify include:

  • Authentication cookies: Maintain a signed-in session so users can access their accounts.

  • Shopping cart cookies: Remember selected items as customers move between pages and complete checkout.

  • User-input cookies: Preserve information during a form submission or another process initiated by the user.

  • Security cookies: Protect the requested service, for example by detecting repeated failed login attempts.

  • Consent preference cookies: Remember whether a visitor accepted or rejected optional cookies.

The exemption depends on the cookie’s actual purpose and necessity. An authentication cookie used for additional advertising or tracking purposes may require a separate consent assessment. Websites should document strictly necessary cookies and explain their purposes in their cookie policy.