All Blog Posts

Cookie Policy Texts

Close
Read time
11 mins
Updated
Jul 31, 2026
Share
  • A cookie text, or cookie message, is the written content in a consent banner explaining what cookies a site uses and why; it is distinct from a full cookie policy.
  • Under the GDPR, cookie text must support clear, informed, opt-in consent obtained before non-essential cookies load, not implied consent from continued browsing.
  • Under the CCPA/CPRA, U.S. sites need a working opt-out mechanism for the sale or sharing of personal data, including recognition of signals such as Global Privacy Control.
  • The EDPB points to roughly 12 months as a sensible benchmark for refreshing consent, with immediate re-consent required after any material change to cookie use.
  • Equally weighted "Accept" and "Reject" options, plain language, and a working link to the full cookie policy are the common thread across every jurisdiction.

The cookie text or cookie message is the actual written content displayed by cookie consent banners that communicate to a website's visitors about its use of cookies. It's not the cookies’ text files themselves that are referred to here.

The cookie text is also not the same thing as a cookie policy text or cookie policy message, which are terms for policy statements about the overall strategy and position of a company regarding the privacy of its visitors. 

Cookieboot Pop Up Banner - Cookiebot

The cookie consent banner is a familiar sight on many websites today, since the GDPR came into force in Europe and many other data privacy laws have been enacted around the world.

However, there are many ways that websites choose to declare their cookies and tracking. There are many different cookie messages on websites, too.

A cookies agreement message targeted at the EU for GDPR compliance should not only state that your website uses cookies and be accompanied only by an “okay” or “accept” button. That does not enable valid consent, as visitors do not have equal access to an option to decline cookie usage.

Many cookie messages (in fact many cookie banners as a whole) are still non-compliant with the GDPR or other laws because they leave no real choice of consent for the visitor and explain poorly how their personal data is collected by the website and used.

The European Data Protection Board (EDPB) is the leading authority on the GDPR in the EU, and its main job consists of adopting guidelines and making decisions on how the GDPR is to be interpreted and enforced by the national data protection authorities in each EU country.

The EDPB guidelines clarify that:

  • Pre-ticked checkboxes on cookie banners are non-compliant. Checkboxes must always be deselected by default, except for the use of strictly necessary cookies, which don’t require user consent.
  • Scrolling, ignoring a cookie banner, or other continued use of a website is not considered valid cookie consent. Visitors must give a clear and affirmative consent, not an implied or assumed consent.
  • Cookie walls (consent conditional for access to a website) are non-compliant.

The GDPR requires that all websites that collect personal data from EU-based visitors have to:

  • Obtain clear and unambiguous consent from users
  • Consent must be obtained priorto any collection or processing of personal data
  • After specifying all types of cookiesand other tracking technologiespresent and operating on the site
  • Use easy to understand language
  • Enable visitors to consent and to change or revoke consenton each specific category of cookies at any time
  • Safely, confidentially, and securely documenteach user consent
  • Renew consent annually, or as often as required by relevant laws, or as business operations or technologies in use change

The “clear and unambiguous prior consent” is part of visitors’ option to opt-in or opt-out of the different cookie categories (preferences, statistics, marketing) at a granular level. Specifying all types of cookies is done in the cookie declaration and depository, which is the comprehensive overview of all known cookies and their purpose.

GDPR compliance mandates that your website must inform its visitors in easy to understand ways and thus enable them to consent and to revoke consent.

This is where the cookies text or cookies message comes in. It is the point at which you must provide specific information about tracking cookies on your website and its purposes.

How you do it can make a real difference for your visitors, and empower them with real, informed choice of consent, building trust with your company.An example of our cookie scripts:

Cookie message scripts screenshot - Cookiebot

The CCPA was amended and expanded by the California Privacy Rights Act (CPRA), effective since January 1, 2023.

The CCPA/CPRA are different from the European GDPR because they don't require organizations to obtain prior consent before the collection and processing of personal data in many cases. There are exceptions, like when the personal data is that of children, for example.

The CCPA compliance requires that businesses must inform visitors of what categories of personal information their websites collect (e.g. through cookies), for what purpose and which third parties it may be shared with or sold to.

The CCPA/CPRA also requires websites to implement a “Do Not Sell or Share My Personal Information” link through which visitors can opt out of having personal information sold to third parties, like Google and Facebook.

The CPRA also permits a consolidated "Your Privacy Choices" (or "Your California Privacy Choices") link, paired with the official opt-out icon, as an alternative to the longer text link. Visitors can allow access to their personal data, but if they change their minds later they must be able to revoke consent, and then sharing or sale of their personal data must cease.

California has also required businesses to honor Global Privacy Control (GPC) and other universal opt-out signals sent automatically by a visitor's browser. Colorado, Connecticut, Montana, and Texas have adopted comparable requirements, and California's rule requiring visible confirmation that an opt-out has been honored took effect January 1, 2026.

