How Should E-Commerce Sites Obtain Cookie Consent?
Introduction
Online retailers commonly use cookies and similar technologies to remember user preferences, measure website activity, personalize advertisements, prevent fraud, and monitor browsing behavior. These activities may involve the collection and processing of personal information under the Data Privacy Act of 2012 (DPA).
The central compliance question is whether a website visitor has been given a genuine and informed choice before tracking begins. A pop-up that merely states “By continuing to browse, you agree to our Privacy Policy” may not, by itself, establish legally valid consent for behavioral tracking or direct marketing.
Retailers should distinguish between a privacy notice, which explains processing, and a consent mechanism, which records the data subject’s affirmative agreement to a specified processing activity. This distinction is reflected in the DPA, its Implementing Rules and Regulations, and the National Privacy Commission’s consent guidelines.
What Law Governs Cookie-Based Tracking?
The DPA applies when cookies or related technologies collect information from which an individual’s identity is apparent or can reasonably and directly be ascertained, either by the entity holding the information or by combining the information with other data. This may include account identifiers, device information, online identifiers, browsing activity, and information linked to a customer profile.
Under Section 12 of R.A. No. 10173, personal information may be processed only when processing is not prohibited by law and at least one lawful basis exists. These bases include consent, contractual necessity, compliance with a legal obligation, protection of vital interests, public authority functions, and legitimate interests that are not overridden by the data subject’s fundamental rights and freedoms.
The same general approach appears in Rule V, Section 21 of the IRR of R.A. No. 10173. Accordingly, consent is not automatically required for every cookie. The retailer must first identify the purpose of the cookie and determine the lawful basis that applies.
For example, a cookie strictly necessary to maintain a shopping-cart session may be connected with the performance of a transaction. By contrast, a cookie used to construct a behavioral advertising profile or to transmit browsing activity to advertising partners ordinarily requires closer scrutiny and, where consent is relied upon, a valid opt-in mechanism.
When Is Consent Required?
Consent is required when it is the lawful basis selected by the retailer for the relevant processing. Consent may also be appropriate where tracking is used for purposes that are not necessary to provide the requested online service, such as behavioral advertising, cross-site profiling, audience measurement involving identifiable users, or sharing browsing information with marketing partners.
Consent under Section 3(b) of R.A. No. 10173 must be a freely given, specific, and informed indication of will. It must be evidenced by written, electronic, or recorded means. The consent must relate to the particular processing activity and may be given by an authorized agent only when the agent has specific authority to do so.
The DPA does not permit a retailer to treat every click, continued visit, or acceptance of a general privacy policy as conclusive consent. The validity of the mechanism depends on the clarity of the information supplied, the availability of a real choice, the specificity of the purpose, and the retailer’s ability to prove what the user accepted.
Privacy Notices Are Not Consent Forms
A privacy notice is a disclosure document. It should explain what information is collected, why it is collected, how it is used, whether it is shared, who controls the processing, what risks and safeguards exist, and how the data subject may exercise privacy rights.
A consent form or consent interface, on the other hand, records the data subject’s agreement to a specified processing activity. The National Privacy Commission has expressly distinguished a privacy notice from a consent form: a privacy notice is a unilateral disclosure, while a consent form communicates the controller’s proposal to process data for a declared purpose and records the data subject’s acceptance.
This distinction was also emphasized in NPC 19-910, where the NPC stated that merely requiring users to agree to a privacy policy or notice does not necessarily amount to obtaining consent. A bundled consent mechanism generally fails when the user is not given a genuine choice about the specific processing activity. See NPC 19-910 (2020) and NPC Circular No. 2023-04 (2023).
What Must a Compliant Cookie Pop-Up Contain?
A cookie pop-up should give the visitor enough information to make an informed decision without requiring the visitor to search through lengthy legal terms. Under Section 9 of NPC Circular No. 2023-04, the information must be relevant, understandable to an average member of the intended audience, and presented in a suitable language or dialect.
At a minimum, the interface should identify:
- The categories of cookies or tracking technologies, such as strictly necessary, preference, analytics, advertising, or social-media technologies;
- The purpose of each category, including whether the technology is used for cart functionality, analytics, personalization, profiling, direct marketing, fraud prevention, or measurement;
- The parties receiving or accessing the information, particularly advertising networks, analytics providers, payment providers, and other third parties;
- Whether the activity is necessary for the requested service or is optional and dependent on consent; and
- How the user may accept, reject, modify, or later withdraw consent.
The pop-up should not make optional tracking appear mandatory. A visitor should be able to reject non-essential cookies through a mechanism that is as accessible as the acceptance mechanism.
