# [Cookie banner: legal requirement or best practice?](https://www.cookiebot.com/en/cookie-banner/)
**Confused about cookie banner requirements? We break it down for you. Learn about global data privacy law compliance and best practices for cookie banners.**
· [Get started with Google Consent Mode and Cookiebot CMP today](https://www.cookiebot.com/en/google-consent-mode/) · [Scan your website for free to see all cookies and trackers in use](https://www.cookiebot.com/)

A cookie banner is a display notice that appears when users visit a website for the first time, or when new consent information is required. It is also known as a cookie consent banner or cookie notice. Cookies banners have two purposes:
- to inform users that the website uses cookies
- to obtain users’ consent for the collection of their personal data

An increasing number of websites around the world need a cookie consent banner. Pretty much every website uses cookies—with some very rare exceptions—and data privacy laws that regulate personal data collection and use, user consent and privacy, and cookie use are coming into force in more and more countries.

---
## What is a cookie banner?

A cookie banner typically contains language that explains the website’s use of cookies, enabling users to make an informed choice regarding access to their personal data. The amount of information may vary depending on the different data privacy laws' requirements, but some of the items they notify visitors about are:
- that the website uses cookies
- why it uses cookies, or the cookie type by purpose
 - essential cookies, without which the website won’t work as intended
 - non-essential cookies, including for statistics, user preferences and customizations, marketing and advertising and third-party
- what choices the user has regarding their data
- that the organization has a privacy policy, of which a cookie policy can be a part, with a relevant link

## Taking action with a privacy banner

A cookie banner gives users a way to inform the website about whether or not it can collect their personal data, and often, at a granular level, which specific data and for what purposes it can be used. This is usually in the form of buttons with the following consent options:
- Confirm or Accept
- Decline or Reject
- Customize or Manage Preferences

---
## Types of cookie consent banners

There are two main types of cookie consent banners based on the data privacy regulations that they help organizations comply with: opt-in consent and opt-out consent.

### Opt-in consent banner

Opt-in consent means that the user must explicitly allow the website to use cookies by selecting an “Accept”, “Confirm” or "Allow" option before any personal data is collected. The EU’s GDPR and ePrivacy Directive (EU cookie law), Brazil’s LGPD, South Africa’s POPIA and Thailand’s PDPA all require explicit consent from visitors before a website can collect their personal data.

### Opt-out consent banner

Opt-out consent doesn’t generally require a website or app to collect visitors’ explicit consent before it uses cookies. Under the opt-out consent model, a website can use cookies and collect personal data without obtaining user consent. Consent may be required if sensitive data or data belonging to children is collected.

---
## What are the requirements for a cookie banner?

Cookie banners must comply with the provisions under data privacy laws like the GDPR, ePrivacy Directive and [California Consumer Privacy Act (CCPA)](https://www.cookiebot.com/en/what-is-ccpa/), and the requirements for each can be different. Basic cookie consent requirements for banners are:
- details about the website’s cookie usage, explained in simple, non-legal language that anybody should be able to understand
- clear options for the user to accept or reject the website’s/app’s use of cookies if it’s an opt-in consent banner
- a clear way for the user to opt out of the website’s use of cookies if it’s an opt-out consent banner
- a link to the website’s privacy policy or cookie policy
- contact information for the company, and, where relevant, how to exercise user rights under relevant regulations

### Requirements for privacy banners compliant with the ePrivacy Directive and GDPR

- **Clear information about cookies:** The cookie banner must clearly explain that the website uses cookies, the types of cookies it uses and for what purpose, and for how long they’ll be stored on their user’s device.
- **Explicit consent option:** Users must actively consent to let the website use cookies.
- **Option to reject cookies:** Users must be given the choice to reject cookies easily.
- **Granular control over cookie preferences:** For consent under the GDPR to be specific to a purpose, users must have the option to customize their cookie preferences if they wish.
- **Link to policies:** Users who want to know more about your detailed cookie or privacy policies must be able to access them with a clear link from the cookie consent banner.

### Requirements for cookie banners compliant with the CCPA/CPRA

- **Information about cookie usage:** The cookie banner must inform users about cookies the website uses and the intended purposes for collecting personal information.
- **Privacy policy link:** The cookie banner must include a link that goes directly to the specific section of the business’s privacy policy that pertains to the use of cookies.
- **Option to opt out of personal data being sold:** The CCPA/CPRA require a cookie consent banner to include a link with prescribed language that says “Do Not Sell Or Share My Personal Information”.

