Cookie consent modals have degraded user experience across the web. However, under the EU ePrivacy Directive (Directive 2002/58/EC as amended) and the GDPR, a website requires prior consent only when it stores or accesses information on a user's terminal equipment for non-essential purposes, or processes personal data without another valid legal basis.
1. The Strategy of Non-Collection
The simplest and most resilient compliance architecture is data avoidance. If an operator does not set analytics cookies, tracking pixels, local storage tokens, or behavioral profiling scripts, the obligation to display a consent modal does not apply:
| Site Component | Traditional Tracking Approach | Data-Minimizing Static Approach |
|---|---|---|
| Traffic Analytics | Client-side tracking cookies and fingerprinting | Standard privacy-respecting server logs or no analytics |
| Web Typography | Dynamic third-party CDN font requests | Locally self-hosted system font stacks |
| Media Delivery | Third-party embedded iframes that set cookies | Native static media assets served from the host domain |
| Consent Modal | Required with opt-in and opt-out mechanisms | Not required under Article 5(3) of the ePrivacy Directive |
Under Article 5(3) of Directive 2002/58/EC and EDPB Guidelines 01/2023, consent is mandatory when accessing or storing information on terminal equipment unless strictly necessary for service delivery. A static site that avoids client-side storage altogether avoids this requirement.
2. Preventing Remote IP Transmission
Under European case law (such as the Munich Regional Court ruling LG München I, 3 O 17493/20 in 2022), dynamic requests to external servers for web assets (such as remote Google Fonts) transmit the visitor's IP address to a third party without an adequate legal basis when the asset could readily be hosted locally.
To safeguard visitor privacy:
- Self-Host All Assets: Bundle CSS, JavaScript, and font files locally on your own domain origin.
- Eliminate External CDN Dependencies: Avoid third-party remote scripts that can track user navigation.
- Implement a Strict Content Security Policy (CSP): Restrict script and asset loading to
'self'to prevent unauthorized outgoing connections.
3. Transparent Privacy Notices
Even when no invasive tracking occurs, GDPR Article 13 mandates that publishers maintain an accessible Privacy Policy. The notice must disclose the operator's identity, the lawful basis for technical server logs (typically Article 6(1)(f) legitimate interests for server security and fault diagnosis), retention durations, and data subject rights. A concise disclosure that truthfully describes a static, tracker-free site provides clear and verifiable compliance.