Specific and Granular Consent
Consent must be specific to the declared processing purpose. Section 8 of NPC Circular No. 2023-04 requires consent to be granular when personal data is processed for multiple unrelated purposes. A retailer should therefore avoid one undifferentiated button covering analytics, personalized advertising, data sharing, and cross-site tracking.
A more defensible structure would permit separate choices, such as:
| Processing activity | Suggested consent treatment |
|---|---|
| Maintaining a shopping cart or login session | Explain the necessity and applicable lawful basis; do not present it as optional advertising consent. |
| Audience analytics linked to identifiable users | Present a separate explanation and opt-in where consent is the selected lawful basis. |
| Behavioral advertising and profiling | Use a separate, affirmative, purpose-specific opt-in. |
| Sharing browsing data with advertising partners | Identify the relevant purpose and recipients, then obtain separate consent when consent is relied upon. |
A single “Accept all” button may be offered, but it should be accompanied by an equally visible means to reject or customize optional processing. Preselected boxes and interfaces that steer users toward acceptance create risks under the requirements of freely given and informed consent.
Freely Given Consent and Deceptive Design
Consent is freely given only when the user has a real choice. The data subject must not be deceived, intimidated, or coerced into agreeing to the processing. This principle was discussed in NPC 19-134 (2021), which described valid consent as freely given, specific, informed, and evidenced by written, electronic, or recorded means.
A retailer should avoid design practices such as:
- using a prominent colored “Accept” button while hiding “Reject” in faint or difficult-to-find text;
- prechecking optional advertising or analytics boxes;
- describing rejection as a negative or inconvenient choice;
- requiring acceptance of unrelated marketing tracking before allowing a purchase; and
- placing several unrelated processing purposes under one compulsory “Agree” button.
The website should also avoid treating continued browsing as consent unless the legal and factual circumstances genuinely support that conclusion. An affirmative selection that identifies the purpose of processing is generally easier to demonstrate than an inference based solely on inactivity or continued use.
Consent, Contracts, and Necessary Cookies
Consent should not be requested where another lawful basis already applies and consent is unnecessary. Section 9 of NPC Circular No. 2023-04 recognizes that requesting consent when another lawful basis governs may contribute to consent fatigue.
For example, a retailer may need certain cookies to authenticate a user, preserve a shopping cart, secure a transaction, or maintain essential website functions. These activities may be evaluated under contractual necessity or another applicable lawful basis, depending on the facts and the precise processing involved.
That does not mean that all cookies used on an e-commerce website are necessary. A cookie that is useful to the retailer but unrelated to the requested service—such as a cookie used to build an advertising profile—should not automatically be characterized as essential merely because it produces commercial value.
NPC Circular No. 2023-04 also recognizes that a contract of adhesion may contain provisions concerning the processing of personal data, provided that transparency, legitimate purpose, proportionality, and fair and lawful processing requirements are satisfied. Contractual language, however, should not be used to conceal optional marketing tracking or to eliminate the user’s genuine choice.
Transparency, Legitimate Purpose, and Proportionality
Rule IV, Section 18 of the IRR of R.A. No. 10173 requires adherence to transparency, legitimate purpose, and proportionality.
Transparency requires the data subject to understand the nature, purpose, and extent of processing, including relevant risks, safeguards, the identity of the personal information controller, and the data subject’s rights.
Legitimate purpose requires processing to be compatible with a declared and specified purpose that is not contrary to law, morals, or public policy.
Proportionality requires processing to be adequate, relevant, suitable, necessary, and not excessive in relation to the declared purpose. Personal data should not be collected through tracking technologies when the same purpose can reasonably be achieved by less intrusive means.
These principles require a retailer to examine not only whether a visitor clicked an acceptance button, but also whether the tracking itself is reasonably connected to the stated purpose and limited to what is needed.
Direct Marketing and User Objections
Direct marketing includes communications containing advertising or marketing material directed to particular individuals. The DPA and its IRR recognize the data subject’s right to object to processing, including processing for direct marketing, automated processing, or profiling.
Under Rule VIII, Section 34 of the IRR of R.A. No. 10173, a data subject who objects or withholds consent should generally no longer have personal data processed, subject to recognized exceptions such as processing required by subpoena, processing necessary for the performance of a contract or service, or processing required by law.
Retailers should therefore connect their cookie-consent system with their marketing preference system. A user who withdraws consent to behavioral advertising should not continue to receive the same tracking treatment merely because the original cookie remains active.
