Cookie Policy Drafting · GDPR · UK GDPR · DPDPA

Cookie Policy Drafting for Websites, Apps, and Platforms

Custom cookie policies and consent notices drafted by lawyers, compliant with the GDPR, the UK GDPR, India’s DPDPA, and California’s CCPA. Drafted alongside your privacy policy and terms as a consistent set. Fixed fees, 24 to 48 hours.

Tell us about your platform. Get a fixed-fee quote in under 2 hours.

Share what your website or app does, what cookies and trackers it uses, and which jurisdictions your users are in. A contract lawyer from our team will assess which documents you need, cookie policy, consent notice, privacy policy, and respond with a precise quote and timeline.

Most cookie policies are drafted in 24 to 48 hours. A complete data pack (cookie policy, privacy policy, consent) in 3 to 5 days.

Or reach us directly
WhatsApp +91 8004800100 · contact@mylegalpal.com



    GDPR · EU
    UK GDPR & PECR
    DPDPA · India
    CCPA / CPRA · US
    Privacy Act · Australia
    PDPA · Singapore

    A cookie policy is where a lot of privacy law actually bites.

    Cookies sound trivial, but they are one of the most heavily regulated parts of running a website. Under the GDPR and the UK GDPR, non-essential cookies, analytics, marketing, advertising, require the user’s prior, informed consent, obtained through a compliant consent banner, along with a cookie policy that explains what cookies you use and why. Get this wrong and you carry real regulatory exposure, exactly the kind that data-protection authorities have started enforcing.

    My Legal Pal drafts cookie policies and consent notices for websites, mobile apps, SaaS platforms, and digital services that comply with the rules that apply to you: the GDPR, the UK GDPR and PECR, India’s DPDPA, California’s CCPA, and equivalent frameworks. Drafted by a contract lawyer for the cookies and trackers your platform actually uses, not a generic template that lists cookies you may not even set.

    A cookie policy does not stand alone. It works with your privacy policy and your consent banner, and the three must align. We draft them as a consistent set so they reference each other correctly and your consent mechanism actually does what the policy says.

    A cookie banner is not consent. Real consent means the user understood the choice, and declining was as easy as accepting. A policy that does not match the banner is a gap a regulator will find.

    How we draft your cookie policy

    From a cookie audit to launch-ready documents, with internal review at every stage.

    Cookie audit

    What cookies and trackers your site actually sets, first-party and third-party, and what each does. The step templates skip.

    Applicable law

    Which rules bind you, GDPR, UK GDPR and PECR, DPDPA, CCPA, based on where your users are.

    Drafting by a lawyer

    A cookie policy that lists your real cookies by category, purpose, and duration, with the consent position for each.

    Consent alignment

    We make sure the policy matches your consent banner and your privacy policy, so the three work together.

    Delivery and walkthrough

    Plain-language summary of what you must do, banner behaviour, opt-out, to stay compliant, not just publish.

    Revisions and launch

    Adjusted to your feedback and delivered ready to publish and to satisfy app store privacy disclosures.

    What do you need a cookie policy for?

    The platform and the regulation decide what your cookie policy and consent must cover. We draft for each of these.

    Website

    Cookie policy and consent for a content or business site.

    E-commerce Store

    Analytics, marketing, and retargeting cookie disclosure.

    SaaS Platform

    Product analytics and functional cookie consent.

    Mobile App

    SDK and tracker disclosure for app store privacy labels.

    GDPR Cookie Consent

    Prior opt-in consent banner and policy for EU and UK.

    DPDPA Cookie Notice

    India’s consent and notice requirements for trackers.

    CCPA Opt-Out

    Do-not-sell and Global Privacy Control handling.

    Consent Banner Copy

    The wording and structure of a compliant banner.

    Complete Data Pack

    Cookie policy, privacy policy, and consent as one set.

    What a compliant cookie policy must actually contain.

    A generated template lists generic cookie categories. A compliant policy documents the cookies your site really sets and implements the consent rules that apply to you. At minimum, ours address the following.

    The cookies you actually use

    A real inventory: the specific cookies and trackers your site sets, first-party and third-party, listed by name, provider, category, purpose, and duration. Regulators expect specifics, not a generic list of cookies you may not even use.

    Cookie categories and consent status

    Strictly necessary, functional, analytics, and marketing cookies, and crucially, which run without consent (necessary only) and which require prior opt-in consent (everything else). Mislabelling an analytics cookie as necessary is a common and serious error.

    First-party and third-party distinction

    Which cookies you set and which are set by third parties (Google Analytics, ad networks, chat tools, embeds). This affects who controls the data and how users exercise their rights, and templates rarely get it right.

