Do You Need a Cookie Banner for Analytics? By Country
In the EU and UK, analytics cookies usually need consent, with narrow exemptions in France, Italy, the Netherlands and the UK. In the US, mostly no. The details.
It depends on where your visitors are and how your analytics works. In the EU and the UK, analytics that stores or reads an identifier on the visitor's device needs prior consent by default, but France, Italy, the Netherlands and (since February 2026) the UK carve out exemptions for tightly limited first-party measurement. In the US there is no general cookie consent requirement; you owe a privacy notice and, in some states, an opt-out from “selling” or “sharing” data. Analytics that stores nothing on the device sits largely outside the consent rule, though not outside privacy law.
Below is the rule, the exemptions regulators actually publish, and a country-by-country table, with the source for each. For how cookie-free measurement works under the hood, see how cookie-free analytics works.
Key takeaways
- The EU consent rule for cookies is Article 5(3) of the ePrivacy Directive; it covers any storage or access on the device, not just cookies, and applies whether or not the data is personal.
- France's CNIL exempts audience measurement from consent only if seven conditions are met, including a single-site scope, a 13-month tracker lifetime and an opt-out.
- The UK's Data (Use and Access) Act 2025 added a statistical-purposes exception to PECR from 5 February 2026, provided users get clear information and a free way to object.
- Germany (TDDDG § 25) has no analytics exemption: if a tool touches the device, you need consent.
- The US has no federal cookie consent law; state privacy laws require notice and opt-outs for sale, sharing and targeted advertising, not opt-in for analytics.
What does the EU cookie law actually require?
The rule lives in Article 5(3) of the ePrivacy Directive (2002/58/EC, as amended in 2009). Storing information on a user's device, or gaining access to information already stored there, is allowed only with the user's consent, unless it is strictly necessary to transmit a communication or to provide a service the user explicitly requested. Consent has the GDPR meaning: freely given, specific, informed and unambiguous. In Planet49 (C-673/17, 1 October 2019) the Court of Justice confirmed that pre-ticked boxes are not consent, and that the rule applies whether or not the stored information is personal data.
Three consequences matter for analytics:
- It is technology-neutral. localStorage, sessionStorage, IndexedDB and fingerprinting are treated like cookies.
- First-party does not mean exempt. A first-party _ga cookie still needs consent; what matters is purpose, not who sets it.
- “Strictly necessary” is narrow. Shopping carts, login sessions, load balancing and the consent cookie itself qualify. Measuring your audience generally does not, unless a national exemption says so.
The EDPB reads Article 5(3) broadly
In Guidelines 2/2023 on the technical scope of Article 5(3), adopted in final form on 7 October 2024, the European Data Protection Board argues that the rule also covers tracking pixels, tracking links and some IP-based tracking when a script instructs the browser to send information. The guidelines are not binding law, and national regulators apply them unevenly, but they mean “we don't use cookies” is not automatically the end of the analysis.
Which EU countries exempt analytics from consent?
The ePrivacy Directive is implemented nationally, and a handful of regulators have said that low-risk audience measurement can count as necessary for the service. The conditions are strict and they differ.
France (CNIL)
CNIL's 2020 cookie guidelines and its analytics guidance (Sheet n°16) exempt audience measurement trackers from consent if all of these hold: users are informed; they can object; the purpose is limited to audience measurement (and A/B testing); the data is not cross-checked with other processing such as customer files; the scope is limited to a single site or app publisher; the last byte of the IP address is truncated; and trackers live no longer than 13 months, with collected data kept no longer than 25 months. CNIL also warns that most large audience measurement offerings do not qualify whatever their configuration, because the vendor reuses the data.
Italy (Garante)
The Garante's cookie guidelines of 10 June 2021 treat analytics cookies like technical cookies, which need no consent, when they are used only to produce aggregate statistics for a single site. For third-party analytics, the identifier must be minimized (at least the fourth octet of the IP masked) and the provider must not combine the data with other information.
Netherlands
Dutch telecom law (Article 11.7a of the Telecommunicatiewet) exempts analytics cookies that have little or no impact on privacy. The Dutch DPA's 2018 guidance for using Google Analytics under that exemption required a processor agreement, IP masking, no data sharing with Google and no other Google services linked to the data. In practice that bar is hard to meet with large third-party tools.
