GDPR Cookie Consent Cheatsheet | iubenda (original) (raw)

Questions ๐Ÿ‡ฌ๐Ÿ‡ง UK ๐Ÿ‡ฎ๐Ÿ‡น Italy ๐Ÿ‡ฉ๐Ÿ‡ช Germany ๐Ÿ‡ซ๐Ÿ‡ท France ๐Ÿ‡ช๐Ÿ‡ธ Spain ๐Ÿ‡ฉ๐Ÿ‡ฐ Denmark ๐Ÿ‡ฌ๐Ÿ‡ท Greece ๐Ÿ‡ง๐Ÿ‡ช Belgium ๐Ÿ‡ฎ๐Ÿ‡ช Ireland ๐Ÿ‡ธ๐Ÿ‡ช Sweden ๐Ÿ‡จ๐Ÿ‡ฟ Czech Republic ๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands ๐Ÿ‡ฑ๐Ÿ‡บ Luxemburg ๐Ÿ‡ฆ๐Ÿ‡น Austria ๐Ÿ‡จ๐Ÿ‡ญ Switzerland ๐Ÿ‡ช๐Ÿ‡บ EDPB
Analytics cookies: do they always require consent? YES If third-party: YES If first-party: NO NO NO YES / NO Not specified YES YES YES YES YES NO NO Not specified YES Not specified
Is consent by scrolling valid? NO NO NO NO NO NO NO NO NO NO NO NO NO NO YES NO
Is consent by continuing navigation valid? NO Likely no, but not specified NO NO NO NO NO NO NO NO NO NO NO NO YES NO
Are explicit โ€œacceptโ€ AND โ€œrejectโ€ buttons required to be on the cookie notice? YES YES YES YES YES YES YES YES YES Not specified YES YES NO YES Not specified
Must accept and reject options be equally conspicuous (equal prominence requirement)? YES YES YES YES YES YES YES YES YES Not specified YES See above Not specified YES YES Not specified YES
Is the prior blocking of cookies necessary where consent is required? YES YES YES YES YES YES YES YES YES YES YES YES YES YES NO YES
Are full cookie walls admitted? Unlikely NO NO Possibly NO Possibly NO NO Likely no NO NO NO NO YES Not specified NO
Must cookies be listed one by one? NO Not specified NO NO NO NO Not clear Not clear Likely no YES YES YES Likely no Likely no Not specified
Must purposes be listed in the first layer of the cookie notice? Not mentioned, but unlikely. Best practice YES YES YES YES YES YES Not specified Not specified YES YES YES Not specified Not specified
Must consent be granular on a per-purpose basis? Per-service but not necessarily per-purpose YES YES YES YES YES YES YES YES YES It should be Not specified (but implied) Not specified (but implied) YES Not specified YES
Is a GDPR-aligned proof of consent required? YES YES YES YES Not specified (but implied) YES YES YES YES YES YES YES YES NO Likely yes
Should withdrawing consent be as simple as giving it? YES YES YES YES YES YES YES YES YES YES YES YES YES YES The FAQs issued by the DSB in December 2023 indicate that โ€œPossibility of revocation: The cookie banner must clearly and precisely describe where and how consent can be revoked. Revocation must be as simple as giving consentโ€. Not specified YES
Is the use of a consent banner recommended? YES YES YES Not specifically YES Not specifically YES YES Not specifically Not specifically YES if non-technical cookies are used YES Best practice Best practice NO
Are strictly necessary cookies exempt from the consent requirement? YES YES YES YES YES YES YES YES YES YES It is only technical cookies that can be placed without the usersโ€™ consent YES YES YES Only those technically strictly necessary for providing the service requested by the user, like session management, entries in an online form via several subpages of a website, information about the consent status (unless a unique online identifier is assigned for this). YES YES
Can GDPR legal bases other than consent (e.g. legitimate interest) apply? NO NO YES NO NO YES NO NO NO NO Technically YES NO NO NO YES
Do third parties have to be listed and identified? YES YES YES YES YES YES YES Not specified Not completely clear YES Not specified YES YES Not specified YES
Is it specified how long the consent to a cookie should last? NO YES YES YES Specified good practice NO YES YES YES YES YES NO YES Not specified Not specified No duration explicitly stated
Are pre-ticked boxes allowed? NO NO NO NO NO NO NO NO NO NO NO NO NO NO YES NO