logoalt Hacker News

latexrlast Wednesday at 3:18 AM1 replyview on HN

> Session auth cookies are the only ones the EU considers strictly necessary.

There are several others which are permissible. The EU has six examples.

https://commission.europa.eu/resources/europa-web-guide/desi...


Replies

buzerlast Wednesday at 3:40 AM

This is what European Commission has determined to be acceptable for them. One very important distinction here is, as far as I understand, that EC is not bound by ePrivacy Directive as directives bound member states and require them to include them on their national law.

The text on that website does state that some DPAs have found some first-party analytics acceptable, but that's not something that is confirmed by CJEU. And ePD does not have single-stop shop so you need to follow every DPAs directions if you are offering services to that DPA's country.