PARTLY

As of 13 August 2026, AI can only partly draft a cookie policy for your UK website.

This still needs a person who signs their name to it.

Can you do it?

5 minutesto a draft.

30 minutesto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsA purpose-built service such as iubenda generates and maintains privacy and cookie compliance documents.

If this goes wrong, your published policy can omit trackers or describe consent inaccurately while your business remains responsible for the compliance failure.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 30 minutes until you can act on the result.

    How to actually do it

    1. Open the live website in a browser and run a cookie or tracker scan before accepting consent, then repeat it after accepting each available consent category.
    2. Export or copy the scan results, including cookie names, domains, providers, purposes, categories and durations, and remove any visitor data from the material you will paste.
    3. Open the documentation for each embedded service and vendor, then gather its stated cookie purposes, retention periods, transfer information and consent requirements.
    4. Record the consent platform settings, the trackers blocked before consent, the withdrawal method, the business contact details and the website URL in the prompt.
    5. Paste the completed prompt and source material into an AI tool and ask it to draft the policy and separate all missing or uncertain facts as requested.
    6. Compare the draft table against both scan results and vendor documentation, then test the live consent banner and withdrawal control to confirm the published instructions work.
    7. Send the draft, inventory, consent settings and verification list to a UK solicitor or privacy specialist before publishing, then set a review process for website and vendor changes.

    Prompt

    Draft a cookie policy for this UK website using only the information supplied below. This is a drafting task, not professional advice. Do not invent cookies, providers, purposes, retention periods, legal bases, international transfers, consent settings or technical details. Where information is missing, write [NEEDS CONFIRMATION] and list the exact fact I need to obtain.
    
    Website name: [NAME]
    Website URL: [URL]
    Business name and contact details: [DETAILS]
    Website audience and services: [DESCRIPTION]
    Cookie or tracker scan results: [PASTE THE COMPLETE SCAN]
    Cookie consent platform and settings: [DETAILS]
    Cookies and trackers that run before consent: [LIST OR NONE]
    Cookies and trackers used after consent: [LIST]
    For each cookie or tracker, include provider, purpose, category, duration, whether it is first-party or third-party, and any international transfer information: [DETAILS]
    Embedded services such as videos, maps, analytics, advertising or payment tools: [LIST]
    Links to relevant vendor cookie information: [LINKS]
    How visitors can withdraw or change consent: [DETAILS]
    Last reviewed date: 2026-08-13
    
    Produce a plain-English UK cookie policy with headings, a table of cookies and trackers, consent and withdrawal instructions, contact details, and a short change log. Keep factual claims tied to the supplied inventory. After the policy, provide a separate verification list showing every missing fact, every item that needs checking against the live website, and every point that should be reviewed by a UK solicitor or privacy specialist before publication.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: legal accountability, verification cost and private data access.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability0
Effort delta1
Total5 / 10

FAQ

Can AI write a cookie policy for my UK website?
Partly. AI can produce a clear first draft from a complete cookie inventory, but it cannot reliably discover every tracker or confirm that your consent setup is compliant. This is not professional advice, and a serious or high-risk case needs a UK solicitor or privacy specialist.
What information does AI need to draft a cookie policy?
Give it a current scan of the website before and after consent, the cookie names and providers, purposes, categories, durations, embedded services, consent platform settings and withdrawal instructions. Vendor documentation is also needed where the scan does not explain transfers or retention.
Can AI check whether my cookie policy is GDPR compliant?
Not reliably on its own. It can compare the wording with the inventory you provide, but compliance also depends on the live consent banner, blocking behaviour, tracker changes and the facts of your processing.
Is an AI-generated cookie policy legally binding?
The document itself is not a transfer of responsibility to the AI tool. Your business remains accountable for the accuracy of the policy and the way cookies are used, so obtain UK solicitor or privacy specialist review where the risks are serious.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.