Schedule a free consultation
How to Check Cookies and Prepare a Cookie Policy?

Cookies are small text files that a website may store on a user's device. They are used, for example, for the proper functioning of the website, to remember user preferences, to obtain statistics, or for marketing purposes.
If a cookie allows for the identification of a user or the analysis of their behavior, such information may be considered personal data. Therefore, an organization must know which cookies its website uses, for what purpose, and to whom this information is transferred.
How to inspect cookies?
The simplest method is to inspect through the browser:
Open the website in Chrome;
Right-click and select Inspect;
Go to the Application section;
On the left side, locate Cookies;
Open your website address and view whether cookies are stored.
Also, inspect Local Storage and Session Storage, as sometimes information is stored not in a cookie, but in other browser storage locations.
It is recommended to run this check on several pages: the homepage, contact page, blog, pages with forms, and pages containing third-party services, such as Google Maps, YouTube, Meta Pixel, or Google Analytics.
What should be included in a Cookie Policy?
A Cookie Policy should be concise, understandable, and actually reflect the actual status of the website. It is advisable to state:
What a cookie is;
What types of cookies the website uses;
For what purpose they are used;
Whether the cookie is strictly necessary for the operation of the website;
Whether analytical or marketing cookies are used;
Whether data is transferred to third parties;
How long the cookie is stored;
How the user can manage or disable cookies.
Main Categories of Cookies
Necessary cookies — required for the technical operation of the website, such as security, form functionality, or remembering user preferences.
Analytical cookies — used to understand how visitors interact with the website, which pages are popular, and how the website can be improved.
Marketing cookies — used for advertising, remarketing, or delivering offers based on user behavior.
When is consent required?
If a cookie is strictly necessary for the operation of the website, its use, as a rule, is permitted without separate user consent, though the user must still be informed.
If a cookie is used for analytics, marketing, behavioral monitoring, or third-party services, the secure approach is for the website to activate such cookies only after obtaining the prior and active consent of the user.
Consent must not be hidden. For example, simply stating—"By using this website, you agree to cookies"—is not considered good practice. The user must have a genuine choice: to accept, decline, or manage cookie categories.
Brief Practical Recommendation
An organization should first conduct a cookie audit—meaning, verify which cookies the website uses. Following this, it should prepare a Cookie Policy and, if necessary, a cookie banner where users can easily obtain information and make their choice.
A Cookie Policy should not be a generic text that is applied uniformly to all websites. It must be based on an actual technical inspection of the specific website.
Author:
David Karashvili
Data Protection Expert
Change of language
