Necessary storage
Authentication, session security, CSRF protection, workspace continuity, and preference storage may require first-party cookies or equivalent browser storage.
Legal
The public site should use only cookies required for security, authentication, and user-requested functionality unless a consent-managed category is intentionally added.
Authentication, session security, CSRF protection, workspace continuity, and preference storage may require first-party cookies or equivalent browser storage.
Analytics, advertising, or other optional trackers must not be enabled until they are inventoried, disclosed, and gated by consent where required.
The final deployment must provide a preference control when optional categories exist, alongside browser-level controls and a current inventory.