Cookie policy: cookies and GDPR on your website
Complete guide to cookie policy and cookie consent for Danish websites. GDPR requirements for cookies, the cookie banner, and when you need a cookie policy.
Karoline, Dokumentkonsulent
If you have a website in Denmark, whether as a private individual, an SME or a larger business, you are most likely obliged to have a cookie policy and to obtain the user's consent before you place certain types of cookies. The rules are set out in GDPR and the cookie order, and Datatilsynet actively supervises.
This guide explains what cookies are, when you must have a cookie policy, what it must contain, and what you risk by getting it wrong.
What are cookies?
Cookies are small text files that a website stores in the user's browser. They are used for a wide range of purposes:
- Session cookies: keep the user logged in to a website
- Preference cookies: remember the user's language choice, currency setting, etc.
- Statistics cookies: track user behaviour for Google Analytics, Matomo and the like
- Marketing cookies: enable targeted advertising via Facebook Pixel, Google Ads, LinkedIn Insight Tag, etc.
The term "cookies" is used broadly and also covers pixels, local storage, fingerprinting and other tracking methods.
The legal framework: GDPR and the cookie order
In Denmark, cookies are primarily governed by two sets of rules:
GDPR (the General Data Protection Regulation)
GDPR applies to all processing of personal data, including cookie-based tracking that can be attributed to an identifiable person. The basic principles are:
- Consent must be freely given, specific, informed and unambiguous
- The user must be able to withdraw consent just as easily as it is given
- You must be able to document the consent
The cookie order
The cookie order (bekendtgørelse nr. 1148 of 9 December 2011) implements the ePrivacy Directive in Danish law. It provides that:
- You may not store cookies on a user's device unless the user is informed and has given consent
- Exempt are necessary cookies (see below) and cookies used solely to carry out a communication
Which cookies require consent?
Necessary cookies, exempt from the consent requirement
Necessary cookies are cookies that are strictly necessary for the website to function. These do NOT require consent:
- Session cookies that keep the user logged in
- Shopping-basket cookies in a webshop
- Cookies that remember the user's GDPR consent choice
- Security cookies (CSRF protection, etc.)
Statistics cookies, require consent
Cookies that collect data about user behaviour (for example Google Analytics, Hotjar, Matomo with a full IP address) require consent, as they process personal data.
Exception: If you use an analytics solution with anonymised IP addresses and without cross-site tracking, some supervisory authorities regard it as possibly exempt, but you should seek specific advice.
Marketing cookies, require consent
Marketing cookies always require consent:
- Facebook Pixel and Meta CAPI
- Google Ads conversion tracking
- LinkedIn Insight Tag
- TikTok Pixel
- Retargeting and audience cookies
What must your cookie policy contain?
According to GDPR and Datatilsynet's guidance, a compliant cookie policy must contain:
1. Who is the data controller?
State your business's full name, CVR number, address and contact details (including an email address for data-protection enquiries).
2. What are cookies?
A short, easily understandable explanation of what cookies are and what they are used for on your website.
3. Categories of cookies
List the specific cookies your website uses, divided into categories:
| Category | Name | Purpose | Duration | Provider |
|---|---|---|---|---|
| Necessary | PHPSESSID | Session management | Session | Own |
| Statistics | _ga | Google Analytics | 2 years | |
| Marketing | _fbp | Facebook Pixel | 3 months | Meta |
This requirement of a specific cookie list is one of the parts Danish websites most often forget.
4. The legal basis for the processing
State the legal basis for each cookie category:
- Necessary cookies: Legitimate interest (GDPR art. 6(1)(f)) or performance of a contract
- All other cookies: Consent (GDPR art. 6(1)(a))
5. Transfers to third countries
Do you use cookies from providers with servers outside the EU (Google, Meta, LinkedIn, etc.)? Then state:
- Which countries the data is transferred to
- The legal basis for the transfer (for example the EU-US Data Privacy Framework)
6. The user's rights
The user has the right to:
- Withdraw consent: just as easily as it is given (via your cookie banner)
- Access: see what data you process about them
- Erasure: demand that personal data be deleted
- Complain: lodge a complaint with Datatilsynet
7. Links to third parties' policies
State links to the cookie and privacy policies of the third parties you share data with (Google, Meta, LinkedIn, etc.).
Cookie-banner rules: what must the banner contain?
Your cookie banner must meet a number of requirements:
Requirements for consent
- The user must actively give consent (a pre-ticked "accept all" button is NOT lawful)
- It must be just as easy to reject all cookies as to accept all
- Banners designed to manipulate the user into accepting (dark patterns) are unlawful
Requirements for information
- The purpose of the cookies must appear clearly
- A link to the full cookie policy must be available
Requirements for documentation
- You must be able to document when, and which version of consent, a given user has given
- Consent logs must be kept for a sufficient time
The consent platform
For most websites it is practically impossible to meet these requirements manually. Use a certified consent management platform (CMP) such as Cookiebot (Usercentrics), CookieYes, Didomi or similar. Many of these integrate directly with WordPress, Shopify and other CMS platforms.
Datatilsynet's supervision and sanctions
Datatilsynet actively supervises cookies on Danish websites. The authority:
- Carries out scans of websites and identifies unlawful cookie use
- Can issue warnings, orders and fines
- Can pass larger cases to the police and involve the EDPB (the European Data Protection Board)
In 2022, Datatilsynet concluded, in line with other EU supervisory authorities, that the standard set-up of Google Analytics could not be used lawfully without supplementary measures, because data is transferred to the USA. Datatilsynet has also focused on whether "reject all" buttons are sufficiently prominent.
Fines: Under GDPR, fines for data-protection breaches can reach up to 4% of global annual turnover or EUR 20 million, whichever is higher. In practice, smaller fines and orders are typically issued to businesses for cookie breaches, but the level depends on the seriousness of the breach.
Specifically on Google Analytics and Danish law
The use of Google Analytics has caused particular debate in Danish and European data-protection law. Datatilsynet has aligned itself with the assessments of other EU countries' authorities that the standard Google Analytics set-up is problematic, since data is transferred to the USA.
Recommendations:
- Be aware that GA4 as a rule does not store IP addresses
- Enter into correct data-processing terms with Google
- Consider EU-hosted analytics alternatives (Matomo, Plausible, Fathom)
Create your cookie policy
LegalDock's cookie-policy template gives you a clear, GDPR-compliant document that covers all the above requirements. The template is easy to adapt to your website, your specific cookies and your business.
Combine the cookie policy with a privacy policy and an approved cookie banner for full compliance.
LegalDock tip: A cookie policy alone is not enough. You must also have a cookie banner that actually obtains consent before marketing cookies are set. The cookie policy is the documentation, the design of the banner is what Datatilsynet looks at.
Related templates
This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.