Quick Answer: Does LGPD require cookie consent?
Not for every cookie and not through one universal rule. The LGPD does not say that every website must obtain consent for every cookie. When a cookie or similar tracker processes personal data, the organization needs an appropriate LGPD legal basis and must comply with principles such as purpose, necessity, transparency, security, and accountability. ANPD guidance says legitimate interest may be appropriate for strictly necessary cookies in suitable contexts and may support limited audience measurement in some cases. For advertising cookies—especially third-party tracking, behavioral profiling, preference prediction, or cross-site tracking—the guide says legitimate interest will generally be harder to justify and that consent may be more appropriate.
Key Takeaways
- The LGPD does not create a blanket “consent for all cookies” rule. Legal basis depends on purpose and context.
- ANPD's cookie document is guidance. Its banner recommendations are non-exhaustive good practices for applying the LGPD.
- Necessary cookies and advertising cookies should not be treated alike. Their privacy impact and legal-basis analysis can be very different.
- Analytics can sometimes use legitimate interest. ANPD highlights lower-risk audience measurement using aggregated data without additional tracking or profiling as an example.
- Advertising tracking is more difficult under legitimate interest. Third-party profiling and cross-site tracking are specifically identified as higher-risk contexts where consent may be more appropriate.
- Consent must be real. No preselected consent, no forced all-or-nothing acceptance, and no assumption that continuing to browse means consent.
Cookie compliance is often implemented backward. A company buys a consent-management platform, installs a banner, creates three categories called “necessary,” “analytics,” and “marketing,” and assumes the legal analysis is finished.
The ANPD's approach points in the opposite direction. Start by understanding which personal data is processed, for which specific purpose, through which technology, for how long, by which parties, and under which legal basis. The banner is then a transparency and control layer built around that analysis—not a substitute for it.
Does Every Website in Brazil Need a Cookie Banner?
The LGPD itself does not contain a rule that literally says: “Every website must display a cookie banner.” Instead, the statute regulates personal-data processing and requires an appropriate legal basis, transparency, necessity, respect for data-subject rights, security, and other safeguards where the technology processes personal data.
The ANPD's official cookie guide describes banners as widely used mechanisms that can materialize the LGPD principles of transparency and free access. It then provides non-exhaustive good-practice recommendations for designing banners compatibly with the law.
Think of the LGPD as the legal framework and ANPD's cookie guide as an official operational interpretation and good-practice resource. The guide does not turn every cookie into a consent cookie and does not say every website needs the same banner configuration.
In practice, a website that uses non-essential tracking based on consent will usually need a mechanism capable of providing the required information, collecting the user's choice, preventing consent-based trackers from firing before the choice, and allowing the user to change that choice later.
Consent vs Legitimate Interest for Cookies
Article 7 of the LGPD contains multiple legal bases for ordinary personal data. Cookies do not sit outside that framework. ANPD explicitly says cookie processing involving personal data must be connected to an applicable legal basis and the specific requirements of that basis.
ANPD says legitimate interest may generally be appropriate in suitable cases for cookies essential to providing the service or operating the page.
Legitimate interest may work in some contexts, especially narrowly scoped measurement using aggregated data without combining trackers or building profiles.
ANPD says legitimate interest will generally be difficult where third-party cookies support behavioral profiles, preference prediction, or cross-site tracking.
When consent is used
Under Articles 5, 8, and 9, valid consent must be free, informed, unequivocal, connected to determined purposes, and capable of later withdrawal through a free and facilitated procedure. The controller also bears the burden of proving that consent was validly obtained.
In the cookie context, ANPD translates those principles into very practical expectations: a real choice to accept or reject, clear information about the purpose and retention period, consent-based trackers disabled by default, and a simple way to revoke the consent.
When legitimate interest is used
Legitimate interest is not “consent without a banner.” Article 10 requires a concrete assessment of legitimate purpose, necessity, the individual's legitimate expectations, fundamental rights and freedoms, and transparency. Only personal data strictly necessary for the intended purpose should be processed.
ANPD's cookie guide says legitimate interest may generally be appropriate for strictly necessary cookies, subject to the facts. It also says audience measurement can sometimes fit legitimate interest where risk is lower—for example, when the processing is limited to identifying aggregate patterns and trends and is not combined with other tracking mechanisms or used to create user profiles.
By contrast, the guide says legitimate interest will often be difficult to justify for advertising cookies, particularly third-party tracking connected with behavioral profiling, preference analysis or prediction, and tracking across different websites.
