A strictly necessary cookie is a cookie that is technically required for a website's core functions to work. It enables features such as session management, security verification, shopping carts and language preferences. Because it is needed to deliver a service the visitor explicitly requested, no consent is required for it, but the duty to inform remains.
The core distinction in cookie regulation is between necessary and non-essential cookies. Under the EU ePrivacy rules, cookies that are strictly necessary for carrying out communication or for providing a service explicitly requested by the user are exempt from the consent requirement, and the Turkish authority's cookie guidance takes the same approach. Typical examples include session ID cookies, security and bot-protection cookies, load balancing, shopping cart contents and the cookie that stores the visitor's own consent choice.
A cookie being useful to the site owner does not make it necessary: analytics or personalisation cookies do not qualify, because the site works without them. The test is technical necessity for the service, not business preference. Site owners should build a cookie inventory, classify each cookie honestly, list necessary cookies in the cookie policy with purpose and duration, and block everything else until consent is given. Labelling analytics or marketing cookies as necessary to avoid the consent requirement is a common mistake that makes the disclosure misleading.
Frequently asked questions
Do strictly necessary cookies require consent?
No. Cookies that are technically required for the site's core functions or for a service the visitor explicitly requested are exempt from consent. The duty to inform still applies: these cookies should be listed in the cookie policy with name, purpose and duration. In the banner, the necessary category is typically shown as always active and cannot be switched off.
How do you decide whether a cookie is strictly necessary?
The test is: can the service the visitor requested be delivered technically without this cookie? If yes, the cookie is not necessary. Session, security and cart cookies pass this test; analytics, personalisation and advertising cookies do not. In borderline cases, look at the cookie's purpose and who benefits: if the benefit mostly goes to the site operator, obtaining consent is the safe approach.
This content is for information only and is not legal advice.