    The consent mechanism

    How consent is obtained, recorded, and withdrawn. Under the GDPR and UK GDPR, consent must be prior, informed, freely given, and as easy to withdraw as to give. The policy must describe a banner that actually does this, not a “by using this site you agree” notice, which is not valid consent.

    Third-party tracker disclosure

    Analytics, advertising pixels, social embeds, and SDKs each set their own cookies and often transfer data internationally. The policy must disclose them and, for apps, feed the app store privacy labels correctly.

    How users control cookies

    Clear instructions for managing, blocking, and deleting cookies through the consent tool and the browser, plus how to opt out of analytics and honour Do Not Track and Global Privacy Control signals where they apply.

    Relationship with the privacy policy

    The cookie policy handles the on-device technologies; the privacy policy handles personal data more broadly. The two must reference each other and never contradict. We draft them as a consistent set.

    Cookie policy questions people actually ask.

    Is a cookie policy legally required?

    If your site uses non-essential cookies, effectively any site with analytics, marketing, or embedded third-party content, then yes. Under the GDPR, the UK GDPR and PECR, and equivalent laws, you must both obtain prior consent for non-essential cookies through a compliant banner and provide a cookie policy explaining what cookies you use. A site with only strictly necessary cookies has lighter obligations, but almost no commercial site is in that category.

    What is the difference between a cookie policy and a privacy policy?

    A cookie policy explains the specific technologies that store and read data on a user’s device: what cookies you set, their purpose, duration, and how to control them. A privacy policy is the broader document covering all personal data you handle, the lawful basis, rights, sharing, and retention. They are separate but linked, and most sites need both. We draft them together.

    Isn’t a cookie banner enough on its own?

    No. A banner without a policy behind it, or a banner that only offers “accept” with no easy way to decline, is not compliant consent under the GDPR and UK GDPR. Consent must be prior (before non-essential cookies fire), informed (the policy explains what they are), and freely given (declining is as easy as accepting). The banner and the cookie policy have to work together, which is exactly what we draft.

    Can I use a free cookie policy generator?

    A generator produces a generic list of cookies that may bear no relation to what your site actually sets, and it cannot align with your specific consent banner. For a simple site it may be tolerable; for any platform running analytics, advertising, or third-party embeds, a generated policy that misstates your cookies or mislabels their consent status is a compliance gap a regulator or a customer’s privacy team will find.

    Do I need consent for Google Analytics?

    In the EU and the UK, yes. Analytics cookies are non-essential, so under the GDPR and UK GDPR they require prior opt-in consent before they fire. This is why a compliant setup blocks Analytics until the user accepts, rather than loading it on arrival. We draft the policy and describe the consent behaviour that makes this compliant.

    Does my mobile app need a cookie or tracker policy?

    Yes. Apps use SDKs and trackers that behave like cookies, and both Apple and Google require you to disclose them accurately in your privacy labels and Data Safety form. A cookie and tracker policy that matches your actual SDKs supports those disclosures and reduces the risk of app store rejection.

    Cookie compliance by regulation.

    Cookie rules differ by region. The regulation that binds you depends on where your users are, and most platforms with any reach need to satisfy more than one.

    GDPR and ePrivacy (European Union)

    The EU sets the strictest standard. The ePrivacy Directive requires prior consent for non-essential cookies, and the GDPR governs the personal data they collect. Consent must be opt-in, granular, never pre-ticked, and as easy to withdraw as to give. We draft policies and consent copy to this standard.

    UK GDPR and PECR (United Kingdom)

    The UK applies the UK GDPR alongside the Privacy and Electronic Communications Regulations (PECR), enforced by the Information Commissioner’s Office (ICO). The requirements closely track the EU but with UK-specific guidance. We draft UK-facing cookie policies to this framework.

    DPDPA (India)

    India’s Digital Personal Data Protection Act, 2023 is consent-centric. As the rules take shape, cookies that collect personal data engage the notice-and-consent framework, and we draft DPDPA-aware cookie notices for businesses serving users in India.

    CCPA and CPRA (United States)

    California focuses on the right to opt out of the sale or sharing of personal information, which reaches many advertising and analytics cookies, and requires honouring the Global Privacy Control signal. We draft cookie policies and opt-out mechanisms for California and the broader US state landscape.

