Cookie Policy
Montague Law | Free Legal Form Template
Introduction and Overview
This Cookie Policy explains how [COMPANY NAME] ("we," "us," or "our") uses cookies, web beacons, pixels, and similar tracking technologies when you visit, interact with, or use our website located at [WEBSITE URL] (the "Site"). This policy is designed to help you understand what these technologies are, why we use them, and the rights and choices available to you regarding their use.
We are committed to transparency about the data we collect and how we use it. This Cookie Policy forms part of, and should be read together with, our Privacy Policy. Where this Cookie Policy refers to "personal data" or "personal information," it carries the same meaning as defined in our Privacy Policy and applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the ePrivacy Directive 2002/58/EC (as amended by Directive 2009/136/EC), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable privacy laws.
We periodically update this Cookie Policy to reflect changes in the cookies and tracking technologies we use, changes to applicable law, or for other operational, legal, or regulatory reasons. The date at the top of this Cookie Policy indicates when it was last revised. We encourage you to review this Cookie Policy regularly to stay informed about our use of cookies and related technologies.
By continuing to use the Site after providing your consent through our cookie consent mechanism (where required by applicable law), you acknowledge that you have read and understood this Cookie Policy. Where consent is the legal basis for placing cookies on your device, we will obtain your affirmative, freely given, specific, informed, and unambiguous consent before setting any non-essential cookies, in accordance with the requirements of the GDPR and ePrivacy Directive.
What Are Cookies
Cookies are small text files that are stored on your computer, smartphone, tablet, or other device when you visit a website. They are widely used to make websites function properly, to improve the efficiency and performance of websites, and to provide reporting information to website operators. A cookie typically contains the name of the domain from which the cookie originated, the lifetime or expiration date of the cookie, and a randomly generated unique identifier or value.
First-party cookies are cookies that are set directly by the website you are visiting. These cookies are generally used to enable core website functionality, remember your preferences, and collect analytics data about how you use the site. Because they are set by the domain you are visiting, first-party cookies are generally considered less intrusive from a privacy perspective, though they remain subject to the consent requirements of applicable data protection law.
Third-party cookies are cookies that are set by a domain other than the one you are visiting. These cookies are typically placed by external services that the website operator has integrated into the site, such as analytics providers, advertising networks, social media platforms, or embedded content providers. Third-party cookies can track your activity across multiple websites, enabling cross-site tracking and behavioral profiling. Because of their capacity for surveillance across the web, third-party cookies are subject to heightened regulatory scrutiny and stricter consent requirements under the GDPR, ePrivacy Directive, and CCPA/CPRA.
It is important to understand that cookies can be used to collect a variety of information, including IP addresses, device identifiers, browser type, operating system, referring URLs, pages visited, time spent on pages, clickstream data, and other behavioral and technical information. Depending on their purpose and configuration, cookies may collect data that constitutes personal data under applicable privacy laws, which is why we provide this detailed Cookie Policy and obtain your consent where required.
Types of Cookies We Use
Strictly Necessary Cookies: These cookies are essential for the operation of our Site. They enable core functionality such as page navigation, access to secure areas of the Site, form submission, shopping cart functionality, and session management. Without these cookies, the Site cannot function properly, and they cannot be disabled through our cookie consent mechanism. Strictly necessary cookies do not require your consent under the GDPR or ePrivacy Directive because they are indispensable to the provision of the service you have explicitly requested. However, we still disclose their use in this Cookie Policy for full transparency.
Functional Cookies: Also referred to as preference cookies, these cookies enable the Site to remember choices you have made, such as your language preference, region or location, font size, accessibility settings, or customized layout configurations. They may also be used to provide enhanced and personalized features. Functional cookies improve your user experience but are not strictly necessary for the Site to operate. We will only set functional cookies with your prior consent, where such consent is required by applicable law.
Analytics and Performance Cookies: These cookies collect aggregated, statistical information about how visitors use our Site, including which pages are visited most frequently, how long visitors spend on each page, bounce rates, traffic sources, and error messages encountered. We use this information to understand usage patterns, improve Site performance, optimize content, and diagnose technical issues. Analytics cookies may be first-party or third-party. We use services such as [ANALYTICS PROVIDER, e.g., Google Analytics] to process this data. These cookies require your consent before they are placed on your device.
