What is the __Secure-ENID cookie?
__Secure-ENID is an HTTP cookie set by Google on the .google.com domain, typically when a visitor interacts with Google services embedded on a website (such as Google Search, Maps, or other Google widgets) or visits Google properties directly.
The "__Secure-" prefix indicates the cookie can only be set over HTTPS connections and is subject to additional browser security restrictions, in line with modern cookie standards.
What data it stores
The cookie stores an identifier used by Google to retain settings and preferences related to search experience and result display (such as language, region, or other personalization options). The exact value format is not publicly documented in detail and may vary.
Data is sent to Google's servers with each request to the .google.com domain or associated services, not to the site embedding the content.
What it is used for
For Google, __Secure-ENID helps maintain a consistent experience across sessions by remembering user preferences without requiring them to be re-entered on each visit.
For site owners embedding Google services (search widgets, maps, etc.), the cookie indirectly supports the proper functioning of those components, though it is not strictly necessary for the site's own core functionality.
Does it require consent?
CookieFix classifies __Secure-ENID under the preferences (functional) category. Since it is a personalization cookie and not strictly necessary for service delivery, it must only be set after obtaining visitor consent, in accordance with the ePrivacy Directive (as implemented in Romania via Law 506/2004) and GDPR principles.
- The site owner must disclose this cookie in the cookie policy.
- The cookie should not be set before the visitor opts in to the preferences category.
- Refusing consent must not block access to the site's core content.
How to block or delete __Secure-ENID
Visitors can delete or block this cookie through their browser's privacy settings (Chrome, Firefox, Edge, Safari), including by clearing cookies for the google.com domain or enabling third-party cookie blocking.
For site owners, a CMP such as CookieFix can automatically block Google scripts that set this cookie until the visitor gives consent for the preferences category, avoiding it being set without a legal basis.
Frequently asked questions
It is a cookie set by Google to remember preferences related to services like search, used on the .google.com domain.
Yes, since it is classified as preferences (functional) and is not strictly necessary, it should only be set with the visitor's consent under GDPR and ePrivacy rules.
Its typical duration is around 13 months, after which it expires automatically.
It can be deleted via browser settings or automatically blocked by a CMP such as CookieFix until consent is given.