What is the SOCS cookie?
SOCS (State of Consent Store) is an HTTP cookie set by Google, typically visible on the .google.com domain. It appears when a visitor interacts with Google services embedded on a website (such as Google Search, YouTube, Google Maps, or other Google widgets), or when a consent choice related to Google properties is recorded.
It is set directly by Google, not by the host website, but it can show up in a third-party cookie scan of any domain that embeds Google services.
What data it stores
SOCS stores the state of consent granted for Google services — essentially an encoded representation of the user's cookie choices (accept/decline by category) for Google. The value is an internally encoded string with no publicly documented format.
The data is sent to Google's servers to keep the consent preference synchronized across various Google services and domains.
What it is used for
The main purpose of SOCS is to remember the user's consent decision toward Google, so they are not asked repeatedly every time they interact with a Google service. For Google, this cookie supports compliance with consent requirements applicable in the European Economic Area.
For the website operator embedding Google services, SOCS has no direct functional role; its presence is simply a side effect of using those services.
Does it require consent?
CookieFix classifies SOCS as strictly necessary, because its role is to remember the consent decision itself, not to track users or serve marketing. Under ePrivacy rules and common GDPR interpretation, cookies strictly necessary for the requested service do not require prior consent, but must still be disclosed in the cookie policy.
- Site owners should list it in their cookie policy, naming Google as the provider and describing its purpose.
- If the site uses additional Google widgets (maps, video, ads), check whether those introduce other cookies that do require consent.
How to block or delete SOCS
A visitor can delete or block SOCS through browser privacy settings (Chrome, Firefox, Edge, etc.), either by clearing cookies for google.com or by blocking third-party cookies. Blocking it may affect the functioning of Google services embedded on the page.
For site owners, a consent management platform like CookieFix can automatically block third-party scripts — including those loading Google services — until the visitor gives consent, ensuring the banner is shown before such scripts run.
Frequently asked questions
No, CookieFix classifies it as strictly necessary, since it stores the consent state itself for Google services rather than tracking or marketing data.
It is set by Google, typically on the .google.com domain, when a website embeds Google services such as Search, YouTube, or Maps.
Its typical duration is about 13 months, after which it expires automatically in the browser.
Yes, even strictly necessary cookies should be disclosed in the cookie policy, naming the provider and its purpose, in line with good GDPR practice.