Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Cookies Policy
I need a cookies policy that clearly explains the types of cookies used on our website, their purposes, and how users can manage their cookie preferences. It should comply with Indonesian regulations and be easy for users to understand.
What is a Cookies Policy?
A Cookies Policy explains how your website uses digital tracking files (cookies) to collect visitor information. Under Indonesia's Electronic Information and Transactions Law, websites must tell users what data they gather and how they use it. This policy helps businesses meet those requirements while building trust with their audience.
The policy outlines which types of cookies you use, how long they stay active, and what happens to the collected data. It should explain if you share information with third parties and give clear instructions for users to manage or disable cookies. Indonesian businesses handling personal data must keep this policy updated and available in both Bahasa Indonesia and English.
When should you use a Cookies Policy?
You need a Cookies Policy when your website starts collecting user data through cookies or similar tracking technologies. This requirement kicks in immediately for Indonesian businesses launching new websites, mobile apps, or online platforms that use any form of visitor tracking—even basic analytics tools.
The policy becomes essential when expanding into e-commerce, implementing marketing tools, or serving customers across multiple languages. Under Indonesian data protection laws, websites handling personal information must clearly disclose their data collection practices. This includes international businesses targeting Indonesian customers and local companies using third-party services like Google Analytics or social media plugins.
What are the different types of Cookies Policy?
- Basic Cookie Notice: The simplest version focusing on essential cookies, typically used by small Indonesian websites and blogs. Covers fundamental tracking and analytics.
- Comprehensive Cookies Policy: Detailed version covering all cookie categories, third-party integrations, and cross-border data flows. Common for e-commerce and financial services.
- Multilingual Cookie Policy: Dual-language version in Bahasa Indonesia and English, mandatory for international businesses serving Indonesian users.
- Mobile App Cookie Policy: Specialized version for mobile applications, addressing device identifiers and app-specific tracking methods.
Who should typically use a Cookies Policy?
- Website Owners: Responsible for implementing and maintaining the Cookies Policy, including regular updates to reflect changes in tracking technologies.
- Legal Teams: Draft and review policies to ensure compliance with Indonesian data protection laws and international standards.
- IT Departments: Implement technical aspects of cookie management and maintain cookie consent mechanisms.
- Marketing Teams: Use cookie-collected data for analytics and campaigns while ensuring compliance with the policy.
- Website Visitors: Must be informed about cookie usage and have options to accept or reject different cookie types.
How do you write a Cookies Policy?
- Cookie Audit: List all cookies your website uses, including third-party tools like analytics or social media plugins.
- Data Collection Details: Document what information each cookie collects and how long it remains active.
- User Controls: Plan how visitors can manage their cookie preferences through your consent mechanism.
- Language Requirements: Prepare content in both Bahasa Indonesia and English if serving international users.
- Technical Integration: Ensure your cookie consent tool aligns with the policy statements.
- Regular Updates: Set up a system to review and update the policy when adding new website features or tracking tools.
What should be included in a Cookies Policy?
- Cookie Types: Clear categorization of all cookies (essential, functional, analytical, advertising) used on the website.
- Data Collection Scope: Detailed explanation of what information is collected and its purpose.
- Storage Duration: Specific timeframes for how long each type of cookie remains active.
- User Rights: Instructions for accepting, rejecting, or modifying cookie preferences.
- Third-Party Access: List of external services accessing cookie data and their privacy policies.
- Contact Information: Details for reaching the data controller with privacy concerns.
- Language Requirements: Policy text in Bahasa Indonesia, with English translation if serving international users.
What's the difference between a Cookies Policy and a Data Breach Response Policy?
A Cookies Policy differs significantly from a Data Breach Response Policy in both scope and purpose, though both deal with data protection under Indonesian law. While a Cookies Policy focuses on proactive disclosure of data collection practices, a Data Breach Response Policy outlines reactive measures for security incidents.
- Primary Focus: Cookies Policies explain routine data collection and user tracking, while Data Breach Response Policies detail emergency procedures for data compromises.
- Timing of Use: Cookies Policies are actively displayed to users during website visits, whereas Data Breach Response Policies activate only during security incidents.
- Legal Requirements: Under Indonesian law, Cookies Policies must be accessible before data collection begins, while Data Breach Response Policies become relevant after a security incident occurs.
- User Interaction: Cookies Policies require active user consent and provide options for cookie management; Data Breach Response Policies involve no direct user interaction until an incident occurs.
Download our whitepaper on the future of AI in Legal
ұԾ’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; ұԾ’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our for more details and real-time security updates.
Read our Privacy Policy.