POLICY GUIDE · UPDATED 1 OCTOBER 2026
What your cookie policy needs
A useful cookie policy tells visitors what your website actually stores or reads, why it does that and how to change their choice. A generic template cannot do the inventory for you.
List what is really on the site
Check the homepage and pages with forms, video, checkout, bookings and marketing integrations. Include local storage and other storage or access technologies, not just traditional cookies. Repeat the inventory before consent, after acceptance and after rejection. Do not describe a tracker as essential simply because your team finds its reports useful.
Explain each purpose plainly
For each relevant cookie or technology, record its name or identifiable pattern, provider, purpose and duration. Say whether it is essential or optional and what choice controls it. “Improves your experience” is not a useful substitute for explaining analytics, advertising, authentication or remembering preferences. If a provider changes the implementation, review the entry.
Connect the policy to working controls
Link the cookie policy from the banner and footer. Provide a visible way to reopen settings and withdraw optional consent. A visitor should not have to email a developer to stop analytics. Your policy and banner must agree: promising to block a tracker is no help if the tag runs before a choice.
ICO: storage and access guidance ↗ · Troubleshoot cookies after rejection ↗
Keep the privacy notice alongside it
The privacy notice covers the wider handling of personal information: who is responsible, purposes and lawful bases, recipients, retention, international transfers where relevant, rights and complaint routes. The cookie policy explains the website technology and choices. They can link to each other, but publishing either document does not by itself fix the behaviour of the site.
Review after website changes
New analytics, an advertising campaign, a booking integration or a different consent plugin can make an old policy inaccurate. Keep a dated inventory and ask the person making changes to identify any new storage or third-party processing. Use an automated scan to find leads for investigation, then confirm actual purposes and expiry settings.
Run a free website scan ↗ · See GDPRFix’s own cookie policy ↗