(Note: It _may_ be compliant for future updates of the directive coming in a couple of years, but iirc that isn't out yet.)
(Note: It _may_ be compliant for future updates of the directive coming in a couple of years, but iirc that isn't out yet.)
The whole "cookie" topic is a dark pattern mostly pushed by ad providers as a friendly word to bypass having to say "may we track everything you do?".
So if it tracks data points that can be used to clearly identify a visitor, or marks the visitor in a way that can be used to personally identify them later, it will need the users consent, regardless of where and how this is stored.
And there was NEVER a requirement for a "cookie banner" in its text. Consent under it can be given in any other way that are not as intrusive, but it was the industry who chose the stupid banner and invasive analytics. Also notice that under both GDPR and ePrivacy Directive, consent is not required for cookies/etc with a legitimate purpose. Examples of those have been given under the ePrivacy Directive from almost the beginning, but more explicitly in the "Opinion 04/2012 on Cookie Consent Exemption" which is from 2012 and predates cookie banners.
[1] Here's an example of asking for consent to store a cookie that doesn't involve a banner: https://www.williamgrant.com . It's in the age-check modal.
I was answering to a claim that cookie banners are required by the ePrivacy Directive. There is no requirement for banner anywhere there or in GDPR. They were invented by the advertisement industry, and almost all the time are found to be non-compliant.
Go to https://gdpr.eu/ and tell me what their cookie banner says.
But not every access, or cookie, will require consent.