The legal requirements are the same for the cookie texts in California, i.e., informing visitors what cookies and tracking technologies are in use, for what purposes, and with whom it is shared.

Websites targeting Californian residents for CCPA/CPRA compliance may not use a cookie consent banner (as shown above), but a cookie declaration including the required opt-out link.

Cookies Text and CIPA Requirements

Separate from the CCPA, the older California Invasion of Privacy Act (CIPA) has become a significant source of litigation over website cookies, chat widgets, and analytics scripts. Originally written for wiretapping and phone recording, CIPA has been used by private plaintiffs to argue that certain tracking technologies amount to unauthorized interception under Sections 631 and 632, with statutory damages of USD 5,000 per violation and no need to show actual harm.

A pending bill, SB 690, would remove the private right of action for one narrower theory — claims that a website's tracking functions as a "pen register" or "trap and trace" device — leaving enforcement of that theory solely to the California Attorney General.

As of the beginning of August 2026, SB 690 has cleared an Assembly committee but still needs a floor vote in both chambers and the Governor's signature before an August 31, 2026 deadline. Even if it passes, the broader wiretapping and eavesdropping theories under Sections 631 and 632 remain open to private lawsuits regardless of its outcome.

In practice, the same clear, prior-consent cookie text recommended for GDPR compliance, rather than a passive cookie declaration alone, is the strongest defense against CIPA exposure, since it demonstrates that visitors were informed and given a genuine choice before any tracking began.

Cookiebot CCPA compliant cookie declaration screenshot - Cookiebot

The primary function of a cookies text is to inform visitors of the following:

  • Which cookies and trackers you use
  • The purposes for their use
  • Third parties with whom personal data is disclosed, shared, or sold
  • What individuals' rights are and how they can exercise them

The cookie text or cookie message is the main way of communicating to your visitors that you use analytics or marketing cookies, for example, to make your website and its services better and provide better user experiences, while at the same time protecting user privacy, giving them a real choice of how their data is used.

It is this balancing act that the cookie notice text is meant to express, making your visitors understand that you use cookies to optimize their website experience, while at the same time making sure that you protect their privacy.

Screenshot of Cookiebot CMP customizable cookie text - Cookiebot
Cookiebot CMP customizable cookie text.

Users might see it as a cookie warning message, but the intent is not to worry visitors, but rather to show how you respect their privacy and how it is integrated in your website's functions, just as the advertisements and analytics are.

Keep the cookie text brief, accurate, and clear. Legal jargon is harder for the average visitors to understand and does not foster trust.

Your cookie text should comply with data privacy regulations and laws based on the location of the visitor whose data you’re collecting. Under the GDPR and Brazil’s General Data Protection Law (LGPD), it should comply with opt-in consent best practices. Under U.S. data privacy laws like the CCPA and Virginia Consumer Data Protection Act (VCDPA), it should comply with opt-out consent best practices.

It’s important to be familiar with all relevant data protection laws in jurisdictions where your visitors reside, and many companies doing business globally may need to comply with multiple different laws. This can make geolocation functionality in a consent management solution very valuable.

Regardless of where the visitors is, there are some best practices that are common for all cookie banner text.

  • Keep it simple: Use straightforward language that any visitors can understand even without legal or technical knowledge. Keep the cookie text short so that users will read the whole thing to make an informed decision about allowing cookies or not.
  • Specify purposes: Explicitly state why you use cookies. Here is the Cookiebot™ website’s cookie consent message example that says, “We use cookies to personalise content and ads, to provide social media features and to analyze our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.” The cookie text makes it clear that Cookiebot™ uses marketing cookies (personalizing content and ads, personalizing social media features) and analytics cookies (analyzing site traffic), and that it shares the data collected with third-party partners.
  • Use clear labeling: For valid consent, the option, like a button, to consent to data collection should be unambiguous, like displaying “Accept”. Note that if the visitors is being asked to “Accept/Allow all”, they must be able to easily learn what “all” cookies they’re agreeing to, and also have the option of providing granular consent, rather than to “all”.. Similarly, the button to reject data collection should say “Reject” or “Deny”. Both the “Accept” And “Reject” options must be equal in appearance and accessibility to be valid consent options.
  • Link to policy: Like the information about cookie usage on your website, the link to your cookies policy should also be written in clear language so that visitors know where the link will take them.
  • Opt out information: Visitors must have the right to withdraw consent at any time, and the cookie banner text should inform them of the procedure to do this.
  • Do not sell information: The CCPA requires the specific language “Do Not Sell or Share My Personal Information” to be included on the cookie banner. This is mandatory for cookie consent from California residents.

Cookiebot CMP can be added to a website with a few lines of JavaScript. Once installed, it automatically scans and catalogs every cookie and tracking technology in use, so there's no manual audit to maintain.

