Leyes de Consentimiento de Cookies por País: Guía Completa (2026)

Verificado de forma independiente contra fuentes primarias (última auditoría: 10 de septiembre de 2026). · Revisado por el equipo editorial de RecordingLaw. · Ley verificada como vigente al 10 de septiembre de 2026. · 22 fuentes primarias citadas en esta página. Cómo verificamos nuestro contenido legal

Leyes de Consentimiento de Cookies por País: Guía Completa (2026)

Actualizaciones

Corrected the UK DUAA cookie exemptions (they are conditional on giving users information and a free way to object, not automatic), the claim that no US state ever requires opt-in consent (Washington health data and Connecticut sensitive data and known-minor advertising do), Switzerland's inform-and-object regime and Canada's penalty picture including Quebec's Law 25 tracking rule, Spain's LSSI cookie fine band, the current list of states requiring a universal opt-out signal, the non-binding status of the EDPB cookie banner taskforce report, the outcome of Meta's court challenge, and stale entries on France, Vietnam, India, Nigeria, the UAE, Germany, Australia and the EU Digital Omnibus. Corrected the last remaining FAQ answer that described the UK DUAA cookie exemptions as automatic (they apply only where users get clear information and a simple free way to object), put the count of states that require honoring a browser-level opt-out signal on one consistent test and added Nebraska for twelve, corrected the German Federal Court of Justice cookie ruling to 28 May 2020 (I ZR 7/16), corrected Brazil's ANPD position to allow legitimate interest for aggregate audience measurement while treating consent as the appropriate basis for advertising cookies, removed two unsourced claims that the CNIL's September 2025 fines were the largest anywhere, repointed the California Privacy Protection Agency link to the agency's own sweep announcement, cited the Commission annex that contains the ePrivacy withdrawal quotes, qualified the US and India rows of the comparison table, and moved Switzerland out of the Middle East and Africa section.

Verificado de forma independiente contra las fuentes primarias citadas; ley aplicable revisada en busca de cambios recientes

Actualización mayor: se agregó el retiro del Reglamento ePrivacy (febrero de 2025), la propuesta de Ómnibus Digital de la UE sobre cookies (noviembre de 2025), los cambios de la DUAA 2025 del Reino Unido a la PECR, el Dictamen 08/2024 del CEPD sobre 'consentimiento o pago', el mandato multiestatal del GPC, las Reglas DPDP 2025 de India, las enmiendas de 2024 a la Ley de Privacidad de Australia, secciones ampliadas por país y mayor detalle sobre la aplicación de la norma. Se amplió de aproximadamente 2.350 a 4.500 palabras.

Revisado y aprobado por un editor

Publicación inicial.

Fuentes y referencias

  1. Directiva ePrivacy 2002/58/CE(eur-lex.europa.eu).gov
  2. TJUE, Asunto C-673/17 (Planet49)(curia.europa.eu).gov
  3. Informe del Grupo de Trabajo del CEPD sobre Banners de Cookies(edpb.europa.eu).gov
  4. Dictamen 08/2024 del CEPD sobre Consentimiento o Pago(edpb.europa.eu).gov
  5. Directrices sobre Cookies de la CNIL(cnil.fr).gov
  6. Directrices sobre Cookies del Garante italiano(garanteprivacy.it).gov
  7. PECR del Reino Unido, 2003(legislation.gov.uk).gov
  8. ICO - Ley de Datos (Uso y Acceso) 2025(ico.org.uk).gov
  9. Guía de Cookies de la ICO(ico.org.uk).gov
  10. CCPA de California(oag.ca.gov).gov
  11. Especificación W3C del Global Privacy Control(w3.org)
  12. PIPEDA de Canadá(laws-lois.justice.gc.ca).gov
  13. CASL de Canadá(laws-lois.justice.gc.ca).gov
  14. OPC de Canadá(priv.gc.ca).gov
  15. LGPD de Brasil(planalto.gov.br).gov
  16. ANPD de Brasil(gov.br).gov
  17. PIPL de China(npc.gov.cn).gov
  18. PPC de Japón, APPI(ppc.go.jp).gov
  19. PIPC de Corea del Sur, PIPA(pipc.go.kr).gov
  20. Reglas DPDP 2025 de India(meity.gov.in).gov
  21. Ley de Privacidad de Australia de 1988(legislation.gov.au).gov
  22. OAIC de Australia(oaic.gov.au).gov
  23. LSSI de España, Ley 34/2002(boe.es).gov
Compartir: