How a cookie works
A website asks the browser to remember a short piece of text — a name, a value and an expiry date. The browser stores it and hands it back automatically every time it makes a request to that site. That is the whole mechanism. Nothing is installed, nothing runs, and a cookie cannot read files on the device or watch what happens in another application.
What varies is who set it and how long it lasts. A cookie set by the site in the address bar is a first-party cookie; one set by another domain whose script is embedded in the page is a third-party cookie. One that vanishes when the browser closes is a session cookie; one with a future expiry date is a persistent cookie. Those two distinctions, source and lifetime, decide almost everything else about how a cookie behaves.
Why cookies matter
Without them the web forgets you between clicks. A shopping basket empties when you open a product page, a login has to be repeated on every screen, and a language preference never sticks. Those are the cookies nobody argues about, because the site simply will not function without them.
The contested ones are the cookies that exist for measurement and advertising: the identifier that lets analytics recognise a returning visitor as the same person, the value that ties a purchase back to the ad that produced it. They are useful, they are not necessary for the page to load, and that difference is exactly what the law hangs on. It is also why browsers have been steadily shortening how long some cookies survive.
Common mistakes with cookies
The first is a cookie policy written from a template that lists cookies the site does not set and omits the ones it does. That is worse than no policy at all, because it is a documented, checkable inaccuracy. Audit what your site actually stores rather than copying a competitor.
The second is assuming a cookie equals a person. It identifies a browser on one device. The same customer on a phone and a laptop is two cookies, and a shared office computer can be several people behind one. The third is loading advertising and analytics cookies before anyone has agreed to them, then showing a banner that pretends to ask.
What to do about them
Open your own site in a private window, look at the storage panel in the browser’s developer tools, and list what appears before you touch anything and after you accept a banner. Most owners are surprised, usually by a plugin or an embedded video player nobody remembered adding.
Then sort that list into cookies the site needs to work and cookies that exist for marketing, block the second group until consent is given, and make the cookie table in your policy match the list exactly. If you run tags through Google Tag Manager, that is where the blocking is easiest to enforce, because every tag sits in one place instead of being scattered through the theme.