Davies Meyer – home
    Tech2 min read

    Cookie

    A cookie is a small piece of data a browser stores for a website and sends with requests under defined conditions. Cookies can support logins or shopping baskets; they can also be used for analytics and advertising.

    Cookie explained

    Cookies do not store the entire website. They often contain an identifier that lets a server recognise a session or stored preferences. Lifetime, domain and other properties determine when a is sent or removed.

    **Separate origin from purpose.** First-party and third-party describe the usage context. They do not automatically determine whether a cookie is necessary or requires permission. An owned analytics cookie may require consent just as an embedded advertising service does.

    **German rules depend on the specific function.** Section 25 TDDDG generally requires consent for storing or accessing information on devices, with limited exceptions such as an indispensable, explicitly requested service. Further processing of personal data needs separate assessment.

    For website delivery, record which data serves which purpose, which providers receive it, and how refusal and withdrawal work. Inspect actual storage and network activity: banner wording alone does not establish behaviour.

    Examples

    Hypothetical application

    A shop needs a session identifier to retain items in a requested shopping basket. An additional advertising serves a different purpose. They should not be grouped indiscriminately as “strictly necessary”.

    Key Points

    • Cookies are data records, not complete user profiles.
    • First-party status does not authorise tracking.
    • Review purpose, access and onward transfer separately.
    • Test refusal and withdrawal in actual behaviour.

    Practical application

    Map each storage and transfer function to a documented purpose and technical control.

    Useful measures

    Functional checks

    Login and basket remain usable when optional processing is declined.

    Consent implementation

    Observed storage and transfer match the user’s selection.

    Common mistakes

    • Equating an owned domain with necessary processing.
    • Checking cookies while overlooking network transfers.

    Sources and context

    • MDN: Using HTTP cookies

      Technical foundations of cookie properties and usage.

    • § 25 TDDDG

      German law on storage of and access to information on user devices, including exceptions.

    Frequently Asked Questions about Cookie

    No. Cookies also support requested functionality. Purpose, data scope, access and implementation matter.

    Loading related terms…

    All Terms