Skip to content

Best practicesPart of: Cookie consent

Cookie policy: what it is, whether you need one and what it must list

A cookie policy is the page that tells visitors which cookies and similar technologies your website uses, why, who sets them and for how long. When you need one, what to put in it, and how to keep it true.

getReport teamUpdated 26 Sept 202614 min read

A cookie policy is the page on a website that tells visitors which cookies and similar technologies the site uses, what each one is for, who sets it and how long it lasts, and how to change their choice. You need one whenever your site uses cookies that need consent, because in the EU and UK consent only counts if the visitor was properly informed first. This guide explains what a cookie policy is, whether your website needs one, what it must list and how to keep it accurate. It is part of our guide to cookie consent and what the law requires.

Watch out

This guide explains the rules in plain language and names its sources, current as of September 2026. It is not legal advice. What you must disclose depends on your country, your visitors and what your site does with data; for a decision with legal consequences, ask a qualified lawyer or your data protection officer.

Quick answer

  • What it is: a plain-language page, or a section of your privacy policy, that lists each cookie or category, its purpose, who sets it, how long it lasts, and how to withdraw consent.
  • Do you need one? In the EU and UK, yes, if your site sets any cookie or tracker that is not strictly necessary. Consent without that information is not valid consent.
  • In the US, there is no federal cookie-policy law, but California's CalOPPA and the CCPA require a privacy policy that covers third-party tracking and how you handle opt-out signals.
  • It can be a separate page or part of the privacy policy. No law requires a document called "cookie policy"; what matters is that the information exists and is easy to reach.
  • Link it from the banner and the footer, and give visitors a way to reopen their cookie choice from it.
  • Keep it true: scan what your site really sets with the free cookie scanner, and update the policy when a new tag or plugin arrives.

Every website that uses cookies makes a small promise about them: what gets stored in the visitor's browser and why. The cookie policy is where that promise is written down. It answers the questions a visitor or a regulator would ask about each cookie:

  • What is it? Its name, or at least its category.
  • What does it do? Keeps the cart, measures visits, targets ads.
  • Who sets it? Your site, or a named third party such as an analytics or advertising provider.
  • How long does it last? Until the browser closes, 30 days, 13 months.
  • Can I say no? And where to change the choice later.

"Cookie" here is shorthand. EU rules cover any information stored on or read from a visitor's device, so a good cookie policy also lists local storage entries, tracking pixels and similar technologies. The European Data Protection Board's Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive name pixels and tracking links explicitly.

The cookie policy is not the banner and not the privacy policy. The banner asks the question; the cookie policy gives the details behind it; the privacy policy covers all personal data the business handles, of which cookie data is one part. Many sites fold the cookie details into the privacy policy as a section, which is perfectly acceptable.

It depends on what your site sets and who visits it.

EU and EEA visitors

Article 5(3) of the ePrivacy Directive allows storing or reading information on a visitor's device only with consent given after "clear and comprehensive information" about the purposes, in line with the GDPR. The GDPR's own definition of consent in Article 4(11) requires it to be informed, and Articles 12 and 13 set out what people must be told when their personal data is collected.

The EU Court of Justice made the cookie part concrete in Planet49 (Case C-673/17, 1 October 2019): the information must include how long cookies last and whether third parties can access them. A banner that says "we use cookies to improve your experience" with an Accept button does not meet that bar by itself. The detail has to be somewhere the visitor can reach before choosing, which in practice means a cookie policy or a second layer of the banner, linked from the first.

Only strictly necessary cookies?

The ePrivacy exemption for strictly necessary cookies (the login session, the cart, the consent cookie, security tokens) removes the consent requirement. Most regulators still recommend telling visitors about them, and the UK's Information Commissioner's Office says so in its guidance on storage and access technologies. If those cookies hold personal data, the GDPR's transparency duties apply anyway. A short section in your privacy policy that lists them is enough.

UK visitors

The UK follows the same model under PECR. The Data (Use and Access) Act 2025 added exceptions, in force since 5 February 2026, for some first-party analytics cookies and cookies that remember appearance preferences. Those no longer need consent, but only if you give clear information about them and a simple, free way to object. In the UK, then, a cookie policy is the condition for using the new exceptions, not a formality they replaced.

US visitors

The US has no cookie consent law in the EU sense, but two California laws still reach your policy:

  • CalOPPA (California Business and Professions Code sections 22575–22579) requires commercial websites that collect personally identifiable information from California residents to post a privacy policy. Since 2014 it must say how the site responds to "Do Not Track" signals and whether third parties may collect personal information about visitors' activity over time and across sites. That is a cookie disclosure in all but name.
  • The CCPA, as amended by the CPRA, requires covered businesses to publish a privacy policy listing the categories of personal information collected, including identifiers such as cookie IDs, and whether they are sold or shared. It also requires a notice at collection. Our guide to what the CCPA requires from a cookie banner covers the opt-out side.

Other US states with comprehensive privacy laws have similar privacy-notice duties. For a US site, the practical answer is the same: describe your cookies and trackers, in a policy of your own or a section of your privacy policy.

A policy that satisfies the EU standard, and serves everyone else too, covers seven things.

