Compliance
Cookie categories explained
Understand necessary, functional, analytics, and advertising cookie categories
Understanding cookie categories is fundamental to setting up compliant consent management. This guide explains each category, what types of cookies and scripts belong in them, why the distinction matters legally, and how to classify your site's cookies correctly.
Why Cookie Categories Matter
Privacy regulations like GDPR, ePrivacy Directive, and CCPA require websites to:
- Inform users about what cookies are used and why.
- Obtain consent before setting non-essential cookies.
- Provide granular choice -- users must be able to accept some categories while rejecting others.
Categorizing cookies correctly ensures your consent banner accurately represents what happens on your site, which is both a legal requirement and a trust signal for visitors.
The Four Standard Categories
1. Necessary (Strictly Necessary)
Purpose: Essential for the website to function. Without these, core features break.
Consent required: No. These cookies are exempt from consent requirements under GDPR/ePrivacy because the site cannot operate without them.
Default state: Always granted. Users cannot disable these.
Examples:
| Cookie/Script | Purpose |
|---|---|
| Session cookies | Keep users logged in |
| CSRF tokens | Prevent cross-site request forgery attacks |
| Shopping cart cookies | Remember items in the cart |
| Load balancer cookies | Route traffic to the correct server |
| Cookie consent state | Remember the user's consent choice itself |
| Authentication tokens | Verify user identity |
| Security cookies | Detect malicious activity, bot protection |
| Accessibility preferences | Font size, high contrast mode (if essential) |
What does NOT belong here:
- Analytics of any kind (even "basic" page view tracking)
- Social media widgets
- Advertising identifiers
- A/B testing tools (unless essential for site function)
- Performance monitoring tools that collect user data
Common mistake: Some sites classify Google Analytics as "necessary." Under GDPR, traffic analytics is never strictly necessary for the website to function, even if it is necessary for your business. It belongs in the Analytics category.
2. Functional (Preferences)
Purpose: Enable enhanced features and personalization that are not strictly required for the site to work, but improve the user experience.
Consent required: Yes. These require opt-in consent under GDPR.
Default state: Denied until the user consents.
Examples:
| Cookie/Script | Purpose |
|---|---|
| Language preference cookies | Remember the user's preferred language |
| Region/currency preferences | Remember location and currency settings |
| Theme/layout preferences | Remember dark mode, sidebar collapsed, etc. |
| Chat widget settings | Remember chat history and preferences |
| Video player preferences | Remember volume, quality, autoplay settings |
| Font size preferences | Remember accessibility choices (if not essential) |
| Recently viewed items | Show recently viewed products |
| Form auto-fill data | Remember form field values |
Google Consent Mode mapping: functionality_storage, personalization_storage
Gray area: Some functional cookies could arguably be classified as Necessary (e.g., language preference for a multilingual site). When in doubt, classify as Functional -- it is safer from a compliance standpoint.
3. Analytics (Statistics / Performance)
Purpose: Collect data about how visitors use the site -- page views, traffic sources, performance metrics, user behavior patterns. Used to improve the site, not to target advertising.
Consent required: Yes. Even anonymized analytics require consent under strict GDPR interpretations (though some EU countries allow analytics with legitimate interest if properly anonymized -- consult legal counsel).
Default state: Denied until the user consents.
Examples:
| Cookie/Script | Purpose |
|---|---|
| Google Analytics (GA4) | Page views, sessions, user behavior |
| Hotjar / FullStory | Heatmaps, session recordings |
| Plausible / Fathom / Matomo | Privacy-focused analytics |
| Microsoft Clarity | Session recording and heatmaps |
| Amplitude / Mixpanel | Product analytics and event tracking |
| Speed/performance monitoring | Page load times, Core Web Vitals |
| A/B testing tools | Optimizely, VWO, Google Optimize |
| Error tracking | Sentry, LogRocket (if they collect user data) |
| Scroll depth tracking | How far users scroll on pages |
Google Consent Mode mapping: analytics_storage
Important distinction: Analytics cookies measure how your site is used. They do not target ads. If a tool does both analytics and advertising (e.g., Google Analytics with cross-site tracking enabled), its advertising features belong in the Marketing category.
4. Marketing (Advertising / Targeting)
Purpose: Track users across websites to build profiles for targeted advertising, retargeting, and conversion measurement.
