GDPR Cookie Policy Generator
Generate a GDPR cookie policy — disclose the cookies your site uses.
This is a starting template, not legal advice. Have a professional review it before publishing.
How to use GDPR Cookie Policy Generator
- Audit your cookies — check browser dev tools to see what your site actually sets.
- Enter the categories and tools — analytics, ads, functional.
- Generate and publish the policy at /cookies, linked from your consent banner.
- Pair with a consent banner — and don't set non-essential cookies before consent.
What is GDPR Cookie Policy Generator?
A GDPR cookie policy generator creates the page that discloses which cookies your website uses, what they do, and how visitors can control them — a specific requirement of EU privacy law (GDPR and the ePrivacy Directive) for any site serving European users. It complements the cookie consent banner: the banner asks permission, the policy explains what they're permitting.
EU law treats cookies (especially non-essential ones — analytics, advertising, tracking) as requiring informed consent, which means telling users what cookies you set and why. A cookie policy is how you provide that information; without it, your consent isn't truly informed, and you're non-compliant.
About the GDPR Cookie Policy Generator
Enter which cookies your site uses — the categories and specific tools (analytics, ads, functional) — and generate a cookie policy to publish.
What the policy covers: cookie categories — strictly necessary (no consent needed — the site can't function without them), functional (preferences, remembering settings), analytics (Google Analytics and similar), and advertising/tracking (AdSense, marketing pixels — the ones most needing consent); what each does and why; third-party cookies — the ones set by tools you embed (analytics, ads, embeds, social), which must be disclosed since you're responsible for enabling them; and how to control them — via your consent banner and browser settings.
How it fits together: the cookie policy pairs with a consent banner (our Cookie Consent Generator) and your broader privacy policy — the three form the GDPR cookie-compliance set. Key compliance points: non-essential cookies require prior consent (don't set analytics/ad cookies before the user agrees — a common violation), consent must be as easy to withdraw as to give, and the policy must be accurate to what you actually set. A generator produces a strong compliant baseline; verify it matches your real cookies (audit via browser dev tools), and for high-risk processing, get professional review. Publish at /cookies or within your privacy policy, linked from the banner.