United Kingdom Website Features And Cookie Policy Disclosures
Typical Cookie Use | Likely Cookie Category | Consent Position | Example Policy Wording | Drafting Notes |
|---|---|---|---|---|
Account registration and login | ||||
Keeps the user signed in and maintains secure account sessions. | Strictly necessary | Usually not required | We use login cookies to authenticate you and keep your account session secure. | Limit this to authentication and security remember-me features may need separate analysis. |
Remember-me login | ||||
Stores a persistent token so the user does not need to sign in each visit. | Functional, Preferences | Depends on implementation | If you select remember me, we use a cookie to recognise your device on future visits. | If optional and persistent, disclose clearly and consider whether user choice supplies the request. |
Shopping basket | ||||
Remembers items placed in the basket while the user shops. | Strictly necessary | Usually not required | We use basket cookies to remember the products you add during your visit. | Exemption is strongest where the cookie is limited to basket and checkout functions. |
Checkout process | ||||
Maintains checkout steps, delivery choices and order state. | Strictly necessary | Usually not required | Checkout cookies are used to process your order and keep your checkout session active. | Do not include upsell, analytics or advertising tags in this category. |
Payment processing and fraud checks | ||||
Supports payment authentication, fraud detection and transaction security. | Strictly necessary | Usually not required | Payment security cookies help process payments, prevent fraud and verify transactions. | Name third-party payment providers where their scripts set cookies or device identifiers. |
Embedded card payment fields | ||||
Allows a payment provider to secure hosted card input fields. | Strictly necessary | Usually not required | Our payment provider may set essential cookies to secure card payment fields. | Check provider documentation and disclose any non-payment analytics separately. |
Password reset | ||||
Maintains a temporary reset session and helps prevent misuse. | Strictly necessary | Usually not required | We use temporary security cookies when you request or complete a password reset. | Keep retention short and avoid using reset events for marketing without consent. |
Multi-factor authentication | ||||
Remembers trusted devices or maintains authentication challenge state. | Strictly necessary, Functional | Depends on implementation | Authentication cookies help verify your identity and may remember trusted devices if selected. | Trusted-device persistence is different from a temporary security challenge cookie. |
Load balancing | ||||
Routes requests to the same server during a session. | Strictly necessary | Usually not required | Load balancing cookies help deliver the website reliably during your visit. | Usually exempt if used only for network management and session routing. |
Web application firewall | ||||
Identifies suspicious traffic and helps protect the site from attacks. | Strictly necessary | Usually not required | Security cookies help detect malicious traffic and protect our website and users. | Disclose provider names such as CDN or security vendors if visible to users. |
Bot detection and rate limiting | ||||
Distinguishes legitimate users from automated or abusive requests. | Strictly necessary | Usually not required | Anti-abuse cookies help us detect bots, limit misuse and keep the service available. | If the tool also profiles users for advertising, separate that use and obtain consent. |
CAPTCHA or abuse prevention challenge | ||||
Checks whether a visitor appears human and reduces spam submissions. | Strictly necessary, Other | Depends on implementation | We use CAPTCHA cookies or similar checks to prevent spam and protect online forms. | Third-party CAPTCHA may involve device data assess whether it loads before necessary. |
Cookie consent banner | ||||
Records cookie choices and prevents repeated consent prompts. | Strictly necessary | Usually not required | We use a consent cookie to remember your cookie choices. | Do not use consent storage to infer marketing preferences unless clearly covered. |
Privacy preference centre | ||||
Stores user choices for analytics, advertising and optional features. | Strictly necessary, Preferences | Depends on implementation | Preference centre cookies remember the privacy choices you make on our website. | Essential storage of choices is different from optional preference personalisation. |
Language selector | ||||
Remembers the user’s chosen language for future visits. | Preferences | Depends on implementation | We use language preference cookies to show the website in your selected language. | If the user actively requests the setting, consent may be less likely to be required. |
Region or country selector | ||||
Remembers selected country, currency, tax or delivery region. | Preferences | Depends on implementation | Region preference cookies remember your selected location settings, such as country or currency. | Geolocation-based personalisation or profiling may require additional disclosure and consent. |
