Blog
Business18 May 2026 7 min🇩🇰 Denmark

Cookie policy: what does GDPR require of your website?

Cookie policy and GDPR: understand the requirements for cookies, consent and the cookie banner on your website. Guide to cookie types, Datatilsynet's guidance and correct implementation.

Karoline, Dokumentkonsulent

Written for Danish law and Danish contract practice.

Almost all websites use cookies. Yet the cookie rules are one of the areas where most businesses still make mistakes, either by lacking a cookie policy, using the wrong type of cookie banner or collecting consent in an invalid way.

This guide explains what you specifically need to have in place: which cookie types require consent, what a cookie policy must contain, and what the Danish Data Protection Agency (Datatilsynet) specifically expects of Danish websites.

What is a cookie?

A cookie is a small text file that a website stores in the user's browser. Cookies are used for many purposes: remembering login status, saving a shopping basket, measuring traffic and showing targeted ads.

The requirement of consent for cookies follows from the cookie order (bekendtgørelse nr. 1148 of 9 December 2011, as amended), which implements the ePrivacy Directive in Danish law. GDPR governs the subsequent processing of the personal data that the cookies collect.

The four cookie types

1. Necessary cookies (technical cookies)

These cookies are necessary for the website to function technically. This can for example be:

  • Session cookies that keep you logged in
  • Cookies that remember the contents of a shopping basket
  • Security cookies (CSRF tokens)
  • Cookies that remember your cookie consent

Consent requirement: None. Necessary cookies may be set without prior consent.

2. Preference cookies (functional cookies)

These cookies remember the user's choices and personalise the experience, for example preferred language, currency or user-interface settings.

Consent requirement: Yes, as a rule they require consent, unless they solely provide a service that the user has expressly requested.

3. Statistics and analytics cookies

These cookies collect data about how users interact with the website, for example Google Analytics, Hotjar, Matomo.

Consent requirement: Yes. Google Analytics and the like require consent, unless the data is fully anonymised (impossible to link to a person) and is not passed on to third parties.

4. Marketing cookies (targeting cookies)

These cookies are used to show targeted ads and track ad campaigns, for example Facebook Pixel, Google Ads, LinkedIn Insight Tag.

Consent requirement: Yes, and here the requirements are strictest. Many platforms require explicit, specific consent for each individual service.

What is a valid cookie consent?

GDPR (article 4(11) and article 7) and the cookie order set out clear requirements for what constitutes valid consent:

The requirements for valid consent

  1. Freely given: you may not cut off access to the website if the user rejects cookies (unless they are strictly necessary)
  2. Specific: the consent must apply to specific purposes and cookies, not a general "accept all" solution without information
  3. Informed: the user must know which cookies are set, who sets them, and for what purposes
  4. Unambiguous: the consent must come from an active act (a click), not from pre-ticked boxes or implied acceptance through continued use

What is not valid consent?

  • "We use cookies. Continued use of the site is considered acceptance": invalid. Implied acceptance is not accepted.
  • Pre-ticked boxes for analytics or marketing cookies: invalid.
  • Only a single "Accept all" button with no option to reject or customise: problematic. Datatilsynet has stated that the reject button must appear just as clearly as the accept button.
  • Cookie wall (access is blocked if cookies are not accepted): as a rule invalid, unless a genuine alternative is offered.

What must a cookie policy contain?

A cookie policy is a document, typically a page of its own or a section in the privacy policy, that documents and explains the use of cookies. The following elements are mandatory:

1. An overview of cookies with a description

State for each cookie (or cookie category):

  • The name of the cookie
  • The purpose
  • The provider/third party
  • The lifetime (session cookie or persistent cookie with the duration stated)
  • The cookie type (necessary, preference, statistics, marketing)

2. The legal basis for the processing

State for non-necessary cookies that the legal basis for the processing of personal data is consent (GDPR article 6(1)(a)).

3. Information about third-party cookies

If you use cookies from Google, Meta, LinkedIn or others, these must be mentioned, the user must know that third parties set cookies via your website.

4. The right to withdraw consent

The user must at any time be able to withdraw a given consent easily. The cookie banner must offer easy access to change preferences.

5. Links to third-party privacy policies

State links to the privacy policies of the third parties that set cookies via your site.

