Not automatically. According to Traficom's guidance, a site that uses only strictly necessary cookies or similar technologies does not need consent for their use. If it uses non-essential technologies for analytics, advertising targeting or certain third-party content, consent is generally required before they are used.
The answer does not depend on whether the business is small or large. It depends on what the website does on the user's device.
What is a cookie?
A cookie is a small piece of information that an online service can store in a user's browser or read from it later.
The same rules can also apply to technologies other than conventional cookies. Checking the browser's cookie list alone may therefore miss part of the picture.
Which cookies do not require consent?
Traficom says consent is not required when storing or using the information is necessary:
- to transmit a communication over a communications network, or
- to provide a service explicitly requested by the user
Examples may include technical measures genuinely needed for certain login, security, shopping basket or user-requested form functions.
It is good practice to explain these uses openly too.
When is consent usually needed?
Common things to check include:
- visitor analytics
- marketing pixels
- remarketing
- behavioural tracking
- social media embeds
- video or map embeds that load third-party tracking
- chat tools and other additional services
A tool being useful to the business does not make it technically necessary for the user.
Where consent is required, non-essential technologies should not start before the user makes a choice.
What became clearer in Finland in 2026?
In August 2026, Finland's Supreme Administrative Court upheld Traficom's interpretation in two precedents, KHO:2026:64 and KHO:2026:65.
For businesses, three points are particularly relevant:
- The exemption from consent is interpreted narrowly. The technology must be genuinely necessary to provide the service the user explicitly requested.
- The rules are not limited to conventional cookies. Other network requests that read information from the user's device can also fall within their scope.
- Rejecting non-essential technologies must be as easy as accepting them. Choices must not steer users towards accepting by making refusal substantially harder.
That makes checking how tools actually operate more important than simply having some kind of banner on the page.
A cookie banner is more than a notice
A poor implementation displays “we use cookies” while loading analytics and marketing tools before the user does anything.
If consent is needed, the banner or other consent controls must actually govern which technologies start.
Traficom also stresses the need to explain clearly which technologies are used, their purposes and duration, and any third parties involved.
Do you need a banner if you do not use analytics?
Possibly not, provided the site has no other technologies that require consent.
Check the actual implementation rather than assuming. An external video, chat, map or spam protection tool may introduce its own technologies.
Review the site's tools as a whole.
What about Google Analytics?
Assess visitor analytics separately for consent requirements. In Finland, Traficom's starting point is that only necessary cookies are exempt.
Do not switch analytics on automatically just because “every website has Analytics”.
What should a business owner do?
- List the website's external tools, embeds and tracking technologies.
- Establish whether they store or read information on the user's device.
- Separate genuinely necessary purposes from other uses.
- Where consent is required, prevent non-essential technologies from starting before the user's choice.
- Make acceptance and rejection equally easy.
- Explain the use clearly in your cookie notice or privacy information.
- Make it easy to change previous choices.
- Review the implementation again whenever new tools are added.
This article provides an overview. If the processing is unclear or your business handles sensitive information, assess the situation separately with an appropriate specialist.
Sources: Finnish Transport and Communications Agency Traficom / National Cyber Security Centre Finland, Evästeet (Cookies) and Korkein hallinto-oikeus vahvisti Traficomin tulkintoja evästeiden käytöstä (28 August 2026). KHO:2026:64 and KHO:2026:65. The EU's Your Europe service, Online privacy.