Advertising and Targeting Cookies: These cookies are used to deliver advertisements that are relevant to you and your interests. They may be set by us or by third-party advertising partners, and they track your browsing activity across websites to build a profile of your interests and display targeted advertisements. Advertising cookies also limit the number of times you see an advertisement and help measure the effectiveness of advertising campaigns. Because these cookies involve cross-site tracking and profiling, they are subject to the strictest consent requirements under data protection law. We will only set advertising cookies with your explicit, informed, prior consent.
Social Media Cookies: These cookies are placed by social media services (such as Facebook, Twitter/X, LinkedIn, or Instagram) that we have integrated into our Site through embedded content, share buttons, or social login features. These cookies can track your browsing activity across our Site and other websites, even if you do not interact with the social media feature. These third-party cookies are governed by the privacy policies and cookie policies of the respective social media platforms. We will only load social media cookies with your prior consent.
How We Use Cookies
We use cookies and similar technologies for several specific purposes. Authentication and security cookies verify your identity when you log into secure areas of our Site, maintain the integrity of your session, and protect against cross-site request forgery and other security threats. These cookies are classified as strictly necessary and do not require your consent.
We use cookies to remember your preferences and settings, such as language selection, regional content preferences, display configurations, and whether you have previously acknowledged informational banners or notices. This ensures a consistent and personalized experience across your visits to the Site without requiring you to re-enter your preferences each time.
Analytics cookies help us understand how our Site is used by collecting data on page views, session duration, navigation paths, traffic sources, device types, and user interactions. This data is typically aggregated and anonymized, though some analytics services may process data that constitutes personal data. We analyze this information to identify areas for improvement, measure the effectiveness of our content, optimize the user experience, and make data-driven decisions about Site development.
Where applicable, we use advertising and targeting cookies to serve relevant advertisements and measure their performance. These cookies enable us and our advertising partners to understand which advertisements you have seen, which you have interacted with, and to limit repetitive advertising. Targeting cookies also allow us to segment audiences and customize marketing messages based on inferred interests and browsing behavior.
We may use cookies to facilitate communication between our Site and integrated third-party services, including content delivery networks, customer relationship management systems, payment processors, and form submission services. These integrations require cookies to function properly and to maintain session continuity across domains.
We also use cookies to conduct A/B testing and measure the performance of different versions of our Site’s content, layout, and features. This testing enables us to make evidence-based improvements and to ensure that the Site delivers the best possible experience to our users.
Cookie Duration
Session Cookies: Session cookies are temporary cookies that are stored in your device’s memory only for the duration of your browsing session. They are automatically deleted when you close your browser. Session cookies are primarily used to maintain state during your visit, such as keeping you logged in as you navigate between pages, preserving the contents of a form you are completing, or maintaining items in a shopping cart. Because they do not persist beyond the end of your session, session cookies generally present a lower privacy risk than persistent cookies.
Persistent Cookies: Persistent cookies remain stored on your device for a predetermined period of time, or until you manually delete them. Their duration can range from a few hours to several years, depending on the purpose for which they are set. Persistent cookies are used to remember your preferences across multiple visits, recognize returning visitors, maintain login sessions over extended periods (where a "remember me" function is provided), and support analytics and advertising functions that require cross-session data collection.
Under the GDPR and ePrivacy Directive, the duration of each cookie must be proportionate to its purpose. Regulators have scrutinized cookies with excessively long lifespans, and we review the retention periods of our cookies regularly to ensure that they do not persist longer than reasonably necessary. A complete list of the cookies we use, together with their respective durations and purposes, is set forth in the Cookie Inventory section of this Cookie Policy.
We recommend that you periodically review and clear the cookies stored on your device, particularly persistent cookies associated with third-party advertising and tracking services. Instructions for managing cookies in your browser are provided in the "Managing Cookies in Your Browser" section below.
Third-Party Cookies
Our Site may include cookies set by third parties, including analytics providers, advertising networks, social media platforms, content delivery networks, and other technology partners. These third-party cookies are not under our direct control, and we encourage you to review the cookie and privacy policies of these third parties to understand their data collection and processing practices.
Analytics Providers: We use third-party analytics services, such as [ANALYTICS PROVIDER, e.g., Google Analytics], to collect and analyze data about how visitors use our Site. These services use their own cookies to collect information such as your IP address, browser type, pages visited, time spent on pages, and traffic sources. [ANALYTICS PROVIDER] may also use this data to provide benchmarking and measurement services. For more information about how [ANALYTICS PROVIDER] uses data, please visit [ANALYTICS PROVIDER PRIVACY URL].
