{"id":1041,"date":"2020-10-27T13:04:00","date_gmt":"2020-10-27T13:04:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=1041"},"modified":"2026-03-12T09:15:05","modified_gmt":"2026-03-12T08:15:05","slug":"cookie-texts","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/cookie-texts\/","title":{"rendered":"Cookie policy texts"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-what-is-a-cookie-text-or-cookie-message\">What is a cookie text or cookie message?<\/h2>\n\n\n\n<p>The <em>cookie text<\/em> or <em>cookie message<\/em> is the actual written content displayed by cookie consent banners that communicate to a website's users about its use of cookies. It's not the cookies\u2019 text files themselves that are referred to here.<\/p>\n\n\n\n<p>The cookie text is also not the same thing as a <a href=\"\/en\/cookie-policy\/\"><em>cookie policy<\/em><\/a> text or <em>cookie policy message<\/em>, which are terms for policy statements about the overall strategy and position of a company regarding the privacy of its users.&nbsp;<\/p>\n\n\n\n<p>Here's an example of a good and informative cookie notice text (on a GDPR-compliant banner):<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"\/media\/4333\/consent_en.png?width=500&amp;\" alt=\"Cookieboot Pop Up Banner - Cookiebot\" width=\"770px\" height=\"449px\"\/><figcaption class=\"wp-element-caption\">The GDPR-compliant Cookiebot CMP cookie consent message and its cookie consent text.<\/figcaption><\/figure>\n\n\n\n<p>The <a href=\"\/en\/cookie-banner\/\">cookie consent banner<\/a> is a familiar sight on many websites today, since the GDPR came into force in Europe and many other data privacy laws have been enacted around the world.<\/p>\n\n\n\n<p>However, there are many ways that websites choose to declare their cookies and tracking. There are many different cookie messages on websites, too.<\/p>\n\n\n\n<p>A cookies agreement message targeted at the EU for GDPR compliance should not only state that your website uses cookies and be accompanied only by an \u201cokay\u201d or \u201caccept\u201d button. That does not enable valid consent, as users do not have equal access to an option to decline cookie usage.<\/p>\n\n\n\n<p>Many cookie messages (in fact many cookie banners as a whole) are still noncompliant with the GDPR or other laws because they leave no real choice of consent for the user and explain poorly how their personal data is collected by the website and used.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-edpb-guidelines-on-valid-consent\">EDPB guidelines on valid consent<\/h3>\n\n\n\n<p><a href=\"https:\/\/www.cookiebot.com\/en\/edpb-guidelines\/\">The European Data Protection Board (EDPB)<\/a> is the leading authority on the GDPR in the EU, and its main job consists of adopting guidelines and making decisions on how the GDPR is to be interpreted and enforced by the national data protection authorities in each EU country.<\/p>\n\n\n\n<p>The <a href=\"\/en\/edpb-guidelines\/\">EDPB guidelines<\/a> clarify that:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"wp-block-list has-background\">\n<li>Pre-ticked checkboxes on cookie banners are noncompliant. Checkboxes must always be deselected by default, except for the use of strictly necessary cookies, which don\u2019t require user consent.<\/li>\n\n\n\n<li>Scrolling, ignoring a <a href=\"\/en\/cookie-banner\/\">cookie banner<\/a>, or other continued use of a website is not considered valid <a href=\"\/en\/cookie-consent\/\">cookie consent<\/a>. Users must give a clear and affirmative consent, not an implied or assumed consent.<\/li>\n\n\n\n<li class=\"cb-rounded\">Cookie walls (consent conditional for access to a website) are noncompliant.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookies-text-for-gdpr-compliance\">Cookies text for GDPR compliance<\/h2>\n\n\n\n<p>The GDPR mandates that all websites that collect personal data from EU-based visitors have to:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"wp-block-list cb-rounded has-background\">\n<li>obtain <strong>clear and unambiguous<\/strong> <strong>consent <\/strong>from users<\/li>\n\n\n\n<li><strong>consent must be obtained<\/strong> <strong>prior<\/strong><em> <\/em>to any collection or processing of personal data<\/li>\n\n\n\n<li><strong>after<\/strong> <strong>specifying all types of cookies<\/strong><em> <\/em>and <strong>other tracking technologies<\/strong><em> <\/em>present and operating on the site<\/li>\n\n\n\n<li>use easy to understand language<\/li>\n\n\n\n<li>enable users <strong>to consent and to change or revoke consent<\/strong><em> <\/em>on each specific category of cookies at any time<\/li>\n\n\n\n<li><strong>safely, confidentially, and securely<\/strong> <strong>document<\/strong><em> <\/em>each user consent<\/li>\n\n\n\n<li>renew consent annually, or as often as required by relevant laws, e.g. some national data protection guidelines recommend more frequent renewal, like every 6 months<\/li>\n<\/ul>\n\n\n\n<p>The \u201c<strong>clear and unambiguous prior consent<\/strong>\u201d is part of users\u2019 option to opt-in or opt-out of the different cookie categories (preferences, statistics, marketing) at a granular level. <strong>Specifying all types of cookies<\/strong> is done in the cookie declaration and depository, which is the comprehensive overview of all known cookies and their purpose.