Necessary Cookies, Analytics and Advertising: Practical Comparison
| Category | Typical use | ANPD guidance signal | What to document |
|---|---|---|---|
| Necessary | Session, cart, authentication, security, load balancing, essential site preferences. | Legitimate interest may generally be appropriate in suitable cases, subject to the concrete assessment. | Why essential, data collected, duration, purpose, necessity, access, third parties. |
| Audience analytics | Visits, page views, performance, aggregated trends, product usage measurement. | Legitimate interest may be possible in some lower-risk contexts, especially aggregated measurement without combining trackers or profiling. | Configuration, identifiability, retention, aggregation, user profile linkage, sharing, transfer, opt-out/opposition process. |
| Advertising | Remarketing, ad personalization, conversion attribution, behavioral audiences, cross-site tracking. | Legitimate interest generally harder to justify; consent may be more appropriate, especially with third-party profiling or cross-site tracking. | Vendor, identifiers, purpose, profiling, matching, destinations, retention, consent state, withdrawal. |
| Preference | Language, region, display or non-essential personalization choices. | Depends on necessity, context, purpose, and whether personal data is processed. | User expectation, essentiality, retention, basis, ability to change the preference. |
What About Meta Pixel, Google Analytics, Ad Tags and Server-Side Tracking?
The ANPD guide is titled “Cookies and Personal Data Protection,” but the LGPD regulates personal-data processing regardless of the technology used. The guide itself emphasizes that indiscriminate personal-data collection and unlimited tracking are incompatible with the LGPD where there is no clear purpose, appropriate legal basis, transparency, or effective control.
Therefore, as an operational inference, the same privacy questions should be asked about technologies that perform similar tracking functions even if they are not technically browser cookies:
- advertising pixels;
- SDKs in mobile apps;
- local storage and similar browser storage;
- device or browser identifiers;
- conversion tags;
- server-side event forwarding;
- hashed audience uploads;
- fingerprinting or probabilistic identifiers;
- cross-device or cross-site identity systems.
Changing the transmission method from browser-side to server-side does not automatically remove the LGPD issue. If personal data is still collected, matched, enriched, profiled, shared, or used for advertising, document the processing based on what actually happens.
Google Analytics
Do not conclude that every analytics implementation can run under legitimate interest merely because ANPD mentions audience measurement as a possible legitimate-interest use case. The guide's lower-risk example is more specific: aggregate pattern and trend identification without combination with other tracking mechanisms or formation of user profiles.
Review your actual configuration: advertising features, user IDs, cross-domain measurement, data retention, integrations, granular events, CRM linkage, geographic processing, and whether the analytics data is used beyond basic audience measurement.
Meta Pixel and advertising tags
Advertising pixels often support attribution, remarketing, audience creation, optimization, behavioral inference, and data matching with third-party platforms. That pattern is much closer to the higher-risk advertising context ANPD describes than to simple aggregated audience measurement.
If consent is the selected legal basis, make sure the pixel or corresponding advertising event does not fire before the necessary consent state is obtained, and make sure withdrawal changes future tracking behavior.
Server-side tracking
Server-side tracking can improve security, performance, and data governance, but it can also make processing less visible to users. Privacy compliance depends on purpose, data, roles, legal basis, transparency, retention, recipients, and controls—not simply whether the event was sent from JavaScript or from a server.
What Should an LGPD Cookie Banner Look Like?
ANPD's guidance uses a layered model: a first-level banner with essential information and high-level choices, followed by a second-level management interface where the user can see categories and more detailed purposes.
ANPD's recommended good practices include:
What should you avoid?
ANPD specifically discourages patterns such as:
- only one first-level “Accept” button where consent is the legal basis;
- making reject/configure controls difficult to see or understand while emphasizing acceptance;
- making rejection of non-essential cookies difficult;
- non-essential cookies enabled by default;
- no second-level management interface;
- no direct mechanism for withdrawal or opposition;
- overly granular information that creates fatigue and prevents meaningful choice; and
- conditioning consent on full acceptance without effective alternatives.
Do You Need a Separate Cookie Policy?
Not necessarily. ANPD says the essential cookie information can be presented in different legitimate ways: as a dedicated section of the privacy notice, as a separate cookie policy, or through the layered banner itself. What matters is that information about cookies and personal-data collection is clear, precise, and easy to access.
For a site with a larger marketing stack, a separate cookie/tracking policy can still be operationally useful because it provides space to describe categories, vendors, purposes, retention, rights, and preference controls without turning the first-level banner into a wall of text.
How Long Can Cookies Be Kept?
ANPD connects cookie retention to the LGPD principles of purpose and necessity. Its guidance says retention should be compatible with the purpose and limited to what is strictly necessary. Indefinite, excessive, or disproportionate retention periods are described as incompatible with the LGPD.
A useful inventory therefore records duration alongside purpose and legal basis. “Persistent” is not enough. Record the actual lifetime configured by the site or vendor and explain why it is needed.
12-Point LGPD Cookie, Pixel and Tracking Audit
This is a practical screening checklist—not a substitute for a complete legal or technical assessment.
Tracking is only one part of the website's LGPD exposure.
See our LGPD for E-Commerce guide for the complete journey from advertising and cookies through checkout, payment, shipping, CRM, support and retention.
2026–2027 Regulatory Signal: Targeted Advertising Is on ANPD's Radar
ANPD's published priority map for 2026–2027 includes monitoring the secondary use of personal data for targeted commercial advertising. The same official announcement also highlights privacy-protective design and default settings in its digital-environment priorities.