For visitors covered by the GDPR, the CMP blocks all cookies and tracking scripts from firing until the visitor has given consent, so nothing collects data ahead of time. For visitors covered by the CCPA/CPRA, the same scan instead populates a cookie declaration listing every tracker found, along with the required "Do Not Sell or Share My Personal Information" link, so California residents can exercise their opt-out rights directly from the banner.

Subscribing to Cookiebot CMP helps support both of these requirements without needing to build or maintain that tracking inventory by hand.

The words on your banner do more than inform visitors. For many advertisers, they now decide what data Google's own platforms are permitted to receive at all. Since March 2024, sites running Google Ads, Analytics, or Floodlight tags in the EEA and UK have needed Google Consent Mode in place, which reads the choices a visitor makes on your cookie banner and passes them to Google as signals rather than letting tags fire unconditionally.

That makes the accuracy of your cookie text more than a legal matter as it now shapes ad measurement and remarketing eligibility directly. A banner that mislabels its cookie categories, or a CMP that doesn't translate consent choices into the right signals, can quietly degrade conversion tracking even on a site whose banner is otherwise compliant. Cookiebot CMP integrates with Google Consent Mode v2 out of the box, mapping accepted and rejected categories from your cookie text to the correct signals automatically, without extra configuration on your part.

For implementation specifics, the Google Consent Mode resource hub covers the setup in full.

Many visitors have stopped reading cookie banners altogether. Faced with a pop-up on nearly every site they visit, people default to clicking whatever makes it disappear fastest: usually "Accept All." This reflex, often called consent fatigue, is understandable. It is also precisely the behavior regulators are now scrutinizing directly, because a banner that relies on it is collecting exhaustion, not valid consent.

That distinction has real financial consequences. On September 1, 2025, France's data protection authority, the CNIL, fined Google EUR 325 million for placing advertising cookies during account creation without valid consent, and fined Shein 150 million the same day for a banner that kept setting tracking cookies even after visitors clicked "Reject All." Neither case turned on what the cookies did, but rather on whether the consent behind them was real.

This is the pattern behind most current enforcement. A "Reject" option that's technically present but visually buried, a rejection that doesn't actually stop tracking, or a banner that never mentions who the data is shared with. The EDPB's guidance on dark patterns treats these as compliance failures in their own right, not just poor design choices.

The practical takeaway for your own cookie text and banner is this: giving visitors a genuine, equally weighted choice between accepting and rejecting is the difference between a banner that holds up under scrutiny and one that doesn't. Cookiebot CMP builds "Accept" and "Reject" with equal visual prominence by default and enforces reject choices at the script level, so a decline actually stops the trackers it's meant to, removing the exact failure points that led to the fines above.

Try Cookiebot™ for yourself and see how easy it is to set up cookie texts and manage consent. Free for 14 days.

Frequently asked questions

A cookie text or cookie message is the informative part of a website's consent banner. In the EU, the ePrivacy Directive requires websites to obtain consent before setting non-essential cookies, while the GDPR sets the standard for how that consent must be given, informing visitors what data is collected, how, for what purposes, and with whom it's shared.

Under the GDPR, valid consent must be a clear, affirmative action by the visitor. This requires an unambiguous indication of their wishes, not something inferred from silence or continued browsing. In the EU, the ePrivacy Directive requires websites to obtain this consent before activating any non-essential cookies or trackers; only strictly necessary cookies, needed for a site to function correctly, are exempt.

Under the GDPR, personal data is any kind of information that can identify a living individual, either directly or indirectly. This includes names, postal addresses, location data from phones, online identifiers such as IP addresses, unique IDs in cookies, search and browser history, etc.

Learn more about GDPR compliance

For cookies specifically, your website must inform visitors about the cookies and trackers in use and get their consent before any non-essential ones are activated. A consent management platform like Cookiebot CMP can help support this part of GDPR compliance by collecting and recording that consent,  though full GDPR compliance also depends on other factors, like how you handle data subject requests and retention.

You can use a consent management platform like Cookiebot CMP to collect consent from visitors. Cookiebot CMP displays a cookie consent banner on a visitor's first visit, or whenever consent is needed for a new purpose. You can use the cookie message provided or customize it with your own text. If you run a WordPress site, the Cookiebot WordPress plugin adds this to your site directly.

When writing your cookie banner text, it's important to use language visitors can understand and to help support your cookie banner's compliance with applicable law. Use simple, direct language to explain why you're using cookies. Make the consent and rejection options unambiguous, with equally clear labels like "Accept" and "Reject." Include a clear link to your cookie policy or privacy policy for visitors who want more detail, and specify how they can change their preferences later. If targeting California residents, include the CCPA-required phrase, "Do Not Sell or Share My Personal Information.