Guide

How to write a cookie declaration that is actually true.

A list of cookies is a transparency document, and a wrong one is a documented inaccuracy. Generate it from what a scan observed rather than from what a vendor’s documentation claims.

Source
A verified scan
Per cookie
Name, provider, purpose, expiry, category
Refresh
Whenever the site changes
Feature
Cookie declarations

What belongs in it

FieldWhat it should say
NameExactly as observed, including wildcards where a family is grouped
ProviderThe vendor, not your own domain, even for first-party cookies their script wrote
PurposeWhat it does, in a sentence a visitor can read
ExpiryWhat the scan observed, not the vendor’s documented default
CategoryThe consent category it is attached to
Storage typeCookie, local storage, session storage: the rule covers all of them

Group families sensibly. A Hotjar declaration listing eleven `_hj` cookies individually is accurate and unreadable; one row describing the family with the observed expiries is both.

The errors that matter

  • Attributing a first-party cookie to your own domain when a vendor’s script wrote it: technically true, materially misleading
  • Copying expiry values from vendor documentation when your scan observed something shorter
  • Listing cookies that are no longer set, usually left over from a removed tool
  • Omitting local and session storage, which the consent rule covers exactly as it covers cookies
  • Putting an advertising cookie such as `_gcl_au` in an analytics category
  • Leaving the consent platform’s own cookie off the list because it is exempt: exempt does not mean undisclosed

Generate it, then keep it current

StrongPrivacy generates downloadable cookie declarations from verified scans, which is one reliable way to keep the document connected to observed behaviour. A manually maintained declaration can also be accurate, but it needs an owner, evidence and a review process or it will drift as the site changes.

Date it

A declaration with a date is a statement about a point in time, which is defensible. A declaration with no date is an implicit claim to be current, which is harder to defend when it is not.

Common questions

Is a cookie declaration legally required?

No instrument names the document, but the transparency obligations effectively require the information in it. Naming the technologies and their purposes is also what Quebec’s Law 25 asks for in terms of informing about identifying and profiling technology.

Should it live in the privacy policy or on its own page?

Either, as long as it is reachable from the banner and from the preference centre. A separate page is easier to keep current because it can be regenerated without a legal review of the whole notice.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.