Almost every business website uses cookies or similar tracking – for analytics, advertising, embedded videos or simply to make the site work. But the little consent banner most visitors click past is a legal requirement, and regulators across Europe have made clear that many banners do not meet the standard. This guide explains when you need cookie consent, what a compliant banner looks like, and how the rules fit together for a business operating in Sweden.
Two sets of rules apply
Cookies sit at the intersection of two regimes. The ePrivacy rules – in Sweden implemented through the Electronic Communications Act – govern the act of storing or reading information on a user’s device, and generally require consent for anything that is not strictly necessary. The GDPR then governs the personal data those cookies collect. In practice you have to satisfy both: consent to place the cookie, and a lawful, transparent basis for processing the data it generates.
Which cookies need consent
Strictly necessary cookies – those required to deliver a service the user has asked for, such as keeping items in a shopping basket or maintaining a login session – do not need consent. Almost everything else does: analytics, marketing and advertising cookies, social-media and video embeds, and third-party trackers. The key point is that these may not be set before the user has actively consented.
What makes consent valid
Under the GDPR, consent must be freely given, specific, informed and unambiguous, given by a clear affirmative action. For cookie banners this means no pre-ticked boxes, no cookies firing before the user chooses, a genuine option to reject that is as easy to use as the option to accept, and clear information about what each category of cookie does. “By continuing to browse you accept cookies” is not valid consent, and a banner with only an “Accept” button generally is not either.
Transparency and control
Visitors need to know, in plain language, which cookies are used, for what purposes, how long they last and who the third parties are. They must also be able to withdraw consent as easily as they gave it, which usually means a persistent way to reopen the cookie settings. A separate, accurate cookie policy supports the banner and demonstrates accountability.
Practical example: an e-commerce site with analytics
An online shop uses necessary cookies for the basket and checkout, plus Google Analytics and an advertising pixel. The necessary cookies load immediately. The analytics and advertising cookies stay dormant until the visitor makes a choice on a banner that offers “Accept all”, “Reject all” and “Manage preferences” with equal prominence. A footer link lets visitors change their mind at any time. That set-up meets both the ePrivacy and GDPR requirements.
Common mistakes companies make
Businesses fire analytics and marketing cookies before consent, use banners with only an “Accept” button, hide or complicate the reject option, rely on pre-ticked boxes or “continued browsing” as consent, forget that international data transfers via ad and analytics tools raise separate GDPR issues, and never give users a way to withdraw consent. Any of these can turn a routine banner into a compliance problem.
Recommended actions
Audit which cookies your site actually sets, classify them as necessary or not, and block the non-essential ones until consent is given – a properly configured consent management tool does this. Offer accept and reject with equal ease, publish a clear cookie policy, provide an ongoing way to change preferences, and review the set-up whenever you add a new tool or tracker.
Frequently asked questions
Do I need consent for Google Analytics?
Yes. Analytics cookies are not strictly necessary, so they require consent before they are set, and the associated data processing must meet GDPR requirements, including any international transfer safeguards.
Is an “Accept all” only banner enough?
Generally no. If accepting is easy but rejecting is hidden or missing, consent is not freely given. Reject should be as accessible as accept.
Who supervises cookie rules in Sweden?
The electronic communications (cookie) rules are supervised by the Swedish Post and Telecom Authority (PTS), while the data protection aspects fall to the Swedish Authority for Privacy Protection (IMY). In practice both dimensions matter.
Conclusion
Cookie compliance is no longer a box-ticking exercise: regulators expect genuine, informed choice and real control for users. A short audit and a properly configured banner usually bring a site into line and reduce risk. Lawgent helps businesses get their cookie banners, policies and data handling right under both the ePrivacy rules and the GDPR. Contact us for a practical review of your website’s tracking and consent set-up.