Website Tracking Compliance in the European Union
What applies in this market
European Union: GDPR and the ePrivacy cookie rules.

Summary
Website tracking is legal in the EU, but only with consent before your tags fire. The ePrivacy Directive decides whether you may place a cookie or fire a tag at all, and requires consent first. The GDPR governs the personal data that follows and sets the standard for valid consent. Non-essential tags wait for a real choice.
The EU is the strictest of the major markets on tracking, and it is where the consent-before-firing rule is most developed. Most of what a site needs to get right in the EU is about timing and choice: nothing non-essential runs before the visitor agrees.
The sections below cover the rules that govern EU website tracking, what compliance requires in practice, and what is changing. The last section shows how to verify your EU compliance.
The rules that govern EU website tracking
The GDPR, for your tags. A tag may not process personal data, which can include cookie IDs and IP addresses, without a lawful basis, and for analytics and advertising that basis is consent collected first. GDPR for analytics tags.
The ePrivacy cookie law. Article 5(3) requires consent before a site stores or reads anything on a visitor’s device, unless it is strictly necessary. This is the source of the cookie banner. The ePrivacy cookie law.
Data transfers. Whether a tool like Google Analytics can send EU data to the US is a separate transfer question, resolved for now by the Data Privacy Framework. Is Google Analytics GDPR compliant?
Consent Mode. Google’s mechanism for relaying EU consent to its tags. Google requires two newer signals for EEA traffic used for ad personalization and measurement, as its own policy separate from EU law. Google Consent Mode v2.
What EU tracking compliance requires in practice
Three things carry the load. Collect consent before any non-essential tag fires. Make the choice real, with a reject option wherever there is an accept button (the EDPB’s position) and no pre-ticked boxes. And honor the choice, so tags a visitor declined actually stay off. Get those right and most of the EU picture is covered.
What is changing
The EU cookie rules are set to move, though not yet. The ePrivacy Regulation was withdrawn, and the Commission’s Digital Omnibus, proposed in November 2025, would relocate cookie-consent rules into the GDPR. As of September 2026 it is still a proposal and has not been adopted. The current rule remains consent before access. See the ePrivacy cookie law for the detail.
How to verify your EU compliance
The core EU requirement, consent before firing and honoring the choice, is testable. DataTrue loads your site in a real browser, in each consent state, and records what every tag does, so you can confirm nothing non-essential fires before consent and that declined tags stay off. Sensitive Data Detection inspects the payloads with fictitious personas. The result is a timestamped record you can show a data protection authority. For specific EU enforcement actions, see our Enforcement Watch tracker.

See how consent verification works
Questions
Is website tracking legal in the EU?
Yes, with consent before your tags fire. The ePrivacy Directive requires consent before a site stores or reads anything on a visitor’s device, and the GDPR governs the personal data that follows. Non-essential analytics and advertising tags must wait for a freely given choice.
Is Google Analytics legal in the EU?
It can be, with consent collected before the tags load and a valid basis for transferring data to the US, currently the Data Privacy Framework. It is not legal by default. See the full answer on our Google Analytics GDPR page.
Do I need a cookie banner in the EU?
In practice yes, for any site using non-essential cookies or tags, because the ePrivacy rules require consent before those are set. Strictly necessary cookies, such as a login or cart, do not need consent.
What is the strictest part of EU tracking law?
The timing. Non-essential tags must not fire before the visitor consents, and a tag that fires on page load ahead of any choice breaks that rule. That is the part worth testing first.
See what your tags do in every consent state
DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
