The written answer
A hosted platform was asked, in writing, why it set an analytics cookie before any consent choice had been made. The answer came back with three claims:
- The cookie is functionally necessary for the product to work.
- It is used for performance monitoring, troubleshooting and internal analytics.
- A processor agreement restricts what the vendor may do with the data.
The vendor, the platform and the brand are all unnamed here and will stay that way. The argument does not need them.
Conceding all three costs nothing
Start by assuming every one of those statements is true. The cookie probably is useful to the product. The data probably is used for troubleshooting. The agreement almost certainly exists and says what they say it says.
Is this true and does this qualify are different questions, and the answer addressed only the first one.
What the exemption actually tests
Regulator guidance on the strictly necessary category, broadly and across jurisdictions, assesses necessity from the perspective of the service the user requested, not from the perspective of the operator's requirements.
The visitor asked for an order. They asked for a table, a booking, a delivery slot. They did not ask for the platform's incident response, its uptime dashboard or its product analytics. Internal analytics is the standard worked example of what does not fall inside that category in essentially every piece of guidance on the point.
We are describing guidance as guidance. Whether any specific cookie qualifies in any specific jurisdiction is a determination for counsel, and it is not one we make.
A processor agreement answers a different question
What it does: it limits what the vendor may do with data it already holds, restricts onward transfer, and allocates liability between the parties. These are real controls doing real work.
What it does not do: it cannot manufacture a lawful basis for collecting something in the first place. An agreement about handling is downstream of the question of whether the collection should have happened.
The two get offered interchangeably because both sound like reassurance, and because the person asking usually wants reassurance rather than a distinction. It is a durable confusion and it is rarely deliberate.
The domain boundary makes it worse
This cookie fires on a page carrying payment and contact details, on a host the customer reads as the brand. To the visitor there is no seam. To the browser there very much is, and the consent layer on the brand's main domain does not reach across it.
The cookie-scope mechanics are covered in a cookie banner is not a consent tool and the multi-vendor funnel this describes in your restaurant website is not one website. We would rather link them than re-explain them.
Who holds it
Purpose determination sits with the brand. You did not classify the cookie, you may not have known it existed, and neither fact helps you when somebody asks.
That is the commercially uncomfortable part of this piece and it is why we wrote it. The decision was made by a vendor, inside a product, in a document you did not read, and the question lands on you.
What the index measured
Our Website Privacy Index scanned 47,505 public websites and scored 47,419, January to September 2026. Of those, 1,475 (3.1%) had a consent platform detected, and of that group 620 (42.0%) fired tracking before any interaction or kept firing after a refusal. 45,944 (96.9%) had no consent platform detected at all.
That 42.0% is a share of the 1,475, never of the whole sample.
The request to send your vendor
Word it plainly and ask for it in writing:
"Please provide your cookie table for our implementation, listing every cookie set on our behalf, its purpose, its duration, and the basis on which it is set. For any cookie classified as strictly necessary, please state which function of the service the visitor requested would fail without it."
A vendor who has thought about this will answer in a day. A vendor who has not will send you the processor agreement again, and that response is itself informative.
The one-sentence test
For each cookie marked necessary, write one sentence justifying it in terms of what the visitor asked for. Notice which sentences you cannot finish.
"The basket cookie is necessary because without it the visitor's order does not persist between pages" finishes cleanly. "The analytics cookie is necessary because we need to know whether the checkout is slow" does not, however true the second half is.
Third-party domains in your funnel are the part a one-off audit structurally cannot keep up with, because they change when the vendor changes them. Managed Privacy covers the full funnel including the domains you do not own, which is the part worth asking about. Or run the free scan and see what loads before anyone agrees to anything.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.