Sample Cookie Policy

About us

A cookie policy protects your visitors' privacy while fulfilling a legal obligation: clearly defining your data collection practices, providing genuine control over preferences, and ensuring transparency regarding data usage.

This sample cookie policy helps you understand your obligations and provides a template you can customize for your website. It outlines the different categories of cookies, the required disclosures you must include, and the most common mistakes to avoid.

Cookie Policy : Why Is It Required?

Contrary to popular belief, it is not the GDPR that directly regulates cookies, but ratherArticle 82 of the Data Protection Act, which transposes the ePrivacy Directive into French law.

This provision requires youto inform your visitors about all the cookies you use and to obtain their consent before setting any cookie that is not strictly necessary for the website to function.

The GDPR, on the other hand, comes into play as soon as these cookies are used to collect personal data (email, purchase history, etc.). In summary:Article 82 governs the placement of cookies, wh GDPR governs what you do with the data they collect.

In practice, your website must list all of its cookies in a dedicated policy (Purpose, duration Data retention, issuer), whether they are essential or not.

To find out exactly what your obligations are, consult the CNIL (National Commission for Information Technology and Civil Liberties) ’s fact sheet on cookies and trackers.

How can we customize our template for your website once you've downloaded the sample cookie policy?

  1. Check which cookies are actually set on your site
    Before drafting your policy, verify which cookies your site actually sets. The free version of an extension like Wappalyzer lets you identify the trackers on a page with just a few clicks.
  2. Identify the different types of cookies
    There are technicalcookies (shopping cart, session, authentication, language preference), which do not require consent; statisticalcookies, which require consent unless a strict exemption applies CNIL (National Commission for Information Technology and Civil Liberties) ; advertisingcookies (retargeting, loyalty), which always require consent; and sharingcookies (social media share buttons), which also require consent.
    Please note: an exemption from consent never waivesthe obligation to inform your visitors, so even technical cookies must be listed in your policy.
  3. Provide details on the data being processed and its duration of Data retention
    For each cookie, specify Purpose, who processes the data, and for how long (a maximum of 13 months is recommended by the CNIL (National Commission for Information Technology and Civil Liberties) for non-essential cookies ).
  4. Report data transfers outside the EU
    If data collected via cookies is transferred outside the EU, specify the legal mechanism governing this transfer.
  5. Enter your email address: Dedicated DPO
    Remind visitors that they have the rightto access, correct, and object to the data collected via cookies, with a dedicated contact person to assist them in exercising these rights (DPO or data controller GDPR).

Where should thecookie policy be made available?

Once you've customized your sample cookie policy, the footer of your website is the ideal place to display it: a link to yourcookie policy must appear there on every page, permanently and in a clearly visible location.

The consent banner must also link directly to the full policy so that visitors can review the details before making their choice.

What are the most common mistakes people make when it comes to cookies?

  • A non-compliant consent banner. A “Decline” button that is missing or less visible than “Accept All,” or cookies set before the user has even made a choice: these are thenon-compliancesmost frequently penalized by the CNIL (National Commission for Information Technology and Civil Liberties). (For more information, see our dedicated checklist).
  • The lack of a link to the cookie management module. Once consent has been given, the user must be able to easily change their mind. Without a permanent and visible link, this option remains merely theoretical.
  • Non-compliant cookie expiration dates. Retaining non-essential cookies for longer than 13 months, or automatically renewing them without obtaining new user consent, is a common non-compliance issue that is easily detected during an audit. Data retention
  • A policy that hasn't been updated after a change in tools. You add a new advertising pixel or switch ad networks during the year, but forget to update yourcookie policy accordingly. As a result, it continues to list tools you no longer use and omits the new ones.
  • A policy copied from another website without any modifications. Using a template found online may seem convenient, but if the cookies listed do not match those actually stored on your website, the document loses all legal validity and could even be used against you in the event of an audit.

Download your free cookie policy template

What you will discover in this medium :

A template ready to customize

This sample cookie policy is a fully drafted Word document with clearly identified fields that need to be customized. All you have to do is fill in your information—you don't have to start from scratch.

