What Is a Cookie and Which Ones Should You Reject?
Short answer
A cookie is a small piece of text a website stores in your browser and reads back on your next visit. Accept necessary cookies and reject everything else. Necessary ones keep you logged in and keep your basket full; marketing and analytics cookies exist to build a profile of you across sites and nothing breaks without them.
On this page
A cookie is a short piece of text a website asks your browser to store, and reads back the next time you visit. That is all it is. It cannot execute, it cannot scan your drive, and it cannot carry malware.
What makes cookies contentious is not the mechanism but the use. The same feature that remembers you are logged in also lets an advertising network recognise you across hundreds of unrelated sites.
Why they exist at all
The web was designed stateless. Each request to a server is independent and carries no memory of the last one. Without cookies, a site has no way to know that the person clicking “checkout” is the same person who filled the basket four clicks earlier.
A cookie solves that by giving your browser a token to hand back on every subsequent request. The server looks up the token and knows which session you are. Everything else, from preferences and consent records to analytics and tracking, is built on that one primitive.
The categories, and what each actually does
Cookie banners split consent into named groups. The names vary; the substance does not.
| Category | What it does | Reject it? |
|---|---|---|
| Strictly necessary | Login session, basket, security tokens, consent record | No, the site breaks |
| Functional / preferences | Language, dark mode, region, layout choices | Keep if you want them remembered |
| Analytics / performance | Counts visits and measures which pages work | Reject; costs you nothing |
| Marketing / advertising | Builds a cross-site profile for ad targeting | Reject |
| Social media | Embedded buttons that report your visit back | Reject |
Necessary cookies cannot legally be made optional under UK and EU rules, which is why the “reject all” button leaves them in place. That is correct behaviour, not a dark pattern.
The common claim that rejecting analytics “breaks the site” is not true. Analytics is instrumentation for the site owner. The page renders identically without it.
First-party and third-party
This distinction matters more than the category labels.
A first-party cookie is set by the domain in your address bar. Reading a news site, a cookie from that news site is first-party. It can only be read by that site.
A third-party cookie is set by a different domain whose content is embedded in the page — an ad slot, an embedded video, a tracking pixel. Because that same network’s code is embedded on thousands of sites, it sees the same cookie on all of them and can assemble the list of pages you have visited.
That is the tracking mechanism. It is not sophisticated; it simply works at scale.
Safari and Firefox block third-party cookies by default and have for years. Chrome has restricted them, deprecated them in stages, and publicly changed course on full removal more than once, so the state of play in Chrome depends on which version and which experiment group you are in.
Reading a cookie banner quickly
Most banners are designed so “Accept All” is one click and refusing is three. Two shortcuts:
Look for “Reject All”. Under UK and EU rules, refusing should be as easy as accepting, so a reject button is usually present even when it is styled as plain text rather than a button.
Otherwise, open preferences and toggle everything off except necessary. The toggles are grouped; it is one tap each.
Be sceptical of the “legitimate interest” tab. Some banners allow analytics and advertising under a legitimate-interest claim with the toggles pre-enabled, sitting behind a second tab you did not see. If a banner has a tab labelled Legitimate interest or Vendors, check it before clicking save.
Setting it once instead of per-site
Browser settings do more than any individual banner choice, because they apply regardless of what the banner says.
- Chrome: Settings → Privacy and security → Third-party cookies → Block third-party cookies.
- Firefox: Settings → Privacy & Security → Enhanced Tracking Protection → Strict.
- Safari: Settings → Privacy → Prevent cross-site tracking (on by default).
- Edge: Settings → Privacy, search and services → Tracking prevention → Strict.
Strict modes occasionally break single sign-on flows and embedded payment widgets. When a login loops endlessly, this is the first setting to relax for that one site.
One consequence worth knowing in advance: the more aggressively you block cookies, the more CAPTCHAs you will see, because the scoring systems rely on exactly this history to recognise you. That is covered in why CAPTCHAs single some people out.
What cookies cannot do, and what replaced them
Cookies cannot read your files, access other sites’ cookies, or persist after you delete them.
But blocking them does not make you unidentifiable. The industry moved on: browser fingerprinting combines screen size, fonts, time zone, graphics behaviour and dozens of other properties into an identifier that needs no stored data at all. Hashed email addresses, used when you log in anywhere, work across devices in a way cookies never could. Server-side tracking moves the collection off your browser entirely.
Rejecting cookies is still worth doing. It reduces the easiest, cheapest and most widespread form of tracking. It just is not the whole of the problem, and anyone telling you it is has something to sell.
Realistic expectations
Rejecting non-essential cookies costs you nothing you will notice. Ads become less relevant, which some people miss and most do not. Sites continue to work.
Clearing cookies is a different matter and should be done per-site rather than globally, because a full clear signs you out of everything and discards the preferences you chose. In Chrome, click the icon left of the address bar → Cookies and site data → Manage on-device site data for the current site only.
If you clear cookies hoping to fix a slow browser, that is the wrong lever — clearing a cache and clearing cookies do different things, and only one of them signs you out of your bank.