Advertising Networks: Where advertising is served on our Site, third-party advertising networks may place cookies on your device to deliver targeted advertisements based on your browsing history, inferred interests, and demographic information. These cookies enable advertising networks to track your activity across multiple websites and to measure the effectiveness of advertising campaigns. Major advertising networks that may place cookies on our Site include [ADVERTISING PARTNERS].
Social Media Platforms: Our Site may contain social media buttons, widgets, or embedded content from platforms such as Facebook (Meta), Twitter/X, LinkedIn, Instagram, or YouTube. These features may set cookies that track your interactions with the embedded content and your browsing activity across other websites, even if you do not have an account with the social media platform or do not actively interact with the feature. These cookies are governed by the privacy and cookie policies of the respective platforms.
We conduct regular audits of the third-party cookies present on our Site to ensure that only authorized cookies are deployed and that all third-party cookies are accurately disclosed in this Cookie Policy and in our cookie consent mechanism. If you have questions about any third-party cookie present on our Site, please contact us at [PRIVACY EMAIL].
We require our third-party service providers to comply with applicable data protection laws and to process any personal data collected through their cookies only for the purposes we have specified. However, we do not control the data processing practices of third parties, and we are not responsible for their compliance with applicable law.
Cookie Consent and Your Choices
When you first visit our Site, you will be presented with a cookie consent banner that informs you about the categories of cookies we use and allows you to accept or decline each category of non-essential cookies. We do not set any non-essential cookies until you have made an affirmative choice through the consent mechanism. This opt-in approach complies with the requirements of the GDPR and ePrivacy Directive, which mandate that consent must be freely given, specific, informed, and unambiguous, and that it must be obtained through a clear affirmative action.
You have the right to accept or decline each category of non-essential cookies individually. Our cookie consent mechanism provides granular controls that allow you to consent to some categories of cookies while declining others. For example, you may choose to accept analytics cookies to help us improve the Site while declining advertising cookies. You are not required to accept any non-essential cookies as a condition of using the Site.
You may withdraw your consent at any time by accessing our cookie preference center, which is accessible via the [COOKIE SETTINGS LINK/ICON] on our Site. Withdrawing your consent does not affect the lawfulness of processing that was carried out based on your consent before its withdrawal. When you withdraw consent, we will stop setting the relevant cookies and will take reasonable steps to delete cookies that were previously placed on your device, although some cookies may need to be deleted through your browser settings.
For visitors located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we operate on a strict opt-in basis for all non-essential cookies, in accordance with the GDPR and ePrivacy Directive. For visitors located in California, we provide a "Do Not Sell or Share My Personal Information" link, as required by the CCPA/CPRA, and honor Global Privacy Control (GPC) signals transmitted by your browser. For visitors in other jurisdictions, we apply the consent requirements mandated by the applicable local law.
We do not use dark patterns, pre-checked consent boxes, or manipulative interface designs in our cookie consent mechanism. Our "Accept" and "Reject" options are presented with equal prominence, and declining cookies requires no more steps than accepting them, in compliance with regulatory guidance from the European Data Protection Board (EDPB), the French Commission Nationale de l’Informatique et des Libertes (CNIL), and other supervisory authorities.
Managing Cookies in Your Browser
In addition to the controls provided by our cookie consent mechanism, you can manage cookies through your web browser’s settings. Most browsers allow you to view the cookies stored on your device, delete individual cookies or all cookies, block cookies from specific websites or all websites, and configure notifications when cookies are set. Please note that if you block or delete essential cookies, some features of our Site may not function properly.
Google Chrome: Open Chrome and click the three-dot menu in the upper-right corner. Select "Settings," then "Privacy and Security," then "Cookies and other site data" (or "Third-party cookies" in newer versions). From this menu, you can block third-party cookies, block all cookies, clear cookies on exit, or manage cookie permissions on a per-site basis. You can also type chrome://settings/cookies in the address bar to navigate directly to these settings.
Mozilla Firefox: Open Firefox and click the hamburger menu in the upper-right corner. Select "Settings," then "Privacy & Security." Under "Enhanced Tracking Protection," you can choose Standard, Strict, or Custom protection levels. The Custom option allows you to block specific types of cookies, including all third-party cookies, cookies from unvisited sites, or all cookies. You can also manage and delete individual cookies from the "Cookies and Site Data" section.
Apple Safari: Open Safari and select "Safari" from the menu bar, then "Settings" (or "Preferences" in older versions). Click the "Privacy" tab. From here, you can block all cookies, prevent cross-site tracking, and manage website data, including viewing and deleting cookies on a per-site basis. Safari blocks third-party cookies by default through its Intelligent Tracking Prevention (ITP) feature.
