A first-party cookie is a small file stored by the browser under the domain of the website the visitor is actually on, the one shown in the address bar. It is the opposite of a third-party cookie, which belongs to a different domain whose content is loaded on the page.
How first-party cookies work
A cookie can be set in two ways. Your web server can send it with the page, in a response header, or a script running on the page can write it with JavaScript. Either way, if it is stored under your domain, it is first-party, and the browser sends it back on every later request to your site.
The label describes the domain, not who controls the data. Google Analytics is the clearest example. Google’s script writes the _ga cookie under your domain, so it is a first-party cookie, even though the data it helps collect goes to Google. The Google Ads conversion linker cookie and Meta’s _fbp cookie work the same way.
Typical first-party cookies on a UK business site include:
- a session cookie that keeps someone logged in or holds their basket;
- the cookie that remembers their choice on your consent banner;
- analytics cookies that recognise a returning browser;
- advertising cookies that store a click identifier so a later sale can be matched to an ad.
Browsers treat them more generously than third-party cookies, but not without limits. Safari’s Intelligent Tracking Prevention caps cookies written by JavaScript at seven days, and in some cases 24 hours, and applies similar limits to some cookies set by servers run by a third party behind your domain.
Why it matters
Being first-party does not change the consent rule. Under regulation 6 of PECR, you need consent before storing or reading a cookie unless it is strictly necessary for a service the visitor asked for. A basket, a login or the consent cookie itself is strictly necessary. Analytics and advertising cookies are not, even when they sit on your own domain.
The Data (Use and Access) Act 2025 introduces a narrow exception for some analytics purposes, where visitors are given clear information and an easy way to object. It does not cover advertising, and how far it reaches depends on the ICO’s guidance and the conditions in the Act. Check the ICO’s current position before relying on it rather than assuming your analytics now falls outside consent.
First-party cookies also carry most of the measurement that still works. Ad platforms increasingly depend on them, together with server-side and consented first-party data, so how they are set and how long they last affects the conversion figures your bidding relies on.
Common mistakes
- Assuming first-party cookies need no consent.
- Classing analytics cookies as strictly necessary to avoid asking.
- Not knowing which cookies plugins, embedded videos and chat widgets set on your domain.
- A cookie policy that lists the cookies of years ago, not the ones on the site today.
- Expecting a 30-day attribution window to work for Safari visitors when the cookie behind it lasts seven days.
How to act on it
Open your site in a private browser window and look at the cookie list in the developer tools before you touch the banner. Anything other than strictly necessary cookies should not be there yet. Accept, reload and check again, then refuse and confirm the non-essential cookies stay away. Your cookie banner, cookie policy and privacy notice should all describe the same set.
If attribution matters to your spend, ask how long your key cookies actually last in Safari and whether a server-side set-up would help. Checking cookie behaviour against what the ad platforms report is part of the tracking review I run in performance marketing.