    What clients say

    Cookie policy and consent banner drafted together for our EU launch. The banner actually blocked analytics until consent, which our old generated policy never did. Passed a customer’s privacy review clean.
    Ethan ClarkeCo-founder, B2B SaaS · Toronto
    Our app’s tracker disclosures never matched the Play Store Data Safety form. They drafted a cookie and SDK policy that lined up with what we actually use. Approved next submission.
    Daniel WongFounder, Fintech Startup · Singapore
    E-commerce cookie policy covering our analytics and retargeting pixels across the EU and UK. The consent categories were done properly, granular, not a single accept button.
    Priya MenonFounder, D2C Brand · Bangalore
    GDPR and UK GDPR cookie policy with a PECR-compliant banner. Our ICO exposure went from a real worry to negligible, and it paired correctly with the privacy policy.
    James WhitmoreHead of Commercial · London
    Cookie policy and consent banner drafted together for our EU launch. The banner actually blocked analytics until consent, which our old generated policy never did. Passed a customer’s privacy review clean.
    Ethan ClarkeCo-founder, B2B SaaS · Toronto
    Our app’s tracker disclosures never matched the Play Store Data Safety form. They drafted a cookie and SDK policy that lined up with what we actually use. Approved next submission.
    Daniel WongFounder, Fintech Startup · Singapore
    E-commerce cookie policy covering our analytics and retargeting pixels across the EU and UK. The consent categories were done properly, granular, not a single accept button.
    Priya MenonFounder, D2C Brand · Bangalore
    GDPR and UK GDPR cookie policy with a PECR-compliant banner. Our ICO exposure went from a real worry to negligible, and it paired correctly with the privacy policy.
    James WhitmoreHead of Commercial · London

    Related data and platform services

    The documents most digital businesses need alongside their cookie policy.

    The broader data-disclosure document.

    The contract every user agrees to.

    Protect confidential information you share.

    Enterprise, vendor, and DPA agreements.

    Frequently asked

    Is a cookie policy legally required?
    If your site uses non-essential cookies (analytics, marketing, third-party embeds), yes. Under the GDPR, UK GDPR and PECR, and equivalent laws, you must obtain prior consent through a compliant banner and provide a cookie policy explaining what cookies you use. Almost every commercial site falls into this category.
    What is the difference between a cookie policy and a privacy policy?
    A cookie policy explains the specific technologies that store and read data on a user’s device. A privacy policy is the broader document covering all personal data you handle, the lawful basis, rights, and retention. They are separate but linked, and most sites need both. We draft them together so they align.
    Isn’t a cookie banner enough on its own?
    No. A banner without a policy behind it, or one that only offers accept with no easy decline, is not compliant consent under the GDPR and UK GDPR. Consent must be prior, informed, and freely given. The banner and the cookie policy have to work together.
    Can I use a free cookie policy generator?
    A generator produces a generic list of cookies that may bear no relation to what your site actually sets, and it cannot align with your specific consent banner. For any platform running analytics, advertising, or third-party embeds, a generated policy that misstates your cookies is a compliance gap a regulator or a customer’s privacy team will find.
    Do I need consent for Google Analytics?
    In the EU and the UK, yes. Analytics cookies are non-essential, so under the GDPR and UK GDPR they require prior opt-in consent before they fire. A compliant setup blocks Analytics until the user accepts, rather than loading it on arrival.
    Does my mobile app need a cookie or tracker policy?
    Yes. Apps use SDKs and trackers that behave like cookies, and both Apple and Google require you to disclose them accurately in your privacy labels and Data Safety form. A policy that matches your actual SDKs supports those disclosures and reduces the risk of app store rejection.
    How long does it take to draft a cookie policy?
    A standard cookie policy is drafted in 24 to 48 hours. With a consent banner and a matching privacy policy as a set, 3 to 5 days. We confirm the timeline in your quote.
    Who drafts the cookie policy?
    A contract lawyer from our team with experience in data-protection and technology law for your jurisdiction. Every policy is reviewed for genuine compliance and for consistency with your privacy policy and consent banner before delivery.
    Prakhar Rai

    Prakhar Rai | Founder and Advocate

    About the founder

    Prakhar Rai is an advocate enrolled with the Bar Council of India and the founder of My Legal Pal. An alumnus of the National Law School of India University (NLSIU), Bangalore, with a Master of Business Laws, Prakhar has 10+ years of experience advising startups, technology companies, SMEs, and individual entrepreneurs across India, the UAE, the UK, and Southeast Asia.

    His practice focuses on technology and data-protection law, with particular depth in privacy and cookie compliance across the GDPR, the UK GDPR, India’s DPDPA, and the US state-privacy landscape. My Legal Pal’s cookie and privacy documentation is led by Prakhar and delivered by a team of qualified lawyers experienced in data protection and platform law.

    Get a cookie policy drafted for your platform.

    GDPR, UK GDPR, DPDPA, and CCPA aware. For websites, apps, and platforms. Drafted with a compliant consent banner and paired with your privacy policy. Fixed fees, 24 to 48 hours for standard policies.

    Call +91 8004800100