This does not create a new universal cookie-consent rule by itself. It does mean that advertising, profiling, reuse of data, and privacy-by-default choices are active regulatory concerns rather than theoretical compliance topics.
Practical Examples
Example 1: Necessary session and security cookies
An e-commerce site uses a session cookie to keep products in the cart and a security cookie to detect abusive login attempts. The site documents why the technologies are necessary, limits their duration and use, provides transparency, and performs a legitimate-interest assessment appropriate to the actual facts.
Example 2: Limited audience measurement
A content site uses a privacy-minimized analytics configuration only to understand aggregate page and traffic patterns. It avoids advertising integrations, cross-site tracking, user profiles, CRM linking, and unnecessary identifiers. The controller documents its legitimate-interest assessment, transparency, retention, safeguards and opposition handling.
This fact pattern is closer to the lower-risk analytics scenario ANPD says can sometimes fit legitimate interest. It is not a blanket approval for every configuration of every analytics product.
Example 3: Advertising pixel and remarketing
A store loads a third-party advertising pixel that connects browsing behavior to ad-platform identifiers, builds audiences, optimizes campaigns, measures conversions, and supports remarketing across other sites or apps.
This is much closer to the advertising/profiling scenario for which ANPD says legitimate interest will generally be difficult to justify and consent may be more appropriate. If the store relies on consent, the implementation should prevent consent-based events from firing before valid consent and should respect later withdrawal.
Example 4: “Accept” only banner
A site says, “We use cookies to improve your experience,” and provides only an “Accept” button while advertising trackers are already active. This creates multiple concerns at once: vague purpose, lack of real choice, trackers enabled before consent, and potentially invalid consent if consent is the chosen legal basis.
Turn Your Tracking Inventory Into a Documented LGPD Review
The Brazil LGPD Compliance Playbook — 2026 Edition includes a Cookie and Tracking Inventory, Legal-Basis Decision Record, Legitimate Interest Assessment, Vendor Privacy and Security Review, International Transfer Review, Privacy Notice Framework, 100-point compliance audit, and a 30-day implementation roadmap.
Frequently Asked Questions
Does the LGPD require every website to have a cookie banner?
The LGPD does not contain a universal sentence requiring every website to display a cookie banner. When cookies or similar technologies process personal data, the processing must comply with the LGPD. ANPD's cookie guide presents banners as a common transparency/control mechanism and provides non-exhaustive good-practice recommendations.
Do all cookies require consent under the LGPD?
No. ANPD says the legal basis depends on the processing context. It notes that legitimate interest may generally be appropriate for strictly necessary cookies in suitable cases and may support limited audience measurement in some contexts. Advertising tracking, especially third-party profiling and cross-site tracking, is a more difficult legitimate-interest case.
Can analytics cookies rely on legitimate interest?
Sometimes. ANPD specifically notes that audience measurement can in certain contexts rely on legitimate interest, especially where processing is limited to aggregate patterns and trends without combination with other tracking mechanisms or formation of user profiles. A company should document the actual configuration and balancing analysis.
Can advertising pixels rely on legitimate interest?
ANPD says legitimate interest will generally be difficult to justify for advertising cookies, particularly when third-party tracking is associated with behavioral profiles, preference analysis/prediction or tracking across different websites. Consent may be more appropriate in those circumstances, subject to the facts.
Can we assume consent if the user keeps browsing?
ANPD guidance advises against tacit or inferred consent and specifically gives continued browsing as an example that should not be assumed to constitute consent. Where consent is used, a clear positive manifestation should be obtained.
Can non-essential cookies be enabled by default?
Where the cookie is based on consent, ANPD recommends that it be disabled by default. The guide specifically discourages non-essential cookies being pre-enabled and requiring users to turn them off manually.
Does a site need a “Reject non-essential” button?
ANPD's non-exhaustive good-practice recommendations say a clearly visible option to reject all non-essential cookies should be available in first- and second-level banners.
Does server-side tracking avoid LGPD cookie requirements?
Not automatically. The legal analysis follows the personal-data processing, purpose, legal basis, transparency, recipients, retention, transfers and controls. Moving a tracking event from the browser to a server changes the architecture, but does not by itself eliminate LGPD obligations.
Do we need a separate cookie policy?
Not necessarily. ANPD says cookie information can be provided as a dedicated section of the privacy notice, a separate cookie policy, or through the layered banner itself, as long as essential information is clear, precise and easy to access.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary source for definitions, principles, legal bases, consent, transparency, legitimate interest, rights, retention, security and accountability.
- ANPD — Cookies and Personal Data Protection Guidance Official guidance page for cookie-related processing under the LGPD.
- ANPD — Full Cookie Guidance PDF Primary guidance used for consent, legitimate interest, analytics, advertising, banner design, retention, and cookie-management recommendations.
- ANPD — 2026–2027 Priority Topics Official 2026 regulatory/fiscalization signal concerning targeted commercial advertising, secondary data use, and protective digital design/defaults.