Cookies Information
We've designed this information page to provide our site visitors with accessible, transparent information about the cookies we use.
What are cookies?
Cookies are small text files that are placed on your computer by the websites that you visit. They are used in order to make websites work, or work more efficiently, as well as to provide statistical information to site owners. Some cookies also enable the display of relevant advertising when you move from site to site.
This information is relevant for visitors to www.complianceaccesspoint.mer.pwc.com and the areas of our site which provide you with access to our blogs, careers information and marketing content. As you move around our site you may see more than one cookie ‘pop up’ appearing — this is to ensure we keep you fully informed about the cookies used in the particular area of the site you are visiting.
For more information about how we process your personal information, please visit our privacy policy.
Necessary Cookies
These cookies are necessary for our site to operate. They don't access or store any personal data. Our website cannot function without these cookies so they are always set on.
You can manage and control cookies through your browser (a good search term is ‘managing cookies’). Your choices will include removing cookies by deleting them from your browser history when you leave our site. If you do switch cookies off for our site it may not work as well as you would expect it to.
The table below provides details about the actual cookies we use. We've included information on the duration of each cookie, its purpose and if its use involves the transfer of information to any of our third party business partners.
Strictly necessary cookies
| Cookie Name | First or third party? | Cookie duration | Cookie description | Information shared with |
|---|---|---|---|---|
authjs.session-token | First party | 30 days idle expiry | The session itself — encrypted JWT holding the Entra access/refresh tokens. | Not shared with third parties |
authjs.callback-url | First party | Session cookie (until browser closes) | Where to return after sign-in. | Not shared with third parties |
authjs.csrf-token | First party | Session cookie | CSRF protection on authentication routes. | Not shared with third parties |
authjs.pkce.code_verifier | First party | 15 minutes | OAuth PKCE verifier during sign-in. | Not shared with third parties |
authjs.state | First party | 15 minutes | OAuth state parameter. | Not shared with third parties |
authjs.nonce | First party | 15 minutes | OIDC nonce. | Not shared with third parties |
cap.login_continue | First party | 5 minutes | Sealed sign-in outcome used to prevent account enumeration. | Not shared with third parties |
First party cookies are directly stored by the website you visit. These cookies allow website owners to collect analytics data, remember language settings, and perform other useful functions.
Third party cookies are created by domains that are not the website you are visiting. These are usually used for analytics and/or online-advertising purposes.
Managing cookies on your device
We use cookies to personalize content and to provide you with an improved user experience. By using this website or application you consent to the deployment of cookies. You can control and manage cookies using your browser. Please note that removing or blocking cookies can impact your user experience, and some functionality may no longer be available.
Using your browser to control cookies
Most browsers allow you to view, manage, delete and block cookies for a website. Be aware that if you delete all cookies then any preferences you have set will be lost, including the ability to opt out from cookies as this function itself requires placement of an opt-out cookie on your device. Guidance on how to control cookies for common browsers is linked below.
For information on additional browsers and device types please see aboutcookies.org or cookiecentral.com.