Back to the help center

Compliance

Cookie categories explained

Understand necessary, functional, analytics, and advertising cookie categories

Understanding cookie categories is fundamental to setting up compliant consent management. This guide explains each category, what types of cookies and scripts belong in them, why the distinction matters legally, and how to classify your site's cookies correctly.

Privacy regulations like GDPR, ePrivacy Directive, and CCPA require websites to:

  1. Inform users about what cookies are used and why.
  2. Obtain consent before setting non-essential cookies.
  3. Provide granular choice -- users must be able to accept some categories while rejecting others.

Categorizing cookies correctly ensures your consent banner accurately represents what happens on your site, which is both a legal requirement and a trust signal for visitors.

The Four Standard Categories

1. Necessary (Strictly Necessary)

Purpose: Essential for the website to function. Without these, core features break.

Consent required: No. These cookies are exempt from consent requirements under GDPR/ePrivacy because the site cannot operate without them.

Default state: Always granted. Users cannot disable these.

Examples:

Cookie/ScriptPurpose
Session cookiesKeep users logged in
CSRF tokensPrevent cross-site request forgery attacks
Shopping cart cookiesRemember items in the cart
Load balancer cookiesRoute traffic to the correct server
Cookie consent stateRemember the user's consent choice itself
Authentication tokensVerify user identity
Security cookiesDetect malicious activity, bot protection
Accessibility preferencesFont size, high contrast mode (if essential)

What does NOT belong here:

  • Analytics of any kind (even "basic" page view tracking)
  • Social media widgets
  • Advertising identifiers
  • A/B testing tools (unless essential for site function)
  • Performance monitoring tools that collect user data
Common mistake: Some sites classify Google Analytics as "necessary." Under GDPR, traffic analytics is never strictly necessary for the website to function, even if it is necessary for your business. It belongs in the Analytics category.

2. Functional (Preferences)

Purpose: Enable enhanced features and personalization that are not strictly required for the site to work, but improve the user experience.

Consent required: Yes. These require opt-in consent under GDPR.

Default state: Denied until the user consents.

Examples:

Cookie/ScriptPurpose
Language preference cookiesRemember the user's preferred language
Region/currency preferencesRemember location and currency settings
Theme/layout preferencesRemember dark mode, sidebar collapsed, etc.
Chat widget settingsRemember chat history and preferences
Video player preferencesRemember volume, quality, autoplay settings
Font size preferencesRemember accessibility choices (if not essential)
Recently viewed itemsShow recently viewed products
Form auto-fill dataRemember form field values

Google Consent Mode mapping: functionality_storage, personalization_storage

Gray area: Some functional cookies could arguably be classified as Necessary (e.g., language preference for a multilingual site). When in doubt, classify as Functional -- it is safer from a compliance standpoint.

3. Analytics (Statistics / Performance)

Purpose: Collect data about how visitors use the site -- page views, traffic sources, performance metrics, user behavior patterns. Used to improve the site, not to target advertising.

Consent required: Yes. Even anonymized analytics require consent under strict GDPR interpretations (though some EU countries allow analytics with legitimate interest if properly anonymized -- consult legal counsel).

Default state: Denied until the user consents.

Examples:

Cookie/ScriptPurpose
Google Analytics (GA4)Page views, sessions, user behavior
Hotjar / FullStoryHeatmaps, session recordings
Plausible / Fathom / MatomoPrivacy-focused analytics
Microsoft ClaritySession recording and heatmaps
Amplitude / MixpanelProduct analytics and event tracking
Speed/performance monitoringPage load times, Core Web Vitals
A/B testing toolsOptimizely, VWO, Google Optimize
Error trackingSentry, LogRocket (if they collect user data)
Scroll depth trackingHow far users scroll on pages

Google Consent Mode mapping: analytics_storage

Important distinction: Analytics cookies measure how your site is used. They do not target ads. If a tool does both analytics and advertising (e.g., Google Analytics with cross-site tracking enabled), its advertising features belong in the Marketing category.

4. Marketing (Advertising / Targeting)

Purpose: Track users across websites to build profiles for targeted advertising, retargeting, and conversion measurement.

Consent required: Yes. This is the most privacy-sensitive category.

