Regardless of the answer here, the fact that there's still a debate about what basic functionality requires a cookie banner is really a testament to how bad this legislation is. How long has this been around, 20 years? And there's still widespread debate and lack of understanding as to what specific functionality requires a cookie banner?
No. It took effect in 2018.
Probably because they're not particularly technical people, and also because of the asymmetric incentives for them personally.
Tell someone to put a cookie banner up when they didn't need to: no consequences.
Tell someone not to put up a cookie banner up when they did need to: potentially big consequences for them and their career.
https://ec.europa.eu/justice/article-29/documentation/opinio...
This says that cookies for a shopping cart or user preferences are exempted from consent. The ICO and the CNIL say the same, as expected.
> consent is not required [for] cookies that are strictly necessary to provide an online service that the person explicitly requested. e.g. […] when your customers use a shopping basket
So shopping carts (user clicked to add to cart) and notification preferences (user clicked to indicate preference) don’t require consent. Same for authentication cookies.
The page is quite clear; the confusion likely arises from how companies implement it.
[0]: https://europa.eu/youreurope/business/dealing-with-customers...
If you really care about not annoying your users and don't intend to track them more than what's absolutely required for the service to work, then talk with your lawyers more. Of course, it is not free as it requires extra work, and it may carry some risk (which your lawyers should minimize) but it may be worth it, many people press the "back" button as soon as they see a cookie banner and try their luck elsewhere.
> A cookie that is exempted from consent should have a lifespan that is in direct relation to the purpose it is used for, and must be set to expire once it is not needed, taking into account the reasonable expectations of the average user or subscriber. This suggests that cookies that match CRITERION A and B will likely be cookies that are set to expire when the browser session ends or even earlier. However, this is not always the case. For example, in the shopping basket scenario presented in the following section, a merchant could set the cookie either to persist past the end of the browser session or for a couple of hours in the future to take into account the fact that the user may accidentally close his browser and could have a reasonable expectation to recover the contents of his shopping basket when he returns to the merchant’s website in the following minutes. In other cases, the user may explicitly ask the service to remember some information from one session to another, which requires the use of persistent cookies to fulfil that purpose.
(Criterion A is cookies that are user “for the sole purpose of carrying out the transmission of a communication over an electronic communications network” and criterion B is cookies that are “strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service”).
If your shopping cart cookie has a lifetime longer than the "reasonable expectations of the average user or subscriber" you may need to obtain consent. That a sufficiently vague criteria that it may not be clear if your particular shopping cart cookie requires consent or not.
[1] https://ec.europa.eu/justice/article-29/documentation/opinio...