Cookie policy template, PECR ready.
PECR, the UK's cookie and tracking rules, is blunt: ask before anything non-essential tracks a visitor, and explain what you set. The cookie policy is where that explanation lives.
This template lists your cookies by category, separates the strictly necessary from the optional, and pairs with your consent banner so the two tell the same story.
The moments this document comes up.
- You add analytics, a chat widget, or any third-party script to your site.
- Your consent banner promises a cookie policy that does not exist yet.
- A privacy-conscious customer or a security review asks how tracking is disclosed.
- You switch analytics tools and the old policy still names the previous one.
What the template covers.
The sections below mirror the document the generator drafts. Every template is a starting point, not legal advice, and says so on its face.
01
What cookies are
02
Cookies we set
03
Strictly necessary cookies
04
Analytics cookies
05
Managing cookies
Drafted from choices you make.
A downloaded template hands you someone else's prose with holes in it. Here the document is generated from a settings sheet, so the wording follows your answers, and changing an answer later regenerates the parts it touches.
COOKIE POLICY
SETTINGS- JurisdictionEngland & Wales
- Analytics providerPostHog
- Consent bannerIn use
- Third-party embedsNone
After generating, the document opens in the editor like any other: edits arrive as tracked changes you accept or reject, compliance checks run against real rulepacks, and exports come out as print-ready PDF or DOCX your lawyer can redline. What a compliance check actually does →
Fair questions.
Do I need a cookie banner as well as a policy?
If you set any non-essential cookies (analytics is the usual one), yes: PECR requires consent before those are set, and a banner is how consent is collected. The policy is the full explanation the banner links to. If you genuinely set only strictly necessary cookies, you need the policy but not a consent banner.
Can I run analytics without consent?
Under PECR as enforced by the ICO, analytics cookies are not strictly necessary, so they need prior consent. Some teams switch to cookieless analytics to reduce the consent surface; if you do, the policy should say so rather than list cookies you no longer set.
What happens when I add a new tool that sets cookies?
The policy is stale from that moment, which is the failure mode of every hand-maintained cookie policy. In StartupDocs you update the setting, regenerate the section, and re-run the PECR rulepack so the policy, the banner, and reality agree again.
Related templates.
Privacy policy
UK GDPR privacy notice for your website and product: what you collect, why, and users' rights.
Terms of service
The terms your site and product run on: acceptable use, IP, liability, and governing law.
Data processing agreement
The Article 28 DPA the first serious customer will ask for before signing.
Draft your cookie policy this week.
It is one of the first-week five: drafted, checked, and exported inside the 7-day free trial. Pay and not have your documents? One email within 30 days refunds every penny, and every export stays yours.