
Definition:
A cookie is a small set of data that a website asks a browser to store and that the browser may send again in later requests. It maintains state across otherwise independent HTTP interactions and is used for functions such as preserving a session, remembering preferences or associating several interactions with the same browser.
Although it is often described as a text file, a cookie is technically a name and value accompanied by attributes that determine its duration, scope and transmission conditions. Not all cookies are used for advertising tracking, and their presence does not mean that they directly contain a user’s identity.
Índice de contenidos
A server can include a Set-Cookie instruction in a response. The browser stores the data and, when the defined conditions are met, includes it through the Cookie header in subsequent requests. The server can then recognise the state associated with the interaction.
A shop may store an identifier linked to an electronic cart; an application may maintain a signed-in session; and a website may retain the selected language. The cookie normally contains a short identifier or preference, while detailed information remains on the server.
Attributes and security
Attributes limit when a cookie is retained and transmitted. Their configuration affects both functionality and data exposure:
- Domain and Path: These define the domains and paths for which the cookie may be sent.
- Expires and Max-Age: These determine when it expires. Without them, it is generally treated as a session cookie.
- Secure: This restricts transmission to HTTPS connections.
- HttpOnly: This prevents access through client-side JavaScript and reduces exposure to certain attacks.
- SameSite: This controls transmission in cross-site contexts and helps limit some unwanted requests.
Cookies should not store passwords, complete payment card numbers or other secrets as readable text. Authentication normally uses a random session identifier together with server-side controls, expiry, rotation and connection protection.
Common uses
The purpose depends on the specific cookie and the system that sets it. Common uses include:
- Sessions and authentication: Maintaining access and associating successive requests with an active session.
- Preferences: Remembering language, region, accessibility or display settings.
- Functionality: Retaining selections, carts or processes started across several pages.
- Measurement: Associating interactions to produce web analytics metrics, subject to the configuration and applicable legal conditions.
- Advertising: Managing frequency, attribution, targeting or campaign measurement where the technology and consent permit it.
Cookies can be classified according to different criteria. These categories can be combined and are not mutually exclusive:
- Session or persistent: Session cookies lack a persistent expiry and are normally discarded when the browser session ends. Persistent cookies retain an expiry date or period.
- First-party or third-party: First-party cookies belong to the website shown in the address bar. Third-party cookies come from another domain integrated into the page, although browsers may block them or restrict their access.
- Necessary, preference, measurement or marketing: This classification describes purpose. The label alone does not determine whether a cookie is exempt from consent.
Other technologies, such as localStorage, also retain information in the browser, but they are not cookies: they are not automatically sent with every HTTP request and have different access and persistence mechanisms.
Origin and development
Lou Montulli developed cookies for Netscape in 1994 to maintain state on the web, initially for uses such as shopping carts. The mechanism spread to other browsers and was eventually standardised as part of HTTP.
The later use of cookies to recognise browsers across visits and different websites increased privacy concerns. Browsers introduced controls for viewing, deleting or blocking cookies and have progressively restricted many third-party uses. At the same time, first-party cookies remain fundamental to sessions, preferences and many web functions.
Cookies, consent and privacy
In the European Union, rules concerning the storage of or access to information on a device primarily derive from electronic privacy law and its national implementation. When a cookie participates in personal data processing, the GDPR is also relevant.
Cookies that are strictly necessary to provide a requested function may be exempt from prior consent under certain conditions. Cookies used for non-exempt measurement, advertising personalisation or tracking generally require clear information and a valid choice before activation. The assessment depends on the purpose, data, third parties and applicable law, not only on the category label.
