> GDPR requires you to request consent for any cookies the “could” be used to identify you, which makes them personal information.
> So if you want to use cookies to link a user’s sessions on your own website together (without actually identifying them) so every request doesn’t look like a totally anonymous, opaque request, then you must show a cookie banner.
Wrong. The ePrivacy directive has an exception for strictly necessary cookies (Article 5.3), which is applicable for user sessions.
The ePrivacy directive: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... Search for “strictly necessary”.
More details in this opinion from WP29, see section 3.2: https://ec.europa.eu/justice/article-29/documentation/opinio...
> You could (presumably) do this through browser fingerprinting and not require consent (since you don’t actually enrich/link the browser fingerprint to be become user data) but you need a cookie banner if you do it with a cookie.
Are you able to identify someone from the fingerprint of their browser? Then the fingerprint is PII. Consent (or any other legal basis from GDPR Article 6) is therefore required if the exemption from the ePrivacy directive is not applicable.
GDPR Article 6: https://www.privacy-regulation.eu/en/6.htm