What is the SIDCC cookie?
SIDCC is an HTTP cookie set by Google on the .google.com domain. It belongs to a broader family of Google authentication and security cookies (alongside SID, HSID, SSID, __Secure-3PSIDCC and others) used to help protect Google accounts from unauthorized access.
It typically appears when a visitor interacts with Google services — for example, signing into a Google account, using Google Maps, YouTube, reCAPTCHA, or other embedded Google components on a third-party site — or when a page loads Google scripts or widgets that require session context.
What data it stores
The cookie stores an encrypted identifier generated by Google, used to verify session authenticity and security signals associated with the account. The value is not human-readable, and Google does not publicly document its exact content in detail; the precise structure varies and cannot be determined from outside.
Data is sent to Google's servers (the google.com domain and related subdomains) whenever the browser makes requests to these services or to Google components embedded on other sites.
What it is used for
Google's stated purpose for the SID/SIDCC cookie family is security: confirming user identity, detecting suspicious activity or fraud attempts, and protecting account data from unauthorized access.
For a site owner integrating Google services (Google sign-in, maps, embedded video, reCAPTCHA), this cookie helps that component function correctly and securely — it is not used for targeted advertising.
Does it require consent?
CookieFix classifies SIDCC as strictly necessary, since it supports security and authentication functions essential to the integrated Google services. Under the ePrivacy Directive (transposed in Romania via Law 506/2004) and GDPR, strictly necessary cookies do not require prior consent, but the site owner must still disclose them in the cookie policy, including provider, purpose, and duration.
Site owners should verify the context of use: if the Google service in question is used purely for authentication or security, classifying it as necessary is justified; if it's part of a broader Google integration with analytics or advertising features, a separate audit of each embedded Google service is recommended.
How to block or delete SIDCC
A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari – per-site cookie management), either individually or by blocking all cookies from the google.com domain. Doing so may affect embedded Google services on the site (for example, Google sign-in or reCAPTCHA may stop working correctly).
- Manual deletion via browser privacy settings
- Blocking third-party cookies from google.com
- Browser extensions for cookie management
Because some Google components can, in other contexts, include measurement elements, site owners who want granular control can use a CMP such as CookieFix, which automatically blocks non-essential scripts until the visitor gives consent.
Frequently asked questions
It's a security cookie set by Google on the .google.com domain, used to verify session authenticity and help protect Google accounts.
No, it's classified as strictly necessary for security and authentication functions, but it must still be disclosed in the site's cookie policy.
Its typical duration is about 1 year, after which it expires automatically.
Embedded Google services on the site, such as sign-in or reCAPTCHA, may stop working correctly.