What belongs in it
| Field | What it should say |
|---|---|
| Name | Exactly as observed, including wildcards where a family is grouped |
| Provider | The vendor, not your own domain, even for first-party cookies their script wrote |
| Purpose | What it does, in a sentence a visitor can read |
| Expiry | What the scan observed, not the vendor’s documented default |
| Category | The consent category it is attached to |
| Storage type | Cookie, local storage, session storage: the rule covers all of them |
Group families sensibly. A Hotjar declaration listing eleven `_hj` cookies individually is accurate and unreadable; one row describing the family with the observed expiries is both.
The errors that matter
- Attributing a first-party cookie to your own domain when a vendor’s script wrote it: technically true, materially misleading
- Copying expiry values from vendor documentation when your scan observed something shorter
- Listing cookies that are no longer set, usually left over from a removed tool
- Omitting local and session storage, which the consent rule covers exactly as it covers cookies
- Putting an advertising cookie such as `_gcl_au` in an analytics category
- Leaving the consent platform’s own cookie off the list because it is exempt: exempt does not mean undisclosed
Generate it, then keep it current
StrongPrivacy generates downloadable cookie declarations from verified scans, which is one reliable way to keep the document connected to observed behaviour. A manually maintained declaration can also be accurate, but it needs an owner, evidence and a review process or it will drift as the site changes.
Date it
A declaration with a date is a statement about a point in time, which is defensible. A declaration with no date is an implicit claim to be current, which is harder to defend when it is not.
Common questions
Is a cookie declaration legally required?
No instrument names the document, but the transparency obligations effectively require the information in it. Naming the technologies and their purposes is also what Quebec’s Law 25 asks for in terms of informing about identifying and profiling technology.
Should it live in the privacy policy or on its own page?
Either, as long as it is reachable from the banner and from the preference centre. A separate page is easier to keep current because it can be regenerated without a legal review of the whole notice.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- ICO: guidance on storage and access technologies
Regulator guidance
Checked
- StrongPrivacy verification guide
Product documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.