ItemWhat to writeWhy
Who you areBusiness name and contact details, or a link to themGDPR Article 13
What cookies areOne or two sentences, with a link to moreVisitors cannot consent to what they do not understand
CategoriesStrictly necessary, preferences, statistics, marketingConsent is given per purpose
Each cookie or trackerName, provider, purpose, first or third party, durationPlanet49: duration and third-party access
Third partiesNamed companies and links to their privacy policiesVisitors must know who receives data
TransfersCountries outside the EU/UK and the safeguard usedGDPR Articles 13 and 44–49
Your choiceHow to change or withdraw consent, with a link or button that reopens the bannerWithdrawing must be as easy as giving consent (GDPR Article 7(3))

Add the date of the last update at the top. Visitors and auditors both look for it.

The core of the policy is a table. A typical row looks like this:

NameProviderPurposeCategoryTypeDuration
session_idexample-shop.hrKeeps you logged in and holds your cartStrictly necessaryFirst-party HTTP cookieSession
consentexample-shop.hrRemembers your cookie choiceStrictly necessaryFirst-party HTTP cookie6 months
_gaGoogle (Google Analytics)Distinguishes visitors to count visitsStatisticsFirst-party HTTP cookie13 months
_fbpMeta (Meta Pixel)Measures and targets adsMarketingFirst-party HTTP cookie3 months

Write the purpose for a person, not a lawyer: "counts how many people visit each page" beats "analytical processing for statistical purposes". Match the durations to what the site really sets; the cookie lifetime fix page explains why 13 months is the common ceiling in EU guidance.

How to write the intro

Keep the text around the table short and in your own voice. Something like:

We use cookies and similar technologies on this site. Some are needed for the site to work, such as keeping your basket. Others help us count visits or show relevant ads, and we only use those if you say yes. The table below lists every cookie, who sets it and how long it lasts. You can change your choice at any time with the "Cookie settings" link at the bottom of every page.

Put the cookie policy where people meet the choice:

  • In the banner, as a link on the first layer ("Read our cookie policy"), and with vendor details on the second layer.
  • In the footer of every page, next to the privacy policy. Many sites add a "Cookie settings" link there too, which reopens the banner.
  • In the privacy policy, with a link to the cookie section or page.

The report's privacy policy check looks for the footer link to a privacy notice; our guide to privacy policy and contact links covers what that page needs.

How to build the list of cookies

The hard part of a cookie policy is not the wording but the list. Themes, plugins, tag managers and embedded videos all set cookies nobody wrote down. Start from what the site does, not from memory:

  1. Scan the page as a first-time visitor. The free cookie scanner loads your page in a fresh browser, records every cookie before and after it clicks Accept, and classifies each one by name, lifetime and first or third party.
  1. Scan your key templates too: the home page, a product or article page, the contact form and the checkout. A chat widget or a map embed may appear on only one of them.
  2. Check the browser yourself. In Chrome DevTools, Application → Storage → Cookies and Local storage show everything the page stored, with expiry dates.
  3. Ask your consent platform. Most consent management platforms scan the site and generate the cookie table. Check their output against your own scan; a cookie the platform has not categorised may be missing from the policy or in the wrong category.
  4. Add what the browser cannot see: server-side tagging and conversion APIs send data to third parties without any cookie in the browser. They belong in the privacy policy.

The report adds the findings that show when the policy and reality have drifted apart:

Keeping the policy true

A cookie policy is out of date the day someone adds a new tag. Treat it like code:

  • Re-scan after every change to Tag Manager, a plugin, the theme or an embed, and at least monthly. The monthly site health routine includes it.
  • Update the date whenever the table changes.
  • Ask again when purposes change. If you add a new category, such as advertising on a site that only did statistics, visitors who consented earlier have not agreed to it.
  • Remove what is gone. A table listing trackers you no longer use makes the whole policy less credible.

On WordPress, consent plugins can generate and update the policy for you; see our guide to choosing a WordPress cookie consent plugin. WordPress core also includes a privacy policy page template under Settings → Privacy, which reminds you to describe cookies but does not list them for you.

Common mistakes

  • A generic template that lists cookies you do not use, and misses the ones you do.
  • "We use cookies to improve your experience" as the whole policy. It names no purpose, no provider and no duration.
  • Hiding the policy behind the cookie wall it describes, or making it load only after Accept.
  • No way to change the choice from the policy page.
  • Calling analytics cookies "necessary" in the table to avoid asking for consent.
  • Durations copied from the vendor's marketing page instead of what the browser really stores.

Questions people ask

A cookie policy is a page, or a section of the privacy policy, that tells visitors which cookies and similar technologies the website uses. For each one it names the purpose, who sets it, whether it is first or third party, and how long it lasts, and it explains how to accept, refuse or change the choice. It is the information behind the cookie banner's question.

Not for every site, but for most. In the EU and UK, any site that sets cookies needing consent must give clear information first, which is what a cookie policy does. Sites with only strictly necessary cookies are exempt from consent, though regulators still recommend describing them. In the US, California's CalOPPA requires a privacy policy that covers third-party tracking.

Yes. No EU, UK or US law requires a separate document called a cookie policy. A clearly headed cookie section inside your privacy policy is fine, as long as it lists the cookies and trackers, their purposes, providers and durations, and is linked from the cookie banner. A separate page is easier to link and to keep updated, which is why many sites use one.

Update it whenever the cookies change: a new plugin, tag, embed or advertising partner, or a tracker you removed. In practice, re-scan the site after every Tag Manager or plugin change and at least once a month, and change the "last updated" date each time the table changes. If you add a new purpose, ask visitors for consent again.

You can, as a starting point. Generators write the standard wording, and consent platforms can build the cookie table from their own scan. Neither knows what your site really sets on every page, so compare the table with a first-visit scan of your key pages, fix categories and durations, and remove cookies you do not use before publishing.

Check your site before and after Check