# Cookie & RGPD

**URL:** <https://forum.mautic.org/t/cookie-rgpd/22987>\
**Category:** Ideas and Feature Requests\
**Created:** [March 10, 2022, 11:00am UTC](https://forum.mautic.org/t/cookie-rgpd/22987 "2022-03-10T11:00:54Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![pierre\_a](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/pierre_a/32/7031_2.png) [@pierre\_a](https://forum.mautic.org/u/pierre_a)\
**Post date:** [March 10, 2022, 11:00am UTC](https://forum.mautic.org/t/cookie-rgpd/22987/1 "2022-03-10T11:00:54Z")

</div>

Hello everyone,  
Currently (in version 4.x) Mautic uses 4 tracking cookies:

- mautic\_device\_id
- mautic\_referer\_id
- mtc\_id
- mtc\_sid

**mautic\_device\_id**  
Mautic tracks visitors to the website. To do this, it assigns a unique identifier to each new visitor and deposits this identifier in the cookie “mautic\_device\_id” on your browser.  
Expiry time of the cookie: 1 year

**mautic\_referer\_id**  
This cookie stores an identifier depending on the last landing page you visited.  
Expiration time: the current session

**mtc\_id**  
This cookie stores the Mautic contact ID of the current visitor.  
It is not used for visitor tracking. It allows the website to know the current visitor when using a REST API call.  
Expiration time: the current session

**mtc\_sid**  
This cookie is deprecated. It stores the same information as “mautic\_device\_id”.  
It is still present to ensure backward compatibility.  
It will disappear in a future version.  
Expiration time: the current session

My idea would be to be able to deactivate the **mtc\_id** and **mtc\_sid** cookies directly via the Mautic configuration page.  
Indeed, in Europe, in order to comply with the RGPD, a complete notice must be produced to explain precisely the role of each cookie.  
In most cases we don’t need **mtc\_id** and **mtc\_sid** cookies, being able to make them inactive will simplify the compliance process for companies.

I think that all companies operating in Europe and wishing to comply with the RGPD will benefit from having the ability to disable these two cookies from Mautic.

What do you think about this idea?

Pierre
