Free Template + Examples

    Cookie Policy Template

    Download free cookie policy templates compliant with GDPR and EU ePrivacy Directive. Includes consent management guidelines.

    22,000+ downloadsUpdated: January 202510 sections included

    Download Free Cookie Policy Template

    Get instant access to a professionally-crafted cookie policy template that includes:

    • GDPR & ePrivacy compliant structure
    • CCPA cookie disclosure requirements
    • PECR (UK) provisions
    • 10 essential sections
    • Real company examples

    Types of Cookies Explained

    Essential Cookies

    Required for basic site functionality like security and navigation

    Performance Cookies

    Track site performance and user behavior for analytics

    Functional Cookies

    Remember user preferences and personalization settings

    Targeting Cookies

    Track users across sites for advertising purposes

    10 Required Sections in a Cookie Policy

    A compliant cookie policy must include these essential sections. Learn more about the regulatory framework in our GDPR guide.

    1

    What Are Cookies

    Clear definition of cookies and similar tracking technologies (pixels, local storage, web beacons)

    Required by: GDPR Art. 13, ePrivacy Art. 5(3)

    2

    Types of Cookies Used

    Categorization of cookies by purpose (essential, analytics, functional, marketing)

    Required by: ePrivacy Art. 5(3), ICO Guidance

    3

    Strictly Necessary Cookies

    Cookies required for core site functionality that do not require consent

    Required by: ePrivacy Art. 5(3) exemption

    4

    Analytics Cookies

    Cookies used to measure site performance, traffic, and user behavior

    Required by: GDPR Art. 6(1)(a), PECR Reg. 6

    5

    Marketing Cookies

    Cookies used for targeted advertising, retargeting, and ad measurement

    Required by: ePrivacy Art. 5(3), GDPR Art. 6(1)(a)

    6

    Third-Party Cookies

    Cookies set by external services embedded on your site (analytics, ads, social media)

    Required by: GDPR Art. 13(1)(e), CCPA 1798.115

    7

    Cookie Duration & Expiration

    How long each cookie persists (session vs. persistent) and specific expiry times

    Required by: GDPR Art. 13(2)(a), ICO Guidance

    8

    How to Manage Cookies

    Browser-level instructions for blocking, deleting, and managing cookies

    Required by: Best practice, PECR Reg. 6

    9

    Cookie Consent Mechanism

    How you obtain, record, and allow withdrawal of consent for non-essential cookies

    Required by: GDPR Art. 7, ePrivacy Art. 5(3)

    10

    Policy Updates

    How users will be notified of changes to your cookie policy

    Required by: Best practice

    Real Cookie Policy Examples

    See how top companies and regulators write key cookie policy sections. For more examples, visit our cookie policy examples gallery.

    BBC

    Cookie Categories

    We use strictly necessary cookies to make our website work. We'd also like to set optional cookies to help us improve our websites and to give you the best experience. We won't set optional cookies unless you enable them. Using this tool will set a cookie on your device to remember your preferences.

    Why it works: Separates essential from optional cookies clearly and gives users genuine control before any non-essential cookies are set

    Shopify

    Third-Party Cookies

    We use cookies from third-party partners such as Google Analytics, Meta Pixel, and Hotjar for analytics and advertising purposes. These partners may combine information collected on our site with other information they have independently collected. Each partner's data practices are governed by their own privacy policies.

    Why it works: Names specific third-party providers, explains the purpose for each, and directs users to individual partner policies for full transparency

    Google

    Cookie Controls

    When you visit any website that uses Google services, cookies may be stored on or read from your browser. You can manage your cookie preferences at any time by visiting g.co/privacytools. You can also configure your browser to block all cookies or to indicate when a cookie is being set.

    Why it works: Provides a dedicated URL for granular cookie management and references browser-level controls as a fallback option

    ICO (UK)

    Cookie Consent

    We use cookies to collect information about how you use our website. We use this information to make the website work as well as possible and improve our services. You can change your cookie settings at any time using our cookie control tool. Some cookies are essential -- we can't provide our services without them.

    Why it works: The UK regulator leads by example with plain language, a clear consent tool, and honest acknowledgment that some cookies are non-negotiable

    The New York Times

    Marketing & Advertising Cookies

    We and our advertising partners use cookies to personalize ads, measure their performance, and deliver relevant advertising to you on and off our sites. You can opt out of personalized advertising by clicking 'Manage Your Privacy Choices' in the footer of every page. Opting out does not mean you will stop seeing ads, but they may be less relevant to you.

    Why it works: Sets honest expectations about opt-out consequences and places the consent mechanism on every page for easy access

    Cookie Compliance Checklist

    Ensure your cookie policy meets all regulatory requirements:

    GDPR / ePrivacy

    • Obtain informed consent before setting non-essential cookies
    • Provide granular opt-in by cookie category (not just accept all)
    • Allow users to withdraw consent as easily as they gave it
    • List all cookies with name, purpose, provider, and duration
    • Do not use pre-ticked checkboxes for consent
    • Re-obtain consent periodically (every 6-12 months)

    CCPA

    • Disclose categories of personal information collected via cookies
    • Provide a 'Do Not Sell or Share My Personal Information' link
    • Honor Global Privacy Control (GPC) browser signals
    • Explain how cookies are used for cross-context behavioral advertising
    • Allow consumers to opt out of sale/sharing of data collected through cookies

    PECR (UK)

    • Obtain consent before storing or accessing cookies on user devices
    • Provide clear and comprehensive information about each cookie's purpose
    • Exempt strictly necessary cookies from consent requirements
    • Keep records of consent for audit and accountability purposes
    • Review and refresh consent on a regular basis

    Need a Custom Cookie Policy?

    Generate a customized, GDPR and ePrivacy compliant cookie policy in 2 minutes that's tailored to your specific website and cookie usage.