Accessibility settings | ||||
Remembers contrast, font size or reduced-motion preferences. | Preferences, Functional | Depends on implementation | Accessibility cookies remember settings such as text size, contrast or motion preferences. | User-selected accessibility settings are commonly expected but should still be disclosed. |
Theme or dark mode | ||||
Remembers the user’s selected visual theme. | Preferences | Depends on implementation | Theme cookies remember your display preference, such as light or dark mode. | Avoid grouping theme cookies with analytics or behavioural personalisation. |
Saved form progress | ||||
Temporarily stores form step or draft progress to prevent data loss. | Functional, Strictly necessary | Depends on implementation | Form progress cookies help save your progress while completing multi-step forms. | Essential for a requested multi-step process may be exempt cross-session drafts need care. |
Contact form submission | ||||
Maintains form session, prevents duplicate submissions and supports spam checks. | Strictly necessary, Functional | Depends on implementation | Contact form cookies help submit your message securely and prevent duplicate or spam submissions. | Separate essential form cookies from analytics events fired on submission. |
Newsletter sign-up form | ||||
Prevents duplicate sign-ups, records form state or tracks campaign source. | Functional, Analytics | Depends on implementation | Newsletter form cookies may help process your sign-up and measure which pages generate subscriptions. | Campaign attribution or marketing tracking normally needs consent before storage/access. |
Live chat widget | ||||
Maintains chat sessions and may identify returning visitors. | Functional, Analytics | Depends on implementation | Live chat cookies keep your chat session active and may recognise returning visitors. | Consent is more likely required if the widget loads tracking cookies before user interaction. |
AI chatbot | ||||
Keeps conversation context, session IDs and visitor status. | Functional, Other | Depends on implementation | Chatbot cookies help maintain your conversation and remember the chat session. | Disclose if conversations are linked to analytics, user accounts or model improvement. |
Support ticket portal | ||||
Authenticates users and maintains support request sessions. | Strictly necessary, Functional | Depends on implementation | Support portal cookies help you log in, view tickets and submit support requests. | Portal analytics or satisfaction tracking should not be treated as essential. |
Site search | ||||
Remembers recent searches or measures search performance. | Functional, Analytics | Depends on implementation | Search cookies may remember recent searches or help us improve search results. | Recent-search convenience differs from analytics of search terms and behaviour. |
Product filters and sorting | ||||
Remembers selected filters, sort order or view layout. | Preferences, Functional | Depends on implementation | Filter cookies remember your selected product filters, sorting or layout preferences. | If used to build a behavioural profile, classify separately from preferences. |
Wishlist or favourites | ||||
Stores or links saved items to a browser or account. | Functional, Preferences | Depends on implementation | Wishlist cookies help save items you choose to keep or revisit later. | Marketing based on wishlists should be separately disclosed and consented where required. |
Personalised recommendations | ||||
Tracks browsing or purchase behaviour to suggest relevant products or content. | Functional, Analytics, Other | Usually required | Recommendation cookies help tailor products or content based on your browsing activity. | Behavioural personalisation normally needs consent unless no device storage/access occurs. |
Recently viewed items | ||||
Records pages or products viewed to show them again later. | Functional, Preferences | Depends on implementation | Recently viewed cookies help show items or pages you have visited before. | Consent is more likely if used across sessions or for profiling beyond user convenience. |
Reviews and ratings widget | ||||
Prevents repeat voting and supports review display or moderation. | Functional, Strictly necessary | Depends on implementation | Review cookies help display ratings, prevent duplicate votes and support moderation. | Third-party review platforms may set analytics or advertising cookies separately. |
Embedded maps | ||||
Displays interactive maps and may collect usage or device data. | Functional, Analytics | Usually required | Map cookies enable interactive maps and may allow the map provider to collect usage data. | Use consent gating if the map provider sets non-essential cookies on load. |
Embedded video player | ||||
Enables video playback and may measure viewing or personalise content. | Functional, Analytics, Other | Usually required | Video cookies enable embedded videos and may help the provider measure video use. | Consider privacy-enhanced embeds or blocking the player until consent is given. |
