Preferences Cookies
Preferences cookies are small files that a website uses to remember choices you have made, such as your language, region, or other settings, so the site can behave the way you want on future visits. They are generally about improving your experience rather than being essential for the website to function. In most EU and UK contexts, cookies of this kind that are not strictly necessary typically require your consent before they are set.
Preferences cookies (often called functionality cookies) are a category of cookies used to store user-selected settings and personalization choices, for example language, region, or display preferences, so that a website can recall them across sessions or pages. As a category label they describe purpose rather than a distinct technical mechanism; similar functions may also be achieved with other client-side storage or comparable technologies, which fall within the same regulatory rules. Under EU and UK law the relevant obligations arise principally from the ePrivacy regime governing the storing of and access to information on a user's device, with the GDPR applying to any resulting processing of personal data. Whether a given preferences cookie is exempt from consent depends on whether it can be treated as strictly necessary to provide a service explicitly requested by the user; many preferences cookies do not meet that threshold and therefore generally require prior consent in most EU jurisdictions and the UK, though the analysis is fact-specific and enforcement positions vary. This entry does not resolve the case-by-case classification of individual cookies, nor does it address opt-out-based frameworks such as certain US state privacy laws, where obligations differ.
Why it matters
Preferences cookies sit in a middle ground that often causes classification difficulty for compliance teams. Because they improve the user experience rather than being strictly essential to deliver a service the user has explicitly requested, many of them do not qualify for the consent exemption that applies to strictly necessary cookies. In most EU jurisdictions and the UK, that means preferences cookies typically require prior consent before they are set, even though users and some organizations intuitively treat them as harmless conveniences. Misclassifying a preferences cookie as essential is a common source of non-compliance under the ePrivacy regime governing the storing of and access to information on a user's device.
The practical stakes are meaningful for anyone maintaining a cookie banner or consent management platform. If preferences cookies are placed before consent is obtained, or are bundled into an 'always on' essential category, the organization may be setting non-consented cookies in breach of applicable EU and UK rules. Because the classification is fact-specific, turning on whether the particular cookie can genuinely be treated as strictly necessary to a service the user explicitly requested, teams cannot rely on the category label alone and must assess each cookie's actual function.
The scope of these obligations also varies by jurisdiction. The consent-first analysis described here reflects EU and UK practice; opt-out-based frameworks such as certain US state privacy laws approach the same technologies differently. Organizations operating across regions therefore need to be careful not to assume that one jurisdiction's treatment of preferences cookies applies everywhere.
Who it's relevant to
Inside Preferences Cookies
Common questions
Answers to the questions practitioners most commonly ask about Preferences Cookies.