Datatilsynet's guidance on cookies

Datatilsynet has published detailed guidance on the use of cookies (available at datatilsynet.dk). The most important points of the guidance for practical implementation:

Prohibition on "nudging"

Datatilsynet has specifically warned against design-based manipulation that makes it harder to reject cookies than to accept them. This includes:

  • An accept button in a strong colour, a reject button in a grey/weak colour
  • "Accept all" with one click, "Customise settings" hidden in a third layer
  • A large, prominent accept button versus a small text link for rejection

Documentation of consent

You must be able to document that a consent has been obtained, when, by whom, for which cookies, and what the user specifically saw when the consent was given. Most consent management platforms (CMPs) handle this automatically.

Updating on new cookies

If you introduce new cookies (for example a new analytics tool), the cookie policy must be updated, and users must be presented with a new consent flow for the new cookies.

Cookie banner: what must it contain?

The design of the cookie banner has a direct bearing on whether the consent is valid. A correct banner contains:

  • A short, clear description of what cookies are used for
  • A button to accept all (non-necessary) cookies
  • A button to reject all (non-necessary) cookies, just as prominent as the accept button
  • A link to the cookie policy for further information
  • The option of granular consent, ideally the option to accept/reject per category

What if I run a webshop?

A webshop typically uses all four cookie types, and on top of that come trading terms, which must inform the user of the terms of purchase. It is important that you have both a cookie policy and trading terms that together cover all the information duties.

Specifically for webshops, it is important to distinguish between:

  • Necessary cookies for the shopping basket and checkout
  • Analytics cookies for conversion tracking (requires consent)
  • Remarketing cookies (Facebook Pixel, Google Ads Remarketing), require explicit consent

If you sell to customers in other EU countries, the ePrivacy implementation of the country in question applies, which can entail stricter rules (for example France via CNIL and Germany via the TDDDG, formerly the TTDSG).

Choosing a Consent Management Platform (CMP)

A CMP is a technical system that handles the display of the cookie banner, the collection and storage of consent, and the updating of the cookie list. Popular CMPs in Denmark:

  • Cookiebot (a Danish solution from Cybot, IAB TCF-certified)
  • Usercentrics
  • OneTrust
  • CookieYes

If you choose a CMP, it should support IAB's Transparency and Consent Framework (TCF) and store consent documentation automatically.

Fines for cookie breaches in Denmark

Datatilsynet has issued orders and filed police reports for cookie breaches:

  • 2021: Datatilsynet filed police reports against several Danish businesses for the use of cookies without valid consent
  • Coordinated EU enforcement actions (the Cookie Consent Taskforce) from 2022 have increased the focus on the area across the EU

The size of any fine depends on the seriousness and duration of the breach. Historically, the level for cookie breaches in Denmark has been more moderate than for serious GDPR breaches, but a lack of consent can still trigger an order, a police report and a fine.

Frequently asked questions

Do I need a cookie banner even if I only use Google Analytics?

Yes. Google Analytics (GA4) sets cookies and passes data on to Google's servers. This requires informed consent, unless you use a fully anonymised solution without transmission to Google.

Can I have a single consent for all cookies?

No, you must as a minimum offer the option to accept/reject per category (necessary, statistics, marketing). An unblocked "accept all" is not sufficient on its own.

What is the lifetime of a consent?

GDPR sets no fixed limit, but good practice is to renew the consent around every 12 months if there are no changes to the cookies. On changes, the consent must be renewed immediately.

Do the rules apply to B2B websites?

Yes. The cookie rules apply when cookies are set in a person's browser, regardless of whether it is a private individual or a business person.

Do I need a separate cookie-policy page?

Not necessarily, the cookie policy can be integrated into the privacy policy as a separate section. Many choose a separate page for clarity.

Conclusion

The cookie rules are not a formality, they are about users' right to decide over what is tracked in their browser. A correct cookie policy and a valid cookie banner protect both your users and your business against fines from Datatilsynet.

Start by mapping which cookies your website sets, assess which of them require consent, and ensure that your cookie banner meets the requirements.


The content of this article is for guidance only and does not constitute legal advice. Datatilsynet's guidance at datatilsynet.dk is the authoritative source for the cookie rules in force in Denmark.

Related templates

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.