Cookie Consent Under Two Laws

Cookie Consent Under Two Laws

A cookie banner is a legal instrument wearing a marketing costume. It looks like a design decision, so design teams build it, and then a regulator reads it as a record of whether cookie consent was ever validly obtained. Two separate laws meet on that banner, and knowing which one does what is the whole of this topic.

Cookie consent starts with the ePrivacy Directive, not the GDPR

Domain V of the CIPP/E Body of Knowledge covers compliance with European data protection law in internet technology and communications. The Body of Knowledge is the blueprint the IAPP publishes for what the exam may test, and cookies sit inside it as a named subject.

The permission to touch a device comes from Article 5(3) of the ePrivacy Directive. Storing information on a user's terminal equipment, or gaining access to information already stored there, requires consent unless a narrow exemption applies. The provision does not say "cookie" and it does not say "personal data". It says information, and it says terminal equipment.

That wording carries consequences. The EDPB guidelines on the technical scope of Article 5(3), adopted in October 2024, apply the rule to pixel tracking, unique identifiers, URL tracking and information gathered from connected devices. A tracker that stores nothing but reads something already on the device is caught. So is one that never touches personal data at all.

The exemptions are narrower than the marketing team hopes

Article 5(3) exempts storage or access carried out solely to transmit a communication, and storage or access strictly necessary to provide a service the user has explicitly requested. A session cookie holding a shopping basket qualifies. Analytics does not become strictly necessary because the growth team relies on it, and a preference cookie does not become strictly necessary because it is convenient.

Where the GDPR supplies the standard for cookie consent

The Directive requires consent. It does not define it. The definition arrives from Articles 4(11) and 7 of the GDPR: freely given, specific, informed and unambiguous, expressed through a clear affirmative action. In Planet49 (Case C-673/17) the Court of Justice held that a pre-ticked box does not meet that standard, and that the consent requirement applies whether or not the information stored is personal data.

Withdrawal must be as easy as giving. Consent bundled into acceptance of a service is unlikely to be freely given where the service does not need it. Both points come from the GDPR, applied to a Directive obligation.

The interplay question the exam actually asks

Two questions live on that banner and candidates answer only one. First, what permits the storage or access on the device? That is Article 5(3), and consent is the route unless an exemption applies. Second, what lawful basis covers the processing that follows once the data is collected? That is Article 6 of the GDPR.

The trap sits in the gap. A stem describes an analytics tracker, notes that the company documented a legitimate interests assessment, and asks whether the tracker may be deployed. The assessment is irrelevant to the first question. No amount of legitimate interest reasoning gives you access to somebody's device when the Directive demands consent for it. Read the wider discussion of when consent is genuinely the right basis and note how sharply that reasoning changes once terminal equipment is involved.

Why cookie consent still varies across the Union

The ePrivacy rules sit in a Directive, so each member state transposed them into national law. The consent standard is harmonised through the GDPR; the surrounding enforcement, the competent authority and the detail of national implementation are not. A CIPP/E question that names a member state is telling you something.

The proposed ePrivacy Regulation would have replaced that patchwork. It was withdrawn, which means the Directive from 2002, as amended in 2009, remains the operative text. Candidates who half-remember a Regulation and answer accordingly lose the mark twice: once on the instrument, once on its effect.

Reading a cookie question under exam conditions

Take the stem in the order the law takes it. Identify what is being stored or read on the device. Ask whether transmission or strict necessity for a requested service explains it, and be honest that it usually does not. Then ask whether the consent obtained meets the GDPR standard: affirmative, specific, informed, revocable.

Only after that does the processing question open, and by then you have already found the answer the stem was built around. The examiner is not testing whether you dislike banners. The examiner is testing whether you know that cookie consent is granted under one instrument and defined by another.

Keep the two instruments separate in your notes and the questions stop being tricky. If you want to work through the wider set of internet-technology compliance duties in Domain V, the CIPP/E study materials at 22academy.com/study take the same approach, one legal question at a time.

Share this Post


Ready to kick-start your career?

GET STARTED NOW



About The Blog


Stay up to date with the latest news, background articles, and tips for your study.


Our latest video





22Academy

Tailored Training Solutions

Let's find the best education solution for your situation. We will contact you for Free Support!

Success! Your message has been sent to us.
Error! There was an error sending your message.
It’s for:
We will only use your email address to contact you regarding your education needs. We do not sell your personal data to third parties.