Cookie Settings
Cookie settings are the controls that let a person choose which cookies and similar data-collection technologies they accept. These controls can appear in two places: within a website's own consent interface, where you agree to specific categories of cookies, and within a web browser or device, where you can allow, block, or delete cookies more broadly. Together they give users a way to manage what data is stored on or read from their device.
"Cookie settings" refers to the user-facing controls governing the acceptance, rejection, and management of cookies and comparable technologies, operating at two distinct layers. At the site level, a website may present settings that let a user select which categories of cookies (for example, the types Mozilla describes for its own properties) they agree to, typically implemented through a consent interface. At the browser or device level, settings allow users to enable, disable, or delete cookies and to configure options such as blocking third-party cookies; the evidence references such controls in Safari on iPhone and in Chrome on Android. Note that browser and device settings operate independently of any site-level consent mechanism, and adjusting one does not necessarily alter the other. The evidence provided describes the existence and location of these controls but does not address whether particular settings satisfy the consent standards of any specific legal regime (such as the ePrivacy Directive or GDPR in the EU, or US state privacy laws); those questions fall outside the scope of this definition and depend on facts not covered by the sources.
Why it matters
Cookie settings sit at the intersection of user autonomy and data collection, giving people a practical way to influence what is stored on or read from their devices. Because these controls exist at two distinct layers, the site-level consent interface and the browser or device settings, understanding both is essential for anyone assessing how user choices are captured and honored. A user who blocks cookies in their browser is exercising a different control than one who declines a category within a website's consent interface, and the two do not automatically reconcile with one another.
For compliance teams, the distinction matters because the mere presence of cookie controls does not, on its own, establish that any particular legal standard has been met. In the EU, for example, the ePrivacy Directive governs the placing of and access to information on a device while the GDPR governs any subsequent processing of personal data, and valid consent under the GDPR must generally be freely given, specific, informed, and unambiguous. Whether a given set of cookie settings satisfies those standards depends on how the controls are designed, presented, and recorded, facts that go beyond the existence of the controls themselves. The evidence describing where these settings live, such as within Mozilla's own consent interface or within Safari on iPhone and Chrome on Android, does not resolve those compliance questions.
Because requirements vary across the EU, the UK, and individual US states such as under the CCPA and CPRA in California, teams should treat cookie settings as one component of a broader consent and preference framework rather than as a standalone guarantee of lawful data collection. The appropriate configuration and the weight given to browser-level signals differ by jurisdiction, and this remains an area where regulatory guidance and enforcement positions continue to evolve.
Who it's relevant to
Inside Cookie Settings
Common questions
Answers to the questions practitioners most commonly ask about Cookie Settings.

