Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Consent Interfaces

Cookie Declaration

Also known as: Cookie List, Cookie Policy Declaration
Simply put

A cookie declaration is a published list on a website that explains which cookies and similar tracking technologies the site uses, what they do, and what information they collect. It is typically presented to help visitors understand and, where required, manage their consent preferences. The specific content and how it must be presented can differ depending on the applicable privacy laws in a given region.

Formal definition

A cookie declaration is a transparency artifact, often generated and maintained through a consent management platform, that enumerates the cookies and comparable technologies (such as pixels, local storage entries, or SDKs) operating on a website. It generally categorizes each item, describes its purpose, the party providing it, and the data it registers, and may indicate retention or the unique identifiers involved. In most EU and UK contexts, such a declaration supports the informed element of consent under the ePrivacy rules and the GDPR by providing clear prior information before non-essential cookies are set, though publishing a declaration alone does not establish valid consent, which additionally requires a clear affirmative action where opt-in applies. Requirements and expected presentation vary across jurisdictions, including the EU, UK, and individual US states, and the declaration itself does not substitute for the underlying legal basis or consent-capture mechanism.

Why it matters

A cookie declaration is one of the primary ways a website satisfies the transparency and information obligations that underpin lawful use of cookies and similar technologies. In most EU and UK contexts, valid consent for non-essential cookies must be informed, which means visitors need clear, accessible information about what is being placed on their device and why before they decide. A cookie declaration is the artifact that typically carries this information, describing each cookie or comparable technology, its purpose, and the data it registers. Without it, a consent request may lack the detail regulators generally expect visitors to have.

The declaration also matters because tracking on a modern website is rarely limited to first-party cookies. As practical examples show, sites often rely on third-party technologies: a cookie that registers a unique device ID to enable targeted advertising across an ad network, a cookie used to distinguish humans from bots for reliable analytics reporting, or a cookie tied to a payment provider such as Stripe to enable card transactions. A cookie declaration helps surface this range of technologies, including pixels, local storage entries, and SDKs that fall within the same rules even though they are not literally cookies, so that visitors and the organizations themselves can understand what is actually operating on the site.

It is important to be clear about the limits of a cookie declaration. Publishing a declaration supports the informed element of consent but does not by itself establish valid consent, which additionally requires a clear affirmative action where opt-in applies, as is generally the case in the EU and UK. Nor does the declaration replace the underlying legal basis or the consent-capture mechanism. Requirements and expected presentation also vary across jurisdictions, including the EU, the UK, and individual US states, so a declaration that is adequate in one region may not meet expectations in another.

Who it's relevant to

Privacy and data protection officers
DPOs and privacy officers rely on cookie declarations to demonstrate that visitors receive clear information about the technologies in use, an element that generally supports the informed component of consent in the EU and UK. They should treat the declaration as one part of a broader compliance approach, verifying that it stays accurate and does not overstate that publishing it alone establishes valid consent.
Legal counsel and compliance teams
Legal and compliance professionals assess whether a declaration meets the transparency expectations of the applicable regime, recognizing that requirements and expected presentation vary across the EU, the UK, and individual US states. They also confirm that the declaration is supported by an appropriate legal basis and consent-capture mechanism rather than substituting for them.
Web developers and site owners
Developers and site owners implement and maintain the declaration, frequently using a consent management platform to enumerate cookies, pixels, local storage entries, and SDKs. Because sites often incorporate third-party technologies such as advertising, analytics, and payment provider cookies, they need to keep the declaration current as the technologies on the site change.
Marketing and analytics teams
Marketing and analytics teams introduce many of the non-essential technologies a declaration must describe, such as cookies that register unique device IDs for targeted advertising or that support usage reporting. They benefit from understanding how these technologies are categorized and disclosed, since in most EU and UK contexts such cookies typically require prior consent before being set.

Inside Cookie Declaration

Cookie inventory or list
An itemized list of the cookies and similar technologies (such as pixels, local storage, and SDKs) set through the website or service, typically identifying the name of each cookie or tracker.
Purpose description
An explanation of why each cookie or category of cookies is used, generally grouped into categories such as strictly necessary, functional, analytics, and advertising cookies. In most EU jurisdictions this granularity supports the informed and specific consent standard under the GDPR and ePrivacy rules.
Category classification
The grouping of cookies by type, which matters because strictly necessary or essential cookies are generally exempt from consent, whereas analytics, advertising, and functional cookies typically require prior consent under EU law.
Duration or retention period
The storage duration of each cookie, distinguishing between session cookies that expire when the browser closes and persistent cookies that remain for a stated period.
First-party and third-party origin
An indication of whether a cookie is set by the website operator directly or by a third party, and where applicable the identity of the third-party provider, which helps users understand who receives information.
Provider or recipient information
Details identifying the party responsible for setting or receiving data through the cookie, which supports the informed element of consent and connects to transparency obligations where personal data is processed under the GDPR.

Common questions

Answers to the questions practitioners most commonly ask about Cookie Declaration.

