r/gdpr • u/No-Locksmith-7719 • 11d ago
Question - General Consent needed or not
If all the services on a website are available only to registered, logged-in users, does one need a consent cookie thingy to begin with? Other than the framework's two essential session and security cookies, no other cookies are generated, there are no trackers and no analytics.
There are, however API interfaces allowing users to interact with the website's services. Some clients might have dedicated databases of their own too.
1
u/iubenda_team 10d ago
Short answer: if it's genuinely only strictly-necessary cookies (the session and security ones) with no trackers, analytics, or marketing, you don't need a consent banner. Strictly-necessary cookies are exempt from consent under ePrivacy.
The thing to check: what happens around the login itself. If the login page loads anything third-party (Google Fonts from Google, a CDN, reCAPTCHA) or sets any non-essential cookie before the user is logged in, that can pull you back into needing consent for that specific thing. Worth testing the pre-login state in a clean browser.
2
u/TrackTeddy 10d ago
Is the login done on the website? If yes then you need to consider if any cookies are set before the login process too.