Microsoft Edge: Open Edge and click the three-dot menu in the upper-right corner. Select "Settings," then "Cookies and site permissions," then "Manage and delete cookies and site data." From this menu, you can block third-party cookies, block all cookies, clear cookies when you close the browser, and add specific sites to allow or block lists.
For other browsers, including Brave, Opera, and Vivaldi, please consult the browser’s help documentation or support resources for instructions on managing cookies. You may also use browser extensions and privacy tools, such as Privacy Badger, uBlock Origin, or Ghostery, to enhance your control over cookies and tracking technologies. Note that the use of such tools may affect the functionality of certain features on our Site.
Do Not Track Signals
Do Not Track ("DNT") is a privacy preference that users can set in certain web browsers. When DNT is enabled, the browser sends a signal to the websites you visit requesting that your browsing activity not be tracked. There is currently no universally accepted standard for how websites should respond to DNT signals, and the World Wide Web Consortium (W3C) has discontinued its efforts to develop a DNT standard.
While we respect your privacy preferences, our Site does not currently alter its data collection or use practices in response to DNT signals from your browser, as there is no consistent industry standard for compliance. However, we do honor Global Privacy Control (GPC) signals, which serve a similar purpose and carry legal weight under the CCPA/CPRA. If your browser transmits a GPC signal, we will treat it as a valid request to opt out of the sale or sharing of your personal information, as required by California law.
We encourage you to use our cookie consent mechanism and cookie preference center to exercise control over the cookies and tracking technologies used on our Site, regardless of whether you have enabled DNT or GPC in your browser. These tools provide more granular and effective control over your privacy preferences than browser-level signals alone.
Web Beacons, Pixels, and Similar Technologies
In addition to cookies, we may use web beacons (also known as "clear GIFs," "pixel tags," or "tracking pixels") and similar technologies on our Site and in our emails. A web beacon is a tiny, transparent image file (typically one pixel by one pixel) that is embedded in a web page or email. When the page or email is loaded, the web beacon sends a request to a server, which records information such as your IP address, the date and time of the request, the URL of the page containing the beacon, and your browser type.
We use web beacons for several purposes, including: measuring email open rates and click-through rates to evaluate the effectiveness of our email communications; counting the number of visitors to specific pages on our Site; tracking conversions and the effectiveness of marketing campaigns; detecting whether an email has been forwarded; and collecting aggregated analytics data about Site usage patterns.
Tracking pixels placed by third-party advertising networks may also be present on certain pages of our Site. These pixels function similarly to third-party cookies and are used to track your browsing activity across websites for the purpose of delivering targeted advertisements. Like third-party cookies, advertising pixels are subject to your consent and can be controlled through our cookie consent mechanism.
We treat web beacons, pixels, and similar technologies in the same manner as cookies under this Cookie Policy. Where these technologies collect personal data or are used for non-essential purposes, we will obtain your consent before deploying them, in accordance with the requirements of the GDPR, ePrivacy Directive, and other applicable laws. The ePrivacy Directive’s Article 5(3) applies to all technologies that store or access information on a user’s device, not just cookies, making its consent requirements technology-neutral.
Local Storage and Similar Technologies
In addition to cookies, our Site may use local storage mechanisms provided by your browser, including HTML5 Local Storage, HTML5 Session Storage, and IndexedDB. These technologies allow websites to store data directly in your browser, similar to cookies, but with greater storage capacity and different technical characteristics. Unlike cookies, data stored through local storage is not automatically sent to the server with each HTTP request.
We may use local storage to cache content for faster page loading, store user preferences and settings, maintain session state for web applications, and support offline functionality where applicable. Local storage data persists until it is explicitly deleted by the website or by you through your browser settings.
Under the ePrivacy Directive and GDPR, local storage is treated in the same manner as cookies for consent purposes. Article 5(3) of the ePrivacy Directive applies to any technology that stores or accesses information on a user’s terminal equipment, which encompasses local storage, IndexedDB, and similar client-side storage mechanisms. Accordingly, we will obtain your consent before using local storage for non-essential purposes.
You can view and delete local storage data through your browser’s developer tools. In most browsers, you can access the developer tools by pressing F12 or Ctrl+Shift+I (Cmd+Option+I on macOS), navigating to the "Application" or "Storage" tab, and viewing the local storage, session storage, and IndexedDB entries for the current domain. You can also clear this data through your browser’s "Clear browsing data" function, though the specific options available vary by browser.