Embedded audio player | ||||
Supports audio playback and may measure listens or device sessions. | Functional, Analytics | Usually required | Audio player cookies enable embedded audio and may measure listening activity. | Third-party player analytics commonly require prior consent. |
Social sharing buttons | ||||
Allows sharing and may let social platforms track page visits. | Functional, Analytics, Other | Usually required | Social sharing cookies enable sharing features and may allow social networks to track interactions. | Use static links if you want sharing without third-party tracking cookies. |
Embedded social media feed | ||||
Displays social posts and may identify logged-in social media users. | Functional, Analytics, Other | Usually required | Social feed cookies display embedded posts and may help the platform recognise users. | Block feeds until consent if scripts set cookies before interaction. |
Social login or single sign-on | ||||
Authenticates users through a third-party identity provider. | Strictly necessary, Functional | Depends on implementation | Single sign-on cookies help authenticate you through your chosen identity provider. | Do not load wider social tracking scripts unless consent has been obtained. |
Website analytics | ||||
Measures visits, events, pages viewed and user journeys. | Analytics | Usually required | Analytics cookies help us understand how visitors use our website and improve it. | UK ICO treats analytics cookies as non-essential, even if used only by the site owner. |
Cookie-less or privacy-focused analytics | ||||
May measure visits without cookies or with minimal local storage. | Analytics | Depends on implementation | We may use privacy-focused analytics to measure site use with limited or no cookie storage. | If no device storage or access occurs, PECR cookie consent may not apply, but privacy duties may. |
Conversion tracking | ||||
Links ad clicks or campaigns to purchases, sign-ups or enquiries. | Analytics, Other | Usually required | Conversion cookies help measure whether advertising or campaigns lead to actions on our website. | Usually advertising or analytics block before consent unless clearly essential. |
Advertising pixels | ||||
Tracks visits and actions for advertising measurement and audience building. | Other, Analytics | Usually required | Advertising cookies and pixels help measure ads and build audiences for marketing. | Name major ad platforms and ensure pixels do not fire before consent. |
Remarketing or retargeting | ||||
Recognises visitors later to show targeted adverts on other sites or platforms. | Other | Usually required | Remarketing cookies help show relevant adverts to people who have visited our website. | This is high-priority for consent controls and clear third-party disclosure. |
Affiliate tracking | ||||
Records referral source so commissions can be attributed. | Analytics, Other | Usually required | Affiliate cookies help attribute referrals and commission payments to partner websites. | Commercial attribution is not usually essential to the user-requested service. |
Campaign attribution | ||||
Stores campaign, source or medium information from tracking links. | Analytics, Other | Usually required | Campaign cookies help us understand which marketing campaigns brought visitors to our website. | UTM values in URLs are not cookies, but storing them on a device may trigger PECR. |
A/B testing | ||||
Assigns visitors to test variants and measures responses. | Analytics, Functional | Usually required | Testing cookies help us compare page versions and improve website design. | May be functional if purely necessary for requested feature, but optimisation testing usually needs consent. |
Feature flags or staged rollouts | ||||
Assigns a visitor to a feature version or rollout group. | Functional, Analytics | Depends on implementation | Feature cookies may help us deliver the correct version of a website feature to your browser. | Operational rollouts may differ from experimentation or behavioural optimisation. |
Heatmaps | ||||
Tracks clicks, scrolls and page interactions to analyse user behaviour. | Analytics | Usually required | Heatmap cookies help us understand how visitors interact with pages, such as clicks and scrolling. | Mask personal data in recordings and obtain consent before non-essential tracking. |
Session replay | ||||
Records user interactions to replay browsing sessions for diagnostics or optimisation. | Analytics, Other | Usually required | Session replay cookies help us review website interactions to improve usability and diagnose issues. | High privacy risk disclose clearly and suppress keystrokes and sensitive fields. |
Error monitoring | ||||
Links errors to a session so technical faults can be diagnosed. | Functional, Analytics | Depends on implementation | Error monitoring cookies help us identify and fix technical problems on the website. | Essential diagnostic cookies may be arguable, but product analytics needs consent. |
Performance monitoring | ||||
