Analytics and Tracking

First-Party Cookie

A cookie set under the domain of the website the visitor is on, used for things like logins, baskets and analytics.

Quick facts: First-Party Cookie

Category
Analytics and Tracking
Level
Beginner
Affects
Cookie consent compliance, analytics accuracy, conversion attribution, cookie policy
Where to see it
Browser developer tools, your consent management platform, Tag Assistant, a cookie audit
In this article4
  1. How first-party cookies work
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A first-party cookie is a small file stored by the browser under the domain of the website the visitor is actually on, the one shown in the address bar. It is the opposite of a third-party cookie, which belongs to a different domain whose content is loaded on the page.

How first-party cookies work

A cookie can be set in two ways. Your web server can send it with the page, in a response header, or a script running on the page can write it with JavaScript. Either way, if it is stored under your domain, it is first-party, and the browser sends it back on every later request to your site.

The label describes the domain, not who controls the data. Google Analytics is the clearest example. Google’s script writes the _ga cookie under your domain, so it is a first-party cookie, even though the data it helps collect goes to Google. The Google Ads conversion linker cookie and Meta’s _fbp cookie work the same way.

Typical first-party cookies on a UK business site include:

  • a session cookie that keeps someone logged in or holds their basket;
  • the cookie that remembers their choice on your consent banner;
  • analytics cookies that recognise a returning browser;
  • advertising cookies that store a click identifier so a later sale can be matched to an ad.

Browsers treat them more generously than third-party cookies, but not without limits. Safari’s Intelligent Tracking Prevention caps cookies written by JavaScript at seven days, and in some cases 24 hours, and applies similar limits to some cookies set by servers run by a third party behind your domain.

Why it matters

Being first-party does not change the consent rule. Under regulation 6 of PECR, you need consent before storing or reading a cookie unless it is strictly necessary for a service the visitor asked for. A basket, a login or the consent cookie itself is strictly necessary. Analytics and advertising cookies are not, even when they sit on your own domain.

The Data (Use and Access) Act 2025 introduces a narrow exception for some analytics purposes, where visitors are given clear information and an easy way to object. It does not cover advertising, and how far it reaches depends on the ICO’s guidance and the conditions in the Act. Check the ICO’s current position before relying on it rather than assuming your analytics now falls outside consent.

First-party cookies also carry most of the measurement that still works. Ad platforms increasingly depend on them, together with server-side and consented first-party data, so how they are set and how long they last affects the conversion figures your bidding relies on.

Common mistakes

  • Assuming first-party cookies need no consent.
  • Classing analytics cookies as strictly necessary to avoid asking.
  • Not knowing which cookies plugins, embedded videos and chat widgets set on your domain.
  • A cookie policy that lists the cookies of years ago, not the ones on the site today.
  • Expecting a 30-day attribution window to work for Safari visitors when the cookie behind it lasts seven days.

How to act on it

Open your site in a private browser window and look at the cookie list in the developer tools before you touch the banner. Anything other than strictly necessary cookies should not be there yet. Accept, reload and check again, then refuse and confirm the non-essential cookies stay away. Your cookie banner, cookie policy and privacy notice should all describe the same set.

If attribution matters to your spend, ask how long your key cookies actually last in Safari and whether a server-side set-up would help. Checking cookie behaviour against what the ad platforms report is part of the tracking review I run in performance marketing.

Do and do not

Do

  • Check which cookies load before and after the banner choice
  • Keep your cookie policy in step with the cookies actually set
  • Allow for Safari's shorter cookie life when reading attribution

Do not

  • Assume first-party means no consent is needed
  • Label analytics cookies as strictly necessary
  • Rely on an exemption without checking the ICO's current guidance

Questions people ask about this

Do first-party cookies need consent in the UK?

Usually, yes, unless they are strictly necessary for a service the visitor asked for, such as a login, a basket or remembering their consent choice. Analytics and advertising cookies need consent under PECR whether they are first-party or third-party. The Data (Use and Access) Act 2025 creates a narrow exception for some analytics, so check the ICO's current guidance before relying on it.

Is the Google Analytics cookie first-party?

Yes. The _ga cookie is written by Google's script under your own domain, which makes it first-party in browser terms. The data it helps collect is still sent to Google, which is why it needs consent and must be described in your cookie policy.

Are first-party cookies going away?

No. The changes in browsers have targeted third-party cookies and the ways first-party cookies can be used for cross-site tracking. First-party cookies are essential for logins, baskets and consent records, and they remain the main way analytics recognises a returning browser, though Safari shortens the life of many of them.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.