GDPR and ePrivacy Directive Compliance
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your use of our Site and our use of cookies is governed by the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the ePrivacy Directive 2002/58/EC (as amended), and their respective national implementations. We are committed to full compliance with these regulations in all aspects of our cookie practices.
Under the GDPR and ePrivacy Directive, we obtain your prior, affirmative, freely given, specific, informed, and unambiguous consent before placing any non-essential cookies or similar technologies on your device. Consent is obtained through our cookie consent banner, which is displayed upon your first visit to the Site and provides clear, comprehensive information about each category of cookies, their purposes, durations, and the identity of any third parties that receive data through cookies. We do not use pre-checked consent boxes, implied consent, or cookie walls that condition access to the Site on acceptance of non-essential cookies.
The legal bases for our use of cookies under the GDPR are as follows: for strictly necessary cookies, we rely on our legitimate interest in providing you with a functional and secure website (Article 6(1)(f) GDPR) and the exemption under Article 5(3) of the ePrivacy Directive for cookies that are strictly necessary for the provision of a service explicitly requested by the user; for all other categories of cookies, we rely on your consent (Article 6(1)(a) GDPR and Article 5(3) of the ePrivacy Directive).
You have the right to withdraw your consent at any time, and we ensure that withdrawing consent is as easy as giving it. You may withdraw consent by accessing our cookie preference center, by adjusting your browser settings, or by contacting us at [PRIVACY EMAIL]. Upon withdrawal of consent, we will cease setting the relevant cookies and will instruct applicable third parties to do the same. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
In accordance with the GDPR, you also have the right to access, rectify, erase, restrict, or object to the processing of personal data collected through cookies, as well as the right to data portability. To exercise these rights, please refer to our Privacy Policy or contact our Data Protection Officer at [DPO EMAIL].
We conduct Data Protection Impact Assessments (DPIAs) where our use of cookies and tracking technologies is likely to result in a high risk to the rights and freedoms of individuals, as required by Article 35 of the GDPR. We maintain a record of processing activities that includes our cookie-based data processing, as required by Article 30 of the GDPR.
CCPA/CPRA Compliance
If you are a resident of California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), provides you with specific rights regarding the personal information that may be collected through cookies and similar technologies on our Site. Under the CCPA/CPRA, "personal information" includes online identifiers, IP addresses, browsing history, and other data commonly collected by cookies.
Under the CCPA/CPRA, you have the right to know what categories and specific pieces of personal information we have collected about you, including through cookies; the right to request deletion of your personal information; the right to opt out of the sale or sharing of your personal information, including through cross-context behavioral advertising enabled by third-party cookies; the right to correct inaccurate personal information; the right to limit the use and disclosure of your sensitive personal information; and the right not to be discriminated against for exercising any of these rights.
We provide a "Do Not Sell or Share My Personal Information" link on our Site, as required by the CCPA/CPRA. Clicking this link will allow you to opt out of the use of cookies and similar technologies that constitute the sale or sharing of your personal information under California law. We also honor Global Privacy Control (GPC) signals transmitted by your browser as a valid opt-out request, in accordance with the California Attorney General’s regulations and enforcement actions.
We do not use dark patterns or asymmetric choice designs in our opt-out mechanisms. The CCPA/CPRA prohibits businesses from using interfaces that have the substantial effect of subverting or impairing a consumer’s choice to opt out, including through confusing language, unnecessary steps, or manipulative design. Our opt-out process requires no more than two steps and does not require consumers to create an account, verify their identity (except as specifically permitted by law), or navigate through unrelated content.
Cookies that are used solely for purposes that do not constitute the "sale" or "sharing" of personal information under the CCPA/CPRA, such as strictly necessary cookies, session management cookies, and first-party analytics cookies configured to prevent data sharing, may continue to operate after you exercise your opt-out rights. For more information about your CCPA/CPRA rights and how we process your personal information, please refer to the California-specific disclosures in our Privacy Policy.
Children’s Privacy
Our Site is not directed to children under the age of 16, and we do not knowingly use cookies or similar technologies to collect personal information from children under 16. We do not knowingly serve targeted advertising to children, and we do not knowingly allow third-party advertising cookies to be placed on the devices of children under 16.
