Nixon Digital

🇳🇱 Webinar | Privacy op gemeentewebsites: wat speelt er en hoe los je het op? 🠮

🇳🇱 Webinar | Privacy op gemeentewebsites 🠮

What is a cookie on a website and what do they do?

what is a cookie on a website and what do cookies do?

Table of Contents

What is a cookie on a website? Whether you are a website owner or an internet user, you have probably encountered cookies before. But what exactly are they?

 

Simply put, cookies are small pieces of data that websites can ask your browser to store on your device. They can help a website recognise a session, remember preferences and customise the browsing experience. Cookies support many useful website functions. For example, they can keep products in a shopping cart, remember a language preference or maintain a secure login session.

 

However, websites can also use cookies for analytics, profiling and advertising. That distinction matters. A cookie is not automatically necessary, harmless or privacy-friendly simply because a website uses it.

What is a cookie and what do cookies do?

HTTP cookies, also known as web cookies, are small pieces of information that a website asks your browser to store on your device.

 

When you visit a website, your browser sends a request to a web server. The website may respond by sending a cookie to your browser. During a later request or visit, your browser can send that cookie back to the relevant website.

 

This allows the website to recognise an existing session or retrieve information associated with it. Cookies can store or reference information such as:

  • Language and regional preferences
  • Session identifiers
  • Login status
  • Shopping-cart identifiers
  • Consent choices
  • Analytics identifiers
  • Advertising identifiers

Websites use cookies for purposes including session management, personalisation, analytics and advertising.

 

However, the cookie does not always contain the information itself. For example, a shopping-cart cookie may contain only a random identifier. The website then uses that identifier to retrieve the contents of the shopping cart from its server.

 

Cookies can help websites remember users and support useful features. However, cookies used for tracking or profiling can create privacy risks, particularly when organisations follow users across websites or combine cookie identifiers with other information.

 

Well-designed websites should avoid storing sensitive information directly in cookies. They should also protect session identifiers and similar data against unauthorised access.

Different types of cookies

Cookies can be classified in different ways. A cookie’s purpose describes why the website uses it. Its provider describes which website or service sets or receives it. Its duration describes how long it remains available.

 

As a result, the same cookie can be first-party, persistent and used for analytics at the same time.

 

Classification  

Common categories

What it describes

Purpose

Necessary, functional, analytics, advertising

Why the cookie is used

Provider

First-party, third-party

Which website or service sets or receives it

Duration

Session, persistent

How long the cookie remains available

 

These classifications overlap. Labels such as first-party, third-party, session or persistent do not by themselves determine whether a cookie is necessary or whether consent is required.

Strictly necessary cookies

Strictly necessary cookies support functions that a website needs to provide a service explicitly requested by the user. Examples may include cookies used for:

  • Maintaining a secure login session
  • Remembering products in a shopping cart
  • Protecting forms against fraud or abuse
  • Distributing traffic between servers
  • Processing an online transaction
  • Storing a user’s cookie preferences

A cookie does not become strictly necessary simply because it is useful to the website owner. For example, a shopping-cart cookie may be necessary to complete an online purchase. An advertising cookie placed on the same website is not necessary for that purchase.

 

Strictly necessary cookies may still contain or refer to identifiers. Website owners must therefore protect them appropriately and explain their purpose clearly.

Functional cookies

Functional cookies support additional website features and preferences.

They may remember:

  • A preferred language
  • A selected region
  • Accessibility settings
  • Display preferences
  • Video-player settings
  • Previous support or chat choices

These cookies can make a website more convenient and personal.

 

However, functional cookies are not automatically strictly necessary. Depending on their purpose, implementation and the applicable law, some functional cookies may require consent.

Analytics and performance cookies

Analytics and performance cookies help organisations understand how visitors use a website. They may measure:

  • Page views
  • Navigation paths
  • Traffic sources
  • Interactions with buttons and forms
  • Technical errors
  • Page performance
  • Completed transactions or conversions

Organisations can use this information to identify broken pages, confusing navigation and technical problems.

 

However, analytics cookies are not automatically anonymous. An analytics service may collect or generate identifiers, device details, IP-related information and behavioural data. In many European jurisdictions, analytics cookies require prior consent. Some national regulators provide limited exceptions for carefully configured, privacy-friendly analytics. However, those exceptions depend on local requirements and the actual configuration of the technology.

 

Website owners should therefore assess how an analytics tool behaves rather than relying only on the label “analytics”.

First-party cookies

First-party cookies are associated with the website a user is currently visiting.

For example, when someone visits example.com, a cookie associated with example.com is generally considered a first-party cookie.

