Witold Wrodarczyk (Adequate) talks with attorney-at-law Agnieszka Grzesiek-Kasperczyk (MyLo law firm).
[Witold Wrodarczyk] On October 1, 2019, the Court of Justice of the European Union announced its ruling in the Planet49 case concerning how consent for installing cookies should be obtained. What follows from it?
[Agnieszka Grzesiek-Kasperczyk] The ruling states that consent to the installation and use of cookies is invalid if it was given by means of a pre-checked checkbox. Consent can be expressed by the user pressing a button or ticking a checkbox while browsing a website or using an app. It cannot be silent or passive consent.
[Update 2021, Adequate] In May 2020, the European Data Protection Board guidelines were issued, setting out the requirements for valid consent for cookies and other similar technologies. They confirm the Planet49 ruling and specify precisely what a correct consent process should look like.

Some commentators say that in practice little changes, because in Poland the rule still applies that browsing the Internet with specific browser settings is considered consent (art. 173 of the Telecommunications Law). And that it’s enough to inform users — via an information bar and a link to a cookie policy page — who the data is shared with and how long the cookies live. Only when cookies constitute personal data does the form of consent and the information provided during installation need to comply with the GDPR.

In my view, that interpretation is incorrect. Besides, the Court’s ruling makes clear that it doesn’t matter in this case whether the cookies constitute personal data.
And do cookies constitute personal data?
Not all of them. However, European case law increasingly takes the view that any cookie containing an identifier to which browsing history and other interactions are attached — one that can be used for purposes such as statistics or remarketing — should be treated as if it had the characteristics of personal data. Even when the data about these files is processed anonymously and specific individuals cannot be identified from it.
And what about when you use marketing automation systems, where cookies are linked to a specific user’s data such as first name, last name, email address or phone number? Or the eCommerce module in Google Analytics, which uses cookies to process transaction IDs that in turn make it possible to find the buyer’s data in the store’s CRM?
In that case there is no doubt that data collected via cookies constitutes personal data. But as I said, it is now accepted that being able to link a cookie to a specific person is not a necessary condition for treating cookies installed for analytics or advertising purposes as if they were personal data. The Court’s ruling goes precisely in that direction.
So the lawyers who claim “this doesn’t apply to us” are wrong?
In my opinion, it’s time they changed their position on this. As recently as May 2019, the ICO itself — the British data protection authority — used default cookie consent on its own website. But in July 2019 the ICO changed its practice and issued cookie guidelines clearly stating that browser settings do not constitute valid consent for cookies.
[Update 2021, Adequate] In 2020 the European Data Protection Board issued clear guidelines on this matter. In December 2021, the first Polish company was reprimanded by the Polish DPA (UODO) for failing to comply with these guidelines.
So what does valid cookie consent look like?
To place cookies other than those necessary for using the site — in particular cookies related to site statistics or marketing — we should obtain consent expressed by pressing a button or ticking a checkbox.
So necessary cookies — e.g. ones that remember a logged-in session, items added to the cart and other user preferences — don’t require consent?
Exactly. You don’t need consent for cookies required to operate functions the user knowingly uses on the site. If, say, the user switches the site to dark mode, the cookie that remembers this setting won’t require consent. Nor do you need consent for cookies that store the user’s preferences regarding cookie consent itself.
Recently I’ve been seeing sites implement a new form of consent, where the user can choose which cookies they accept and which they don’t. They can consent to, say, statistics cookies but not marketing ones. Of course there’s also an option to accept all cookies.
What matters, though, is that it isn’t too convoluted. Checkboxes must not be pre-checked. A user who wants to limit the cookies a site saves cannot be forced to untick checkboxes, scroll through lists, read long and confusing texts, click through successive options… It must be clear from the message that they are consenting to cookies.
Let’s look at the example below. The site letresor.pl asks us for cookie consent. The consent button is more prominent. When we go to the settings, the more prominent button is “accept all”, which works just like full consent on the previous screen. To limit cookies, you have to choose “save these settings”. Isn’t that manipulating the user into consenting to all cookies after all?


It’s only logical that sites won’t discourage users from allowing cookies. The consent and refusal buttons are the same size and their functions are clearly described. In this case, color or position in no way makes the choice harder for the user, nor can it be claimed that the user is being misled.
[Update 2023, Agnieszka Grzesiek-Kasperczyk] The illustration shows screenshots of a site that no longer exists. At the time it operated, such a solution could be considered correct. Today, in light of current guidelines and regulators’ decisions, it should be said that the first screen — next to “I agree” and “go to settings” — should include an “I do not agree” button allowing full refusal with a single click, just as full consent is possible.
I saw an English satirical site that put the word “WHATEVER” on its cookie consent button. Is that acceptable?
The button doesn’t have to say “I agree”. What matters is that it’s clear to the user what choosing a given option does. So if the consent window’s message reads “Do you consent to cookies?” and the user gets the options “go to settings” and “I don’t care” — then choosing the latter should be considered consent. It’s more a question of whether such a message fits the content of your site and the profile of your users, but that’s hardly a job for a lawyer.
[Update 2023, Adequate] Another question is whether the screen shouldn’t also feature a refusal button, e.g. “no way!”. See also the update to the previous question.

We tested the cookie consent widgets of many well-known Polish websites and online stores. In many cases we noticed that cookies — including analytics and advertising ones — were loaded onto the device before consent was given. In many cases, selecting particular options actually had no effect on which cookies were placed. Often, cookies were also installed that the site didn’t mention at all.
It should be obvious that a legal formula and a button alone don’t settle the matter. Cookie consent widgets must be properly installed and must actually implement the options offered to the user. It cannot be a dummy.
Cookie consent is opt-in consent — it is required before the site places cookies. You cannot save cookies first and only then ask for consent or offer a way to object. First consent, then cookies.
As a lawyer, I can speak to the form and manner of obtaining consent — but the technical implementation, the cookie audit, and making sure the user’s choices are actually honored are the responsibility of the site’s administrators.
Do we need to implement this urgently? Several months have passed since the CJEU ruling, and many large sites still inform users about cookies “the old way”. The example I showed at the beginning concerns gov.pl, which still uses only an information bar whose closing actually changes nothing.
Maybe they only use necessary cookies?
I checked. My computer received a _ga cookie with a Google Analytics user identifier. Depending on settings beyond the user’s control, Analytics can be used to collect site visit statistics, but also to build remarketing lists and target advertising.
Every case requires individual assessment. As a rule, consent should be obtained for placing Google Analytics cookies containing a user identifier. It’s hard to say when inspections will begin and what their practical consequences will be. If your way of collecting consent is challenged, a different lawyer’s opinion or the fact that other sites do it the same way will be no defense. I believe it’s worth adapting your cookie consent collection as soon as possible, rather than waiting for the first financial penalties.
Thank you for the conversation.
Agnieszka Grzesiek-Kasperczyk is an attorney-at-law and partner at the MyLo law firm. She specializes in online marketing and e-commerce law. Author of Poland’s first online course “GDPR for marketers” and a trainer in law for marketers.