GDPR
GDPR & ePrivacy Directive
Europe and the UK's core privacy framework - including cookie rules under the ePrivacy Directive alongside GDPR.
Quick navigation
GDPR
What it means
GDPR explains how businesses must collect, use, store, share, and delete personal data. The ePrivacy Directive (and national laws such as the UK PECR) add specific rules for cookies, pixels, and similar tracking technologies.
For website owners, this usually means clear cookie information, a real choice before non-essential cookies run, proof of consent, and an easy way for visitors to change their mind - across EU, EEA, and UK traffic.
European Union & United Kingdom
Who must comply
- You are established in the EU or EEA.
- You sell goods or services to people in the EU or EEA, even if your company is elsewhere.
- You monitor behavior of EU or EEA visitors through analytics, ads, pixels, heatmaps, or similar tools.
GDPR
What you need to do
- Ask for opt-in consent before analytics, advertising, or tracking cookies are placed.
- Explain cookie categories in plain language, including who receives the data and why it is used.
- Keep consent records that show what the visitor agreed to and when.
- Let visitors withdraw or update consent as easily as they gave it.
- Have a lawful basis, retention rules, and vendor controls for personal data.
Plain language
What it is not
GDPR
FAQ
Do I need GDPR compliance if I am outside Europe?
Yes, if you target people in the EU or EEA or track their behavior. Location of the visitor matters, not only the location of your company.
Can analytics cookies run before consent?
In most GDPR scenarios, no. Analytics, advertising, and personalization cookies should wait until the visitor actively accepts them.
What counts as proof of consent?
A defensible record should show the visitor's choice, timestamp, policy version, categories accepted, and enough technical context to prove what happened.