Websites can use first-party cookies for:

  • Login sessions
  • Shopping carts
  • Language preferences
  • Consent settings
  • Analytics
  • Personalisation
  • Conversion measurement
  • Advertising

First-party only describes which website sets or receives the cookie. It does not mean that the cookie is automatically necessary, harmless or exempt from consent requirements.

 

A first-party analytics or advertising cookie may still require consent.

Session cookies

Session cookies are temporary cookies designed to remain available during a browsing session.

 

Websites commonly use them for:

  • Authentication
  • Shopping carts
  • Navigation
  • Security
  • Multi-step forms

 

A session usually begins when a user opens a website or web application. It ends when the user logs out, closes the browser or otherwise ends the session.

 

The browser normally removes session cookies when the session ends. However, exact behaviour can vary because some browsers can restore previous sessions.

Non-necessary cookies

Non-necessary, or non-essential, cookies are not required to provide the basic service requested by the user.

 

They commonly support:

  • Optional personalisation
  • Audience measurement
  • Advertising
  • Retargeting
  • Social-media integrations
  • Embedded third-party content

 

When consent is required, these cookies and the technologies that place or access them should remain inactive until the user has made a valid choice.

 

Rejecting non-essential cookies should not prevent the user from accessing website features that do not depend on those cookies.

Targeting and advertising cookies

Targeting and advertising cookies help organisations deliver, personalise and measure advertising.

 

They may be used to:

  • Build audience profiles
  • Display personalised advertisements
  • Retarget previous website visitors
  • Limit how often an advertisement appears
  • Measure advertising conversions
  • Connect activity across websites or services
  • Analyse the performance of advertising campaigns

 

These cookies may collect information about pages viewed, links clicked, products considered and interactions with advertisements.

 

Targeting and advertising cookies usually require prior consent. They should not activate while the user is still deciding whether to accept or reject them.

 

Advertising technologies do not always rely only on cookies. They can also use pixels, scripts, local storage, server-side identifiers and other techniques.

Third-party cookies

Third-party cookies are associated with a domain or service other than the website the user is currently visiting.

 

A website may include third-party services for:

  • Embedded videos
  • Payment processing
  • Customer-support tools
  • Social-media content
  • Fraud prevention
  • Analytics
  • Advertising
  • Audience measurement

 

Not every third-party cookie is used for advertising. A payment provider, embedded video service or fraud-prevention tool may also place a third-party cookie.

 

However, third-party tracking can create significant privacy risks when it allows organisations to follow users across different websites or combine information from multiple sources.

 

Many browsers restrict third-party cookies in certain circumstances. The exact behaviour depends on the browser, user settings, browsing mode and technical implementation.

Persistent cookies

Persistent cookies remain stored after the user ends the current browsing session.

 

They remain available until:

  • Their configured expiry date passes
  • The website replaces or removes them
  • The user deletes them
  • The browser or device clears them

 

Persistent cookies can remember preferences across visits. They can also support longer-term analytics, profiling and advertising.

 

A persistent cookie should not remain stored longer than necessary for its stated purpose. Website owners should therefore review both its purpose and its configured retention period.

Zombie cookies

The term “zombie cookie” describes tracking information that is recreated after a user has deleted it.

 

For example, a service may use another storage mechanism to restore a deleted identifier. As a result, the identifier appears to return without the user actively accepting it again.

 

This practice can undermine user choice and create serious privacy and compliance concerns. A user who deletes or rejects tracking technologies should not have those identifiers secretly restored through another method.

Benefits of cookies

Cookies are not inherently bad. When organisations use them proportionately and securely, they can make websites safer, more useful and easier to navigate.

 

They optimise session management.

HTTP requests do not automatically remember previous interactions. Cookies allow a website to connect multiple requests to the same session.

 

As a result, users can:

  • Remain logged in
  • Move between checkout pages
  • Keep products in a shopping cart
  • Complete multi-step forms
  • Use secure account features
  • Return to an unfinished process

 

The website does not necessarily store all this information inside the cookie. Instead, the cookie can contain a random identifier that connects the browser to information stored securely on the server.

 

They allow for a more personal experience

Cookies can prevent users from having to select the same settings during every visit.

For example, a website may remember:

  • Language
  • Region
  • Currency
  • Accessibility preferences
  • Display settings
  • Privacy choices

 

E-commerce websites can also use cookies to retain products in a shopping cart or remember recently viewed items.

 

Advertising technologies may use cookies and related identifiers to personalise or measure advertisements. However, where this involves non-essential tracking or profiling, the website may first need the user’s consent.

