Quick answer: EU cookie consent law in 2026 still runs on the ePrivacy Directive plus GDPR — not a new regulation. Your banner needs a real “Reject” option, no pre-ticked boxes, and clear info before any non-essential cookie loads. A proposed update (Articles 88a and 88b) is still in negotiation and isn’t binding yet.
If you run a website that reaches EU visitors, you’ve probably heard “the cookie law is changing” more than once this year. It’s a fair thing to wonder about. Rumors like that cost small business owners real money, because agencies use them to sell rushed rebuilds nobody needs yet.
Here’s the honest version, based on what’s actually in force right now and what’s still just a proposal.
What Law Actually Governs Cookies in the EU Right Now?
Two laws work together here, and people mix them up constantly.
The ePrivacy Directive (2002/58/EC, updated in 2009) is the one that specifically covers cookies. It says any cookie that isn’t strictly necessary for a service you asked for needs your prior consent before it’s set.
The GDPR doesn’t mention cookies by name. However, it defines what valid consent actually looks like — freely given, specific, informed, and unambiguous. So the Directive tells you when you need consent, and GDPR tells you what counts as real consent.
Both apply at the same time. A banner that satisfies one but not the other still isn’t compliant.
Is There a New EU Cookie Law Coming in 2026?
Sort of — but nothing has passed yet. The European Commission formally withdrew the long-stalled ePrivacy Regulation in February 2025, after eight years of Council deadlock. That draft was meant to modernize cookie rules and finally replace the old Directive.
In its place, the Commission published the Digital Omnibus proposal in November 2025. Instead of a separate ePrivacy law, it folds cookie consent directly into the GDPR through two new articles:
- Article 88a would stop websites from re-prompting users who already refused consent, which is a common annoyance right now.
- Article 88b would make browser-level consent signals — like Global Privacy Control — legally binding, so a compliant site would have to respect that signal instead of showing a banner at all.
As of mid-2026, this proposal is still in Trilogue negotiations between the Parliament, Council, and Commission. It is not law. Nothing changes for your website today because of it. That said, it’s worth tracking, because once it passes, sites will get a limited window (reportedly around six to twenty-four months, depending on the article) to comply.
What Does a Compliant Cookie Banner Actually Need in 2026?
This is the part that matters for your business today, regardless of what happens with the Digital Omnibus. A compliant banner needs to:
- Block non-essential cookies until consent is given. Analytics and advertising cookies cannot fire before the user clicks accept.
- Offer an equally visible “Reject” button. It cannot be hidden behind a “Settings” or “Manage Preferences” link while “Accept” sits front and center.
- Avoid pre-ticked boxes. Every checkbox for a non-essential category must start unchecked.
- Explain cookie purposes in plain language. Not just “we use cookies,” but what kind, and why.
- Let users withdraw consent as easily as they gave it. A permanent, reachable settings link, not a one-time popup.
The European Data Protection Board’s Cookie Banner Taskforce report sets out these exact expectations after reviewing thousands of user complaints across the EU. That report is one of the closest things website owners have to an official checklist, and it’s worth reading directly if you want the source material rather than a summary.
Why Do So Many Cookie Banners Still Get This Wrong?
Because “dark patterns” are still everywhere, and most site owners don’t realize their plugin is generating one by default.
A recent study cited in industry compliance guides found that only about 30.66% of websites had a visible “reject all” button in 2026. That means roughly seven in ten sites are technically out of compliance the moment a regulator looks closely.
The most common mistakes I see on client sites before I touch them:
- Reject buried two clicks deep. Accept is one click; Reject requires opening a settings panel first. That’s a classic dark pattern under EDPB guidance.
- Analytics scripts loading before consent. Google Analytics or Meta Pixel fires the instant the page loads, regardless of what the banner says.
- A cookie policy that hasn’t been updated in years. New ad platforms get added, but the policy still lists tools you stopped using in 2022.
None of these are exotic problems. They’re mostly configuration mistakes in whatever consent plugin got installed once and never revisited.
How Long Does Cookie Consent Last?
Most EU data protection authorities, especially France’s CNIL, treat consent as stale after 12 months. After that, you’re expected to ask again. You also need fresh consent any time you add a new tracking purpose — consent given for analytics doesn’t automatically cover advertising you bolt on later.
If a visitor clears their cookies, your record of their consent disappears too. Legally, that means you have no proof they ever agreed, so the banner needs to reappear.
What Happens If You Get This Wrong?
The penalties aren’t hypothetical. GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher. And enforcement has been active, not theoretical: France’s CNIL fined Google €325 million and Shein €150 million in September 2025 over cookie consent violations, according to a detailed 2026 practitioner guide from Consenteo.
Most small businesses won’t attract a fine that size. However, national authorities also issue smaller corrective orders that require changes within weeks, and those compound daily if ignored. It’s rarely worth the risk for the cost of fixing a banner properly the first time.
How Do I Fix My Cookie Banner Without Overhauling My Whole Site?
You usually don’t need a full rebuild. Most of the time, this is a targeted fix:
- Audit what actually loads before consent using your browser’s network tab.
- Reconfigure your consent management plugin so non-essential scripts are genuinely blocked, not just hidden.
- Rebuild the banner layout so Reject and Accept carry equal visual weight.
- Update your cookie policy to match what’s actually running on the site today.
- Set a reminder to refresh consent records every 12 months.
If you’re also updating your privacy policy at the same time — which you should, since the two documents need to match — I’ve written about building a privacy policy page that satisfies Google AdSense reviewers, and the same principles apply to GDPR compliance. You can also generate a starting draft with the free Privacy Policy Generator before customizing it for your specific cookies and vendors.
Frequently Asked Questions
Does the ePrivacy Regulation replace the EU Cookie Directive in 2026? No. The proposed ePrivacy Regulation was withdrawn in February 2025. Cookies are still governed by the original ePrivacy Directive (2002/58/EC) alongside GDPR, and that remains true throughout 2026.
Do I need a cookie banner if my business is based outside the EU? Yes, if you target EU residents or process their personal data. GDPR’s Article 3(2) applies based on who you’re serving, not where your company is registered.
Is “by continuing to browse, you agree to cookies” legal? No. Continued browsing is not valid consent under GDPR or CJEU case law, including the Planet49 ruling. Users must take a clear, affirmative action like clicking “Accept.”
How often do I need to re-collect cookie consent? Most EU regulators, following CNIL guidance, treat consent as expired after 12 months. You should also re-collect consent any time you add a new tracking tool or purpose.
Will browser-level consent signals like Global Privacy Control become mandatory? Not yet. That’s proposed under Article 88b of the Digital Omnibus package, but it’s still in EU Trilogue negotiations as of mid-2026 and isn’t legally binding.
What’s the maximum GDPR fine for cookie consent violations? Up to €20 million or 4% of global annual turnover, whichever is higher. Regulators have issued fines at that scale, including a €325 million penalty against Google in September 2025.
Cookie compliance isn’t glamorous work, but it’s the kind of thing that quietly protects your business while you focus on everything else. If your banner hasn’t been touched since it was installed, that’s usually a sign it’s worth a second look — especially before the Digital Omnibus changes eventually land.
I help small businesses and startups across the EU, US, and UK fix exactly this kind of thing on WordPress and Wix sites, alongside the rest of their build. If you want a second pair of eyes on your setup, message me on WhatsApp and I’ll take a look.