Measures page speed, latency and service reliability by session or device. | Analytics, Functional | Depends on implementation | Performance cookies help us measure loading times and improve service reliability. | Aggregate server logs differ from browser cookies or local storage identifiers. |
Content delivery network | ||||
Improves content delivery, security and traffic routing. | Strictly necessary, Functional | Usually not required | CDN cookies help deliver website content efficiently and protect the service. | Check whether CDN add-ons include analytics or advertising products. |
Browser local storage | ||||
Stores settings, identifiers or cached data in the browser instead of a cookie. | Functional, Preferences, Analytics | Depends on implementation | We may use browser storage to remember settings or support website functions. | PECR applies to storing or accessing device information, not only cookie files. |
Offline mode or progressive web app | ||||
Caches files or settings so parts of the site work offline or load faster. | Functional, Strictly necessary | Depends on implementation | Offline storage helps the website load faster and provide selected functions when offline. | Caching required service files differs from storing behavioural identifiers. |
Web push notifications | ||||
Stores subscription identifiers and notification preferences. | Preferences, Functional | Depends on implementation | Notification cookies or storage remember your push notification subscription and preferences. | Browser notification permission is separate from cookie consent and marketing consent. |
Location-based services | ||||
Stores approximate location, postcode or location preference. | Preferences, Functional, Other | Depends on implementation | Location cookies may remember your selected location to show relevant local content or services. | Precise geolocation and profiling require stronger privacy notices and permissions. |
Age gate | ||||
Remembers that a visitor has completed an age confirmation step. | Strictly necessary, Functional | Depends on implementation | Age gate cookies remember that you have completed an age confirmation check. | If legally or safety required for access, essential classification may be justified. |
File upload or media upload | ||||
Maintains upload sessions and resumes interrupted uploads. | Strictly necessary, Functional | Depends on implementation | Upload cookies help maintain upload sessions and support resumable file transfers. | Analytics around uploads should be separated from session continuity cookies. |
Online document generator | ||||
Maintains the user’s questionnaire session and document drafting progress. | Strictly necessary, Functional | Depends on implementation | Document generator cookies keep your drafting session active and help save your progress. | If generation cannot work without session storage, classify as essential analytics is separate. |
AI content generation | ||||
Links prompts, outputs or usage limits to a user session. | Functional, Strictly necessary, Analytics | Depends on implementation | AI tool cookies help maintain your session, apply usage limits and deliver generated content. | Disclose any analytics, model improvement or cross-session profiling separately. |
Usage limits or quotas | ||||
Tracks free trials, rate limits or document generation counts. | Strictly necessary, Functional | Depends on implementation | Usage limit cookies help apply fair use limits, trial restrictions or service quotas. | Essentiality is stronger for fraud prevention or access control than marketing segmentation. |
Subscription paywall | ||||
Checks entitlement and controls access to subscriber-only content. | Strictly necessary, Functional | Usually not required | Paywall cookies verify access rights and help deliver subscriber-only content. | Advertising or content recommendation cookies around the paywall require separate treatment. |
User dashboard preferences | ||||
Remembers dashboard layout, widgets or saved views. | Preferences, Functional | Depends on implementation | Dashboard preference cookies remember your chosen layout, widgets or saved views. | User-selected settings may be requested, but behavioural optimisation is separate. |
Comments section | ||||
Remembers commenter details or manages comment sessions and moderation. | Functional, Preferences | Depends on implementation | Comment cookies may remember your commenter details and support comment moderation. | Optional remembering of name/email should not be bundled with essential moderation cookies. |
Forum or community area | ||||
Maintains login sessions, unread posts and user preferences. | Strictly necessary, Functional, Preferences | Depends on implementation | Community cookies keep you signed in and remember forum preferences such as unread posts. | Separate community operation from ads, recommendations or social tracking. |
Surveys and polls | ||||
Prevents repeat responses and stores survey progress. | Functional, Analytics | Depends on implementation | Survey cookies help record that you have responded and may save survey progress. | Experience analytics or profiling from surveys should be consented and disclosed separately. |
