In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
We list concepts and examples of cookie types, how to classify them in your documentation, Privacy Policy, Legal Bases of LGPD, etc.
In effect since August 2020, the General Data Protection Law (LGPD) will require a drastic change in the operations of companies that use data from their customers and users. Starting from August, data can only be used if it complies with the principles of LGPD - the so-called Legal Bases of LGPD - and is transparently and objectively consented to.
This will cause numerous websites to not only change their privacy policies and the information their cookies store but also various processes and ways of handling people's data. In this article, we will see how the use of cookies will be affected and how your company can continue to use them in a way that respects the law.
Cookies are small text files that can store what the user is doing for a certain period. Some cookies store your browsing history, as well as logins and passwords. It is because of them that you can access your Facebook account without having to enter your email every time, as the browser (using cookies) does it for you.
In addition to various functional aspects, cookies also provide excellent service in well-known systems such as Google Drive, for example. Thanks to the cookie's ability to store information, we can work on our texts, spreadsheets, presentations, even offline, and when we reconnect, our work is not lost.
First-Party and Third-Party Cookies, terms used to refer to cookies generated by the website owner or by third parties.
First-Party Cookies are those generated by the website's own domain. From the website owner's perspective, they are the information that visitors generate during their browsing session.
Many website builders or e-commerce services use cookies to provide these functionalities to their customers. So, don't be surprised if you see that your website triggers first-party cookies without notifying you. They have practically become a "market standard."
Regarding the cookie's storage capacity, this information is indeed "generated" by our browsing, and cookies are one way to store it. How does it work?
When the system generates a cookie, it has an identifier that stores the information in the company's database as well as in the visitor's browser. A very simple example is when we access a news portal and encounter the famous paywall message, "you have reached the limit of daily free articles, subscribe to our services."
How does it know that you have already read a specific article?
Simple, through the cookies it stores in your browser for each article read.
(Does this mean that if I clear my cookies or browse anonymously, I can read freely?... Wait, wait... do you think they haven't thought about that too? 😉)
On the other hand, Third-Party Cookies are cookies from third-party sources external to the website's domain. In other words, they are cookies from third-party companies that also set cookies to record information about their visitors.
Most of the time, these third-party cookies should (or at least should) all be authorized to be present. Otherwise, the website owner may be surprised by the number of entities "sucking" data from their site(s).
Here are some common examples of services that use cookies:
5th Article 5 of the Lei Geral de Proteção de Dados - LGPD provides legal definitions of terms that you will come across frequently when researching the regulation. Among these definitions is that of personal data:
**"personal data: **information related to an identified or identifiable natural person."
We have the last two words in italic because they are the most important for the subject at hand.
Not all data that cookies carry is personal. For example, your visit to our website is not personal data. However, once you register your email on a site like Facebook, you are identifying yourself. Therefore, this is personal data that can be collected by a cookie.
And it is from there that the LGPD starts to affect how your data is used by websites and how your website handles user data.
The problem with the use of cookies arises when it is not known what data is being collected, for what purposes, and by whom. It is a matter of privacy and transparency, values that are the foundation of the LGPD.
The use of cookies that violates the LGPD will be penalized, and among the penalties are expensive fines.
All websites that process data, specifically those that use First or Third Party Cookies. If your website processes personal data or data that, when combined, can identify an individual person, it needs even more careful review of how this information is processed.
But, should this be listed in the Cookie policy or the Privacy Policy?
That depends on the company's choice to differentiate these aspects, as it may be a different approach based on the business model. Some companies address regulations for their "digital" data in the Cookie policy and the "offline" data in the Privacy Policy. However, it varies greatly, so we recommend consulting an expert who can analyze your business model and all the data flows and mappings of your company to understand the need for such differentiation.
To ensure that a website is compliant with LGPD when using cookies, there are certain principles to consider, especially if you have a valid "reason" or legal basis that supports the use of data and cookies on your site. For many, this legal basis is "Consent."
What does that mean?
In order for companies to process personal data of data subjects (individuals like you and me), they now need to have a strong legal basis provided by the law (LGPD). This "permission" is known as the Legal Bases of LGPD.
Therefore, while consent is not the only legal basis that allows companies to use data, it plays a crucial role when it comes to cookies. This is why cookie banners serve an essential purpose: notifying and informing visitors, as well as correctly collecting and storing individual consents.
Regardless of the information carried by a cookie, it should have been consented to by the user. But what makes consent valid? And what should be communicated to the user?
The user must be clearly and objectively informed about the purpose for which their data will be collected. Additionally, they must give their explicit consent, or opt-in, by clicking on a banner.
To automate this process, Cookie Notices or Cookie Banners are used.
They serve to fulfill the sixth principle of the law: transparency.
