Strictly necessary cookies

A strictly necessary cookie is a type of cookie used by a website to function correctly and without which the site would not work. This type of cookie does not collect personally identifiable information (PII) about users and does not track their browsing habits.

They are essential to accessing the website’s features such as signing in, adding items to a cart, or e-billing. Strictly necessary cookies are first-party session cookies, but not all first-party cookies are strictly necessary cookies. They allow users to navigate between pages without losing previous actions from the same session.

Strictly necessary cookies are the only cookies that cookie laws exempt from user consent. Since these cookies are essential for website functionality, website owners do not have to get consent from the user to place strictly necessary cookies on their devices. However, GDPR and the ePrivacy Directive require websites to inform users of the purpose of the necessary cookies on the site.

You may also like:

You can check if the cookies used on your website and your consent management mechanism meet the requirements of GDPR with Free Online Cookie Scanner | Piwik PRO Analytics Suite


  • Privacy by design in practice: How “just enough” data beats “just in case” collection

    While collecting more data “just in case” feels safer, according to Matt Gershoff, it’s also one of the biggest sources of unnecessary compliance risk, analytical noise, and wasted organizational resources in the analytics industry today. His approach of “just enough” data collection is more intentional, more aligned with privacy regulation, and often more analytically effective.

  • 4 ways to make your analytics HIPAA-compliant: Implementation guide

    Healthcare organizations have four main approaches to achieving HIPAA-compliant analytics. Each has different trade-offs in cost, technical complexity, and analytics capabilities. This guide compares all four implementation methods – from using Google Analytics with workarounds to deploying fully HIPAA-compliant analytics platforms – so you can choose the right approach for your organization’s needs and resources.