Under the GDPR, the processing of personal data of a child below the age of 16 (or such lower age as specified by EU Member State law, which may not be below 13) based on consent requires the authorization of the holder of parental responsibility. Under the CCPA/CPRA, businesses must obtain opt-in consent before selling or sharing the personal information of consumers under the age of 16. For consumers between 13 and 16, the consumer must affirmatively authorize the sale or sharing; for consumers under 13, a parent or guardian must provide consent.
If we become aware that we have inadvertently collected personal information through cookies from a child under the applicable age threshold, we will take prompt steps to delete that information and to disable the relevant cookies. If you believe that a child under the applicable age has provided personal information through our Site, please contact us immediately at [PRIVACY EMAIL].
We encourage parents and guardians to monitor their children’s internet usage and to educate them about the importance of online privacy and the use of browser settings, cookie controls, and privacy tools to manage tracking technologies.
Cross-Border Data Transfers
Cookies placed on your device by us or by third parties may result in the transfer of your personal data to countries outside of your country of residence, including transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States or other jurisdictions that may not provide the same level of data protection as your home jurisdiction.
Where personal data collected through cookies is transferred outside the EEA, the United Kingdom, or Switzerland, we ensure that appropriate safeguards are in place, as required by Chapter V of the GDPR. These safeguards may include: transfers to countries that the European Commission has determined provide an adequate level of data protection (adequacy decisions); Standard Contractual Clauses (SCCs) approved by the European Commission; Binding Corporate Rules approved by a supervisory authority; or, where applicable, reliance on the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, or the Swiss-U.S. Data Privacy Framework.
Some of our third-party analytics and advertising partners, including [ANALYTICS PROVIDER], are headquartered in the United States and may process data collected through their cookies on servers located outside the EEA. We require these partners to implement appropriate data transfer mechanisms and to comply with applicable data protection laws when processing personal data originating from the EEA, the United Kingdom, or Switzerland.
For more information about the specific safeguards we have implemented for international data transfers, including copies of applicable Standard Contractual Clauses, please contact us at [PRIVACY EMAIL] or refer to the international data transfers section of our Privacy Policy.
Cookie Policy Updates and Notifications
We may update this Cookie Policy from time to time to reflect changes in the cookies and tracking technologies we use, changes in applicable law or regulatory guidance, changes to our business practices, or for other operational, legal, or regulatory reasons. When we make material changes to this Cookie Policy, we will notify you by posting the updated policy on our Site with a revised "Last Updated" date and, where appropriate, through additional notice mechanisms such as a prominent banner on our Site, email notification to registered users, or re-presentation of our cookie consent mechanism.
If a material change to this Cookie Policy affects the legal basis for our use of cookies or the categories of cookies we deploy, we will re-obtain your consent where required by applicable law before implementing the change. This ensures that your consent remains informed and specific, as required by the GDPR and ePrivacy Directive.
We encourage you to periodically review this Cookie Policy to stay informed about how we use cookies and similar technologies. Your continued use of the Site after the posting of changes constitutes your acknowledgment of the changes, though where consent is required, continued use alone does not constitute consent.
Previous versions of this Cookie Policy are available upon request. If you have questions about any changes to this Cookie Policy, please contact us at [PRIVACY EMAIL].
How to Contact Us
If you have any questions, comments, or concerns about this Cookie Policy, our use of cookies and similar technologies, or your rights under applicable data protection law, please contact us using the following information:
[COMPANY NAME], [COMPANY ADDRESS]. Email: [PRIVACY EMAIL]. Telephone: [PHONE NUMBER]. Website: [WEBSITE URL].
If we have appointed a Data Protection Officer (DPO) or privacy representative, you may also contact them at: [DPO NAME], [DPO EMAIL], [DPO ADDRESS].
If you are located in the EEA and believe that our processing of your personal data through cookies violates the GDPR or ePrivacy Directive, you have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. If you are located in California and believe your rights under the CCPA/CPRA have been violated, you may file a complaint with the California Attorney General at https://oag.ca.gov/contact/consumer-complaint-against-business-or-company or the California Privacy Protection Agency at https://cppa.ca.gov/.
Drafting a Compliant Cookie Policy
A legally compliant cookie policy is a foundational requirement for any organization that operates a website and uses cookies or similar tracking technologies. Under the GDPR, the ePrivacy Directive, the CCPA/CPRA, and the growing patchwork of state, national, and international privacy laws, organizations must clearly and comprehensively disclose their cookie practices and provide users with meaningful choices about tracking. This section provides practical guidance for companies seeking to draft or improve their cookie policies.