The Cookie Banner is that little pop-up window you can see on most websites nowadays, including when you entered our blog. This banner communicates that the site uses cookies. Ours says the following:
"Take control of your privacy. Our site uses cookies to enhance navigation." Then, there are two links: Privacy Policy and Terms of Use. Right after, there's a button for you to view your privacy options and an "accept" button, indicating that you agree to the use of your data.
The cookie banner, or cookie notice, which is a feature of the Consent Management Platform, serves to explicitly state the practice (use of cookies), the purpose (enhancing navigation), and offer users the possibility to fully or partially agree to the data processing.
This is what LGPD requires: transparency and objectivity, without complications.
In this way, the use of cookies is permitted and can greatly assist in your business operations.
GDPR, the European data protection regulation, has a limit of twelve months for the use of a cookie. However, LGPD does not establish an "expiration" deadline.
But one of the principles for data processing is necessity. According to the regulation, data can only be retained for the time necessary to fulfill its purpose. If a cookie carries information that no longer needs to be used, it becomes invalid under the law.
Additionally, there are various initiatives by browsers—especially Apple's Safari, which automatically blocks third-party cookies. This "trend," as it is known in the market, has been widely discussed since 2015, even before GDPR. However, it is always being rethought or adapted because the entire advertising and analytics market relies heavily on the widespread use of cookies.
Thus, any changes in this regard will indeed be revolutionary and will bring many changes to the ecosystem as a whole.
It is important that your privacy policy includes a detailed and specific explanation of how your website uses cookies.
As described earlier, many companies make distinctions between the cookie policy and the privacy policy. This is not mandatory, but it may be necessary based on the business model. So, don't cling to templates, but strengthen transparency and accessibility for the information listed there.
It is important to avoid confusion at this point, as many people end up mixing up these concepts. I'll provide a simple explanation below, which will help us understand the order of things and facilitate overall comprehension.
Remember: Tags and Pixels trigger Cookies.
Tag & Pixel: Code that goes into the HTML of your website to call a specific service. These are scripts (programming codes) that call a server and perform specific functions based on these requests.
Cookies: Text files read and triggered by Tags & Pixels, which store data and serve to identify whether a browser is new (if there is no cookie, the tag triggers) or already known (if It has the cookie, It will overwrite it).
To maintain compliance with the law, it is necessary to pay attention to the principles of LGPD and have knowledge of the regulation as a whole.
Furthermore, once it is decided that the company will indeed use first-party or third-party cookies in its operations, the categorization or organization of these cookies is the basis for communicating with visitors in your cookie policy and banner.
In general, the market uses five main groups to classify their tags and consequently the cookies triggered by them:
Necessary: Without them, your business model doesn't work, or you have to use them due to legal requirements/legislation.
(e.g., first-party cookies, gateway authentication, etc.)
Advertising: With them, you trigger remarketing, populate ad pixels, email sequences, etc.
(e.g., Facebook Pixel and Google Ads)
Analytics: With them, you have an analysis of what visitors do, where they come from, how they behave on your site.
(e.g., Google Analytics, Hotjar, etc.)
Performance: Tags that maintain site functionality and ensure its operation, e.g., preventing DDoS attacks.
(e.g., Cloudflare)
Functional: Tags that handle functional aspects, such as remembering preferences or recognizing that the user is already logged into the system.
(e.g., Chatbots, Helpcenters)
To facilitate data collection and record user consent, there are Consent Management Platforms (CMPs) like AdOpt.
In this link, you can learn more about our service: In summary, a Cookie Banner that helps your website comply with LGPD, GPDR, CCPA... standards while also being a comprehensive tool for managing consent and communicating with visitors.
Get started for free now and avoid LGPD, GPDR, CCPA... fines!
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Tired of the ads from that site you visited following you around? Is your computer running slow when accessing a particular website? Want to delete all cookies from a specific service or site?
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
While both regulations share the goal of safeguarding individuals' rights regarding the processing of their personal data, there are some important differences between them. It is crucial to understand these distinctions and their implications, particularly in the context of internet cookies.
In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
On October 18, 2022, the National Data Protection Authority (ANPD) released the "Guidance on Cookies and Personal Data Protection." Highly anticipated by professionals in the field, this document is of utmost importance as it examines various applicable legal scenarios and establishes the requirements to be observed in the case of cookie usage.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
Every day, millions of users generate data on the web, which is used by companies around the globe to improve their offerings. Therefore, in 2018, a law was created to regulate the use of personal data by companies, and this directly impacts digital marketing. We're talking about LGPD.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!
What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
In this article, we will answer all your questions regarding fines under the LGPD (Brazil's General Data Protection Law).
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
16 May 2023
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications