CookieFox

← All posts · · 2 min read

Cookie policy - what it must contain and how to write one

A cookie policy explains to your visitor which cookies you store, why and for how long. It is not decoration: it is how you discharge the duty to inform, and without it the consent your banner collects rests on nothing. Below is the list of elements whose absence shows up at an audit.

What the document has to cover

  • Who the controller is - name, address, contact details, plus the DPO where one is appointed.
  • Cookie categories - necessary, functional, analytics, marketing - each with a plain-language note on what that group actually does.
  • The individual cookies - name, provider, purpose and storage duration. "We use analytics cookies" is not a description.
  • Third-party recipients - who else writes cookies on your site (Google, Meta, Hotjar…).
  • How to withdraw consent - a visible mechanism on the page, not just browser instructions.
  • User rights and how to lodge a complaint with a supervisory authority.

Quote the law that is actually in force

Cite the national rule that implements the ePrivacy Directive, and check it is current. Poland is a good example of how fast this ages: since 10 November 2024 the basis is article 399 of the Electronic Communications Law (act of 12 July 2024), which replaced article 173 of the old Telecommunications Law. A policy still quoting the latter is citing a provision that no longer exists - the single most common flaw in documents written before 2025.

What to avoid

Two classic mistakes: a cookie list detached from reality - copied from someone else's site or never updated - and pointing only at browser settings as the way to withdraw consent. Withdrawal has to be as easy as giving consent, which is an explicit requirement of GDPR article 7(3), and browser settings do not meet it.

A policy that keeps itself current

A hand-maintained list goes stale the moment marketing adds one more pixel. CookieFox generates the cookie policy from a scan of your own site: every cookie found lands in the document with its name, provider, purpose and duration, and the Polish version cites article 399 of the Electronic Communications Law. The document gets its own address, so you can link it from the footer and from the banner itself.

Create a free account, scan your site and see what it actually stores. For consent itself, start with our GDPR guide.

A GDPR-compliant cookie banner in minutes

CookieFox scans your site, blocks scripts until consent and keeps a consent register. Deployment is a single line of code.

Create a free account