Germany
Germany has no analytics exemption. Section 25 of the TDDDG (the Telecommunications Digital Services Data Protection Act, renamed from TTDSG in May 2024) requires consent for any storage or access on the device that is not strictly necessary, and German regulators consistently put analytics outside “strictly necessary.” German courts have also held that the rule binds everyone who causes the access, not only the site operator.
What changed in the UK in 2026?
The UK's rule is regulation 6 of PECR, which mirrored the EU directive. The Data (Use and Access) Act 2025 (Royal Assent 19 June 2025) amended it, and the cookie changes took effect on 5 February 2026 under the Act's sixth commencement regulations. The most relevant new exception covers storage or access whose sole purpose is to collect information for statistical purposes about how a service is used, with a view to improving it.
The ICO's guidance on storage and access technologies sets the conditions: you give clear and comprehensive information, you offer a simple and free means to object, and if you use a third-party provider it must act as your processor, not a joint controller, using the information only to help you. Analytics that feeds advertising or the vendor's own products falls outside the exception. The Act also raised maximum PECR fines to UK GDPR levels: up to £17.5 million or 4% of global turnover.
Do US websites need a cookie banner for analytics?
Generally no. There is no federal cookie law, and none of the state comprehensive privacy laws (California's CCPA as amended by CPRA, and the laws of Virginia, Colorado, Connecticut, Texas and the other states that have followed) requires opt-in consent for first-party analytics. What they do require:
- A privacy notice at or before collection that describes what you collect and why.
- An opt-out of “selling” or “sharing” personal information, and of targeted advertising. Under the CCPA, “sharing” means for cross-context behavioral advertising. Analytics run by a service provider bound by contract usually is neither.
- Honoring opt-out preference signals such as Global Privacy Control where the state requires it (California, Colorado and others).
- Opt-in consent for sensitive data in several states, which ordinary page analytics should never collect.
The bigger US risk has been litigation, not regulation. Plaintiffs filed thousands of demands under the California Invasion of Privacy Act (CIPA), claiming that pixels and analytics scripts were illegal “pen registers” or wiretaps. On the pen-register front this is changing: Governor Newsom signed SB 690 in September 2026, and from 1 January 2027 private suits under Penal Code § 638.51 over website tracking are barred, leaving those claims to the attorney general. Wiretap claims under § 631, often aimed at session replay and chat widgets, are unaffected.
What is the rule country by country?
| Jurisdiction | Law | Consent needed for analytics cookies? | Analytics exemption |
|---|---|---|---|
| EU baseline | ePrivacy Directive Art. 5(3) | Yes, by default | Only where national law or the regulator provides one |
| France | Loi Informatique et Libertés Art. 82; CNIL guidelines | Yes, unless exempt | Yes: 7 CNIL conditions, 13-month trackers |
| Italy | Codice Privacy Art. 122; Garante guidelines (2021) | Yes, unless exempt | Yes: aggregate, single-site, minimized identifiers |
| Netherlands | Telecommunicatiewet Art. 11.7a | Yes, unless low impact | Yes: little or no privacy impact |
| Germany | TDDDG § 25 | Yes | No |
| Spain | LSSI Art. 22.2; AEPD cookie guide | Yes in practice | AEPD guidance is cautious; treat as consent |
| UK | PECR reg. 6 as amended by DUAA 2025 | Not if the statistical exception applies | Yes, from 5 Feb 2026: info + free objection, processor only |
| Switzerland | Telecommunications Act Art. 45c; revised FADP (2023) | Generally no opt-in | Information and opt-out model |
| US (federal) | None | No | Not applicable |
| California | CCPA/CPRA; CIPA | No opt-in; notice and opt-out of sale/sharing | Not applicable |
| Quebec | Law 25, s. 8.1 | Tracking that identifies or profiles must be off by default | Narrow |
Two caveats on the table. First, an exemption covers the consent requirement only. GDPR still applies to any personal data you process, so you still need a lawful basis (usually legitimate interest), a privacy policy and a processor agreement. Second, the exemptions are conditional: one non-qualifying feature, such as linking analytics to an ad platform, puts you back in consent territory.