Required Information GDPR

PurposeData c Data retention periods, user rights, transfers outside the EU, and contact information for the DPO: our sample cookie policy already includes all the information required by regulations.

A structure validated section by section

Our sample cookie policy follows a comprehensive template drafted by our legal experts specializing in GDPR. From the definition of a cookie to how users can control them, including details on each category of cookies: a comprehensive template designed to cover every possible scenario, with ready-to-use alternative paragraphs tailored to your specific situation.

Accessibility and transparency for your clients

Clear explanations, free of legal jargon, so that your visitors can easily understand their rights and exercise them with ease: this is as much a matter of building trust as it is a legal obligation.

Further information

Having a cookie policy is the first step: it explains to your visitors which cookies are used on your site, by whom, and for what purpose.

The second step is the cookie banner: it allows you to collect your visitors’ preferences. And its configuration is crucial! The “ CNIL (National Commission for Information Technology and Civil Liberties) ” can verify this remotely in just a few clicks, without even needing to conduct an in-depth audit of your site.
In particular, you must ensure that opting out is just as easy as opting in, that the “Accept” and “Reject” buttons are presented equally, that the user’s choice is re-confirmed after 6 months, and that cookies requiring consent are not set before consent is given.

Download our checklist and verify that your cookie banner is compliant in just 6 minutes. Or , let Dipeeo draft your cookie policy and set up your cookie banner: we’ll handle your compliance from start to finish.

  1. Customized legal documents: privacy policy, cookie policy, data processing register…
  2. Unlimited advice: a dedicated legal advisor available every day to answer all your questions.
  3. A collaborative platform (SaaS): track your compliance in real time and centralize your documents by entity.
  4. A “ GDPR -compliant” label: visible proof of compliance and a unique selling point to reassure your clients and partners.
  5. Monitoring your tools: verifying that your CMP, ad pixels, and tracking tools are compliant.
  6. Raising Awareness Among Your Teams: Fun Quiz Sessions to Train Your Employees.

Contact Dipeeo, an external DPO for more than 600 companies.

FAQ: Cookie Policy

What are the risks of non-compliance withcookie policies ?

 

Failure to comply with the rules governing cookies may result in penalties from the French Data Protection Authority ( CNIL (National Commission for Information Technology and Civil Liberties)), which can amount to up to 2% of global revenue, and can damage your website’s reputation. The cookie banner is one of the most frequently penalized violations, as it can be controlled remotely with just a few clicks.

 

Should I update mycookie policy regularly?

 

Yes, whenever you change your tracking tool (new ad pixel, new ad network, new analytics tool) and at least once a year.
A policy that no longer reflects the cookies actually placed on your site loses all legal validity, even if it was compliant at the time it was drafted.

 

Cookie Policy andPrivacy Policy : What's the Difference?

 

The Privacy Policy covers all processing of personal data by your company (forms, clients, HR, etc.).
TheCookie Policy is a separate document dedicated solely to the trackers placed on your website and the consent rules that apply to them.
The two documents complement each other; neither replaces the other.

 

Do all cookies require the user's consent?

 

No. Cookies that are strictly necessary for the website to function (shopping cart, session, authentication) are exempt from the consent requirement, as are certain statistical cookies that meet the strict conditions set by the CNIL (National Commission for Information Technology and Civil Liberties) (anonymization, no cross-referencing of data).
Advertising, social sharing, or statistical cookies that are not exempt require prior consent.

Download the resource

Already 500 compliant companies

When human expertise meets technological power for your GDPR compliance.

A GDPR legal expert
as a new colleague

At Dipeeo, our GDPR experts - specialized lawyers and former in-house counsel - take care of your compliance from A to Z. 

  • A dedicated legal expert

  • An outsourced DPO registered with the CNIL (National Commission for Information Technology and Civil Liberties))

  • Unlimited, tailor-made advice 

  • Cutting-edge expertise

No more stress, no more wasted time, we manage everything for you.

A single tool to manage your compliance

outsourced dpo

Discover the
news GDPR