Analytics and Tracking

Cookie

A small text file a website stores in your browser so it can recognise you later, used for baskets, logins, analytics and advertising.

Quick facts: Cookie

Category
Analytics and Tracking
Level
Beginner
Affects
Analytics accuracy, ad targeting, remarketing, PECR compliance, logins and baskets
Where to see it
Browser developer tools, CMP cookie scanner, cookie policy, Tag Assistant
In this article4
  1. How cookies work
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A cookie is a small text file that a website asks your browser to store, so the site can recognise the same browser on later page views or visits. Cookies keep you logged in, remember what is in a basket, record consent choices, and let analytics and advertising tools count and follow visits.

How cookies work

When your browser loads a page, the site can send back an instruction to save a cookie: a name, a value (often a random ID), the domain it belongs to and an expiry date. On every later request to that domain, the browser sends the cookie back. That is how a site knows the person on page three is the same one who added an item to the basket on page one.

Cookies are usually described in three ways:

  • Who sets them. A first-party cookie belongs to the site in the address bar. A third-party cookie belongs to another domain, such as an ad network loaded within the page.
  • How long they last. A session cookie is deleted when the browser closes; a persistent cookie stays until its expiry date or until the visitor clears it.
  • What they are for. Strictly necessary, functional, analytics or advertising. This is the distinction the law cares about.

Browsers add their own limits. Safari blocks third-party cookies by default and caps how long some first-party cookies set by scripts can last. Firefox keeps each site’s third-party cookies in a separate store so they cannot follow people across sites. Chrome still allows third-party cookies by default at the time of writing (October 2026), after Google dropped its plan to remove them.

Why it matters

In the UK, cookies are governed by regulation 6 of the Privacy and Electronic Communications Regulations (PECR), which the ICO enforces. The rule covers cookies and any similar technology that stores or reads information on a visitor’s device. You must tell people clearly what each cookie does and get their consent before setting it, unless it is strictly necessary to provide a service they asked for.

Strictly necessary covers things like a shopping basket, a login session, security, load balancing and the cookie that remembers someone’s consent choice. Analytics and advertising cookies are not strictly necessary, even when they are first-party and useful to you. The Data (Use and Access) Act 2025 adds a narrow exception for some analytics cookies, where visitors are told and can object easily; check the ICO’s current guidance on whether and how it applies before relying on it.

Where a cookie holds an identifier linked to a browser, it usually counts as personal data, so UK GDPR applies too. That is why your privacy notice, cookie policy and banner need to describe the same set of cookies.

Common mistakes

  • Setting analytics or advertising cookies on page load, before the visitor has chosen anything.
  • Labelling analytics cookies as strictly necessary to avoid asking.
  • A cookie policy listing the cookies of three years ago, with nothing about tags added since.
  • Assuming that a first-party cookie needs no consent.
  • Not knowing which cookies plugins, chat widgets and embedded videos set.

How to act on it

Open your site in a private browser window, leave the banner alone, and look at the cookies in the browser’s developer tools (in Chrome, the Application tab, then Cookies). Anything there that is not strictly necessary is being set without consent. Then accept, reload and note what appears.

From that list, update your cookie policy and make sure your cookie banner blocks each non-essential cookie until its category is accepted. Repeat the check whenever you add a tool. A cookie audit and a sound consent set-up are the groundwork for the tracking I put in place through my performance marketing service.

Do and do not

Do

  • Block non-essential cookies until the visitor consents
  • Keep your cookie policy matched to what the site actually sets
  • Re-check cookies after adding any plugin or tag

Do not

  • Label analytics cookies as strictly necessary
  • Assume first-party cookies need no consent
  • Rely on the analytics exception without checking current ICO guidance

Questions people ask about this

Do I need a cookie banner if I only use Google Analytics?

In most cases, yes. GA4 sets analytics cookies, which need consent under PECR unless an exemption applies. The analytics exception added by the Data (Use and Access) Act 2025 is narrow and comes with conditions, and GA4's links to Google's advertising features may take it outside that exception, so check the ICO's current guidance before removing a banner.

What is the difference between cookies and local storage?

Both store information in the browser. Cookies are sent to the server with every request and carry an expiry date, while local storage stays in the browser until it is cleared and is read by scripts on the page. For PECR the difference does not matter: both store information on the device, so the same consent rules apply.

How long can a cookie last?

As long as the site sets it to; UK law sets no fixed maximum, but the ICO expects the duration to be proportionate to the purpose. GA4's main cookie, for example, lasts two years by default unless you change it, and Safari shortens some script-set cookies regardless. Each cookie's lifetime should be listed in your cookie policy.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.