Cookie policy: declarations and consent
Everything about cookie policy in Denmark: which cookies require consent, what a cookie declaration must contain, CMP and fines for non-compliance.
Karoline, Dokumentkonsulent
Does your website have a cookie banner that just pops up and asks people to "accept all"? Then there is a high probability that you are not compliant with the rules in force, and Datatilsynet has started to look more closely at exactly this.
Cookies are not just a technical question. They are a legal question: the cookie order and GDPR set specific requirements for how you obtain and document consent for the use of cookies. This guide explains the rules and what your cookie policy must contain.
What are cookies?
Cookies are small text files stored on the user's computer or device when they visit your website. They are used to:
- Remember settings: language choice, login status, shopping basket
- Track user behaviour: which pages are visited, time on the page, click stream
- Target ads: show users ads based on their behaviour (retargeting)
- Analyse traffic: Google Analytics, Hotjar and similar analytics tools
- Integrate with social media: Facebook Pixel, LinkedIn Insight Tag
The legal basis for cookies in Denmark
The cookie order
The requirement of consent for cookies itself is set out in the cookie order (bekendtgørelse nr. 1148 of 9 December 2011, as amended), which is issued under the telecommunications legislation and implements the ePrivacy Directive (2002/58/EC, amended by 2009/136/EC). The order requires:
- That the user is clearly informed that the website uses cookies
- That the user is informed of the purposes of the cookies
- That the user gives prior consent to non-necessary cookies
GDPR and cookies
GDPR (Regulation 2016/679) applies when cookies process personal data (for example IP addresses, user IDs). This means that consent for such cookies must also meet GDPR's consent requirements:
- Freely given: consent may not be a condition of access
- Specific: separate consent options for different cookie categories
- Informed: the user must know what they are consenting to
- Unambiguous: a clear affirmative act, pre-ticked boxes are not valid consent
- Revocable: the user must be able to withdraw consent easily
Datatilsynet's guidelines
Datatilsynet has issued guidance on cookies and has intensified its supervision in recent years. Orders have been issued to businesses with non-compliant cookie banners, including banners that make it harder to reject than to accept cookies.
Cookie categories: what requires consent?
Necessary cookies (no consent required)
These cookies are technically necessary for the website's basic functions and can be set without consent:
- Session cookies (login status, shopping basket)
- Security cookies (CSRF protection)
- Load-balancing cookies
- Cookies that remember consent choices
Preference cookies (consent required)
Cookies that remember the user's choices and improve the user experience:
- Language setting
- Screen-size adjustments
- Personalisation of content
Statistics cookies (consent required)
Cookies that collect data about how the website is used:
- Google Analytics (as a rule requires consent, unless the data is fully anonymised and not passed on)
- Hotjar, Mouseflow and other behaviour-analytics tools
- Internal web statistics
Marketing cookies (consent required)
Cookies used for targeted advertising and cross-site tracking:
- Facebook Pixel
- Google Ads (conversion tracking and remarketing)
- LinkedIn Insight Tag
- Snapchat Pixel
What must your cookie policy contain?
A legally valid cookie policy (cookie declaration) must as a minimum contain:
1. Which cookies the website uses
A complete list of all cookies including:
- The cookie name
- The purpose (what is it used for?)
- The type (session, persistent, third-party)
- The expiry date
- The controller/provider (for example Google, Meta, Hotjar)
2. The purpose of the different cookie categories
Clear and understandable descriptions of what the different cookie categories are used for and who has access to the data.
3. Consent and withdrawal
- How to give consent
- How to withdraw consent
- A link to consent management (cookie banner/CMP)
4. Links to third-party privacy policies
If you use cookies from Google, Meta, LinkedIn and others, you should link to their privacy policies.
5. The date of update
State when the cookie policy was last updated.
6. A link to your privacy policy
The cookie policy should link to your privacy policy for the overall picture of data processing.
Cookie Consent Management Platform (CMP)
A CMP is the technical solution that presents the cookie choice to users and stores the consent. A compliant CMP must:
- Show all cookie categories with separate on/off options
- Make it just as easy to reject as to accept
- Show a clear "Reject all" button
- Not use dark patterns (greying out "Reject" buttons, complex menu structures for rejecting)
- Store documentation of the consent (time, options, version of the policy)
Popular CMP solutions: Cookiebot (Usercentrics), OneTrust, Didomi, Iubenda.
Dark patterns in cookie banners: what is prohibited?
Datatilsynet and the European Data Protection Board (EDPB) have specifically warned against:
- Asymmetric design: a large green "Accept all" button, a small grey "Settings" link
- Pre-ticked boxes: marketing cookies are active by default
- Manipulative language: "Help us improve your experience" as consent text for marketing
- Cookie walls: access to the content conditional on consent to non-necessary cookies
Google Analytics and consent
Google Analytics 4 (GA4) sets cookies that can identify users. Datatilsynet and the EDPB have clearly stated that valid consent is required for GA4 cookies in the EU/EEA.
Alternatively, you can use Consent Mode v2 (Google's solution), which models data in the absence of consent, but this reduces data precision.
Documentation and audit trail
GDPR requires that you can prove that you have obtained valid consent. Your CMP should store:
- A timestamp for the consent
- The version of the cookie policy at the time of consent
- The user's specific choices (which categories accepted/rejected)
Do not store more than is necessary to document the consent, the documentation itself is also a processing of personal data that must be kept to a minimum.
Frequently asked questions about the cookie policy
Do I need a cookie policy if I only use necessary cookies?
You are not obliged to obtain consent, but it is good practice to inform users that you use necessary cookies. A short cookie note in the privacy policy is sufficient.
Is Google Analytics lawful without consent?
No, not in its standard form. GA4 cookies identify users and require consent in the EU/EEA. Datatilsynet has confirmed this. You must either obtain consent via a CMP or switch to a cookieless analytics solution (for example Plausible, Fathom).
What is the consequence of lacking a legally valid cookie policy?
Datatilsynet can issue orders and fines. Fines for cookie breaches in the EU have varied from warnings to million-kroner fines for large businesses. For SMEs, orders and smaller fines are most realistic, but it is best to avoid them.
Must the cookie policy be updated when we add new third-party services?
Yes. If you add a new third-party cookie (for example a new advertising platform), your cookie policy must be updated, and your CMP must include the new cookie.
What is the difference between a cookie policy and a privacy policy?
The cookie policy focuses specifically on the use of cookies. The privacy policy covers all processing of personal data on your website and in your business, including cookies. Many businesses incorporate the cookie policy into the privacy policy.
Checklist: is your website cookie-compliant?
- A cookie banner is shown to new visitors
- "Reject all" is just as accessible as "Accept all"
- Separate categories with individual on/off options
- No pre-ticked boxes for non-necessary cookies
- The cookie policy is published and up to date
- Documentation of consent is stored in the CMP
- All third-party cookies are identified and listed
- Links to third parties' privacy policies
Conclusion
Cookie compliance is an area that requires ongoing attention. The rules are clear, but technical implementation takes time. Start by auditing your website for all active cookies, introduce a compliant CMP with correct categories and consent flows, and ensure an up-to-date cookie policy.
The content of this article is for guidance only and does not constitute legal advice. Contact a GDPR specialist or lawyer for advice on your specific website's cookie compliance.
Related templates
This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.