Begin by conducting a thorough cookie audit. Use a combination of automated scanning tools (such as those provided by cookie consent management platforms) and manual review to identify every cookie, web beacon, pixel, local storage entry, and similar technology deployed on your website. For each technology identified, document its name, provider, purpose, category (strictly necessary, functional, analytics, advertising, or social media), duration (session or persistent, with specific expiration), and the domain from which it is set (first-party or third-party). This audit should be repeated regularly, as new cookies are frequently introduced when website code changes or new third-party services are integrated.
Your cookie policy must be written in clear, plain language that is accessible to a general audience, not just legal professionals. Avoid dense legalese, undefined jargon, and overly broad statements such as "we use cookies to improve your experience." Instead, explain specifically how each category of cookies is used, what data they collect, who receives the data, and how long it is retained. The GDPR requires that information provided to data subjects be "concise, transparent, intelligible and easily accessible, using clear and plain language" (Article 12(1)).
Structure your cookie policy into clearly labeled sections that address: what cookies are; the categories of cookies used; the specific purposes of each category; the identities of third parties that set or receive data from cookies; the legal basis for processing (consent or legitimate interest, as applicable); how users can manage, withdraw consent, or delete cookies; and your contact information. Include a comprehensive cookie table or inventory that lists each cookie by name, provider, purpose, category, duration, and type (first-party or third-party). This table is a regulatory expectation in many jurisdictions and a best practice in all.
Ensure that your cookie consent mechanism is aligned with your cookie policy. The categories and descriptions presented in your consent banner should match those documented in your policy. Misalignment between the two is a common compliance failure and a frequent target of regulatory enforcement. Your consent mechanism must block all non-essential cookies and scripts before consent is obtained, provide granular category-level controls, present accept and reject options with equal prominence, and record verifiable proof of consent that includes the time, date, and scope of consent given.
Finally, keep your cookie policy up to date. Review it at least quarterly, and update it whenever you add or remove cookies, change analytics or advertising providers, modify your consent mechanism, or when applicable law changes. Designate a clear internal owner for cookie compliance, whether in the legal, privacy, marketing, or engineering department, and establish processes for cross-functional coordination when changes to the website affect cookie behavior.
Cookie Consent Management Platforms
A Cookie Consent Management Platform (CMP) is a technology solution that helps website operators manage cookie consent in compliance with applicable data protection laws. CMPs typically provide automated cookie scanning, customizable consent banners, granular consent controls, consent record storage, and integration with tag management systems to block non-essential cookies until consent is obtained. Implementing a CMP is considered an industry best practice and is effectively a regulatory expectation for websites that serve users in jurisdictions with cookie consent requirements.
Leading CMPs include OneTrust, Cookiebot (by Usercentrics), CookieYes, Didomi, Osano, TrustArc, and Quantcast Choice. Each platform varies in features, pricing, ease of implementation, and suitability for different types of organizations. OneTrust is an enterprise-grade privacy platform that offers comprehensive cookie consent management alongside broader privacy program functionality, including data subject access request management, data mapping, vendor risk management, and privacy impact assessments. OneTrust’s pricing starts at approximately $10,000 per year, making it most suitable for mid-size to large enterprises with mature privacy programs.
Cookiebot (now part of the Usercentrics platform) is a widely used CMP that serves over 600,000 websites worldwide. Its key differentiator is its robust auto-blocking engine, which can automatically detect and block cookies without requiring manual script tagging. Cookiebot offers a free tier for websites with up to 50 subpages, with paid plans starting at approximately $13 per month. CookieYes is another popular option, offering a user-friendly interface, automated cookie scanning, and compliance with GDPR, CCPA, and other major privacy laws, with pricing starting from free for basic use up to enterprise tiers.
When selecting a CMP, consider the following factors: compliance coverage (does the platform support the specific regulations applicable to your user base, including GDPR, ePrivacy, CCPA/CPRA, LGPD, POPIA, and others?); auto-blocking capability (can the platform automatically prevent non-essential cookies from firing before consent is obtained, or does it require manual script tagging?); customization and branding (can the consent banner be customized to match your website’s design while remaining compliant?); consent record storage (does the platform maintain verifiable, auditable records of consent?); integration ecosystem (does the platform integrate with your tag manager, analytics tools, and advertising platforms?); and cost and scalability (is the pricing appropriate for your website’s traffic volume and number of subpages?).
