Skip to main content
Privacy Compliance

Do Cookieless Analytics Need Consent in the EU and UK?

By , MarTech & Analytics Engineer

Published Updated

Quick answer: Removing cookies from your analytics setup removes local write operations, but Article 5(3) of the ePrivacy Directive also covers reading device parameters. A script that sends the visitor’s IP address, User-Agent or screen dimensions to your server accesses information on their device and needs consent under the same rule. Exemptions exist in France and Italy under specific conditions, as of October 2026. Germany, Ireland and Spain have none. The UK added a limited statistical-purposes exception in February 2026 — it eases the GDPR side but not the ePrivacy side.

What does Article 5(3) of the ePrivacy Directive cover?

Article 5(3) of Directive 2002/58/EC covers two operations on a user’s device: storing information, and gaining access to information already stored. The word “cookie” doesn’t appear; the text protects the terminal device from any uninvited interaction. The EDPB’s Guidelines 2/2023 on the technical scope of Art. 5(3) (version 2.0, October 2024) explain how this reaches cookieless tools:

  • Para 33. A JavaScript file that the browser executes and that sends information back to a server “clearly falls within the scope of Article 5(3).” This applies whether or not the script writes a cookie. The access happens when the script reads device properties — viewport size, User-Agent string, language — and transmits them.
  • Para 43. HTTP headers sent automatically by the browser — User-Agent, Accept-Language, Referer — “can lead to” Art. 5(3) where the recipient uses them to build a visitor profile beyond basic routing. The Board treats this as fact-specific.
  • Paras 54–56. IP-address-only collection “could” fall under Art. 5(3), but the Board is less certain here than it is about client-side scripts. This is an open question, not a confirmed consent trigger on its own.

The two exceptions in Art. 5(3) are: access strictly necessary to transmit a communication, or access for a service “explicitly requested by the subscriber or user.” Regulators have consistently held that publisher analytics serve the site operator, not the visitor, and do not qualify.

Under the EDPB Opinion 5/2019 (para 40), the ePrivacy Directive is lex specialis over the GDPR for operations on terminal devices. You cannot use GDPR legitimate interest to authorise a client-side script that Art. 5(3) requires consent for. Consent under Art. 5(3) is separate from GDPR consent; where both apply, you need to meet both.

Does a daily rotating hash count as personal data?

Many cookieless analytics tools avoid writing cookies by building an ephemeral session ID on the server from the visitor’s IP address, User-Agent and a daily salt — a method Plausible Analytics describes publicly: SipHash(daily_salt + website_domain + IP + user_agent), with the salt discarded every 24 hours.

Under GDPR Article 4(1), personal data is any data that can identify a natural person directly or indirectly. The CJEU in Breyer v. Bundesrepublik Deutschland (C-582/14, para 49) confirmed that an IP address is personal data where the operator “has the legal means which enable it, in practice, to identify the data subject.” Para 63 says the test is whether identification is “reasonably likely” given practical means — not whether it is possible in theory.

A server-side hash is pseudonymised, not anonymous. Before the hash exists, the raw IP must pass through the server and be processed in memory. That transient processing is a GDPR operation. The resulting hash identifies a single browser session over a 24-hour window; that is a distinct identifier, even though it resets daily. Discarding the raw IP after the hash is built reduces risk but does not retroactively make the processing anonymous.

This analysis applies on top of, not instead of, Art. 5(3). If a client-side script triggers Art. 5(3), the GDPR question about the hash is the second problem, not the first.

Which EU countries have an analytics exemption?

As of October 2026:

CountryRegulatorFirst-party analytics exemption?Notes
FranceCNILPartialSpecific conditions must be met; see below
ItalyGarantePartialNo persistent ID; no 3rd-party sharing; mask at least the last IP octet
SpainAEPDNoMay 2024 guidance: analytics are not strictly necessary
GermanyDSKNoOH Digitale Dienste v1.2, Nov 2024, paras 77, 87–90: no reach-measurement exemption
IrelandDPCNoAnalytics serve the operator, not the user
UKICOPartial (since Feb 2026)See below

If you have visitors from Germany, Ireland or Spain alongside French or Italian ones, you cannot rely on the partial exemptions alone. The right approach is either a consent banner for all visitors with the CNIL/Garante setup serving exempt traffic, or a banner everywhere.

What changed for UK visitors in 2026?