Pop-up or announcement banner | ||||
Remembers that a visitor has dismissed a notice or promotion. | Preferences, Functional | Depends on implementation | Banner cookies remember whether you have dismissed notices or pop-ups. | Promotional targeting or frequency capping may be advertising rather than preference storage. |
Ad frequency capping | ||||
Limits how often a visitor sees the same advert. | Other | Usually required | Advertising cookies help limit repeated adverts and measure advertising delivery. | Frequency capping is part of advertising delivery and normally needs consent. |
Third-party advertising | ||||
Selects, delivers and measures adverts using third-party identifiers. | Other | Usually required | Advertising cookies are used by us and our partners to deliver and measure adverts. | List advertising partners or provide a current partner list where practical. |
Personalised advertising | ||||
Builds or uses profiles to show adverts based on interests or behaviour. | Other | Usually required | Personalised advertising cookies help tailor adverts based on your browsing activity and interests. | Requires clear consent and privacy information on profiling and third-party sharing. |
Ad measurement | ||||
Measures ad impressions, clicks and conversions. | Analytics, Other | Usually required | Ad measurement cookies help measure advert views, clicks and campaign performance. | Even non-personalised ad measurement may need consent if cookies or device access are used. |
CRM visitor tracking | ||||
Links website visits to contact records, leads or sales activity. | Analytics, Other | Usually required | CRM cookies may link website activity to enquiries or customer records for sales follow-up. | High transparency needed where anonymous browsing becomes linked to an identifiable contact. |
Email campaign click tracking on site | ||||
Recognises visitors arriving from marketing emails and tracks subsequent actions. | Analytics, Other | Usually required | Email campaign cookies help measure what visitors do after clicking links in our emails. | Email marketing consent is separate from cookie consent for on-site tracking. |
Referral programme | ||||
Stores referrer codes to attribute sign-ups, rewards or discounts. | Functional, Analytics, Other | Depends on implementation | Referral cookies help apply referral codes and attribute rewards or discounts. | Applying a requested discount may be functional broader marketing attribution may need consent. |
Loyalty programme | ||||
Recognises loyalty members and applies points, benefits or offers. | Functional, Preferences, Other | Depends on implementation | Loyalty cookies help recognise members and apply programme benefits or offers. | Personalised offers and profiling require clear notice and may need consent. |
Currency or pricing display | ||||
Remembers selected currency or price display preferences. | Preferences, Functional | Depends on implementation | Currency cookies remember your chosen currency or pricing display setting. | Dynamic pricing based on behaviour needs separate, prominent privacy disclosure. |
Store locator or stock checker | ||||
Stores postcode, preferred store or location choice. | Preferences, Functional | Depends on implementation | Store locator cookies remember your preferred store or location search. | Precise location access requires browser permission and privacy information beyond cookie wording. |
Appointment booking | ||||
Maintains selected time slots and booking session state. | Strictly necessary, Functional | Depends on implementation | Booking cookies keep your selected appointment slot and booking session active. | Calendar analytics, remarketing or abandoned booking tracking should be separated. |
Event registration | ||||
Maintains registration progress and ticket selections. | Strictly necessary, Functional | Depends on implementation | Event registration cookies keep your registration session and ticket selections active. | Marketing pixels on event pages normally need consent before firing. |
Download tracking | ||||
Measures downloads of PDFs, templates or files. | Analytics | Usually required | Download analytics cookies help us understand which files visitors download. | Server-side aggregate logs differ from cookie-based user-level download tracking. |
Document previewer | ||||
Supports embedded viewing and remembers viewing state or page position. | Functional, Preferences | Depends on implementation | Previewer cookies help display documents and remember your viewing position. | Third-party preview tools may also set analytics cookies. |
Print or export settings | ||||
Remembers selected export format, page size or print options. | Preferences, Functional | Depends on implementation | Export preference cookies remember options such as format, page size or print settings. | Usually low risk where tied to a user-requested export function. |
Tag manager or consent mode | ||||
Controls which tags run and may pass consent signals to vendors. | Strictly necessary, Functional | Depends on implementation | Tag management cookies help apply your consent choices and control optional website tags. | The manager may be essential, but the tags it deploys may still need consent. |
Cross-device tracking | ||||
Links activity across browsers or devices for measurement or personalisation. | Other, Analytics | Usually required | Cross-device cookies or identifiers may help recognise activity across devices for measurement or personalisation. | High privacy impact explain purposes, partners and opt-out or withdrawal routes. |
Device fingerprinting | ||||
Uses device characteristics to recognise a browser without traditional cookies. | Other, Analytics | Usually required | Fingerprinting technologies may use device information to recognise browsers for security, analytics or advertising. | Security-only use may differ from tracking disclose clearly because PECR covers similar technologies. |
Fraud risk scoring | ||||
Uses identifiers or device signals to detect suspicious transactions or account abuse. | Strictly necessary, Other | Depends on implementation | Fraud prevention cookies help assess transaction risk and protect accounts and payments. | Separate fraud prevention from advertising fingerprinting or behavioural marketing. |
Security incident logging | ||||
Correlates suspicious events with a browser session or device. | Strictly necessary | Usually not required | Security logging cookies help detect, investigate and prevent misuse of our website. | Keep security identifiers proportionate and avoid repurposing them for analytics. |
Embedded third-party booking widget | ||||
Supports appointment booking and may track widget interactions. | Functional, Analytics | Depends on implementation | Booking widget cookies enable appointment booking and may measure use of the booking tool. | Gate the widget or configure it to avoid non-essential cookies before consent. |
Embedded shop widget | ||||
Maintains product selections, cart state and checkout links. | Strictly necessary, Functional, Analytics | Depends on implementation | Shop widget cookies help display products, maintain basket choices and support checkout. | Third-party shop analytics and marketing pixels should be controlled separately. |
Help centre suggestions | ||||
Uses previous help searches or page views to suggest support articles. | Functional, Analytics | Depends on implementation | Help centre cookies may remember support searches and suggest relevant help articles. | If suggestions are behaviourally profiled across visits, consent is more likely required. |
Accessibility overlay widget | ||||
Stores selected accessibility adaptations and widget state. | Preferences, Functional | Depends on implementation | Accessibility widget cookies remember the accessibility options you choose. | Check whether the overlay vendor also sets analytics or tracking cookies. |
Embedded marketing form | ||||
Captures form state and may link submissions to marketing profiles. | Functional, Analytics, Other | Usually required | Marketing form cookies may process your submission and link it to marketing campaign activity. | Lead tracking and profiling should be opt-in where cookies or similar technologies are used. |
Customer satisfaction widget | ||||
Stores feedback status, survey prompts or satisfaction scores. | Analytics, Functional | Depends on implementation | Feedback cookies help show satisfaction surveys and remember whether you have responded. | Feedback analytics beyond preventing repeat prompts usually needs consent. |
Exit-intent pop-up | ||||
Detects exit behaviour and limits repeated display of offers or prompts. | Analytics, Other, Functional | Usually required | Exit-intent cookies help show and limit exit prompts or offers. | Behaviour detection for marketing is unlikely to be strictly necessary. |
Abandoned basket tracking | ||||
Records basket activity to send reminders or analyse checkout drop-off. | Analytics, Other | Usually required | Abandoned basket cookies help us analyse checkout drop-off or send basket reminders where permitted. | Distinguish essential basket storage from reminder marketing and tracking. |
Back-in-stock alerts | ||||
Stores alert preferences or links product interest to a user session. | Functional, Preferences, Other | Depends on implementation | Stock alert cookies help remember products for which you requested availability notifications. | Email or SMS alerts require separate direct marketing compliance checks. |
Product comparison tool | ||||
Stores selected items for comparison across pages or visits. | Functional, Preferences | Depends on implementation | Comparison cookies remember items you select for comparison. | Persistent comparison lists used for profiling should be analysed separately. |
Inventory reservation | ||||
Temporarily reserves stock while the user completes checkout. | Strictly necessary | Usually not required | Reservation cookies temporarily hold selected items while you complete checkout. | Keep duration proportionate to the reservation period. |
