Cookie consent modals have degraded user experience across the web. However, under the EU ePrivacy Directive (Directive 2002/58/EC as amended) and the GDPR, a website requires prior consent only when it stores or accesses information on a user's terminal equipment for non-essential purposes, or processes personal data without another valid legal basis.

1. The Strategy of Non-Collection

The simplest and most resilient compliance architecture is data avoidance. If an operator does not set analytics cookies, tracking pixels, local storage tokens, or behavioral profiling scripts, the obligation to display a consent modal does not apply:

Site Component Traditional Tracking Approach Data-Minimizing Static Approach
Traffic Analytics Client-side tracking cookies and fingerprinting Standard privacy-respecting server logs or no analytics
Web Typography Dynamic third-party CDN font requests Locally self-hosted system font stacks
Media Delivery Third-party embedded iframes that set cookies Native static media assets served from the host domain
Consent Modal Required with opt-in and opt-out mechanisms Not required under Article 5(3) of the ePrivacy Directive

Under Article 5(3) of Directive 2002/58/EC and EDPB Guidelines 01/2023, consent is mandatory when accessing or storing information on terminal equipment unless strictly necessary for service delivery. A static site that avoids client-side storage altogether avoids this requirement.

2. Preventing Remote IP Transmission

Under European case law (such as the Munich Regional Court ruling LG München I, 3 O 17493/20 in 2022), dynamic requests to external servers for web assets (such as remote Google Fonts) transmit the visitor's IP address to a third party without an adequate legal basis when the asset could readily be hosted locally.

To safeguard visitor privacy:

  • Self-Host All Assets: Bundle CSS, JavaScript, and font files locally on your own domain origin.
  • Eliminate External CDN Dependencies: Avoid third-party remote scripts that can track user navigation.
  • Implement a Strict Content Security Policy (CSP): Restrict script and asset loading to 'self' to prevent unauthorized outgoing connections.

3. Transparent Privacy Notices

Even when no invasive tracking occurs, GDPR Article 13 mandates that publishers maintain an accessible Privacy Policy. The notice must disclose the operator's identity, the lawful basis for technical server logs (typically Article 6(1)(f) legitimate interests for server security and fault diagnosis), retention durations, and data subject rights. A concise disclosure that truthfully describes a static, tracker-free site provides clear and verifiable compliance.