Cookie consent is the permission a website visitor must give before cookies or similar techniques are placed on or read from their device. Only cookies that are strictly necessary for the communication or for a service the user has explicitly requested may be placed without consent.
Legal basis
The core rule is Article 11.7a of the Dutch Telecommunications Act, which implements the ePrivacy Directive. It requires prior information and consent for storing or accessing data on terminal equipment. What counts as valid consent is determined by the GDPR: Articles 4(11) and 7 require a freely given, specific, informed and unambiguous indication of wishes by a clear affirmative action, which must be as easy to withdraw as it was to give. A narrow exemption exists for analytics with limited privacy impact, but it falls away as soon as the data are shared with third parties or used for advertising.
How it works in practice
A compliant banner offers refusal as visibly and in as few clicks as acceptance. It contains no pre-ticked boxes, scrolling does not amount to consent, and the site places no tracking until the visitor has chosen. Consent must also be demonstrable: most consent platforms therefore log, per visitor, which categories were accepted and when. Do not forget withdrawal, usually a permanent link or button in the footer.
Where it goes wrong
The Dutch regulator focuses on nudging within the banner: a green accept button against a grey text link, a refusal option hidden behind a second screen, or a cookie wall that makes the site unusable if you decline. Things also go wrong technically, with advertising network scripts loading with the page long before the visitor has clicked anything. That is easy to establish with a network inspection and is a favourite starting point for enforcement.
Related terms
Cookie consent connects to the data protection impact assessment where tracking is combined with profiling, and to the personal data breach where a script leaks data to a third party.
Would you like your banner and cookie statement reviewed? Our IT law specialists check them technically and legally.

