Free Cookie Policy Template
A cookie policy informs website visitors about the cookies and tracking technologies your site uses. Use our free UK template to create a clear, compliant cookie policy that meets the requirements of the UK GDPR and the Privacy and Electronic Communications Regulations 2003.
This Policy is issued in compliance with: Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR, as amended), which requires prior informed consent before non-essential storage of or access to information on a user's terminal equipment; the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, where personal data is processed through cookies; and the Digital Markets, Competition and Consumers Act 2024 (DMA 2024), which extends PECR-style rules to any similar device-fingerprinting or tracking technology. We follow the ICO Cookie Guidance (2019, refreshed 2024).
Cookies may be "first-party" (set by the Website you are visiting) or "third-party" (set by another domain whose content is embedded on the Website). They may be "session" cookies, deleted when you close your browser, or "persistent" cookies, remaining on your device for a set period.
Some cookies involve the processing of personal data (for example where online identifiers are used under UK GDPR Article 4(1)). Where this is the case, the additional rights and obligations set out in the UK GDPR and Data Protection Act 2018 apply in addition to PECR.
These cookies are essential for the Website to function and cannot be switched off in our systems. They are usually only set in response to actions you take — setting privacy preferences, logging in, or completing forms. You can configure your browser to block these, but parts of the Website may not work correctly.
Legal basis: These cookies are exempt from the consent requirement under PECR Regulation 6(4) as they are strictly necessary for the provision of a service which you have requested. Where personal data is processed, our lawful basis is UK GDPR Article 6(1)(b) (contract) or 6(1)(f) (legitimate interest in operating a secure and functional website).
Cookies used:
session_id - Maintains user session - Expires: session end
cookie_consent - Records cookie consent preferences - Expires: 12 months
b) Analytics and Performance Cookies
These cookies allow us to count visits and traffic sources so we can measure and improve Website performance. They help us understand which pages are most and least popular and how visitors move around the site.
Legal basis: Consent under PECR Regulation 6(1) and UK GDPR Article 6(1)(a). Although the ICO accepts that first-party analytics carry low privacy risk, they remain outside the "strictly necessary" exemption and therefore require consent.
Cookies used:
_ga - Google Analytics, distinguishes users - Expires: 2 years
_ga_XXXXXXX - Google Analytics, maintains session state - Expires: 2 years
We do not control third-party cookies. You should check the relevant third-party website for more information and how to manage or disable them. Where third-party providers transfer data outside the UK, we rely on UK Addendum to the EU Standard Contractual Clauses, UK International Data Transfer Agreement (IDTA) or an adequacy regulation under UK GDPR Articles 44–49.
Consent must meet the UK GDPR standard (Article 4(11) and Article 7): it is freely given, specific, informed and unambiguous, and given by a clear affirmative act. Pre-ticked boxes, continued browsing and "bundled" consent are not valid.
Withdrawal: You may withdraw consent at any time using the cookie settings control linked in the footer of the Website. Withdrawal is as easy as giving consent (UK GDPR Article 7(3)) and does not affect the lawfulness of prior processing.
Most browsers allow you to refuse or accept cookies and delete existing ones. Instructions are usually in your browser's "Help" menu or settings. Below are links to common browser controls:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Options → Privacy and Security → Cookies and Site Data
- Apple Safari: Preferences → Privacy → Manage Website Data
- Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data
You may also use browser "Do Not Track" signals or privacy-focused extensions. We honour the Global Privacy Control (GPC) header as a valid opt-out signal in line with ICO guidance.
Third-party opt-out links:
Google Analytics: https://tools.google.com/dlpage/gaoptout
To exercise these rights please contact us using the details below. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Apex Solutions Ltd
10 Innovation Drive
London
EC2A 4NE
Email: privacy@apex-solutions.co.uk
Phone: +44 20 7946 0958
Data Protection Officer / Privacy Contact: Jane Smith, Data Protection Officer
DPO Email: dpo@apex-solutions.co.uk
What Is a Cookie Policy?