Default state: Denied until the user consents.

Examples:

Cookie/ScriptPurpose
Google Ads (conversion tracking)Measure ad conversions
Google Ads (remarketing)Show ads to previous visitors
Meta (Facebook) PixelTrack conversions and build audiences
LinkedIn Insight TagB2B advertising and audience building
TikTok PixelConversion tracking and retargeting
Pinterest TagConversion tracking and audience building
Twitter/X PixelConversion tracking
CriteoRetargeting display ads
AdRollCross-platform retargeting
DoubleClick / Google Marketing PlatformProgrammatic advertising
Social sharing widgetsFacebook Like, Twitter Share (when they track)
Affiliate tracking cookiesTrack referral sources for commissions
Cross-site tracking scriptsAny script that follows users across sites

Google Consent Mode mapping: ad_storage, ad_user_data, ad_personalization

How to Classify Your Cookies

Step 1: Run a Scan

  1. In your GetCookies dashboard, run a full scan on your domain.
  2. The scan detects all cookies and scripts on your site.
  3. GetCookies automatically classifies known cookies using its database of 30,000+ recognized cookies.

Step 2: Review Unclassified Items

After the scan:

  1. Go to Scan Results for your domain.
  2. Look for items marked as "Unclassified" or "Unknown."
  3. For each unclassified item, determine its purpose by:
  • Checking the cookie name against the service provider's documentation.
  • Looking at the domain the cookie comes from.
  • Checking what script sets the cookie.

Step 3: Assign Categories

For each unclassified cookie or script:

  1. Click on the item in the scan results.
  2. Select the appropriate category from the dropdown.
  3. Add a description of the cookie's purpose (this appears in your cookie declaration).
  4. Save.

Decision Guide

Use this flowchart to decide which category a cookie belongs in:

  1. Does the site break without it? (Login fails, cart empties, forms do not submit)
  • Yes → Necessary
  • No → Continue
  1. Does it improve the user experience without tracking behavior? (Language, theme, preferences)
  • Yes → Functional / Preferences
  • No → Continue
  1. Does it measure how the site is used without identifying users for advertising? (Page views, performance, errors)
  • Yes → Analytics
  • No → Continue
  1. Does it track users for advertising, build audience profiles, or measure ad conversions?
  • Yes → Marketing
  1. Still unsure?
  • Default to Marketing -- this is the safest choice from a compliance standpoint. Over-classifying as Marketing means users must consent before it loads, which is always legally safe.

Common Classification Mistakes

Mistake 1: Classifying GA4 as Necessary

Google Analytics is never strictly necessary. A website functions without it. Always classify as Analytics.

Mistake 2: Missing hidden trackers

Some scripts load additional scripts dynamically. A Facebook Pixel might load additional tracking scripts that are not visible in your HTML. Run a full scan to catch these.

Mistake 3: Ignoring third-party iframes

Embedded YouTube videos, Google Maps, and social media embeds often set cookies. These need to be categorized and blocked until consent.

Mistake 4: Forgetting server-set cookies

Not all cookies come from JavaScript. Your server may set tracking cookies via HTTP headers. These show up in scans but are sometimes overlooked. Ensure they are classified.

Mistake 5: Classifying A/B testing as Necessary

Unless your A/B testing tool is essential for the site to function (rare), it belongs in Analytics. Tools like Optimizely, VWO, and Google Optimize collect user behavior data.

Once all cookies are classified, GetCookies automatically generates a Cookie Declaration that lists:

  • Cookie name
  • Provider/domain
  • Category
  • Purpose description
  • Expiration time

You can embed this declaration on your cookie policy page. It updates automatically when you run new scans and reclassify cookies.

Keeping Categories Current

Your cookie inventory changes as you add new tools, update plugins, or integrate new services:

  1. Schedule regular scans (weekly or monthly) to detect new cookies.
  2. Review after changes -- any time you add a new tool, marketing pixel, or plugin, run a scan.
  3. Check scan comparison -- GetCookies can compare scan results over time to highlight new or removed cookies.
  4. Update your privacy policy -- if new categories of data collection are introduced, update your policy accordingly.

Still stuck?

Email [email protected] with your domain and what you tried. Signed-in customers can also open a ticket from the dashboard.