---
## Best practices for cookie banner design

Good design makes it easy for users to understand the information on your cookie banner and take action to opt in (or out), making your cookie banner effective, user-friendly and more likely to be compliant. Your cookie banner should:
- use fonts and text sizes that are easy to read
- match your brand colors and style for visual consistency
- include your corporate logo for easy visual recognition
- use clear labels on buttons that make it apparent what users’ options are
- display the banner prominently on the screen, without overtaking all of it
- employ accessibility best practices

## Can I control cookies on my website without a cookie banner?

Cookie use is a potential privacy risk and a legal liability for your website because they can track, store and share behavior about your end users. On average, a website has 20 cookies in use. It’s important to stay up to date on which cookies and other trackers are in use at any given time to comply with regulations and accurately inform users.

---
## Why choose Cookiebot™?

Cookiebot CMP is a mature technology that has been evolving and improving for many years. Today, it’s the most powerful tool on the market for detecting tracking technologies in operation on websites and to control these based on genuine end-user consent.

### Compliance and technology for a sustainable internet economy

Cookiebot CMP launched in Denmark in 2012 to help balance data privacy and data-driven business on websites around the world. Its unrivaled website scanner and full cookie control enables compliance with major data privacy laws around the world.

### Optimized for better usability and higher conversion rates

With a modern look and feel, the new generation of cookie banners from Cookiebot CMP make the user consent journey effortless and intuitive.

### Fully flexible and customizable

The new generation of cookie banners are the most customizable cookie banners online.

### Optimized for mobile

The new cookie banners are fully responsive and optimized for mobile use.

### Achieve seamless compliance with major data privacy regulations

The cookie banners from Cookiebot CMP provide your website with plug-and-play compliance for major data privacy laws.

---
## Frequently asked questions

Does the new banner support IAB’s TCF Framework? 
All Cookiebot CMP banners support the IAB TCF.

How do you make a GDPR banner? 
A “GDPR banner” or cookie banner must be able to manage end-user consents and control all cookies and trackers in use on your website.

---
## Resources

* [Guide on how to configure the new cookie banners from Cookiebot CMP](https://support.cookiebot.com/hc/en-us/articles/4403348431506/)
* [Get started with Google Consent Mode and Cookiebot CMP](https://www.cookiebot.com/en/google-consent-mode/)
* [Why choose Cookiebot CMP?](https://www.cookiebot.com/en/why-choose-cookiebot-cmp/)
* [Learn more about GDPR and cookie consent](https://www.cookiebot.com/en/gdpr-cookies/)
* [Learn more about CCPA compliance with Cookiebot CMP](https://www.cookiebot.com/en/ccpa/)
* [Learn more about US data privacy laws in the making](https://www.cookiebot.com/en/us-data-privacy-laws/)
* [See current EDPB guidelines for valid GDPR cookie consent](https://www.cookiebot.com/en/edpb-guidelines/)

## Stay informed

Join our growing community of data privacy enthusiasts now. Subscribe to the Cookiebot™ newsletter and get all the latest updates right in your inbox.

## Download the CMP integration for your preferred CMS

## Usercentrics Cookiebot WordPress Plugin

*Used by: Brand A, Brand B, Brand C*

---

## Product
[Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/) · [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/) · [WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/) · [Pricing](https://www.cookiebot.com/en/pricing/)

## Regulations
[DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/) · [GDPR (EU)](https://www.cookiebot.com/en/gdpr/) · [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/) · [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/) · [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/) · [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/) · [Google Consent Mode](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/) · [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)

## Partners
[Become an affiliate](https://www.cookiebot.com/en/affiliates/) · [Become a partner](https://www.cookiebot.com/en/resellers/) · [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

## Resources
[Blog](https://www.cookiebot.com/en/blog/) · [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/) · [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/) · [Google Consent Mode V2 Certification](https://courses.usercentrics.com/course/google-consent-mode-v2) · [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/) · [Developer documentation](https://www.cookiebot.com/en/developer/) · [Cookiebot vs CookieYes](https://www.cookiebot.com/en/cookiebot-best-cookieyes-alternative/) · [Cookiebot vs OneTrust](https://www.cookiebot.com/en/onetrust-alternative/) · [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

## Company
[About us](https://www.cookiebot.com/en/about/) · [Careers](https://usercentrics.com/career/) · [Support](https://support.cookiebot.com/hc/en-us/)

---
[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](https://www.cookiebot.com/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/)

©2026 Cookiebot™ by [Usercentrics](https://usercentrics.com/)