When you visit a website, small text files are often saved in your browser. These are called cookies. They’re used to help the website remember information about you – from being logged in to which products you’ve added to your cart.
Cookies aren’t dangerous or mysterious, but they’re important to understand – both as a user and as a business owner with a website.
What is a cookie technically?
A cookie is a small text file – often just a few kilobytes – that a web server sends to your browser when you visit a page. The browser saves the file and sends it back on your next visit, so the site recognises you.
Cookies can be temporary (session cookies) that are deleted when you close your browser, or persistent (persistent cookies) that are stored for a set period.
What types of cookies are there?
Necessary cookies
These are absolutely essential for the website to function. They keep you logged in, remember your cart and secure your forms against attacks. You can’t opt out of them – and no consent is required for them.
Preference cookies
Remember your settings when you return – for example language choice, region or theme (dark/light mode). Requires consent.
Statistics cookies
Collect anonymous data about how visitors use the website. Google Analytics is the most common example. Helps the website owner understand which pages are popular and how users navigate. Requires consent.
Marketing cookies
Track you across multiple websites to show relevant ads. Meta Pixel, Google Ads tracking and LinkedIn Insight Tag are common examples. Requires consent and is the category visitors most often reject.
Third-party cookies
Set by services outside the site you’re visiting – for example embedded YouTube videos or social sharing buttons. Often used for ad tracking. These are gradually being phased out by browsers.
Cookies and GDPR – what applies?
Under GDPR and the EU’s ePrivacy Directive, you must:
- Obtain active consent before non-essential cookies are set. Just informing visitors is not enough – the user must actively choose to accept.
- Make it equally easy to reject as to accept. A button that’s hard to find or hidden behind many clicks is not compliant.
- Have a clear cookie policy that explains which cookies you use, why and how long they’re stored.
- Document the consent so you can prove the visitor consented.
- Let users change their mind – it must be possible to withdraw consent at any time.
No cookie may be set before consent is given – not even Google Analytics.
What does your website need?
To comply with GDPR, your website needs:
- A cookie banner shown on the first visit
- The ability to accept all, reject all or choose by category
- An accessible cookie policy
- A solution that blocks cookies until consent is given (e.g. Cookiebot, CookieYes)
Cookie-free alternatives are growing
Third-party cookies are becoming increasingly difficult to use. Safari and Firefox already block them, Chrome plans to phase them out. Alternatives like server-side tracking, first-party data and contextual advertising are therefore growing rapidly.
If you run e-commerce or advertising, you should already start planning for a cookie-lite future.
Need help with cookie management?
We help businesses implement correct consent solutions, write cookie policies and ensure no tracking occurs without consent. Read more about our support service and accessibility review, or contact us for a review of your cookie situation.




