Glossary

First-party cookie

A cookie stored on the domain the visitor is actually on, which says who holds it, not who benefits from it, and therefore says nothing about whether it needs consent.

Set for
The current host or an allowed parent Domain
Consent-exempt?
Only if strictly necessary
Classified by
Cookie name first, domain second

What it is

A cookie is first-party in the current context when it belongs to the site the visitor is using: it may be host-only or use a permitted parent Domain attribute and is also constrained by Path, Secure and SameSite rules. That is a statement about storage and request context, not about purpose or beneficiary. First-party does not mean harmless or exempt.

Google Analytics is the clearest counterexample. `_ga` is written by a script running in your page, on your domain, and it exists to identify a returning visitor for measurement. It is first-party and it is not strictly necessary.

Why the scanner reads the name first

StrongPrivacy classifies a cookie by matching its name before falling back to the domain holding it. The name identifies the vendor even when the cookie was written first-party by their script, which is exactly the case that domain-based classification gets wrong.

This is why the cookie library is organised by name

Every entry under /cookies is keyed on the name pattern the scanner matches, because that is the signal that survives a vendor moving to first-party storage.

Common questions

Do first-party cookies need consent?

If they are not strictly necessary for a service the visitor requested, yes, in prior-consent jurisdictions. The rule is about purpose and necessity; the domain is irrelevant to it.

Are first-party cookies affected by browser restrictions?

Less than third-party ones, which is why so many vendors moved to first-party storage. Some browsers still cap the lifetime of cookies written by script, so observed expiry can be shorter than what the vendor documents.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.