Withdrawing Consent and Managing Consent Records
Consent must be capable of being withdrawn. A withdrawal mechanism should be easy to locate and use, such as a persistent privacy-preference link in the website footer or account settings.
Withdrawal should not require the user to repeat the entire registration or purchasing process. The retailer should explain the effect of withdrawal, including whether certain optional features will stop working and whether previously collected information will be retained under another lawful basis.
Under Section 12 of NPC Circular No. 2023-04, a personal information controller must be able to demonstrate, with sufficient evidence, that consent was obtained for the particular purpose. The retailer should maintain records showing:
- the version of the consent notice presented;
- the date and time of the user’s choice;
- the categories and purposes accepted;
- the mechanism used to obtain consent;
- any later modification or withdrawal; and
- the relevant changes to the consent interface or privacy information.
The record should be limited to what is needed to demonstrate consent. Maintaining excessive information about the user merely to prove consent may itself raise proportionality and data-minimization concerns.
Marketing Communications and the Cybercrime Prevention Act
Cookie consent does not resolve every issue involving electronic marketing. The transmission of unsolicited commercial communications is separately addressed in Section 4(c)(3) of R.A. No. 10175, the Cybercrime Prevention Act of 2012, as discussed in Disini, Jr. v. Secretary of Justice, G.R. No. 203335, 2014.
Commercial electronic communications are prohibited unless the recipient gave prior affirmative consent, the communication is primarily a service or administrative announcement to an existing user, subscriber, or customer, or the communication satisfies the statutory conditions concerning an effective opt-out mechanism, truthful identification of the source, and the absence of misleading information intended to induce the recipient to read the message.
Accordingly, a retailer should separately manage: website tracking consent, consent for personalized advertising, consent for email or text marketing, and the user’s ability to opt out of future commercial communications.
Common Cookie-Consent Defects
The following practices create significant compliance concerns:
- placing all cookies under one mandatory acceptance button;
- calling advertising or profiling cookies “essential” without a service-related justification;
- using the privacy policy as the only evidence of consent;
- failing to identify third-party advertising or analytics recipients;
- using prechecked boxes for optional processing;
- making rejection more difficult than acceptance;
- continuing optional tracking after consent has been withdrawn; and
- keeping no reliable record of the user’s specific choices.
The NPC’s order in CID CDO 25-001, In the Matter of World App Processing of Personal Information (2025) further illustrates the importance of specific and granular consent. The order distinguished a privacy notice from a consent form and stated that consent for multiple unrelated purposes should not be presented as an all-inclusive choice.
Recommended Website Pop-Up Structure
An e-commerce website may use the following structure, subject to review against its actual processing activities:
First layer: State that the website uses necessary cookies and, subject to the user’s choice, optional analytics, personalization, and advertising cookies. Provide a short description of each purpose and show separate options to accept optional cookies, reject optional cookies, or manage preferences.
Second layer: Present a settings panel with separate categories and clear descriptions. Optional categories should not be preselected. If data is shared with third parties, identify the relevant recipients or provide sufficiently specific information about the recipient categories and their purposes.
Third layer: Provide the detailed privacy and cookie information, including retention, withdrawal, data-subject rights, complaint procedures, and the identity and contact details of the personal information controller.
After consent: Store evidence of the user’s selections, activate optional technologies only after the applicable choice, and provide a continuing means to change or withdraw consent.
Recommendations for Online Retailers
Online retailers should conduct a cookie audit before designing the pop-up. The audit should identify every cookie, software development kit, pixel, tag, local-storage mechanism, and third-party connection operating on the website or mobile application.
For each technology, the retailer should document its purpose, data collected, recipients, retention period, applicable lawful basis, and whether it is necessary for the requested service. The retailer should then align the consent interface with that documented assessment.
The retailer should also test the interface from the perspective of an ordinary user. The acceptance and rejection options should be equally visible, the wording should be understandable, and the system should not activate optional tracking before the required choice is recorded.
Finally, consent records, privacy notices, cookie inventories, vendor agreements, and preference-management procedures should be reviewed whenever the website, advertising tools, analytics provider, or processing purposes change.
Conclusion
A legally defensible cookie pop-up must do more than announce that the website uses cookies. It must provide understandable information, separate necessary processing from optional tracking, obtain a genuine and purpose-specific choice where consent is relied upon, permit withdrawal, and preserve sufficient evidence of the user’s decision.
For online retailers, the safest approach is to treat behavioral advertising, profiling, and non-essential sharing as distinct processing activities rather than placing them under a single blanket acceptance. Compliance should be built into the website’s design, vendor controls, consent records, and marketing procedures from the beginning.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

