Privacy policy and cookie policy – what must a website provide information about?

A website often needs to handle two parallel information issues: personal data under the GDPR and cookies under the rules on electronic communication. The documents should be coordinated but not mixed to such an extent that the user does not understand what applies.

The essentials in brief

  • The privacy policy must provide the information required by, among other things, GDPR Articles 13 and 14.
  • The Swedish Post and Telecom Authority (PTS) requires information on which cookies are used and for what purposes.
  • As a general rule, non-essential cookies require consent.
  • The user must be able to withdraw their consent.
  • Third-party cookies, storage duration, and what information is collected must be clearly described.
Personal data Purpose, legal basis, recipients, storage, and rights.
Cookies Name/category, purpose, storage duration, and third parties.
Consent Choice must be voluntary, informed, and possible to withdraw.
CMP/banner The technical solution must reflect the choices described in the policy.
Updates Inventory cookies and processing activities when the website or tools are changed.

What should the privacy policy contain?

The Swedish Authority for Privacy Protection (IMY) states that data subjects should receive clear information about which personal data is processed, why it is used, how long it is stored, and what rights exist. Articles 13 and 14 contain more detailed requirements depending on how the data is collected.

Cookie policy and PTS information requirements

PTS states that the website must inform users about the purposes of the cookies, which cookies are used, whether they come from third parties, how long they are stored, what information they collect, and that consent can be withdrawn.

Necessary and non-essential cookies

Necessary cookies required for a service that the user explicitly requests may be exempt from the consent requirement. Statistics, advertising, and similar are not automatically 'necessary' just because the business wants to use them.

Documents and technology must align

A correct text is not enough if the cookie banner loads tracking before consent is given or if the option to withdraw is missing. Therefore, the policy should be supplemented with an actual cookie inventory and regular checks of the website's behavior.

Common mistakes

  • Copying a general privacy policy without mapping actual processing activities.
  • Labeling analytics or marketing cookies as 'necessary'.
  • The cookie policy not matching the scripts that are actually loaded.
  • Making it easier to accept than to refuse/withdraw.
  • Not updating policies when new apps or marketing tools are added.

Frequently asked questions

Are both a privacy policy and a cookie policy needed?

Often, yes. They can be combined, but the information about personal data processing and cookies must still be clear and complete.

Must all cookies have consent?

No. Necessary cookies may be exempt, but as a general rule, non-essential cookies require consent.

What should be stated about third-party cookies?

It should be clear that third parties are used, for what purpose, what data is involved, and how long the cookies are stored.

Does the privacy policy have to use legal jargon?

No. The GDPR requires that the information be concise, clear, transparent, intelligible, and easily accessible.

Privacy Policy & Cookie Policy Template Package

The template package contains policy texts and a cookie inventory that can be adapted to the website's actual processing activities and tools.

View the template at Mallbutiken.se →

Read also

Sources and further reading

Last updated: October 5, 2026. This article provides general information and does not replace individual legal advice.

Back to blog