Skip to main content
FixMyTech

What Is a Cookie and Which Ones Should You Reject?

By

Published

7 min read

Share

Short answer

A cookie is a small piece of text a website stores in your browser and reads back on your next visit. Accept necessary cookies and reject everything else. Necessary ones keep you logged in and keep your basket full; marketing and analytics cookies exist to build a profile of you across sites and nothing breaks without them.

On this page

A cookie is a short piece of text a website asks your browser to store, and reads back the next time you visit. That is all it is. It cannot execute, it cannot scan your drive, and it cannot carry malware.

What makes cookies contentious is not the mechanism but the use. The same feature that remembers you are logged in also lets an advertising network recognise you across hundreds of unrelated sites.

Why they exist at all

The web was designed stateless. Each request to a server is independent and carries no memory of the last one. Without cookies, a site has no way to know that the person clicking “checkout” is the same person who filled the basket four clicks earlier.

A cookie solves that by giving your browser a token to hand back on every subsequent request. The server looks up the token and knows which session you are. Everything else, from preferences and consent records to analytics and tracking, is built on that one primitive.

The categories, and what each actually does

Cookie banners split consent into named groups. The names vary; the substance does not.

Category What it does Reject it?
Strictly necessary Login session, basket, security tokens, consent record No, the site breaks
Functional / preferences Language, dark mode, region, layout choices Keep if you want them remembered
Analytics / performance Counts visits and measures which pages work Reject; costs you nothing
Marketing / advertising Builds a cross-site profile for ad targeting Reject
Social media Embedded buttons that report your visit back Reject

Necessary cookies cannot legally be made optional under UK and EU rules, which is why the “reject all” button leaves them in place. That is correct behaviour, not a dark pattern.

The common claim that rejecting analytics “breaks the site” is not true. Analytics is instrumentation for the site owner. The page renders identically without it.

First-party and third-party

This distinction matters more than the category labels.

A first-party cookie is set by the domain in your address bar. Reading a news site, a cookie from that news site is first-party. It can only be read by that site.

A third-party cookie is set by a different domain whose content is embedded in the page — an ad slot, an embedded video, a tracking pixel. Because that same network’s code is embedded on thousands of sites, it sees the same cookie on all of them and can assemble the list of pages you have visited.

That is the tracking mechanism. It is not sophisticated; it simply works at scale.

Safari and Firefox block third-party cookies by default and have for years. Chrome has restricted them, deprecated them in stages, and publicly changed course on full removal more than once, so the state of play in Chrome depends on which version and which experiment group you are in.

Most banners are designed so “Accept All” is one click and refusing is three. Two shortcuts:

Look for “Reject All”. Under UK and EU rules, refusing should be as easy as accepting, so a reject button is usually present even when it is styled as plain text rather than a button.

Otherwise, open preferences and toggle everything off except necessary. The toggles are grouped; it is one tap each.

Be sceptical of the “legitimate interest” tab. Some banners allow analytics and advertising under a legitimate-interest claim with the toggles pre-enabled, sitting behind a second tab you did not see. If a banner has a tab labelled Legitimate interest or Vendors, check it before clicking save.

Setting it once instead of per-site

Browser settings do more than any individual banner choice, because they apply regardless of what the banner says.

  • Chrome: Settings → Privacy and security → Third-party cookies → Block third-party cookies.
  • Firefox: Settings → Privacy & Security → Enhanced Tracking Protection → Strict.
  • Safari: Settings → Privacy → Prevent cross-site tracking (on by default).
  • Edge: Settings → Privacy, search and services → Tracking prevention → Strict.

Strict modes occasionally break single sign-on flows and embedded payment widgets. When a login loops endlessly, this is the first setting to relax for that one site.

One consequence worth knowing in advance: the more aggressively you block cookies, the more CAPTCHAs you will see, because the scoring systems rely on exactly this history to recognise you. That is covered in why CAPTCHAs single some people out.

What cookies cannot do, and what replaced them

Cookies cannot read your files, access other sites’ cookies, or persist after you delete them.

But blocking them does not make you unidentifiable. The industry moved on: browser fingerprinting combines screen size, fonts, time zone, graphics behaviour and dozens of other properties into an identifier that needs no stored data at all. Hashed email addresses, used when you log in anywhere, work across devices in a way cookies never could. Server-side tracking moves the collection off your browser entirely.

Rejecting cookies is still worth doing. It reduces the easiest, cheapest and most widespread form of tracking. It just is not the whole of the problem, and anyone telling you it is has something to sell.

Realistic expectations

Rejecting non-essential cookies costs you nothing you will notice. Ads become less relevant, which some people miss and most do not. Sites continue to work.

Clearing cookies is a different matter and should be done per-site rather than globally, because a full clear signs you out of everything and discards the preferences you chose. In Chrome, click the icon left of the address bar → Cookies and site data → Manage on-device site data for the current site only.

If you clear cookies hoping to fix a slow browser, that is the wrong lever — clearing a cache and clearing cookies do different things, and only one of them signs you out of your bank.

Frequently asked questions

Does deleting cookies log me out of everything?
Yes, that is exactly what happens. Your session cookie is what tells each site you are already signed in, so clearing cookies site-wide means signing back into every service. Most browsers let you clear cookies for one site only, which is usually what you want.
Are cookies dangerous?
Not in themselves. A cookie is inert text and cannot run code or carry a virus. The privacy concern is tracking across sites, and the security concern is a stolen session cookie letting someone into your account, which is why public-computer sign-outs matter.
Why do cookie banners keep appearing on the same site?
Because your choice is itself recorded in a cookie. If you block cookies, browse privately, or clear them regularly, the site has no record of your preference and asks again. It is an irony nobody has resolved.
What are third-party cookies and are they being removed?
Cookies set by a domain other than the one in your address bar, typically ad networks embedded in the page. Safari and Firefox block them by default and have done for years; Chrome has restricted them while retreating from a full removal more than once.
Does rejecting cookies stop ads?
No. You will see the same number of ads, just less specifically targeted at you. Blocking advertising entirely requires an ad blocker, which works differently and operates on the content of the page rather than on stored data.

All Explainers guides