Skip to content
+370 5 212 1506 info@dat.lt

Cookies and consent banners: what the ERĮ and the GDPR require

25 September 2026 · Good to know

Storing information on a visitor’s device, or reading it from there, is allowed only with their consent, after they have been given clear and comprehensive information, including about the purposes (Article 73(4) ERĮ, the Lithuanian Law on Electronic Communications). The law has only two exceptions: where it is done solely to transmit information over a network, and where it is strictly needed to provide a service the person has asked for. Analytics, advertising and social media tags usually fall outside both. The consent must meet the GDPR standard: freely given, specific, informed and unambiguous (Article 4(11) GDPR), and it must be as easy to withdraw as to give (Article 7(3) GDPR).

A privacy policy can inform people about cookies, but it does not create consent. We explained this in Privacy policy: is it mandatory and when to update it. This article covers the difference between necessary and non-necessary cookies, what a lawful consent banner looks like, who supervises it and what the consequences can be.

What Article 73 ERĮ protects

The ERĮ implements Directive 2002/58/EC on privacy and electronic communications (Annex 2 ERĮ). European guidance on cookies is written under that directive, so it also helps to interpret Article 73(4) ERĮ. The rule protects the device itself: the computer, phone or tablet. So it does not matter whether the cookie is personal data. In Case C‑673/17 (Planet49) the Court of Justice held that the requirement is the same whether or not the information stored or accessed on the device is personal data (point 2 of the operative part).

The rule is not limited to cookies. The European Data Protection Board (EDPB) says in Guidelines 2/2023 that a tracking pixel or tracking link placed in a website or an email also amounts to storing information on the device and gaining access to it (paragraphs 50 and 51). This matters for newsletters that count opens. When email advertising itself needs consent is covered in our article on direct marketing by email and SMS.

Which cookies are strictly necessary

The exception is narrow. A cookie may be used without consent if its sole purpose is to transmit information over a network, or if it is strictly needed for a service the person has asked for (Article 73(4) ERĮ). In Opinion 04/2012 (WP194), the Article 29 Working Party reads the second exception as two tests. The person asked for a specific function, and the function would not work if the cookie were switched off.

Under this test, shopping cart, login session and security cookies usually work without consent (WP194, section 5). So do cookies that remember the settings a person has chosen for the service (EDPB Cookie Banner Taskforce report, paragraph 30).

Not strictly necessary:

  • analytics cookies – the website can still be used with them switched off (WP194, section 4.3);
  • third-party advertising and ad measurement cookies (WP194, section 4.2);
  • tracking cookies of social media plug-ins (WP194, section 4.1).

Lithuanian law has no separate exception for analytics. Article 73(4) ERĮ has only the two exceptions described above.

Labelling a cookie as “necessary” when it serves another purpose is a mistake the EDPB Cookie Banner Taskforce discussed separately. The taskforce discussed the website owner’s responsibility to keep the cookie list, to provide it to the competent authorities when asked, and to show that the listed cookies are necessary (paragraphs 26 and 28). So when we prepare a cookie policy, we always ask the client for two things: a list of every cookie the website uses, with a description, and information on how the chosen cookie banner works.

What a lawful consent banner looks like

Where the ERĮ does not define a term itself, it takes the definition from other acts, including the GDPR (Article 3(102) ERĮ). So cookie consent is judged by the same criteria as any other consent under the GDPR. When such consent is valid is covered in more detail in Consent under the GDPR: when you need it and when it is invalid. For cookies, this gives six rules.

Consent comes before the cookies are set. The EDPB says consent is given before processing starts (Guidelines 05/2020, paragraph 90). A tag that fires when the page opens, before the person has clicked anything, has no consent.

No pre-ticked boxes. Silence, pre-ticked boxes or inactivity are not consent (Recital 32 GDPR). For cookies, the Court of Justice confirmed this for a pre-ticked box (Planet49, point 1 of the operative part).

Browsing is not consent. Scrolling a page or similar activity does not, in any circumstances, meet the requirement of a clear affirmative action (EDPB Guidelines 05/2020, paragraph 86). A line saying “by continuing to browse you accept cookies” creates no consent.

