22 JUL 2026
Cookie policy and privacy policy: what you really need and who for
“I’ve got one, I copied it from another site”: it’s the most frequent answer when we ask about privacy and cookies, and it’s also the most dangerous. Cookie policy or privacy policy are two different documents, with different purposes, and one doesn’t replace the other — while a version pasted from the web, with the wrong data controller’s name and cookies you don’t use, is often worse than nothing. Let’s look at what they really are, what each must contain, and when you need one, the other or — almost always — both.
Two documents, two purposes.
The privacy policy — in Italian informativa sulla privacy — concerns all the personal data you process: who collects it, which data, for what purpose, for how long, to whom it’s disclosed and with what rights for the data subject. It’s required by the GDPR every time you process a personal datum, even just the name and email left in a contact form. If you collect anything, you need it.
The cookie policy is a more specific document: it concerns the site’s cookies and other tracking tools. It lists which cookies you use, whose they are, what they’re for and how long they last. It’s needed when the site installs cookies that go beyond the strictly technical ones — analytics or advertising, for example — and it must be accompanied by the consent banner. In practice, the privacy policy is the umbrella; the cookie policy is the chapter dedicated to trackers.
What the privacy policy must contain.
A well-made privacy notice answers, in readable form, precise questions: who the data controller is, with a real contact; what data you collect and how; for what purposes and on what legal basis; how long you keep it; to whom you disclose it or whether you transfer it outside the EU; and what rights the person can exercise — access, rectification, erasure, objection. These are the contents the GDPR sets out in Articles 13 and 14.
The key word is “true.” A notice that names a controller who isn’t you, or describes processing you don’t carry out, doesn’t protect you: it exposes you, because it states what’s false. Better a few exact lines about your real case than ten generic pages copied elsewhere. It’s a document that speaks about you: it has to tell the truth about you.
What the cookie policy must contain (and the banner).
The cookie policy transparently lists the site’s trackers: name, owner, purpose, duration and — for third-party cookies — the link to the provider’s notice. But the document alone isn’t enough: if you use non-technical cookies, you need a banner that blocks them before consent and lets people refuse as easily as they accept. The Garante’s 2021 guidelines and the European taskforce are clear on this point.
The classic mistake is to have a nice cookie policy and a fake banner, which loads analytics and advertising from the first instant and asks permission after the fact. In that case the document becomes the written proof of what you should have done and don’t. Cookie policy and banner are two sides of the same obligation: to describe and, before that, to respect the choice.
Cookie policy or privacy policy: which you need (usually both).
Let’s try to answer the practical question. A site with a simple contact form and no cookies beyond the technical ones needs at least the privacy policy. The moment you add Google Analytics, advertising pixels or embedded videos, non-technical cookies come into play: then you also need the cookie policy and the consent banner. Since almost every real site uses at least one tracker, in practice the answer is: almost always both.
The shortcut of copying one from the web fails twice. It gets the controller wrong, so it states what’s false; and it lists cookies you don’t have and omits ones you do, so it’s useless exactly where it should protect you. And if your site also falls under accessibility obligations, the whole legal area has to be reviewed with the same seriousness: tailored documents, not recycled templates.
Check your site’s cookies and GDPR compliance for free →
EAA compliance: an accessible, compliant site, legal area included →
It isn’t bureaucracy: it’s trust (and law).
It’s easy to experience privacy and cookie policies as an annoying tax to discharge by copying the first template. But they’re also a signal of seriousness towards your visitors: stating clearly what data you collect and why builds trust exactly where the visitor is most wary. A site transparent about data sells better than one that hides the matter under a deceptive banner.
When we build a site, we write the notices on your real case — the true controller, the actual cookies, the processing you genuinely do — and we connect them to a banner that respects the choice. It isn’t the glamorous part of a project, but it’s the one that, on the day of an inspection or an awkward question, makes the difference between a calm answer and a problem.
Read also: Google Analytics 4 and privacy in the EU, are you compliant? →
Sources.
The figures and claims in this article come from here. These are primary sources, not summaries: open them and check for yourself.
- Garante Privacy — cookie guidelinesItaly’s rules on cookies and banners: when consent is needed and how it must be collected.
- GDPR Regulation 2016/679 — EUR-LexArticles 13 and 14 set out what the privacy notice must contain: controller, purposes, bases, timeframes, rights.
- EDPB — cookie banner taskforce reportWhat Europe’s regulators consider improper in banners: the common frame beyond national rules.
- Garante Privacy — official websiteThe Italian authority with templates, FAQs and rulings on notices, cookies and data subjects’ rights.
Let’s talk about your website.
Free analysis of your current website; a fixed quote within 24 hours of the call.