Cookies and visitor activity trackers
Brief guidance on visitor activity trackers in the context of health and care.
Visitor activity trackers help you to track your website visitors. They usually use cookies or similar technology to tell you which pages your visitors access and how they interact with the website, for example whether they use the search function.
Cookies are small files, which are downloaded to a user’s device when accessing certain websites. These cookies allow the website to recognise the user's device and store some information about how the user is using a website.
For further information about the use of cookies and similar technologies, see the guidance from the Information Commissioner’s Office (ICO).
User consent to use tracking mechanisms
If you want to use cookies and similar technologies that are not strictly essential or necessary for the operation of the website, you are required to obtain user consent. This is usually done via a pop-up on the website. The ICO provides guidance on how to obtain consent including helpful pictures of compliant cookie banners.
Ensuring that visitor activity trackers are used appropriately
Inappropriate use of visitor activity trackers could result in a breach of data protection laws. This could occur if for example excessive information was collected by an activity tracker, particularly where marketing cookies are installed.
Inappropriate use of visitor activity trackers could also pose a risk to confidentiality. For example, if user-derived information such as an IP address or personal details input by the user are linked with their search for health and care information about a specific condition. This could especially apply if the website asks the user to confirm if they have the condition.
Auditing the tracking and profiling on your website
To ensure you are not collecting excessive data, it is important to regularly audit your tracking or profiling of website users and the data you are storing or passing to tracking services. You can use readily available low cost analytics tools to audit and categorise the types of cookies on your website. This will enable you to isolate or remove cookies you do not require.
More steps to take to make sure your tracking and profiling is appropriate
To ensure that the tracking and profiling activity on your website is appropriate, you should:
- have clear lines of accountability and responsibility for tracking and profiling activity within your organisation (who authorises the use of cookies or similar technology, who can deploy them)
- have a clear process for monitoring of visitor activity tracking and profile management within the organisation (for example, regularly scanning cookies deployed, highlighting new or suspect cookies for further investigation)
- ensure visitor activity trackers cannot be added or removed from their website without organisational approval - this applies to internal and external staff, such as contractors
These IG pages provide clear and consistent IG advice and guidance to patients and service users, health and care staff and IG professionals. NHS England convenes a working group to check and challenge the guidance.
Last edited: 7 May 2026 4:25 pm