Checklist

Do essential cookies need consent?

Start a free audit

Essential and strictly necessary are claimed labels. Verify cookies and network rows before Accept. This page is testing guidance, not legal advice.

In brief

Essential and strictly necessary are labels a CMP can show. A cookie audit asks whether cookies, storage, or marketing-looking requests appeared before Accept, including items in an Essential bucket. Category checkboxes are claims. Runtime rows are what you verify. ConsentProbe can list those pre-Accept findings. A free US-baseline scan is not an EU or California legal conclusion. This page is testing guidance, not legal advice.

Not legal advice

This FAQ explains how to observe cookies labeled essential, strictly necessary, or similar before Accept. It is not legal advice (非正式法律意见), not a ruling that any cookie is necessary or exempt, and not a GDPR, ePrivacy, CPRA, or other certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.

Last updated September 24, 2026. The before-Accept audit owns the longer protocol. The first-party versus third-party guide owns party labels. The pre-consent checklist owns the multi-step pass. The first-party analytics FAQ owns analytics IDs. This page stays on claimed Essential labels versus runtime.

Short answer

Essential and strictly necessary are labels. A cookie audit answers a different question. Did cookies, storage, or marketing-looking requests appear before the visitor clicked Accept, including items the CMP put in an Essential bucket?

Category checkboxes are claims. Runtime cookies and network rows are what you verify. Some jurisdictions treat certain functional cookies differently from advertising. That classification is for counsel. In a test, list what appeared before a choice, note the claimed category, and flag mismatches, such as an ads ID inside Essential.

ConsentProbe can list pre-Accept findings with request and cookie surfaces. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not decide what is necessary. This page is testing guidance, not legal advice (非正式法律意见).

Labels versus runtime

Three layers get mixed when a banner says only essential cookies load. Separate them before you write the finding. Stay with present before Accept under Essential. Leave legal permission with counsel.

CMP category labels, runtime evidence, and banner screenshots.
LayerWhat it isWhat it does not prove alone
CMP Essential or Strictly necessary categoryA claimed bucket in the banner UIThat every cookie in it is lawful without consent
Runtime cookie and network evidenceWhat the browser set and requested before AcceptLegal permission, which stays with counsel
Banner screenshotThe UI claim on screenThat the network matched the category

Five-step check before Accept

Stop after these five steps if you only need the Essential-label inventory. Open the before-Accept audit for the longer method. Open the party-label guide when domain context matters. Open the pre-consent checklist for the platform-agnostic pass. Open the first-party analytics FAQ when the disputed item looks like analytics.

  1. Use a clean profile. Do not click Accept or Reject.
  2. Load the storefront once. Screenshot the CMP categories if they are visible.
  3. Capture cookies and storage. Note names the CMP, or your docs, call Essential.
  4. Capture Network for ads, analytics, and marketing hosts that still fired.
  5. Write one finding sentence per mismatch: claimed Essential, observed a marketing-style surface before choice.

Mismatch patterns you can observe

The rows below are observations from a labeled visit. They are not a statutory list of necessary cookies, and they do not name a penalty. An example finding sentence is: claimed Essential, observed an ads-style cookie on Fresh before any click.

Common Essential-label claims and the runtime red flag.
ClaimWhat you hoped to seeRed flag
Only Essential before AcceptMarketing cookies and beacons stay offAds or attribution IDs on Fresh
Analytics is EssentialA documented functional need, and timing that matches itAn analytics ID before choice, with no other check
Strictly necessary toggled on, others offNon-Essential buckets stay coldReject-looking UI with Accept-looking network

When hand-sorting Essential buckets gets slow

Checking Essential buckets across templates by hand is slow. ConsentProbe runs Fresh on the storefront URL, and Reject when that is the claim. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not decide what is necessary, does not install a CMP, and does not issue a certificate.

FAQ

Do essential cookies need consent?

Labels do not answer that. Verify what fired before Accept, and ask counsel what is lawful.

Can strictly necessary cookies fire before Accept?

Some may, under counsel's classification. An audit only shows timing and surfaces.

What if an ads cookie sits in Essential?

Treat it as a claim-versus-runtime mismatch. Capture the cookie, the request, and a screenshot. The evidence pack guide lists the file fields.

How does this differ from first-party analytics?

The first-party analytics FAQ owns that question. The same rule applies here: an observation is separate from permission.

Does ConsentProbe decide what is necessary?

No. Reports are technical observations. ConsentProbe does not install a CMP and does not classify cookies for counsel.

Is this legal advice?

No (非正式法律意见). Talk to counsel for a legal conclusion. This page is testing guidance.

Limits of this page

This page tells you how to treat Essential and strictly necessary as claimed labels and how to verify what fired before Accept. It is not legal advice (非正式法律意见), not a classification of exempt cookies, and not a certificate. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the before-Accept audit for the full protocol, the party-label guide for domain context, the pre-consent checklist for the pass order, and the first-party analytics FAQ when the item looks like analytics.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Do essential cookies need consent? | ConsentProbe