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/en\/TXT\/?uri=CELEX%3A32016R0679\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR<\/a> also mandates that your website must <strong>inform<\/strong> its users <strong>in easy to understand ways<\/strong> and thus <strong>enable users to consent and to revoke consent.<\/strong><\/p>\n\n\n\n<p>This is where the <strong>cookies text<\/strong> or <strong>cookies message<\/strong> comes in. It is the point at which you must provide specific information about <a href=\"\/en\/tracking-cookies\/\">tracking cookies<\/a> on your website and its purposes.<\/p>\n\n\n\n<p>How you do it can make a real difference for your users, and empower them with real, informed choice of consent, building trust with your company.An example of our <a href=\"\/en\/cookie-scripts\/\">cookie scripts<\/a>:<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-default\"><img decoding=\"async\" src=\"\/media\/3570\/skaermbillede-2019-06-04-kl-115505.png?width=500&amp;\" alt=\"Cookie message scripts screenshot - Cookiebot\" width=\"584px\" height=\"208px\"\/><figcaption class=\"wp-element-caption\">Cookie agreement message scripts load the cookie consent banner with its cookie notice text.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookies-text-for-ccpa-compliance\">Cookies text for CCPA compliance<\/h2>\n\n\n\n<p>The CCPA regulates how businesses are allowed to process and sell the personal data of California residents. It has been amended and expanded with the <a href=\"\/en\/cpra\/\">California Privacy Rights Act (CPRA)<\/a> coming into effect in July 2023.<\/p>\n\n\n\n<p>The CCPA\/CPRA are different from the European GDPR because they don't require organizations to obtain prior consent before the collection and processing of personal data in many cases. There are exceptions, like when the personal data is that of children, for example.<\/p>\n\n\n\n<p>The CCPA\/CPRA states that businesses must inform users of what categories of personal information their websites collect (e.g. through cookies), for what purpose and which third parties it may be shared with or sold to.<\/p>\n\n\n\n<p>The CCPA\/CPRA also requires websites to implement a \u201c<strong>Do Not Sell or Share My Personal Information\u201d<\/strong> link through which users can opt out of having personal information sold to third parties, like Google and Facebook. Users can allow access to their personal data, but if they change their minds later they must be able to revoke consent, and then sharing or sale of their personal data must cease.<\/p>\n\n\n\n<p>The legal requirements are the same for the cookie text in California, i.e. informing users what cookies and tracking technologies are in use, for what purposes, and with whom it is shared.<\/p>\n\n\n\n<p>Websites targeting Californian users for CCPA\/CPRA compliance may not use a cookie consent banner (as shown above), but a cookie declaration including the required opt-out link.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"\/media\/4337\/ccpa_main_en.png?width=500&amp;\" alt=\"Cookiebot CCPA compliant cookie declaration screenshot - Cookiebot\" width=\"770px\" height=\"353px\"\/><figcaption class=\"wp-element-caption\">A CCPA\/CPRA-compliant cookie text with the mandatory \u201cDo Not Share Or Sell My Personal Information\u201d link integrated by Cookiebot CMP.<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookies-message-examples\">Cookies message examples<\/h2>\n\n\n\n<p>The primary function of a cookies text is to inform the users of the following:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"wp-block-list cb-rounded has-background\">\n<li>which cookies and trackers you use<\/li>\n\n\n\n<li>why you use them<\/li>\n\n\n\n<li>who you share personal with or which third parties you sell or disclose it to<\/li>\n\n\n\n<li>how users can provide and revoke consent or opt out, depending on the law<\/li>\n<\/ul>\n\n\n\n<p>The cookie text or cookie message is the main way of communicating to your visitors that you use analytics or marketing cookies, for example, to make your website and its services better and provide better user experiences, while at the same time protecting user privacy, giving them a real choice of how their data is used.<\/p>\n\n\n\n<p>It is this balancing act that the cookie notice text is meant to express, making your users understand that you use cookies to optimize their website experience, while at the same time making sure that you protect their privacy.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"\/media\/3577\/cookie-banner-content-example.png?width=500&amp;\" alt=\"Screenshot of Cookiebot CMP customizable cookie text - Cookiebot\" width=\"608px\" height=\"398px\"\/><figcaption class=\"wp-element-caption\">Cookiebot CMP customizable cookie text.<\/figcaption><\/figure>\n\n\n\n<p>Users might see it as a cookie warning message, but the intent is not to worry users, but rather to show how you respect their privacy and how it is integrated in your website's functions, just as the advertisements and analytics are.<\/p>\n\n\n\n<p>Keep the cookie text brief, accurate, and clear. Legal jargon is harder for the average user to understand and does not foster trust.