Checklist
Do essential cookies need consent?
Essential and strictly necessary are claimed labels. Verify cookies and network rows before Accept. This page is testing guidance, not legal advice.
In brief
Essential and strictly necessary are labels a CMP can show. A cookie audit asks whether cookies, storage, or marketing-looking requests appeared before Accept, including items in an Essential bucket. Category checkboxes are claims. Runtime rows are what you verify. ConsentProbe can list those pre-Accept findings. A free US-baseline scan is not an EU or California legal conclusion. This page is testing guidance, not legal advice.
Not legal advice
This FAQ explains how to observe cookies labeled essential, strictly necessary, or similar before Accept. It is not legal advice (非正式法律意见), not a ruling that any cookie is necessary or exempt, and not a GDPR, ePrivacy, CPRA, or other certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.
Last updated September 24, 2026. The before-Accept audit owns the longer protocol. The first-party versus third-party guide owns party labels. The pre-consent checklist owns the multi-step pass. The first-party analytics FAQ owns analytics IDs. This page stays on claimed Essential labels versus runtime.
Short answer
Essential and strictly necessary are labels. A cookie audit answers a different question. Did cookies, storage, or marketing-looking requests appear before the visitor clicked Accept, including items the CMP put in an Essential bucket?
Category checkboxes are claims. Runtime cookies and network rows are what you verify. Some jurisdictions treat certain functional cookies differently from advertising. That classification is for counsel. In a test, list what appeared before a choice, note the claimed category, and flag mismatches, such as an ads ID inside Essential.
ConsentProbe can list pre-Accept findings with request and cookie surfaces. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not decide what is necessary. This page is testing guidance, not legal advice (非正式法律意见).
Labels versus runtime
Three layers get mixed when a banner says only essential cookies load. Separate them before you write the finding. Stay with present before Accept under Essential. Leave legal permission with counsel.
| Layer | What it is | What it does not prove alone |
|---|---|---|
| CMP Essential or Strictly necessary category | A claimed bucket in the banner UI | That every cookie in it is lawful without consent |
| Runtime cookie and network evidence | What the browser set and requested before Accept | Legal permission, which stays with counsel |
| Banner screenshot | The UI claim on screen | That the network matched the category |
Five-step check before Accept
Stop after these five steps if you only need the Essential-label inventory. Open the before-Accept audit for the longer method. Open the party-label guide when domain context matters. Open the pre-consent checklist for the platform-agnostic pass. Open the first-party analytics FAQ when the disputed item looks like analytics.
- Use a clean profile. Do not click Accept or Reject.
- Load the storefront once. Screenshot the CMP categories if they are visible.
- Capture cookies and storage. Note names the CMP, or your docs, call Essential.
- Capture Network for ads, analytics, and marketing hosts that still fired.
- Write one finding sentence per mismatch: claimed Essential, observed a marketing-style surface before choice.
Mismatch patterns you can observe
The rows below are observations from a labeled visit. They are not a statutory list of necessary cookies, and they do not name a penalty. An example finding sentence is: claimed Essential, observed an ads-style cookie on Fresh before any click.
| Claim | What you hoped to see | Red flag |
|---|---|---|
| Only Essential before Accept | Marketing cookies and beacons stay off | Ads or attribution IDs on Fresh |
| Analytics is Essential | A documented functional need, and timing that matches it | An analytics ID before choice, with no other check |
| Strictly necessary toggled on, others off | Non-Essential buckets stay cold | Reject-looking UI with Accept-looking network |
When hand-sorting Essential buckets gets slow
Checking Essential buckets across templates by hand is slow. ConsentProbe runs Fresh on the storefront URL, and Reject when that is the claim. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not decide what is necessary, does not install a CMP, and does not issue a certificate.
FAQ
Do essential cookies need consent?
Labels do not answer that. Verify what fired before Accept, and ask counsel what is lawful.
Can strictly necessary cookies fire before Accept?
Some may, under counsel's classification. An audit only shows timing and surfaces.
What if an ads cookie sits in Essential?
Treat it as a claim-versus-runtime mismatch. Capture the cookie, the request, and a screenshot. The evidence pack guide lists the file fields.
How does this differ from first-party analytics?
The first-party analytics FAQ owns that question. The same rule applies here: an observation is separate from permission.
Does ConsentProbe decide what is necessary?
No. Reports are technical observations. ConsentProbe does not install a CMP and does not classify cookies for counsel.
Is this legal advice?
No (非正式法律意见). Talk to counsel for a legal conclusion. This page is testing guidance.
Limits of this page
This page tells you how to treat Essential and strictly necessary as claimed labels and how to verify what fired before Accept. It is not legal advice (非正式法律意见), not a classification of exempt cookies, and not a certificate. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the full protocol, the party-label guide for domain context, the pre-consent checklist for the pass order, and the first-party analytics FAQ when the item looks like analytics.
- Pre-Consent Cookie Audit: A Storefront Checklist
- First-party vs third-party cookies before consent: what should you check?
- Pre-consent audit checklist: what to verify before Accept
- Are first-party analytics cookies allowed before Accept?
- Reject All Still Tracking: What to Check After You Say No
- What belongs in a cookie consent audit evidence pack?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- Which cookie consent test should you run first?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.