A privacy policy and a cookie policy sound like they might be the same document with two names. They are not. A privacy policy discloses everything a business does with personal data, wherever it comes from: account signups, checkout forms, support tickets, and yes, cookies too. A cookie policy is narrower and more mechanical: it lists the specific cookies and tracking technologies a site sets, what each one does, how long it lasts, and how a visitor can turn the non-essential ones off. One document explains your data practices in general terms. The other is closer to an itemized inventory of one particular data-collection method. Most sites end up needing both, but not because more paperwork is always better, it is because the two documents answer to different legal requirements and different reader questions.

Cookie policy vs. privacy policy

Cookie policyPrivacy policy
ScopeCookies and tracking tech onlyAll personal data, any method
Typical contentCookie names, purpose, durationData categories, basis, retention
Legal driverePrivacy consent rulesGDPR, CCPA/CPRA, similar laws
Usually paired withA cookie consent bannerAccount and checkout forms
Can it stand alone?Rarely, linked from the policyYes, the baseline every site needs

What a privacy policy actually covers

A privacy policy is the general-purpose disclosure. It answers the questions that apply no matter how the data got to you: what personal data you collect, why you collect it, who you share it with, how long you keep it, and what rights a visitor or customer has over their own information. Under the EU’s General Data Protection Regulation, Articles 13 and 14 spell out exactly what this notice has to include, the identity of the data controller, the purposes and legal basis for each type of processing, and any third parties data is shared with. Under the CCPA and its CPRA amendments, California residents get a parallel set of disclosures plus specific rights: to know what is collected, to delete it, and to opt out of its sale or sharing.

Because a privacy policy has to cover every collection method a business uses, cookies are one line item among many, not the whole document. A typical privacy policy touches account data collected at signup, payment data handled at checkout, support messages, marketing list subscriptions, and only then, usually in its own section, the data collected through cookies and similar technologies on the site itself. That section is often a summary with a link out, rather than the full technical detail, which is exactly the gap a cookie policy fills.

A cookie policy narrows in on one collection method: cookies, along with related technologies like local storage, pixels, and SDKs that behave the same way. Where a privacy policy might say “we use cookies and similar technologies for analytics and advertising” in a single sentence, a cookie policy is expected to get specific: which cookies, set by which domain, for how long, and for what purpose. A useful cookie policy typically groups cookies into categories (strictly necessary, functional, analytics, advertising) and, for anything beyond strictly necessary, explains how a visitor can decline or later change their choice.

This level of detail exists because of a separate piece of EU law from the GDPR: the ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC, often shortened to the “cookie law”). Article 5(3) requires consent before storing or accessing information on a user’s device, unless the storage is strictly necessary to deliver a service the visitor explicitly requested, a shopping cart session or a login token, for example. That consent requirement is why cookie banners exist at all, and it is a narrower, more specific rule than the general data protection principles GDPR sets out. A cookie policy is the document that makes good on that specific disclosure, listing exactly what is being consented to.

Where the two overlap, and why that causes confusion

The overlap is real, and it is the reason people assume one document can do both jobs. Cookies collect personal data (an analytics cookie tied to a visitor ID is personal data under GDPR’s broad definition), so anything a cookie policy discloses also has to be reflected, at a higher level, in the privacy policy’s description of data collection methods and purposes. If your privacy policy says “we do not use cookies for advertising” while your cookie policy lists three ad-network cookies, that is not two documents covering different things, it is one document contradicting the other, and it is the kind of inconsistency a regulator or a privacy-focused visitor notices immediately.

The cleanest way to avoid that is to treat the cookie policy as the detailed backup for whatever the privacy policy states in summary. The privacy policy’s cookie section should describe the categories of cookies used and link to the full cookie policy for the itemized list. Neither document should introduce a data use the other does not account for.

Not every site needs a separate cookie policy document. A site that sets only strictly necessary cookies, a session cookie for login state, a cart cookie for checkout, has a much lighter disclosure obligation than one running analytics, retargeting pixels, and third-party ad tags, because strictly necessary cookies are exempt from the ePrivacy consent requirement in the first place. For a site in that position, a clear cookie section inside the privacy policy, without a consent banner and without a separate document, is often enough.

The moment a site adds anything beyond strictly necessary, analytics like Google Analytics, advertising pixels from Meta or Google Ads, third-party embeds that set their own cookies, the calculus changes. Consent has to be obtained before those cookies fire, the visitor needs a way to see and change their choices later, and the itemized detail (which cookies, whose domain, how long) becomes long enough that folding it into the privacy policy makes both documents harder to read. That is the point where a standalone cookie policy, linked from the privacy policy and from the consent banner itself, is the more practical structure.

Matching the disclosure to what the site actually does

A few common setups make the decision concrete. A brochure site with no analytics and no third-party embeds rarely needs more than a privacy policy with a short cookie section, since there is nothing beyond strictly necessary cookies to disclose in detail. An e-commerce store running Google Analytics and a retargeting pixel needs both documents: the privacy policy to cover order and account data generally, and a cookie policy to itemize the specific analytics and advertising cookies plus the consent mechanism controlling them. A SaaS product with EU or California users, even one that only sets a handful of first-party cookies, still benefits from a standalone cookie policy once the visitor base includes people covered by consent-based rules, since it keeps the itemized detail out of the privacy policy and makes the consent banner’s “learn more” link point somewhere genuinely complete.

The safest default, if a site collects any personal data through cookies beyond what a login or cart strictly requires, is to publish both documents and keep them consistent with each other rather than trying to decide in advance which one a regulator or a privacy-conscious visitor will read first. Our Cookie Policy generator builds the itemized, category-based document from a short set of questions about what your site actually sets, so the categories and durations match what is really running rather than a generic template, and it is built to link cleanly from whatever privacy policy you already have. If you have not published a privacy policy yet either, see our Privacy Policy generator to cover the general disclosure first.

If you are still deciding whether your site needs a cookie policy at all, What Is a Cookie Policy? covers the baseline case, and Cookie Policy Requirements for Google Analytics and Ad Pixels walks through the specific disclosures those two common tools require.