Does publishing a cookie declaration mean I have obtained valid consent?
No. A cookie declaration is a transparency and information tool, not a consent mechanism. It typically lists the cookies and similar technologies in use, their purposes, and related details to help satisfy the informed element of consent and broader transparency obligations. Under EU law, valid consent must still be freely given, specific, informed, and unambiguous, requiring a clear affirmative action collected through a separate consent mechanism (often part of a consent management platform). The declaration supports informed consent but does not by itself constitute consent, and displaying one does not authorize the placing of non-essential cookies. Requirements also differ under frameworks such as certain US state privacy laws, which may rely on opt-out rather than opt-in.
Is a cookie declaration the same thing as a cookie banner or consent notice?
Not exactly. These serve related but distinct functions. A cookie declaration is generally a fuller informational document or page describing the cookies and similar technologies deployed, their categories, and their purposes. A cookie banner or consent notice is the interface presented to users to request consent or offer choices before non-essential technologies are set. In practice the two are often linked, and a CMP may generate both, but they are conceptually separate: one informs, the other captures a choice. Whether either alone is sufficient depends on the applicable legal regime and the facts of a given deployment.
How often should a cookie declaration be updated?
As a general matter, a cookie declaration should reflect the technologies actually in use, so it typically needs updating whenever cookies, pixels, SDKs, or similar technologies are added, removed, or changed in purpose. Many organizations combine periodic scanning or auditing with review triggered by changes to third-party tags. This entry does not prescribe a specific interval, as appropriate frequency depends on how often your site or app changes and on any expectations set by relevant data protection authorities, which may evolve. The underlying goal is accuracy, so the update cadence should be tied to the rate of change in your technology stack.
What information is typically included in a cookie declaration?
Cookie declarations commonly list the individual cookies and similar technologies in use, along with details such as their name, the party setting them (first- or third-party), their stated purpose or category (for example strictly necessary, functional, analytics, or advertising), and their duration or retention period. Some also indicate the data recipients or link to relevant privacy information. Because similar technologies such as pixels, local storage, SDKs, and fingerprinting fall within the same rules even though they are not literally cookies, a thorough declaration should account for these as well. The exact contents that are adequate depend on the applicable legal regime and are out of scope for a single universal specification.
How can I make sure my cookie declaration accurately reflects the cookies actually set?
Accuracy generally depends on identifying the technologies present, which is often done through automated scanning tools, manual review of network traffic, and coordination with teams that manage third-party tags and integrations. Because tags can change dynamically or be introduced by third parties, discrepancies between a declaration and actual behavior are a common challenge. Scanning tools support this effort but do not replace review, since they may miss technologies that fire only in certain conditions. Combining tooling with governance over who can add tags helps keep the declaration aligned with reality, though no single approach guarantees completeness.
Should a cookie declaration be available in each jurisdiction's language and reflect local requirements?
Cookie consent and transparency obligations vary between the EU, the UK, individual US states such as California under the CCPA and CPRA, and other regimes, so a declaration intended to be understood by users in a given market is generally provided in a language and form suited to that audience. The informed element of consent under EU law depends on users being able to understand the information presented, which has implications for language and clarity. Because obligations and enforcement positions differ by jurisdiction and continue to evolve, organizations operating across regions often tailor content and presentation accordingly. Determining what is legally sufficient in a specific jurisdiction requires legal judgment and is beyond the scope of this definition.

Common misconceptions

A cookie declaration is the same thing as obtaining consent.
A declaration is an informational disclosure of what cookies are used; it supports the informed element of consent but does not itself constitute a clear affirmative action. Under EU law, valid consent generally still requires a separate mechanism, such as a consent banner or CMP, through which the user actively agrees before non-exempt cookies are set.
Publishing a cookie declaration satisfies all applicable legal requirements for cookies.
The ePrivacy Directive and its national implementations govern the placing of and access to information on a device, while the GDPR governs any resulting processing of personal data. A declaration addresses transparency but does not by itself meet consent, record-keeping, or lawful-basis obligations, which vary between the EU, the UK, and individual US states such as under the CCPA and CPRA.
Only literal HTTP cookies need to be listed.
Similar technologies such as pixels, local storage, SDKs, and fingerprinting fall within the same rules even though they are not literally cookies. A declaration that omits these technologies may present an incomplete picture of the tracking in use.

Best practices

Keep the declaration accurate and up to date by scanning the website regularly, since cookies set by third parties and tag changes can introduce new trackers that are not reflected in a static list.
Classify cookies by category and purpose, and describe them in plain language, so users can make specific and informed choices in line with the consent standards commonly applied in most EU jurisdictions.
Include similar technologies such as pixels, local storage, and SDKs, not only literal cookies, to reflect the full scope of tracking that falls within the same rules.
Present the declaration alongside, but distinct from, the consent mechanism, treating disclosure and the collection of a clear affirmative action as separate steps rather than assuming the declaration alone establishes consent.
Tailor the declaration to the jurisdictions you operate in, noting that obligations differ between the EU, the UK, and individual US states, and avoid presenting one region's approach as universal.
Coordinate the declaration with your consent logging and record-keeping practices and treat CMP-generated lists as a support for compliance rather than a substitute for legal review, since tools do not replace legal judgment.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.