First-Party Cookies

First-party cookies are cookies whose domain belongs to the context of the website being visited. They can support sign-in, language preferences, shopping baskets, or first-party audience measurement. Whether a cookie is technically treated as first party depends on the site and domain context, not on which company developed the software involved.

First party does not automatically mean necessary or privacy-friendly. A cookie in the site's own domain context may still enable tracking and pass data to service providers. Purpose, access, data flows, retention, and user choices determine the legal and ethical assessment. Security attributes and minimal lifetimes should also be chosen deliberately for functional cookies.

  • Belong to the domain context of the visited site
  • Common for sign-in, baskets, and preferences
  • Can still enable tracking
  • Not automatically necessary or consent-free
  • Assess purpose, access, and lifetime

Frequently asked questions

A first-party cookie is a cookie in the domain context of the website a user is currently visiting.

No. Purpose, data access, recipients, and retention matter, not merely the technical first-party classification.