Dangers of cookies

Cookies cannot execute programs or directly infect a device with malware. Nevertheless, their use can create privacy and security risks.

 

Tracking and profiling

Tracking cookies can record behaviour over time. When organisations combine cookie identifiers with browsing history, account information or other data, they may infer a person’s:

  • Interests
  • Habits
  • Purchases
  • Preferences
  • Location
  • Likely future behaviour

 

Cross-site tracking can be particularly intrusive because it follows users beyond a single website.

 

Session hijacking

When a user logs in, a website may place a session cookie in the browser. This cookie helps the website recognise that the user has already authenticated.

 

If an attacker obtains a valid session identifier, the attacker may be able to impersonate the user. Depending on the service, this could provide unauthorised access to:

  • Online accounts
  • Personal information
  • Company systems
  • Purchases or payments
  • Confidential documents

 

Website owners can reduce this risk by using HTTPS, limiting cookie lifetimes and applying appropriate security attributes. For example:

 

  • Secure limits the cookie to encrypted HTTPS connections.
  • HttpOnly helps prevent JavaScript from reading the cookie.
  • SameSite controls whether the browser sends the cookie in certain cross-site situations.

 

These controls reduce risk, but they do not replace secure website development and proper access controls.

 

Excessive or unknown data collection

A website may use more cookies and trackers than its owner realises. This often happens when teams add:

  • Marketing tags
  • WordPress plugins
  • Embedded videos
  • Chat tools
  • Advertising pixels
  • A/B-testing software
  • New campaign technologies

 

Over time, technologies can remain active even after the organisation has stopped using them.

 

A consent-management platform may only control technologies that have been identified and configured correctly. Hard-coded scripts or newly introduced plugins may operate outside that configuration.

 

Website owners should therefore test what their live website actually does rather than relying only on the settings shown inside their consent-management platform.

The future of cookies

The web is likely to become more privacy-conscious, but it will not become completely cookieless. First-party cookies will continue to support important functions such as:

  • Authentication
  • Security
  • Shopping carts
  • Consent preferences
  • Language settings
  • Session management

 

At the same time, browsers, regulators and users are placing greater restrictions on cross-site tracking.

 

As a result, organisations should reduce unnecessary tracking and collect only the information they genuinely need. They can also explore approaches such as contextual advertising, aggregated measurement and privacy-preserving analytics.

 

However, replacing a cookie with another identifier does not automatically improve privacy. Technologies such as fingerprinting, link decoration and hidden server-side matching can be even less transparent because users may struggle to detect or control them.

 

The better approach is not to find a new way to follow every user. Instead, organisations should understand which information they genuinely need and design their websites accordingly.

Cookies and GDPR

Cookies are not automatically personal data. However, a cookie identifier can become personal data when an organisation can connect it to an identifiable person, account, device or profile.

 

The GDPR recognises that cookie identifiers and other online identifiers can leave traces. When organisations combine those traces with unique identifiers or other information, they may use them to identify people or create profiles.

 

When cookie use involves personal data, organisations must comply with GDPR principles such as:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Storage limitation
  • Security
  • Accountability

 

In addition, European ePrivacy rules generally require consent before a website stores information on a user’s device or accesses information already stored there. Limited exceptions apply when the storage or access is:

  1. Used solely to transmit a communication over an electronic communications network; or
  2. Strictly necessary to provide a service explicitly requested by the user.

 

This means that the ePrivacy rules can apply even when the information stored in a cookie is not personal data.

 

A legitimate interest under the GDPR does not automatically allow an organisation to place or access non-essential cookies. The organisation must first comply with the applicable ePrivacy requirements.

 

Because national laws and regulator guidance can differ, organisations operating in multiple countries should also consider the requirements in each relevant market.

 

To comply with the GDPR and applicable ePrivacy requirements, website owners should:

 

  1. <>Obtain consent before placing or accessing non-essential cookies and similar technologies.
  2. Explain clearly which technologies are used, what information they collect and why they are used.
  3. Record consent choices appropriately and retain evidence of the relevant consent configuration.
  4. Keep optional technologies inactive when a user rejects them.
  5. Avoid making optional cookies a condition for using services that do not require them.
  6. Make withdrawing consent as easy as giving it.
  7. Keep the cookie notice aligned with the behaviour of the live website.
  8. Repeat testing after website releases, campaign launches and technology changes.

 

A cookie banner alone does not prove that a website complies. The banner must also control the relevant technologies correctly.

In conclusion, what is a cookie on a website?

A cookie on a website is a small piece of data that helps a browser and website remember information between requests or visits.

