A cookie is a small text file that a website asks your browser to store, so the site can recognise the same browser on later page views or visits. Cookies keep you logged in, remember what is in a basket, record consent choices, and let analytics and advertising tools count and follow visits.
How cookies work
When your browser loads a page, the site can send back an instruction to save a cookie: a name, a value (often a random ID), the domain it belongs to and an expiry date. On every later request to that domain, the browser sends the cookie back. That is how a site knows the person on page three is the same one who added an item to the basket on page one.
Cookies are usually described in three ways:
- Who sets them. A first-party cookie belongs to the site in the address bar. A third-party cookie belongs to another domain, such as an ad network loaded within the page.
- How long they last. A session cookie is deleted when the browser closes; a persistent cookie stays until its expiry date or until the visitor clears it.
- What they are for. Strictly necessary, functional, analytics or advertising. This is the distinction the law cares about.
Browsers add their own limits. Safari blocks third-party cookies by default and caps how long some first-party cookies set by scripts can last. Firefox keeps each site’s third-party cookies in a separate store so they cannot follow people across sites. Chrome still allows third-party cookies by default at the time of writing (October 2026), after Google dropped its plan to remove them.
Why it matters
In the UK, cookies are governed by regulation 6 of the Privacy and Electronic Communications Regulations (PECR), which the ICO enforces. The rule covers cookies and any similar technology that stores or reads information on a visitor’s device. You must tell people clearly what each cookie does and get their consent before setting it, unless it is strictly necessary to provide a service they asked for.
Strictly necessary covers things like a shopping basket, a login session, security, load balancing and the cookie that remembers someone’s consent choice. Analytics and advertising cookies are not strictly necessary, even when they are first-party and useful to you. The Data (Use and Access) Act 2025 adds a narrow exception for some analytics cookies, where visitors are told and can object easily; check the ICO’s current guidance on whether and how it applies before relying on it.
Where a cookie holds an identifier linked to a browser, it usually counts as personal data, so UK GDPR applies too. That is why your privacy notice, cookie policy and banner need to describe the same set of cookies.
Common mistakes
- Setting analytics or advertising cookies on page load, before the visitor has chosen anything.
- Labelling analytics cookies as strictly necessary to avoid asking.
- A cookie policy listing the cookies of three years ago, with nothing about tags added since.
- Assuming that a first-party cookie needs no consent.
- Not knowing which cookies plugins, chat widgets and embedded videos set.
How to act on it
Open your site in a private browser window, leave the banner alone, and look at the cookies in the browser’s developer tools (in Chrome, the Application tab, then Cookies). Anything there that is not strictly necessary is being set without consent. Then accept, reload and note what appears.
From that list, update your cookie policy and make sure your cookie banner blocks each non-essential cookie until its category is accepted. Repeat the check whenever you add a tool. A cookie audit and a sound consent set-up are the groundwork for the tracking I put in place through my performance marketing service.