Does cookieless analytics need a banner?
A tool that stores nothing on the device and reads nothing from it does not trigger the storage-or-access rule in the way cookies do, which is why cookieless analytics is commonly run without a banner. Our cookieless tracking explainer shows the mechanics: a daily-rotating, server-side hash instead of a stored ID.
The honest caveats: the EDPB's broad reading of Article 5(3) means some regulators may look at what the script asks the browser to send, not only at storage; GDPR still applies to the IP address while it is processed; and you still need a privacy policy entry. VisitTrack's cookieless mode, for example, stores nothing in the browser, and its docs still tell you to mention it in your privacy policy. A cookieless tracking setup reduces your obligations. It does not remove them.
How do you decide whether your site needs a banner?
- 1.List every script on your site that sets cookies or uses browser storage. Open DevTools → Application → Cookies and Local Storage on a fresh profile, or run the page through our cookie banner checker.
- 2.Classify each by purpose: strictly necessary (login, cart, security), analytics, advertising, embedded content.
- 3.For analytics, check where your visitors are. If EU or UK traffic is meaningful, the default is consent.
- 4.Check whether an exemption fits your setup: CNIL's seven conditions for France, the Garante's for Italy, the Dutch low-impact rule, the UK statistical exception. If you use one, document why in your records of processing.
- 5.If nothing fits, either load analytics only after consent or switch the EU portion of your traffic to a mode that stores nothing on the device.
- 6.Remove anything that turns analytics into advertising: ad-platform links, cross-site identifiers, data sharing with the vendor.
- 7.Update your privacy policy and include an opt-out link for analytics, which most exemptions require anyway.
If you are on Google Analytics, step 4 rarely succeeds, for the reasons covered in Is Google Analytics legal in the EU?. If you need cross-day journeys for non-EU visitors but no banner for EU visitors, a hybrid setup (cookieless in the EU, a first-party ID elsewhere) is one way to get both; it is what VisitTrack's hybrid mode does.
What does a compliant banner look like when you need one?
- Reject is as easy as accept. CNIL fined Google €150 million and Facebook €60 million in December 2021 because refusing took more clicks than accepting.
- Nothing non-essential loads before a choice. Analytics tags wait for the consent signal.
- Choices are granular (analytics separately from advertising) and as easy to withdraw as to give.
- Consent is logged with a timestamp and the banner version, so you can prove it later.
Not legal advice
This is a summary of laws and regulator guidance as of October 2026, for general information only. Rules change and national regulators interpret them differently. Check with a qualified privacy lawyer before relying on an exemption.
Do I need a cookie banner for Google Analytics?
Yes, for EU and UK visitors in almost all cases. GA4 sets identifying cookies and Google uses the data for its own purposes too, which rules out the CNIL, Italian, Dutch and UK analytics exemptions for typical setups.
Are first-party analytics cookies exempt from consent?
Not automatically. The EU rule applies to first-party and third-party cookies alike. Only specific national exemptions, such as CNIL's audience measurement exemption, waive consent, and only when every condition is met.
Do UK websites still need consent for analytics cookies in 2026?
Not always. Since 5 February 2026, PECR allows storage or access purely for statistics that improve your service, without consent, if you give clear information and a free way to object, and any provider acts only as your processor.
Do US websites need cookie consent?
No federal or state law requires opt-in consent for ordinary analytics cookies in the US. You need a privacy notice, and in states like California an opt-out for selling or sharing data and support for Global Privacy Control.
Is cookieless analytics exempt from GDPR?
No. Cookieless analytics avoids most of the ePrivacy consent rule because nothing is stored on the device, but GDPR still governs any personal data processed, such as IP addresses during hashing. You still need a lawful basis and a privacy policy.
What are CNIL's conditions for exempt analytics?
Inform users, let them object, limit the purpose to audience measurement, don't cross-check data with other processing, limit scope to one publisher, truncate the last IP byte, and cap tracker lifetime at 13 months with data retained at most 25 months.
Does localStorage need consent like cookies?
Yes. The ePrivacy rule covers any information stored on or read from the device, so localStorage, sessionStorage and similar techniques are treated the same as cookies.