 

Some cookies provide essential functions, such as maintaining a secure login session or remembering a shopping cart. Others support personalisation, analytics or advertising.

 

You can classify cookies according to their purpose, provider and duration. These classifications can overlap. Website owners should therefore not assess a cookie based only on labels such as first-party, third-party, session or persistent.

 

Instead, they should examine:

  • Why the cookie is used
  • What information it contains or refers to
  • Which parties receive the information
  • How long the cookie remains stored
  • Whether consent is required
  • Whether the live website respects the user’s choice

 

Used carefully, cookies can make websites secure and convenient. Used without transparency, proper consent or appropriate safeguards, they can create privacy and security risks.

 

For website owners, the most important question is not simply whether the website uses cookies. The more important question is whether every cookie and related technology behaves in line with the user’s choice.

How does Nixon Digital help you comply?

Managing cookie compliance across one or more websites can be challenging. Website teams regularly add new pages, plugins, campaigns and third-party services. As a result, the technologies used by the live website can change without the privacy or compliance team noticing.

 

A consent-management platform can help control known technologies. However, it does not automatically prove that every script, cookie and tracker follows the configured consent rules.

 

Hard-coded scripts, incorrectly categorised technologies and newly introduced plugins may still activate outside the consent-management platform.

 

Nixon Pro scans websites across multiple pages and helps organisations identify cookies, third parties and privacy risks that require further investigation.

 

A Nixon Pro scan can help organisations answer questions such as:

  • Which cookies and third parties are active on the website?
  • Do non-essential technologies activate before consent?
  • Does the live website match the cookie notice?
  • Do accept and reject choices work as intended?
  • Have new website releases introduced unexpected technologies?
  • Do privacy issues appear only on specific pages?

 

Recurring scans also help teams verify that their website continues to behave as intended after changes and releases.

 

Learn more about website privacy scanning with Nixon Pro.

What is a cookie on a website?
A cookie is a small text file that a website stores on your device through your browser. It holds a short piece of data, often just an ID, that lets the website recognize you when you come back, keep you logged in, or remember your settings. The cookie itself cannot run code. It is only stored information that the website (or a third party connected to it) reads on a later visit.
Cookies let websites remember things between page loads and visits. They keep you signed in, hold the contents of your shopping cart, remember your language and currency, and tell analytics tools that you are the same visitor who came yesterday. Marketing cookies go a step further. They link your activity across websites so advertisers can build a profile of what you are likely to click or buy.

The four most common uses are session management (logins, shopping carts), preferences (language, region, dark mode), analytics (measuring traffic and behavior) and advertising (targeting and retargeting). The first two are usually first-party cookies set by the website itself. The last two are often third-party cookies set by external companies whose scripts run on the page.

By origin, cookies are first-party (set by the website you are visiting) or third-party (set by another domain whose script the website loads). By duration, they are session cookies (deleted when you close the browser) or persistent cookies (stored for a set period). By purpose, GDPR groups them as strictly necessary, functional, analytics or marketing. Only strictly necessary cookies are exempt from consent.

Cookies themselves cannot carry viruses or run code. The risk is in what is stored in them and who can read them. A cookie containing a session token can be stolen if a website is not properly secured over HTTPS. Third-party tracking cookies are not dangerous in the malware sense, but they can expose your browsing behavior to companies you never directly interacted with.

Session cookies disappear when you close your browser. Persistent cookies have an expiration date set by the website, ranging from a single day to several years. Under GDPR guidance, non-essential cookies should not last longer than their stated purpose requires. The European Data Protection Board has indicated that 6 to 12 months is a reasonable upper limit for most marketing and analytics cookies.
Yes. Every modern browser lets you delete cookies for individual websites or all websites at once, through the privacy or settings menu. You can also block third-party cookies entirely, or set the browser to clear cookies automatically when you close it. Deleting cookies will sign you out of most websites and reset your saved preferences, but it does not break anything.
Almost every modern website uses at least one cookie, even if only a session cookie to keep the website working. A truly cookie-free website is rare in practice. Under GDPR and the Digital Omnibus, websites in the EU must inform visitors about non-essential cookies and obtain valid consent before setting them.

Want to be absolutely sure that your website is compliant?

Want to be absolutely sure that your website is compliant?

Check your website for GDPR or CCPA violations. Gain insight into the behavior of third-party cookies, trackers, domains, and fonts.

Nixon Pro: Website privacy audit tool. Check for third-party cookies, trackers, fonts and domains.

Check your website on trackers & cookies

Scan your website and see every privacy compliance issue before a regulator does.

Share:

Gain insights on everything website privacy related: