Cookie Policy Generator
Find out what your cookies do, list them properly and explain the choices visitors have.
Checks
Preview
Highlighted hints mark fields you have not filled in; downloads and printouts show a blank line there instead. To print, choose your printer or “Save as PDF” and turn off “Headers and footers”.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the Cookie Policy Generator
A cookie policy has to say which cookies your site sets, who sets them, what they do and how long they last — and how visitors can accept, refuse and change their minds. The hard part is finding out what each cookie is. Paste the names, a table copied from your browser’s developer tools, Set-Cookie headers, a document.cookie string, a cookie-manager export or a HAR file, and the tool looks each one up in the Open Cookie Database (2,266 cookies, Apache-2.0): provider, purpose, category and typical lifetime, with the real lifetime taken from your HAR or export when it has one.
You then check and edit the table — the tool flags cookies it could not find and “functional” ones that may not be strictly necessary, and moves third-party ones that need consent — and it writes a clear policy with the cookie table by category, the consent and withdrawal instructions, and the rules that apply: the ePrivacy Directive and GDPR in the EU, PECR in the UK (including its exceptions for statistics and website appearance) and India’s DPDP Act. Everything runs in your browser; cookie values are thrown away as soon as they are read.
How to use it
- Enter your site’s name and web address (it tells first-party cookies from third-party ones).
- Collect your cookies — DevTools → Application → Cookies, or a HAR exported with sensitive data — after accepting all cookies in a private window, and paste them or drop the file into Find your cookies.
- Check every row: the category, the provider and purpose, the duration and whether it is first or third party. Describe the ones the database does not know.
- Choose the regions to explain, say whether you use a cookie banner and how long a choice is remembered, and add a contact e-mail.
- Read the Checks, then copy the HTML into your cookie policy page (or download HTML, Markdown, DOCX, text or the CSV table) and link to it from your banner and footer.
Examples
_ga, _ga_X4B7Q2LM9P, IDE, PHPSESSID, __cf_bm
Analytics: _ga and the GA4 property cookie (2 years); Marketing: IDE on doubleclick.net (third party); Strictly necessary: PHPSESSID (session) and Cloudflare’s __cf_bm — a table for each, and the providers’ privacy pages.
YSC, VISITOR_INFO1_LIVE
The database calls YSC “functional”, but it is set by youtube.com: the tool moves it to Preferences (consent needed) and flags it for checking; VISITOR_INFO1_LIVE goes to Marketing.
Chrome 130+ default “Export HAR”
The tool explains that Chrome left the cookies out and how to export “with sensitive data” instead — and to delete that file afterwards.
Common uses
- Writing a cookie policy for a blog, shop or SaaS site before turning on analytics or ads.
- Auditing what a WordPress or Shopify site actually sets after installing plugins.
- Producing a cookie table (CSV) for a privacy team or a client.
- Checking what an unfamiliar cookie in your browser is.
What needs consent
- EU/EEA: storing or reading anything on a visitor’s device needs consent after clear and comprehensive information, unless it is for transmission or strictly necessary for a service the visitor explicitly asked for (ePrivacy Directive art. 5(3)). Consent must meet the GDPR standard and be as easy to withdraw as to give (art. 7(3)). Scrolling is not consent, pre-ticked boxes are invalid, and access must not depend on accepting (EDPB Guidelines 05/2020).
- UK: the same rule in PECR reg. 6 and Schedule A1, which also allows, without consent but with clear information and a simple, free way to object, statistics used only to improve your own service or site, not shared except with those helping you make the improvements (para. 5) and storage that adapts appearance and functionality to preferences (para. 6). Strictly necessary storage explicitly includes security, fraud prevention, fault detection, authentication and remembering selections (para. 4).
- India: no cookie-specific law. Cookies that process personal data come under the DPDP Act 2023, whose consent rules (s.6, in force from 13 May 2027) ask for consent that is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and as easy to withdraw as to give.
Getting the classification right
Regulators single out cookies labelled “essential” that are not (EDPB Cookie Banner Taskforce report). The Open Cookie Database uses “Functional” for essential cookies, but also files some analytics and advertising helpers there — so the tool flags each functional cookie that does not belong to the software running your site, payments, security or consent tools, and moves third-party ones to Preferences. Decide each one yourself: only storage the visitor cannot use a requested service without is exempt. Unknown cookies usually come from a plugin, theme, embed or tag manager — search your site’s code or switch scripts off one at a time.
Sources
- Directive 2002/58/EC, consolidated — art. 5(3) · GDPR — art. 7
- PECR 2003 reg. 6 and Schedule A1, as substituted by the Data (Use and Access) Act 2025
- EDPB Guidelines 05/2020 on consent · EDPB Cookie Banner Taskforce report
- Digital Personal Data Protection Act, 2023 — s.6
- Open Cookie Database (Apache License 2.0), snapshot · Chrome DevTools 130: HAR exports exclude sensitive data by default
Limitations
- The database describes common cookies; it cannot know your own site’s cookies or every plugin. Check every row before you publish.
- It does not crawl your site — cookies set only on some pages, after login or after consent appear only if you visit those pages before exporting.
- First-party detection uses the cookie’s domain; a list of bare names has none, so set “Set by” yourself.
- A template, not legal advice. The policy explains your cookies; you still need a consent banner that actually blocks non-essential cookies until visitors agree.
Privacy
Everything happens in your browser. Pasted text and files are read locally; cookie values are discarded straight away and the paste box is cleared after a lookup. The Open Cookie Database is part of this page and loads the first time you look something up. If you tick Keep a draft in this browser, the form and cookie list (without values) are saved in local storage.
Frequently asked questions
How do I find out what cookies my website uses?
Open the site in a private window, accept all cookies, visit the main pages, then open the browser’s developer tools (F12) → Application (Chrome, Edge) or Storage (Firefox) → Cookies, and copy the table — or export a HAR file from the Network tab with sensitive data included. Paste or drop it here.
Do strictly necessary cookies need consent?
No. Storage that is strictly necessary for a service the visitor explicitly asked for — a session, a shopping basket, security, remembering their cookie choice — is exempt under ePrivacy art. 5(3) and UK PECR Sch. A1 para. 4. Analytics, advertising and most embeds need consent in the EU.
Can I use analytics cookies without consent in the UK?
Statistics cookies used only to improve your own service or website, with the information not shared except with those helping you make the improvements, are allowed without consent if you give clear information and a simple, free way to object (PECR Sch. A1 para. 5). Analytics providers that also use the data for their own purposes, and anything used for advertising, still need consent, and the EU rule is unchanged.
Why does my HAR file show no cookies?
Chrome 130 and later export HAR files without Cookie, Set-Cookie and Authorization headers by default. Turn on Settings → Preferences → Network → “Allow to generate HAR with sensitive data” and choose “Export HAR (with sensitive data)”. That file contains live session cookies: use it here (it stays on your device) and delete it afterwards.
Is the Open Cookie Database reliable?
It is a community-maintained list of more than 2,000 common cookies under the Apache 2.0 licence — a good starting point, not an authority. Some entries are marked “functional” that are not strictly necessary, which is why the tool flags them and you decide.
Do I need a cookie policy in India?
There is no cookie-specific law, but cookies that process personal data are part of your privacy obligations. From 13 May 2027 the DPDP Act requires consent that is free, specific, informed and as easy to withdraw as to give. A clear cookie policy and a consent banner are how websites meet that.