Do you use cookies or another similar form of tracking technology on your website?
While these solutions can be incredibly useful for gathering customer insights to create personalized marketing content, you must be cautious.
There are numerous laws, including the General Data Protection Regulation (GDPR) and the California Consumer Protection Act (CCPA), regulating the use of cookies. Fail to comply with these, and you’re likely to face serious consequences.
Having a comprehensive cookie policy is an integral part of following the rules, but it also helps maintain ethical practice and respect user privacy.
Download our free cookies policy template today, and read on to learn more about this area of privacy control.
Cookies are small text files that your website stores on the user’s device to gather information about them while they’re browsing. They allow your site to remember things about their visit, like the user’s device and how they interacted with your pages. This information isn’t just handy for the visitor; it also gives you useful insights into how people are using your site.
For users, cookies can:
For companies, cookies on your site can:
Not all cookies are built equal, though. In fact, there are different types, categorized by ownership, purpose, and duration.
First-party cookies are set directly by you to gather data as well as make your site easier to use and improve visitor experience. Third-party cookies, on the other hand, come from external services (like advertising networks or social media plugins) and often track users across multiple websites.
Then there's the difference in duration, starting with session cookies. These are temporary and only last while a visitor is browsing your site, whereas persistent cookies stick around until they’re deleted or expire, even after the browser is closed. It’s these cookies that can help remember login details or returning visitor preferences.
You may have heard of a privacy policy, which is a document outlining all your data processing activities for legal purposes. A cookie policy is similar, but more specific, as it exclusively deals with your use of cookies.
Your cookie policy page should provide users with detailed information about the types of cookies your website uses and how they’re used. It should also explain what controls you have in place to allow users to customize, limit, or prevent the placing of cookies on their devices.
But where should your cookie policy reside? The best practice is to display a cookie banner (otherwise known as a cookie notice) on your site to inform visitors of their use and allow them to accept or deny. Your cookie policy can be linked in this banner.
Is it mandatory to have a cookie policy? As we noted earlier, there are a number of laws regulating the use of cookies, and many of them insist that websites should have a cookie policy. In fact, it’s required by both the EU and the US, among other places.
The two main policies affecting cookie usage in the EU are the GDPR and the ePrivacy Directive (or the EU Cookie Law, as it’s sometimes known).
The GDPR was enacted in 2018 and is a broad regulation covering the use of any personal data. Cookies can be regarded as personal identifiers under Recital 30 if they can identify a user through their tracking. In this case, GDPR rules apply. You need explicit consent to use them and must provide complete transparency about what data is collected and how it’s used.
While the GDPR has a broader focus on overall privacy protection, the EU Cookie Law is more specific to regulating tracking technologies. It requires you to:
So, to be clear, it’s not enough to have pre-ticked boxes or assume a user’s silence means they agree. Consent must be given through an explicit action to avoid any ambiguity. The most common way to do this is via a button on the cookie banner or notice, which pops up when users first visit a website.
Want the full picture? Read our EU Cookie Law: The Online Privacy Compliance Guide
The US has separate, state-regulated policies concerning data privacy (rather than a wider federal law). The first and most well-known of these is California’s CCPA/CPRA.
Like the GDPR, this law protects consumers’ personal information, which, under its definition of this term, can include cookies that are used to potentially identify users. Under the CCPA/CPRA, businesses must disclose in a policy what categories of personal information (including cookie data) they collect, how it’s used, and with whom it’s shared.
The main difference between the CCPA and the GDPR? California’s law doesn’t require explicit opt-in to cookie usage like the GDPR does. Businesses don’t need prior permission to set cookies. However, if they’re used for selling or sharing personal information, then users must have the ability to opt out.
Looking for an easier way to stay compliant? Try Osano Cookie Consent and let us handle the hard work for you.
It’s common practice to have a section on cookies within your wider privacy policy, but do you need to have a separate cookie policy distinct from this document, too? Technically, it’s not strictly required. The EU and US laws mentioned above don’t specify that you need to have a dedicated cookie policy, but they do mandate that you provide comprehensive and detailed information on your use of cookies in an easily accessible format.
Because of this, it’s recommended that you set apart your cookie policy and privacy policy for clarity and to promote depth of information. What’s more, you can link to your cookie policy from your cookie notice/banner, promoting transparency around usage, which is in line with compliance.
According to data privacy and cookie-specific regulations, there are some bits of information that must be readily available to consumers in the name of transparency. So, in order to stay compliant and respect your website users’ rights, the following information should be detailed in your cookie policy:
The best way to start your cookie policy is by letting users know that cookies are in use. That way, you’re being clear and open from the start. But not everyone might immediately understand what a cookie is and what the implications of using them are, so it’s important to follow your initial declaration up with a simple, easy-to-comprehend definition and explanation.
Under data privacy law, users must be able to select which information they choose to share with companies. In order to do that, they need to know precisely what cookies you wish to place and what each of their functions is. This way, they can make an informed decision on what they're comfortable sharing and what they would rather not.
This section is also a good place to highlight any third parties that run cookies on your site, such as Google Analytics, for instance.
This clause is similar to the previous one, but worth exploring separately to provide greater depth of information. For example, your declaration of what types of cookies you use may be accompanied by general descriptions, while this point discusses specifically how each cookie is used by your business.
Is its purpose to remember login details for easy website access in the future? Or is it to document user activity for the purpose of targeted ads? This information is likely to have an impact on whether users consent to the use of different cookies.
It’s not enough to give users the option of opting out of cookies; you also need to provide useful information on how to do this. So, a section of your cookie policy should be dedicated to clearly walking users through this process. This might include directing them to browser settings or your cookie banner, or providing a direct link to opt out from within your policy itself.
How should you end your cookie policy? To stay accountable, you should finish by including your company contact details. This lets users know exactly who is responsible for the website and data practices, and gives them a clear way to reach you if they have any questions about cookies or wish to exercise their rights.
Lastly, you should keep a record within the document of when your cookie policy was last reviewed or updated and what was changed. This is part of a good cookie governance process. It also builds trust, demonstrating that you’re proactive in maintaining compliant privacy practices as your cookie practices inevitably change over time.
Still not sure where to begin when creating your organization’s own cookie policy? Download our free template below to get a head start. We’ve included all essential sections, including explaining what a cookie is for your users. All you have to do is customize it to reflect your own use of tracking technology.