Strictly necessary cookies

A strictly necessary cookie is a type of cookie used by a website to function correctly and without which the site would not work. This type of cookie does not collect personally identifiable information (PII) about users and does not track their browsing habits.

They are essential to accessing the website’s features such as signing in, adding items to a cart, or e-billing. Strictly necessary cookies are first-party session cookies, but not all first-party cookies are strictly necessary cookies. They allow users to navigate between pages without losing previous actions from the same session.

Strictly necessary cookies are the only cookies that cookie laws exempt from user consent. Since these cookies are essential for website functionality, website owners do not have to get consent from the user to place strictly necessary cookies on their devices. However, GDPR and the ePrivacy Directive require websites to inform users of the purpose of the necessary cookies on the site.

You may also like:

You can check if the cookies used on your website and your consent management mechanism meet the requirements of GDPR with Free Online Cookie Scanner | Piwik PRO Analytics Suite


  • HIPAA-compliant analytics for healthcare systems: How hospital marketing teams can measure what matters

    Patients now research symptoms, compare providers, and book appointments entirely online before ever contacting a hospital. Healthcare marketers need to adapt to digital-first patient journeys, run campaigns for numerous service lines, manage hospital marketing analytics across multiple locations, and prove ROI to administrators. For nonprofit hospitals, the picture is broader still — donation tracking is…

  • Privacy by design in practice: How “just enough” data beats “just in case” collection

    While collecting more data “just in case” feels safer, according to Matt Gershoff, it’s also one of the biggest sources of unnecessary compliance risk, analytical noise, and wasted organizational resources in the analytics industry today. His approach of “just enough” data collection is more intentional, more aligned with privacy regulation, and often more analytically effective.