Purpose and Scope
This policy outlines how [Organisation Name] uses cookies and tracking technologies on [Website Address], and details the options available to site visitors. It applies to everyone accessing the site and works alongside our Privacy Policy. Technologies covered include cookies, web beacons, marketing pixels, and local browser storage.
Working through related paperwork at the same time? See also our UK Social Media Policy Template, US Social Media Policy Template and Subject Access Request Procedure Template.
Cookie Definitions and Classifications
Cookies are small text files stored on a user’s device during a website visit.
- First-Party Cookies: Set directly by [Organisation Name].
- Third-Party Cookies: Set by external providers with embedded tools or widgets on our site.
- Session Cookies: Temporary files that expire when the user closes their browser session.
- Persistent Cookies: Files that stay on the user’s device for a set duration or until cleared manually.
- Strictly Necessary Cookies: Essential files required for basic site operations, including session management, security, cart functionality, and consent tracking. These run without user consent.
- Functional Cookies: Files that remember user preferences like language or region.
- Analytics Cookies: Files that gather usage statistics, such as pages visited and time spent on page, to help improve the site. These require prior user consent.
- Marketing Cookies: Cookies and pixels used to track ad performance or serve targeted content on external platforms. These require prior user consent.
Inventory Requirements
[Organisation Name] maintains an active inventory for every cookie deployed on the site, recording:
- Cookie name
- Setting entity (first-party or third-party provider)
- Operational purpose
- Expiration or retention period
Consent Mechanics and User Controls
- Initial Visit: A consent banner appears when a visitor first arrives, giving clear options to accept or refuse each non-essential cookie category. Accepting and declining options must be equally easy to select.
- Pre-Consent Blocking: The site automatically blocks non-essential cookies (Functional, Analytics, and Marketing) until the visitor grants explicit consent.
- Consent Retention: Choices remain saved for [Period]. After this duration, the site prompts the visitor for consent again.
- Modifying Preferences: Visitors can update or revoke consent anytime using the cookie settings link in the website footer.
- Cookie Erasure: Revoking consent prevents new non-essential cookies from firing. Visitors can clear or block existing cookies through their browser settings. Blocking strictly necessary cookies may disable key features like login or checkout.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
Third-Party Integrations
Embedded external content (such as videos, maps, social media widgets, and payment forms) may drop third-party cookies controlled by the originating providers.
- Embedded content tied to non-essential cookies only loads after a visitor explicitly consents.
- We maintain a list of external providers and their privacy policies alongside our main cookie inventory.
Website Audit and Maintenance Procedure
- Run a technical scan using browser developer tools or a dedicated scanner to log all active cookies, scripts, and pixels.
- Classify every detected cookie. Mark essential items required to deliver user-requested services, and place all non-essential cookies into consent-required categories.
- Test the consent banner to ensure it blocks non-essential cookies before the visitor gives consent.
- Check that the cookie preference link in the footer remains visible and operational.
- Ensure this policy is linked directly inside the consent banner and the main Privacy Policy.
- Run a new scan and update the cookie inventory whenever teams add, modify, or remove plugins, scripts, pixels, or embedded tools.
Governance and Review
- Policy Owner: [Role]
- Contact for Inquiries: [Email Address]
- Review Cycle: Reviewed [Frequency, e.g. annually] or immediately after major site changes, verified with a fresh technical scan.
- Last Updated: [Date]
FAQs on a cookie policy
What is a cookie policy?
A cookie policy outlines how your organisation uses cookies and tracking technologies on your website, and details the options available to site visitors. It applies to everyone accessing the site and works alongside our Privacy Policy.
Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.
What does a cookie policy include?
This template covers cookie definitions and classifications, inventory requirements, consent mechanics and user controls and third-party integrations.
Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.
How to implement a cookie policy with Whale
Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.
Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.