What GDPR actually requires
The GDPR is the EU's data protection law. It governs how organisations collect, use, store and share personal data of people in the EU and UK. For cookies specifically, it requires informed, freely given, specific and unambiguous consent before any non-essential cookie is set.
Key requirements
- Obtain explicit opt-in consent before setting non-essential cookies
- Provide clear information about what each cookie does and who receives the data
- Make it as easy to withdraw consent as it was to give it
- Keep a record of every consent so you can prove it was obtained lawfully
- Allow users to change their consent preferences at any time
- Avoid 'dark patterns' that nudge users toward accepting all cookies
At a glance
Full name
General Data Protection Regulation
Region
European Union & United Kingdom
Status
In force since May 2018
Who it affects
Any website or service that processes personal data of people in the EU or UK — regardless of where the organisation is based.
Penalties
Up to €20 million or 4% of global annual turnover, whichever is higher. Several regulators have issued seven-figure fines for cookie-consent failures specifically.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
