What are computer cookies?
25 March 2025
Computer cookies are small data files that websites store on your device when you visit them. Your device stores these cookies and sends them back to the website the next time you visit, enabling the site to recognise you and remember certain information about your browsing activity.
For instance, an online store may use cookies to remember what items you have added to your shopping cart. Websites can also use cookies to keep you logged in, track user behaviour, and personalise your browsing experience.
Why are they called ‘cookies’?
There are different theories behind the origin of the term for ‘cookies.’ Many believe it stems from fortune cookies, which contain a hidden message inside, similar to how internet cookies store small pieces of data. Others think that the name comes from the story of Hansel and Gretel, where the children left a trail of breadcrumbs to find their way back, much like how cookies help track online activity!
Types of cookies
Cookies can be categorised in two ways: first-party and third-party. This refers to who sets the cookie.
- First-party cookies are created and stored by the website you are visiting. These cookies help with site functionality, such as remembering login details, language preferences, or shopping cart contents.
- Third-party cookies are set by domains other than the website you are visiting. These are commonly used for advertising, tracking, and social media integrations. Due to privacy concerns surrounding third-party cookies, many web browsers block them by default. Google, for example, is phasing out third-party cookies as part of a broader effort to enhance online privacy.
There are two additional categories within first and third-party cookies: persistent cookies and session cookies.
- Session cookies are temporary and expire when you close your browser. They are often used for security purposes, such as keeping you logged into your online banking session.
- Persistent cookies remain stored on your device for a set period or until you delete them. They are used to remember preferences or track users for targeted advertising.
Links to data protection
Use of computer cookies is considered to be processing of personal data. It is covered by the Privacy and Electronic Communications Regulations (PECR) and the UK General Data Protection Regulation (UK GDPR).
These laws require that websites provide visitors with clear information about cookies so they can understand how their browsing information is being collected and used. Users must also be given a choice about which non-essential cookies they want to accept.
Essential cookies, such as those needed for security features or shopping cart functionality, are necessary for a website to operate. These cookies do not require consent, but websites must still be transparent about using them.
Non-essential cookies, such as those used for analytics or advertising, require explicit consent from visitors. The UK GDPR defines ‘consent’ as being freely given, specific, informed, and unambiguous. This means users must provide informed consent through explicit affirmative action, such as ticking a box to agree to a particular type of cookie.
Generally, when using cookies, websites must provide the following information:
- what cookies are intended to be used
- the purpose for using the cookies
- any third parties who may process information stored in or accessed from the user’s device as a result of accessing the website
- the duration for which the cookies will be stored
- consent to store cookies on devices
How to ensure compliance
If you operate an online service or website, you must ensure compliance with PECR and the UK GDPR. Your IT provider may physically set the computer cookies. However, you (as the data controller) are responsible for ensuring consent is obtained where necessary.
The Information Commissioner’s Office (ICO) provides guidance on complying with cookie legislation. Veritau clients can contact our information governance team for more information.