Consent required: Yes. This is the most privacy-sensitive category.
Default state: Denied until the user consents.
Examples:
| Cookie/Script | Purpose |
|---|---|
| Google Ads (conversion tracking) | Measure ad conversions |
| Google Ads (remarketing) | Show ads to previous visitors |
| Meta (Facebook) Pixel | Track conversions and build audiences |
| LinkedIn Insight Tag | B2B advertising and audience building |
| TikTok Pixel | Conversion tracking and retargeting |
| Pinterest Tag | Conversion tracking and audience building |
| Twitter/X Pixel | Conversion tracking |
| Criteo | Retargeting display ads |
| AdRoll | Cross-platform retargeting |
| DoubleClick / Google Marketing Platform | Programmatic advertising |
| Social sharing widgets | Facebook Like, Twitter Share (when they track) |
| Affiliate tracking cookies | Track referral sources for commissions |
| Cross-site tracking scripts | Any script that follows users across sites |
Google Consent Mode mapping: ad_storage, ad_user_data, ad_personalization
How to Classify Your Cookies
Step 1: Run a Scan
- In your GetCookies dashboard, run a full scan on your domain.
- The scan detects all cookies and scripts on your site.
- GetCookies automatically classifies known cookies using its database of 30,000+ recognized cookies.
Step 2: Review Unclassified Items
After the scan:
- Go to Scan Results for your domain.
- Look for items marked as "Unclassified" or "Unknown."
- For each unclassified item, determine its purpose by:
- Checking the cookie name against the service provider's documentation.
- Looking at the domain the cookie comes from.
- Checking what script sets the cookie.
Step 3: Assign Categories
For each unclassified cookie or script:
- Click on the item in the scan results.
- Select the appropriate category from the dropdown.
- Add a description of the cookie's purpose (this appears in your cookie declaration).
- Save.
Decision Guide
Use this flowchart to decide which category a cookie belongs in:
- Does the site break without it? (Login fails, cart empties, forms do not submit)
- Yes → Necessary
- No → Continue
- Does it improve the user experience without tracking behavior? (Language, theme, preferences)
- Yes → Functional / Preferences
- No → Continue
- Does it measure how the site is used without identifying users for advertising? (Page views, performance, errors)
- Yes → Analytics
- No → Continue
- Does it track users for advertising, build audience profiles, or measure ad conversions?
- Yes → Marketing
- Still unsure?
- Default to Marketing -- this is the safest choice from a compliance standpoint. Over-classifying as Marketing means users must consent before it loads, which is always legally safe.
Common Classification Mistakes
Mistake 1: Classifying GA4 as Necessary
Google Analytics is never strictly necessary. A website functions without it. Always classify as Analytics.
Mistake 2: Missing hidden trackers
Some scripts load additional scripts dynamically. A Facebook Pixel might load additional tracking scripts that are not visible in your HTML. Run a full scan to catch these.
Mistake 3: Ignoring third-party iframes
Embedded YouTube videos, Google Maps, and social media embeds often set cookies. These need to be categorized and blocked until consent.
Mistake 4: Forgetting server-set cookies
Not all cookies come from JavaScript. Your server may set tracking cookies via HTTP headers. These show up in scans but are sometimes overlooked. Ensure they are classified.
Mistake 5: Classifying A/B testing as Necessary
Unless your A/B testing tool is essential for the site to function (rare), it belongs in Analytics. Tools like Optimizely, VWO, and Google Optimize collect user behavior data.
Cookie Declaration
Once all cookies are classified, GetCookies automatically generates a Cookie Declaration that lists:
- Cookie name
- Provider/domain
- Category
- Purpose description
- Expiration time
You can embed this declaration on your cookie policy page. It updates automatically when you run new scans and reclassify cookies.
Keeping Categories Current
Your cookie inventory changes as you add new tools, update plugins, or integrate new services:
- Schedule regular scans (weekly or monthly) to detect new cookies.
- Review after changes -- any time you add a new tool, marketing pixel, or plugin, run a scan.
- Check scan comparison -- GetCookies can compare scan results over time to highlight new or removed cookies.
- Update your privacy policy -- if new categories of data collection are introduced, update your policy accordingly.
Still stuck?
Email [email protected] with your domain and what you tried. Signed-in customers can also open a ticket from the dashboard.