Cookie Policy
| Policy owner | Version | Effective date | Next review |
|---|---|---|---|
| [Accountable owner or department] | [Version] | [Date] | [Date] |
Policy objective: [Outcome this policy governs]
Scope: [People, systems, locations, and activities covered]
1. Scope and Definition
[Domains, apps, effective date, definition of cookie and similar technology, and owner.]
2. Cookie Categories and Purposes
[Purpose classification and whether each category is essential, consent-based, or opt-out.]
3. First-Party Inventory
[Cookie name, provider, domain, purpose, duration, data collected, and trigger for every first-party cookie.]
4. Third-Party and Advertising Technologies
[SDK or third-party tag, recipient, data transfer, cross-site use, and vendor documentation.]
5. Essential Cookies
[Authentication, security, load balancing, preference, and fraud-prevention cookies that cannot be disabled.]
6. Analytics and Measurement
[Measurement provider, event scope, retention, aggregation, and consent signal.]
7. Personalization and Advertising Choices
[Ad and personalization vendors, profiling description, consent withdrawal, and regional choice.]
8. Retention and Expiry
[Session or persistent duration, renewal, deletion, and device-level implications.]
9. Browser Controls and Consent Withdrawal
[Preference center URL, browser settings, global privacy signal, and consequences of disabling.]
10. Updates and Contact
[Change notice, privacy-policy link, and privacy contact.]
Exceptions, Enforcement, and Review
- Exception authority: [Role authorized to approve a documented exception]
- Required evidence: [Risk assessment, compensating control, owner, and expiry date]
- Enforcement: [Investigation and proportionate consequence process]
- Review trigger: [Scheduled cadence and events requiring an earlier review]
Implementation notice: Cookie consent and advertising rules differ by jurisdiction. The inventory must be reconciled with the live tag manager and reviewed by privacy counsel.