A cookie policy is a document published on a website that explains what cookies and similar technologies are used, what data they collect, why they are used and how visitors can manage their preferences. It is a key part of any website’s privacy compliance framework.
In the UK, the use of cookies is regulated by the Privacy and Electronic Communications Regulations 2003 (PECR) alongside the UK General Data Protection Regulation (UK GDPR). PECR requires that website operators obtain informed consent before placing non-essential cookies on a visitor’s device.
The UK Information Commissioner’s Office (ICO) actively enforces cookie compliance in Britain and has issued detailed guidance on what constitutes valid consent under English law. A clear and accurate UK cookie policy is essential for demonstrating compliance and building trust with your British visitors.
What's Covered in This Template
Our cookie policy template covers everything you need to inform visitors and comply with UK regulations.
What Cookies Are
A plain-language explanation of cookies and similar technologies for non-technical visitors.
Types of Cookies Used
Classification of cookies by purpose: strictly necessary, performance, functionality and targeting cookies.
First-Party Cookies
Details of cookies set directly by your website, their names, purposes and expiry periods.
Third-Party Cookies
Information about cookies set by external services such as Google Analytics, social media plugins and advertising networks.
Cookie Consent Mechanism
Explanation of how visitors can give, refuse or withdraw consent through your cookie banner or preference centre.
How to Manage Cookies
Instructions for controlling cookies through browser settings, with links to guides for major browsers.
Data Collected via Cookies
What personal data cookies may collect, such as IP addresses, browsing behaviour and device information.
Data Sharing
Whether cookie data is shared with third parties and the purposes for which it is shared.
Retention Periods
How long each category of cookie remains on the visitor’s device before expiring.
Contact Information
Details of the data controller and how visitors can contact you with questions or complaints about cookies.
How to Create a Cookie Policy
Follow these steps to produce a clear and compliant cookie policy for your website.
- 1
Audit Your Cookies
Scan your website to identify all cookies and tracking technologies in use, including those set by third-party services.
- 2
Categorise Each Cookie
Group cookies by type: strictly necessary, performance, functionality and targeting. Record each cookie’s name, purpose and duration.
- 3
Describe Data Collection
Explain what data each category of cookie collects and how that data is used, stored and shared.
- 4
Set Up Consent Mechanism
Ensure your website has a cookie banner or preference centre that allows visitors to accept, reject and manage non-essential cookies.
- 5
Publish and Review
Publish the policy on your website with a prominent link. Review and update it whenever you add new cookies or change your tracking practices.
Legal Considerations
Cookie compliance in the UK involves both PECR and the UK GDPR working together.
This template is for informational purposes only and does not constitute legal advice. Consult a qualified solicitor for advice specific to your situation.
Reviewed for England & Wales law
PECR Consent Requirements
Regulation 6 of UK PECR requires that website operators in England and Wales obtain consent before storing or accessing information on a user’s device, unless the cookie is strictly necessary for providing a service the user has requested. Pre-ticked boxes and implied consent do not constitute valid consent under British law.
UK GDPR and Lawful Basis
Where cookies collect personal data in the United Kingdom, the UK GDPR applies. British consent must be freely given, specific, informed and unambiguous. The UK website must be able to demonstrate that consent was obtained and provide an easy way for users to withdraw it under English data protection law.
ICO Enforcement
The UK ICO has the power to issue enforcement notices and fines for non-compliance with PECR in Britain. In recent years, the ICO has increased its focus on cookie compliance and has taken action against British websites that use cookie walls, dark patterns or fail to obtain valid consent under English law.
Analytics and Marketing Cookies
The UK ICO has confirmed that analytics cookies (including Google Analytics) are not strictly necessary and require consent from British users. Marketing and advertising cookies always require explicit opt-in consent before being placed on the user’s device under UK PECR and the UK GDPR.
Frequently Asked Questions
Create Your Cookie Policy Now
Ensure your website is compliant with UK cookie regulations. Fill in the details, preview your policy and download it as a PDF in minutes.
Free · Instant PDF · No account required