What is the l7_az cookie?
l7_az is an HTTP cookie set by PayPal on the .paypal.com domain when a visitor interacts with a PayPal button, form, or widget embedded on a website (for example, during checkout or when logging into a PayPal account).
It is not set directly by the site the visitor is browsing, but by PayPal's backend infrastructure that runs in the background whenever a PayPal element (payment button, checkout iframe, SDK script, etc.) is loaded.
What data it stores
Cookies with the l7_ prefix are generally associated with load-balancing and traffic-routing mechanisms used by PayPal's technical infrastructure (such as BigIP/F5-based systems or equivalent), helping route a user's requests to the same server or cluster for the duration of a session.
The exact value is an internal technical identifier generated by PayPal's systems; its precise format is not publicly documented, and the content should not be interpreted by third-party sites. The data is sent to PayPal's own domains, not to the site hosting the widget.
What it is used for
The main purpose of l7_az is to maintain the technical continuity of a user's session while interacting with PayPal services — for example, ensuring that successive requests within a payment flow reach the same backend server, avoiding errors or interruptions.
For the website embedding PayPal, this cookie has no marketing or analytics function; it simply supports the correct operation of the PayPal button or checkout process displayed on the page.
Does it require consent?
Under CookieFix's classification, l7_az is a strictly necessary cookie, since it supports the technical operation of a service actively requested by the user (the payment process). Strictly necessary cookies do not require prior consent under the ePrivacy Directive (2002/58/EC, transposed in Romania via Law 506/2004) and the GDPR framework, but they still need to be disclosed in the site's cookie policy.
Website operators should document this cookie in their cookie policy, noting that it is set by PayPal as a third party, in the context of a service actively invoked by the user.
How to block or delete l7_az
Visitors can delete or block l7_az through their browser settings (Chrome, Firefox, Safari, Edge — per-site cookie management), though blocking it may affect the functioning of PayPal buttons or forms on the site.
- Manual deletion: via the browser's privacy settings, searching for cookies from the paypal.com domain.
- Site-level blocking: since this is a strictly necessary cookie set by a third party at the user's active request, it is typically not included among scripts blocked by a CMP before consent, as the PayPal service is explicitly triggered by the user's interaction (e.g., clicking the payment button).
- A platform like CookieFix can still control whether and when the PayPal script/widget loads on the page, blocking it automatically until an explicit user action, for sites that prefer a stricter approach.
Frequently asked questions
No, it is classified as strictly necessary because it supports the technical functioning of a PayPal service actively requested by the user, so it falls outside the prior-consent requirement.
It is set by PayPal, as a third party, whenever a PayPal element (button, iframe, SDK) is loaded on the site's page.
The PayPal button or checkout process may not work correctly, since the cookie helps maintain technical session continuity within PayPal's infrastructure.
Yes, even though it doesn't require consent, site operators should disclose it in their cookie policy as a strictly necessary cookie set by PayPal.