Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

enforce_policy Cookie (PayPal) – What It Is & Its Purpose

enforce_policy is an HTTP cookie set by PayPal on the .paypal.com domain, used to enforce PayPal's security and usage policies. It is classified as strictly necessary because it supports the safe operation of PayPal services embedded on a website.

Name
enforce_policy
Provider
PayPal
Category
Necessary
Type
HTTP cookie
Lifetime
1 year
Domain / notes
.paypal.com
Consent
No, but it must be listed in the cookie policy

What is the enforce_policy cookie?

enforce_policy is an HTTP cookie placed by PayPal, the online payments company, when a visitor interacts with a PayPal payment button, checkout widget, or any PayPal module embedded on a website (for example, in an online store).

The cookie typically appears as soon as the PayPal script loads on the page, regardless of whether the user completes a payment, and it is tied to PayPal's own technical infrastructure rather than the host site's content.

What data it stores

The cookie is stored on the .paypal.com domain and typically lasts 1 year. The exact value format is defined and controlled internally by PayPal; it is not publicly documented in detail, but it is associated with enforcing PayPal's usage and security rules rather than with direct personal identification data.

Data collected through this cookie is sent to PayPal's own servers and is not accessible to or processed by the administrator of the site where it is embedded.

What it is used for

The stated purpose of this cookie is to help PayPal apply and verify compliance with its usage and security policies during transactions and interactions carried out through its services.

For the website integrating PayPal, this cookie indirectly supports the correct and secure functioning of the payment module, as part of the technical mechanisms required to process online payments.

Does it require consent?

CookieFix classifies enforce_policy as a strictly necessary cookie. Under the ePrivacy Directive (transposed in Romania via Law 506/2004) and ANSPDCP guidance, cookies strictly necessary to deliver a service explicitly requested by the user (here, processing a payment) do not require prior consent.

However, the site administrator should still list this cookie in the cookie policy, naming the provider (PayPal), its purpose, and duration, to meet GDPR transparency obligations.

How to block or delete enforce_policy

A visitor can delete or block this cookie via browser settings (Chrome, Firefox, Edge, Safari), under the cookie management section for the paypal.com domain. Blocking it may prevent PayPal payments from completing correctly.

Because it is strictly necessary, a CMP like CookieFix does not block it, but it can delay loading of PayPal scripts until the user interacts with the payment module, avoiding premature setting of other, non-essential PayPal cookies.

Frequently asked questions

No, it's a technical cookie PayPal uses to enforce its internal security and usage policies, not for advertising tracking.

No, since it's classified as strictly necessary for PayPal's payment service to function, it doesn't require prior consent under ePrivacy, but it must be disclosed in the cookie policy.

The PayPal payment process may not work correctly, or you may need to re-authenticate the payment session.

The data is managed exclusively by PayPal; the administrator of the site embedding the PayPal module has no access to the cookie's content.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.