Regardless of which CMP you select, ensure that it is configured correctly. A misconfigured CMP can provide a false sense of security while leaving your website non-compliant. Specifically, verify that the CMP blocks all non-essential cookies and scripts before consent is obtained; that the consent banner presents accurate, up-to-date information about your cookie categories; that accept and reject options are presented with equal prominence; that consent records include the timestamp, categories consented to, and the version of the cookie policy in effect at the time of consent; and that the CMP re-scans your website regularly to detect newly added cookies.
It is important to understand that a CMP is a tool, not a complete compliance solution. A CMP manages the technical aspects of cookie consent, but your organization remains responsible for maintaining an accurate and comprehensive cookie policy, conducting regular cookie audits, ensuring that third-party service providers comply with applicable laws, responding to data subject rights requests, and keeping the CMP configuration aligned with your actual cookie practices and legal obligations.
Common Cookie Policy Mistakes
Failure to Block Cookies Before Consent: The most common and consequential cookie compliance violation is loading non-essential cookies before the user has provided consent. Analytics tags, advertising pixels, and social media widgets frequently fire on page load, before the visitor interacts with the consent banner. This directly violates Article 5(3) of the ePrivacy Directive and has been the basis for some of the largest cookie-related fines in Europe, including a EUR 150 million fine imposed on a major retailer by the CNIL in 2023. Organizations must implement technical measures, such as a properly configured CMP with auto-blocking capability, to prevent non-essential cookies from executing until valid consent is recorded.
Using Dark Patterns and Asymmetric Choice Architecture: Regulatory authorities have increasingly targeted cookie consent interfaces that use dark patterns to manipulate user choices. Common violations include making the "Accept All" button large, prominently colored, and easy to find while hiding the "Reject" or "Manage Preferences" option behind smaller text, muted colors, or multiple additional clicks. The EDPB, CNIL, and other supervisory authorities have explicitly stated that rejecting cookies must be as easy as accepting them. The CCPA/CPRA similarly prohibits interfaces that have the "substantial effect of subverting or impairing a consumer’s choice to opt out." Using pre-checked consent boxes is also a violation under the GDPR, as confirmed by the Court of Justice of the European Union in Planet49 (Case C-673/17).
Vague, Incomplete, or Outdated Cookie Disclosures: Many cookie policies use imprecise language such as "we use cookies to improve your experience" without specifying the types of cookies used, their purposes, their durations, or the identities of third parties that receive data. This fails to meet the transparency requirements of Article 13 and Article 12(1) of the GDPR. Equally problematic are cookie policies and cookie inventories that are not regularly updated. Cookies change frequently as new tags, scripts, and integrations are added to a website, often by marketing or engineering teams without notifying the legal or privacy team. Organizations should scan their websites for new cookies at least monthly and update their cookie policies and consent mechanisms accordingly.
Failing to Maintain Adequate Consent Records: If an organization cannot demonstrate when, how, and under what terms a user gave consent, it is unable to satisfy its burden of proof under the GDPR (Article 7(1)) and is exposed to significant regulatory risk. Adequate consent records must include the identity of the user (or a pseudonymous identifier), the date and time of consent, the specific categories of cookies consented to, the version of the cookie policy and consent notice in effect at the time of consent, and evidence that consent was given through a clear affirmative action. Organizations should use a CMP that automatically records and stores this information.
Cookie Walls and Forced Consent: Conditioning access to a website or its content on the acceptance of non-essential cookies (a "cookie wall") is generally considered non-compliant with the GDPR’s requirement that consent be freely given. The EDPB has stated that consent is not freely given if access to services is conditional on consent to the processing of personal data that is not necessary for the provision of the service. While some national regulators (notably in the Netherlands) have permitted cookie walls in limited circumstances involving free content funded by advertising, the prevailing regulatory position is that cookie walls undermine the voluntariness of consent and should be avoided.
Ignoring Global Privacy Control and Opt-Out Signals: Under the CCPA/CPRA, businesses are required to honor Global Privacy Control (GPC) signals transmitted by a user’s browser as a valid opt-out request. Failure to recognize and act on GPC signals has been the subject of enforcement actions, including a significant fine imposed on Sephora in 2022. Organizations should configure their websites and CMPs to detect GPC signals and automatically apply them as opt-out preferences. Additionally, organizations should ensure that the "Do Not Sell or Share My Personal Information" link required by the CCPA/CPRA is prominently displayed and functional.
This template is provided by Montague Law for informational purposes only and does not constitute legal advice. Consult a qualified attorney before using this document.