The Data Use and Access Act 2025 (DUAA), section 112, came into force on 5 February 2026 (SI 2026/82). It adds a statistical-purposes exception: a data controller can process personal data for statistical purposes that serve the public interest without needing a separate GDPR consent or legitimate interest assessment, provided they give clear information and offer a free way to object.

The ICO’s guidance (final April 29, 2026) sets out what this means for analytics:

  • It applies to first-party analytics only — data collected directly from visitors to your own site, used to produce aggregate statistics.
  • It does not cover advertising analytics, behavioural profiling or cross-site tracking.
  • PECR regulation 6 still applies. The DUAA exception is a UK GDPR processing basis; it does not change the ePrivacy rule about storing and accessing device data. You still need to meet the PECR requirement for clear information and an easy way to object.
  • In practice, a banner or a clearly visible footer notice that explains the analytics and links to an opt-out satisfies both requirements together.

For tools that send data to Google — GA4, Google Ads — the DUAA exception does not remove the need for Consent Mode for UK visitors where Google requires it.

The CNIL’s partial exemption is not a “cookieless shortcut.” It is a specific configuration that keeps the tool out of the cross-site tracking category. The CNIL uses a self-assessment tool as of July 2025; it does not run a certification programme, so you cannot point to a certificate as proof of compliance.

The conditions:

  • Publisher-only data. Analytics data stays with the site publisher. No passing to third-party ad networks, no cross-site matching, no combining with other customer data.
  • Anonymised aggregates. The dashboard shows aggregate page counts and sessions. It cannot reconstruct individual visit paths.
  • Provider as processor. The analytics vendor processes data on the publisher’s behalf with no independent purpose.
  • No persistent cross-session ID. The tool cannot recognise the same visitor on two separate days.
  • IP truncation before storage. If city-level geolocation is resolved, the last IP octet is removed before the IP is stored. Geolocation goes no finer than city level.
  • Accessible opt-out. An objection mechanism — a footer link, a settings page — must be easy to find and use.
  • Recommended limits. The CNIL recommends trackers not exceed 13 months and data retention not exceed 25 months. These are recommendations, not hard requirements.

Italy’s Garante conditions (June 2021 guidelines) are similar: no persistent identifier across sessions and masking of at least the last IP octet before storage.

If you want to confirm that your analytics tool actually meets these conditions — rather than just claiming to — the DevTools audit post walks through what to check.

For advertising analytics, and for any analytics in Germany, Ireland or Spain, you need a consent banner and — where Google tags are involved — the Consent Mode setup.

Configuring this across EU and UK jurisdictions, including Consent Mode and GTM consent gating, is part of my consent mode work.

Frequently asked questions

Does Plausible Analytics need a consent banner in Germany?

Yes. Germany's OH Digitale Dienste v1.2 (Nov 2024) makes no blanket exemption for analytics. TDDDG §25 requires consent for any client-side script that reads device parameters, and the DSK has not recognised aggregate analytics as strictly necessary.

Does the CNIL exemption apply to any cookieless tool?

No. The CNIL's partial exemption requires specific conditions: anonymised aggregates, no third-party sharing, geolocation no finer than city level, last IP octet removed before storage, an accessible opt-out, and the provider acting as processor. The CNIL uses a self-assessment tool; it does not run a certification programme.

Can I use legitimate interest instead of consent for analytics?

Not if Art. 5(3) of the ePrivacy Directive applies first. The ePrivacy Directive is lex specialis over the GDPR, so you cannot use GDPR legitimate interest to bypass an unfulfilled ePrivacy consent requirement. If the client-side script read is invalid, any downstream processing is too.

Does the UK analytics exception replace the consent banner?

No. DUAA 2025 s.112 creates a statistical-purposes processing exception under UK GDPR, but PECR reg. 6 still applies to storing and accessing device data. You still need clear information and a free way to object — which in practice means a banner or a clearly visible notice.

Sources

  1. EDPB Guidelines 2/2023 on the technical scope of Art. 5(3) ePrivacy Directive, version 2.0
  2. CNIL, Cookies et autres traceurs
  3. Garante, Linee guida cookie e altri strumenti di tracciamento (10 giugno 2021)
  4. DSK, Orientierungshilfe Digitale Dienste v1.2 (November 2024)
  5. AEPD, Guía sobre el uso de cookies (mayo 2024)
  6. ICO, Guidance on the use of storage and access technologies
  7. CJEU, Breyer v. Bundesrepublik Deutschland (C-582/14)
  8. EDPB Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR