Skip to Content Skip to Navigation

You’ve seen alerts about them pop up around the web, but what exactly are cookies and how do they affect online privacy?

Cookies are small text files that get stored on a user’s device each time they visit a website or app. They collect information such as website activity, browser settings and login credentials to support features like targeted ads, shopping carts, and auto-filling web forms.

While cookies were designed to improve online experiences by “remembering” information about users, the potential for bad actors to use cookies for compiling unique behavioural profiles about people has been flagged as a threat to user privacy.

Regulators in the European Union acknowledge concerns about unwanted tracking and advertising, as well as the risk that such personal data could be shared or sold to third parties without user consent.

To address these concerns, the EU cookie law was created: ordering all websites that operate in the EU to disclose the usage of cookies and get informed consent from visitors before collecting any information.

Types of cookies and what they’re used for

There are four main types of cookies to consider for your cookie privacy policy:

Essential cookies, which enable core website features like shopping carts and user accounts.

Performance cookies, which track usage trends and user behaviour.

Functionality cookies, typically used for customising a user’s website experience.

Targeting/advertising cookies, used to determine what promotional content to show the user.

Depending on how these cookies are implemented on a given site, they may collect a range of identifying and non-identifying information about you.

Sometimes they last only as long as the time you spend using the site, and are deleted once you close your browser window (these are known as session cookies or temporary cookies). Sometimes they remain on your device to give you a more consistent experience between visits (these are known as permanent cookies or persistent cookies).

First-party vs third-party cookies

You may have heard the terms “first-party” and “third-party” used in conjunction with cookies. They refer to whether the cookie stored on your device is coming from the website you’re visiting (first-party) or from someone else (third-party).

The idea of having some mysterious company “watching” you may seem insidious, but by and large, third-party cookies aren’t as sinister as they sound. Typically, third-party cookies serve a legitimate purpose, employed by websites using third-party platforms to enable useful functions — eg. Google Analytics for usage tracking, Doubleclick for targeted advertising, and Facebook Like buttons on blog posts and news articles.

Yet, while you might be happy for a website to offer you a customised user experience on their own platform, you might not want that website’s advertising partner to track your experience across other platforms as well. But their third-party cookie could facilitate exactly that.

So, to give people more control over their privacy, regulations exist stating that users must be given the option to opt-out of third-party cookies.

Do I need a cookie policy for my website?

While current cookie laws in the EU and US may not apply to your business’ location, it’s considered good practice to disclose any cookies your website or app may use. As people become more concerned about protecting their privacy, the more transparency you can offer, the better.

Generally, it’s a safer bet to include cookie-related information in your privacy policy to reduce the likelihood of legal non-compliance.

Looking for a cookie policy generator?

Create a cookie policy statement for your website or app with Generate your privacy policy now.