Cookie
Cookie explained
Cookies do not store the entire website. They often contain an identifier that lets a server recognise a session or stored preferences. Lifetime, domain and other properties determine when a is sent or removed.
**Separate origin from purpose.** First-party and third-party describe the usage context. They do not automatically determine whether a cookie is necessary or requires permission. An owned analytics cookie may require consent just as an embedded advertising service does.
**German rules depend on the specific function.** Section 25 TDDDG generally requires consent for storing or accessing information on devices, with limited exceptions such as an indispensable, explicitly requested service. Further processing of personal data needs separate assessment.
For website delivery, record which data serves which purpose, which providers receive it, and how refusal and withdrawal work. Inspect actual storage and network activity: banner wording alone does not establish behaviour.
Examples
Hypothetical application
A shop needs a session identifier to retain items in a requested shopping basket. An additional advertising serves a different purpose. They should not be grouped indiscriminately as “strictly necessary”.
Key Points
- Cookies are data records, not complete user profiles.
- First-party status does not authorise tracking.
- Review purpose, access and onward transfer separately.
- Test refusal and withdrawal in actual behaviour.
Practical application
Map each storage and transfer function to a documented purpose and technical control.
Useful measures
Functional checks
Login and basket remain usable when optional processing is declined.
Consent implementation
Observed storage and transfer match the user’s selection.
Common mistakes
- Equating an owned domain with necessary processing.
- Checking cookies while overlooking network transfers.
Sources and context
- MDN: Using HTTP cookies
Technical foundations of cookie properties and usage.
- § 25 TDDDG
German law on storage of and access to information on user devices, including exceptions.
Frequently Asked Questions about Cookie
No. Cookies also support requested functionality. Purpose, data scope, access and implementation matter.
No. An owned domain does not settle the legal question. In Germany, the conditions and exceptions in section 25 TDDDG and any further data protection requirements matter.
No. Other browser storage and direct requests can also transmit data. Review more than the cookie list.
Loading related terms…
All TermsArticles about Cookie

Privacy-First Lead Generation: How to Win High-Quality Leads Without Third-Party Cookies
The end of third-party cookies forces marketing teams to rethink. Privacy-First Lead Generation uses zero-party data, consent-based strategies, and contextual signals for better leads with full GDPR compliance.

Cookie-less Marketing: How to Prepare for the Future
The end of third-party cookies is coming – for real this time. Why first-party data, server-side tracking, and contextual targeting must be priorities now.

Marketing as an Operating Discipline: Why Almost Every CMO Talks About AI and Few Have Built It
The gap between intent and execution is not a technology problem, it is an operating model problem. How to move marketing from a project organisation to an operating discipline with systems, roles and cadence.