Refusing must be a real option. Consent is not freely given if the person cannot refuse it (Recital 42 GDPR), and withdrawing it must be as easy as giving it (Article 7(3) GDPR). In the EDPB taskforce, a vast majority of supervisory authorities considered it an infringement where a banner has an “Accept” button but no option to refuse on any layer (paragraph 8). The taskforce members also agreed that consent is not valid where the only alternative is a “reject” link embedded in the banner text without sufficient visual emphasis (paragraph 14). Changing the choice later must be easy; the EDPB taskforce recommends a permanently visible icon or link (paragraph 32).

No cookie walls. If content can only be seen after clicking “Accept cookies”, the person has no real choice, so consent is not freely given (EDPB Guidelines 05/2020, paragraphs 39–41).

The information must be complete. You must state the purposes (Article 73(4) ERĮ), how long the cookie runs and whether third parties can access it (Planet49, point 3 of the operative part). Also state who the controller is (Article 13(1)(a) GDPR).

Legitimate interest does not work here. The EDPB taskforce says that setting and reading cookies cannot be based on the controller’s legitimate interest (paragraph 24). In Guidelines 1/2024 (version for public consultation), the EDPB adds that where these techniques are used for direct marketing, consent will likely be the appropriate basis for the further processing of the data obtained too (paragraph 115).

What most often goes wrong

  • Analytics and advertising tags fire as soon as the page opens, and the banner only informs.
  • The banner has only an “I agree” button and a sentence saying that browsing means consent.
  • “Reject” is hidden on the second layer or written in barely readable type.
  • Analytics is labelled as “necessary cookies”.
  • The cookie list in the policy does not match what the website actually sets.
  • The website developer installed the banner, but nobody checked how it actually works.

Who supervises and what is at stake

Compliance with the ERĮ rules on data processing and privacy protection, including Article 73, is supervised by the State Data Protection Inspectorate (VDAI) (Article 5(2)(1) ERĮ). There are two kinds of consequences.

First, administrative liability under the Code of Administrative Offences (ANK). A breach of the data processing and privacy protection rules laid down in the ERĮ carries a fine for individuals of one hundred and fifty to five hundred and eighty euros, and for heads of legal entities or other responsible persons of three hundred to one thousand one hundred and fifty euros (Article 83(1) ANK). A repeated breach carries higher fines (Article 83(2) ANK). VDAI officials investigate these offences (Article 589(29) ANK). Only natural persons are liable under the ANK (Article 2(1) ANK): an individual who runs the website, or the head or another responsible person of a legal entity, not the company itself.

Second, liability under the GDPR. Where cookies collect personal data, the EDPB taskforce says that if there was no valid consent, the further processing of that data cannot comply with the GDPR (paragraph 24). A breach of the lawfulness and consent conditions falls in the highest fine bracket: up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR).

The practical consequence often hurts more than a fine. Analytics and advertising data collected without valid consent was collected unlawfully. Relying on it for decisions and audiences becomes risky.

When to call a lawyer

  • when you install or change a consent management tool and want it checked before launch;
  • when you do not know which of your cookies are really necessary;
  • when your website runs advertising, social media or other third-party tags;
  • when your newsletters or app use tracking pixels;
  • when you receive a complaint, a VDAI inquiry or a remark from a partner about cookies.

Frequently asked questions

Do analytics cookies need consent?

Yes. Article 73(4) ERĮ has only two exceptions: transmission over a network and a service the person has asked for. Analytics is neither, because the website can be used without it (WP194, section 4.3). Lithuanian law has no separate exception for analytics.

Can we show content only to people who accept cookies?

No. The EDPB says that where content is blocked until the person clicks “Accept cookies”, they have no real choice, so consent is not freely given and is invalid (Guidelines 05/2020, paragraphs 39–41).

Is consent needed if the cookie collects no personal data?

Yes. Article 73(4) ERĮ applies to any information on the person’s device. In Case C‑673/17 the Court of Justice held that the requirement is the same whether or not that information is personal data. That only decides whether the GDPR applies as well.

Must the banner have a “Reject” button?

The law does not name the button. Consent must be freely given (Article 4(11) and Recital 42 GDPR), and withdrawing it must be as easy as giving it (Article 7(3) GDPR). A vast majority of the supervisory authorities in the EDPB taskforce considered a banner with “Accept” but no refusal option on any layer to be an infringement. The safest design has “Reject” on the same layer and with the same prominence as “Accept”.

How to start

Send us the website address, the cookie list and the cookie policy. We will check what fires before consent, whether the cookies are categorised correctly and whether the banner lets people refuse as easily as they accept.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles