Cookie law continues to evolve around the world. Just look at the recent developments in Turkey and Germany. n Turkey, the Turkish Data Protection Authority published its Draft Guidelines on Cookies on January 11, 2022. These draft guidelines offer a good snapshot of where Turkey is headed in terms of cookie regulation. Meanwhile, Germany's DSK proceedings on its New Cookie Guidance are also picking up speed. We have already seen how CNIL's cookie guidelines impacted many websites. A lot of big techs were fined for violating cookie rules.
Read what constitutes the CNIL’s guidelines and recommendations on cookies here.
Cookies are everywhere. Websites use them to track visitors, store their preferences, and display personalized ads. However, cookies are also part of data privacy regulation since some of them collect and share visitors’ personal data with third parties. Cookie law by authorities like CNIL observed that many websites still do not comply with the regulatory norms for cookies.
Try CookieYes' cookie consent manager to comply with major cookie laws worldwide, including GDPR, CCPA, CNIL, ePrivacy Directive, and Italy Garante.
What is a cookie audit?
What are cookies and how do they work?


Viewing cookie details in Chrome inspect element (Ctrl + Shift + I)
First-party cookies and third-party cookies
First-party cookies are generated by the website that the user is visiting. They are used for improving the user browser experience and for authentication. E.g. when the users log in to a website, the server creates and sends first-party cookies with unique IDs to collect the login information. So, when they revisit the website some other time, the server will recognize them from the ID, and hence, the users do not need to log in again.
Third-party cookies are generated by a website different from the one that the user is visiting. They are mostly used for advertisements, analytics, or cross-site tracking. E.g. Google Analytics is a popular tool for measuring website analytics. If you use Analytics, it will send and store cookies on the users' devices via your website to collect and generate the site's analytics report.
Did you know that Google Chrome will completely phase out third-party cookies by 2022? Read about it here.
Necessary and non-necessary cookies
Necessary or essential cookies are necessary for a website to function or offer the services that the user requests. Disabling these cookies may affect the website's partial or full primary functionality and may prevent it from providing the services explicitly requested by the users. For example, cookies that hold items in an online shopping cart may be disabled.
Non-necessary or non-essential cookies are cookies used for additional website services that the users may not request. Even without these cookies, the website will continue to work properly and offer its primary services. E.g. social media plugins used by some websites use non-essential cookies to let logged-in users share site content on the social platform.
What are the criteria for strictly necessary cookies? Find out the answer here.
Session and persistent cookies
Session cookies are short-lived cookies that expire when a user session is over. They are used for short-lived purposes such as online form submission or remembering information while navigating the web pages. E.g. when you fill in an online form, the website uses session cookies to remember the information you provided when you proceed to the next page. They expire once you submit the form or close the browser.
Persistent cookies have a longer expiration date that could be up to years. These cookies remain in the user device until their expiration date or whenever the users clear them from the browser. E.g. when the users choose a UI preference, the persistent cookies will remember it and load it every time they revisit.
How to do a cookie audit?
1. Identify the cookies
The very first step in auditing the cookies on your website is to identify them. You will need to know about the cookies set by your website and the third parties.
To identify the cookies, you can check them using your internet browser. In the browser, open the developer console and look for the list of cookies set by the website. (Note: use incognito or private mode and do not activate third-party cookie blocking or Do Not Track in the browser).
Find out how to manually check for cookies set by your website here.
However, this method is time-consuming, and if any cookie takes time to download, it will not show in the list. The better option is to use a scanning tool to identify the cookies. Online cookie scanner tools such as the one powered by CookieYes scan your website for cookies in seconds and generate a detailed report. They are faster, more efficient, and free!
2. Understand the cookies
3. Become cookie compliant
After you identify the type of cookies, you need to check whether your website is compliant with privacy regulations for these cookies.
Privacy regulations like GDPR and CCPA are applicable worldwide. They have strict standards that will apply to websites receiving traffic from the EU and the US (California).
Under the privacy regulations like GDPR, if your website uses cookies that collect and use the users’ personal data, you must collect explicit consent from its visitors to use cookies on their device.
If your website has not taken the following measures, you may be at risk of non-compliance, which is a punishable offense.
- Inform the users about cookies on your website and details about them in clear and plain language.
- Get user consent before storing non-essential cookies on their device.
- Allow opt-out for non-essential cookies and tell them about it.
- Opting out is as easy and clear as opting in.
- Let the users selectively opt-in to each cookie type.
- Let the users easily withdraw consent at any time and inform them about it.
- Keep proof of cookie consent registered by the users.




