Cookie Policy Generator
Generate a cookie policy page listing every cookie, its purpose, provider and retention. Covers GDPR, ePrivacy and CCPA disclosure. Free, no signup.
Last reviewed by the Radiatus Cloud team
Cookie Policy Generator
Create a standard cookie policy for GDPR/ePrivacy Directive compliance.
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
What a cookie policy has to contain
A cookie policy is the page your banner links to. Regulators expect it to be specific rather than generic: for each cookie you set, a visitor should be able to see its name, who sets it, what it does, how long it lasts, and which category it falls into. A page that says "we use cookies to improve your experience" and stops there does not meet the transparency requirements of GDPR Articles 13 and 14.
This generator produces a structured policy with a real cookie table rather than prose. You enter the cookies your site actually sets, grouped by category, and the tool renders a formatted table plus the surrounding sections regulators look for: what cookies are, the legal basis you rely on for each category, how to withdraw consent, how to control cookies at the browser level, and how to contact you about it.
Find out what you actually set first
The single most common failure is a policy that describes cookies the site does not use, or omits ones it does. Before generating, open your browser's developer tools, go to the Application or Storage panel, clear all cookies for your domain, then load your site and accept everything. What appears is your real cookie inventory. Third-party embeds are the usual surprise: an embedded video, a map, a chat widget or a font provider can each set cookies you never chose.
Legal basis per category
Strictly necessary cookies do not require consent, because they are exempt under the ePrivacy Directive's Article 5(3) carve-out for cookies strictly necessary to deliver a service the user requested. Everything else, including analytics, does require prior consent in the EU and UK. The generated policy states the basis per category rather than applying one blanket claim, which is what makes it defensible.
Keep it current
A cookie policy is a living document. Every new marketing tag, embed or A/B testing tool changes the inventory. The generated page includes a visible last-updated date, and it is worth re-auditing whenever you add a third-party script. An out-of-date policy is worse than a thin one, because it demonstrates you had a process and stopped following it.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Do I need a cookie policy if I only use analytics?
Yes. Analytics cookies are non-essential, which triggers both the consent requirement and the transparency requirement. The policy can be short, but it needs to name the cookies, say who sets them, and explain their retention and purpose.
Can the cookie policy live inside my privacy policy?
It can, and many small sites do exactly that. The requirement is that the information is accessible and clear, not that it sits on a dedicated URL. A separate page is usually easier to keep current and easier to link from the banner, which is why this generator produces a standalone page.
How do I find every cookie my site sets?
Clear cookies for your domain, reload the site, accept all consent options, then inspect the Application or Storage panel in browser developer tools. Repeat on pages with embeds such as video, maps or chat, because those set cookies that never appear on your homepage.
How often should the policy be updated?
Whenever your cookie inventory changes, and as a routine check every six to twelve months. Adding a single marketing pixel changes what you must disclose. The generated page carries a last-updated date so visitors and regulators can see when you last checked.
Does a cookie policy satisfy CCPA?
Not on its own. California requires disclosure of categories of personal information sold or shared plus a Do Not Sell or Share mechanism. The generator includes an optional CCPA section covering that disclosure, but you also need the opt-out control itself, which belongs in your banner or footer.
Privacy & Security
Local generation.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.