What Are the Telecommunicatiewet + GDPR Cookie Consent Requirements?
Everything you need to know about Telecommunicatiewet + GDPR cookie consent compliance in 2026. Complete guide covering opt-in consent requirements, cookie banner elements, consent records, and technical implementation for Netherlands.
Summary
This guide provides comprehensive technical implementation requirements for Netherlands (Telecommunicatiewet + GDPR). The Dutch Telecommunications Act (Telecommunicatiewet) Art. 11.7a implements the EU ePrivacy Directive. Consent required before placing non-essential cookies. GDPR applies in parallel for personal data processing. Enforced by Autoriteit Persoonsgegevens (Dutch DPA) and ACM.
This jurisdiction requires an opt-in consent model (prior consent), meaning websites must obtain explicit user consent before placing non-essential cookies or similar tracking technologies. Users must actively accept cookies through clear consent mechanisms.
Additional requirements for this jurisdiction include: providing consent banners and privacy information in all required languages, and special protections and consent mechanisms for children's personal data.
Website owners and operators subject to these regulations must implement compliant cookie consent banners, maintain proper consent records, and ensure their tracking technologies respect user privacy choices. This guide outlines all technical requirements needed to achieve compliance.
Key Requirements Overview
Technical Requirements
Required Banner Elements
First Layer (Cookie Banner)
- Concise Purpose Summary
- Accept All Button
- Reject All Button Or Link
- Manage Preferences Button
- Link Privacy Policy
- Clear Controller Identity
Second Layer (Preferences Modal)
- Granular Purpose Toggles
- Vendor List If Applicable
- Retention Periods If Known
- Third Country Transfers Notice If Applicable
Implementation Guidance
Cookie walls are prohibited under Dutch DPA guidance. Analytical cookies for visitor counting with limited privacy impact are exempt from consent. Reject button must have equal prominence to accept button. Pre-ticked boxes and implied consent (e.g. 'by continuing to browse') are not valid. The Dutch DPA actively monitors ~10,000 websites annually and enforces with fines up to €600,000.
Special Protections
Children's Privacy
Parental consent required for children under 16 (GDPR Art. 8; Netherlands has not lowered the age threshold).
Sensitive Data
Explicit consent required for special categories of personal data under GDPR Art. 9.
Record Keeping Requirements
Required Consent Record Fields
For each consent action, you must maintain records containing:
- Timestamp ISO
- User Choices By Purpose
- Policy Version
- Jurisdiction Detected
- Consent UI Version
- Ip Country At Consent
CookieChimp handles all of this automatically. Our platform maintains comprehensive consent records including all required fields, timestamps, consent strings, IP addresses, user agents, and more. Records are securely stored and easily exportable for compliance audits. Learn more about our consent management
Exempt Cookie Types
The following types of cookies are typically exempt from consent requirements:
Legal References & Resources
Official legal documents and regulatory guidance for this jurisdiction:
Frequently Asked Questions About Telecommunicatiewet + GDPR Cookie Consent
Found an issue or have feedback on this page?
Explore Other Jurisdictions
View AllEU (GDPR + ePrivacy Directive Art. 5(3))
EU/EEA
ePrivacy governs cookies; GDPR governs personal data.
UK (UK GDPR + PECR)
United Kingdom
PECR governs cookies; UK GDPR governs personal data.
Switzerland (FADP + TCA)
Switzerland
Hybrid model: some cookies allowed under legitimate interest; profiling/marketing require consent. Opt-out always required.