Legal notice acknowledgement | ||||
Records that a user has seen or acknowledged a required notice. | Strictly necessary, Functional | Depends on implementation | Notice cookies remember that you have seen or acknowledged important website notices. | Essentiality depends on whether acknowledgement is needed to provide or evidence the service. |
Terms acceptance record | ||||
Records acceptance state for website terms or updated conditions. | Strictly necessary, Functional | Usually not required | Terms cookies record that you have accepted the current website terms where required. | Avoid using this cookie for unrelated analytics or marketing segmentation. |
Browser compatibility check | ||||
Stores compatibility or feature support information for site operation. | Functional, Strictly necessary | Depends on implementation | Compatibility cookies help ensure website features work correctly in your browser. | Do not confuse compatibility checks with fingerprinting for tracking. |
App deep linking | ||||
Remembers app installation prompts or supports links between web and app journeys. | Functional, Analytics, Other | Depends on implementation | App linking cookies may support web-to-app journeys and remember app prompt choices. | Attribution SDKs and install tracking usually need consent where device identifiers are used. |
Shareable draft link | ||||
Maintains access permissions or draft state for shared content. | Strictly necessary, Functional | Usually not required | Draft link cookies help manage access to shared drafts and keep the drafting session secure. | Do not include analytics on recipients under this essential wording. |
Electronic signature workflow | ||||
Authenticates signers and maintains signing session state. | Strictly necessary, Functional | Usually not required | E-signature cookies help authenticate signers and maintain secure signing sessions. | Identity verification, audit trails and marketing tracking should be described separately. |
Identity verification | ||||
Supports verification sessions, anti-fraud checks and secure document upload. | Strictly necessary, Other | Depends on implementation | Identity verification cookies help complete verification checks and protect against fraud. | Biometric or special category processing needs privacy notice detail beyond cookie wording. |
UK cookie consent rule | ||||
Regulation 6 restricts storing or accessing information on user equipment without clear information and consent, subject to exemptions. | Other | Depends on implementation | UK rules require us to give clear cookie information and obtain consent unless an exemption applies. | Useful background record do not present as a website feature in a customer-facing table unless appropriate. |
Consent standard for cookies | ||||
Consent must be freely given, specific, informed and unambiguous where relied on for non-essential cookies. | Other | Depends on implementation | Where required, we ask for your consent before setting non-essential cookies. | Cookie banners should avoid pre-ticked boxes or implied consent for non-essential cookies. |
When Does A UK Cookie Policy Need To Mention A Website Feature?
A UK cookie policy should describe each feature that stores or reads information on a user’s device, not just files called cookies. This includes analytics tags, advertising pixels, chat widgets, embedded videos, payment fraud tools, preference settings and consent-management platforms.
Which Website Features Usually Need Cookie Consent In The UK?
Consent is usually required for analytics, advertising, remarketing, social media plugins, personalisation, A/B testing, heatmaps, session recording and most third-party embedded content. These are not normally treated as strictly necessary because the website can usually operate without them.
Which Cookies Are Usually Exempt From Consent?
Cookies that are genuinely essential to provide a service requested by the user are usually exempt. Common examples include shopping basket cookies, secure login/session cookies, checkout security, load balancing, consent-record cookies and basic security cookies. They should still be disclosed in the cookie policy.
Why Does Implementation Matter?
The same feature can fall into different categories depending on how it is configured. For example, a video embed may be consent-free only if it does not set non-essential cookies before play, and analytics may require consent unless configured in a way that does not involve device access or similar tracking.
What Should Be Checked Before Publishing A Cookie Policy?
- Run a cookie scan and compare the results with actual site features.
- Separate strictly necessary cookies from analytics, advertising, preference and functional cookies.
- Identify third-party providers and link to their privacy or cookie information where appropriate.
- Check that non-essential cookies are blocked until valid UK GDPR and PECR consent is obtained.
- Update the wording when adding new tools such as chat, embedded media, remarketing pixels, payment services or analytics platforms.

FAQs
You Might Also Be Interested In