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-best-practices-for-a-legally-compliant-cookie-banner-text\">Best practices for a legally compliant cookie banner text<\/h2>\n\n\n\n<p>Your cookie text should comply with data privacy regulations and laws based on the location of the user whose data you\u2019re collecting. Under the GDPR and <a href=\"\/en\/lgpd\/\">Brazil\u2019s General Data Protection Law (LGPD)<\/a>, it should comply with opt-in consent best practices. Under US data privacy laws like the CCPA and Virginia Consumer Data Protection Act (VCDPA), it should comply with opt-out consent best practices.<\/p>\n\n\n\n<p>It\u2019s important to be familiar with all relevant data protection laws in jurisdictions where your users reside, and many companies doing business globally may need to comply with multiple different laws. This can make geolocation functionality in a consent management solution very valuable.<\/p>\n\n\n\n<p>Regardless of where the user is, there are some best practices that are common for all cookie banner text.<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"wp-block-list cb-rounded has-background\">\n<li><strong>Keep it simple: <\/strong>Use straightforward language that any user can understand even without legal or technical knowledge. Keep the cookie text short so that users will read the whole thing to make an informed decision about allowing cookies or not.<\/li>\n\n\n\n<li><strong>Specify purposes: <\/strong>Explicitly state why you use cookies. Here is the Cookiebot\u2122 website\u2019s cookie consent message example that says, \u201cWe use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you\u2019ve provided to them or that they\u2019ve collected from your use of their services.\u201d The cookie text makes it clear that Cookiebot\u2122 uses marketing cookies (personalizing content and ads, personalizing social media features) and analytics cookies (analyzing site traffic), and that it shares the data collected with third-party partners.<\/li>\n\n\n\n<li><strong>Use clear labeling: <\/strong>For valid consent, the option, like a button, to consent to data collection should be unambiguous, like displaying \u201cAccept\u201d. Note that if the user is being asked to \u201cAccept\/Allow all\u201d, they must be able to easily learn what \u201call\u201d cookies they\u2019re agreeing to, and also have the option of providing granular consent, rather than to \u201call\u201d.. Similarly, the button to reject data collection should say \u201cReject\u201d or \u201cDeny\u201d. Both the \u201cAccept\u201d And \u201cReject\u201d options must be equal in appearance and accessibility to be valid consent options.<\/li>\n\n\n\n<li><strong>Link to policy:<\/strong> Like the information about cookie usage on your website, the link to your cookies policy should also be written in clear language so that users know where the link will take them.<\/li>\n\n\n\n<li><strong>Opt out information: <\/strong>Users must have the right to withdraw consent at any time, and the cookie banner text should inform them of the procedure to do this.<\/li>\n\n\n\n<li><strong>Do not sell information: <\/strong>The CCPA requires the specific language \u201cDo Not Sell or Share My Personal Information\u201d to be included on the cookie banner. This is mandatory for cookie consent from California residents.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-to-show-a-cookies-agreement-message-on-your-website\">How to show a cookies agreement message on your website<\/h3>\n\n\n\n<p>Subscribing to Cookiebot CMP enables easy, automatic privacy protection on your website for GDPR and CCPA\/CPRA compliance.<\/p>\n\n\n\n<p>Cookiebot CMP can be implemented on your website with a few lines of JavaScript.<\/p>\n\n\n\n<p>Once employed, it will automatically scan and find all cookies and tracking technologies in use, then block all activation and data collection until the end users have given consent\u2014in the case of GDPR compliance.<\/p>\n\n\n\n<p>For CCPA compliance, the cookie declaration, which is the automated result of the deep scan listing all cookies and trackers uncovered, includes the required \u201cDo Not Sell Or Share My Personal Information\u201d link to enable users to exercise their rights to opt out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-privacy-paradox-cookie-messages-vs-information-avoidance\">Privacy paradox: cookie messages vs information avoidance<\/h2>\n\n\n\n<p>Have you ever heard of the <strong>privacy paradox<\/strong>?<\/p>\n\n\n\n<p><a href=\"http:\/\/www.law.harvard.edu\/programs\/olin_center\/fellows_papers\/pdf\/Svirsky_81_revision.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">A recent study out of Harvard University tested the \u201cprivacy paradox\u201d<\/a>, i.e. how people express the importance of their privacy, yet act in ways that are in direct opposition to those supposedly strongly held beliefs.<\/p>\n\n\n\n<p>The experiment found that people are, indeed, inconsistent about their privacy. They are willing to pay for privacy, but they are also willing to trade off their privacy for small amounts of money.<\/p>\n\n\n\n<p>The study hints at an explanation too: <strong>people choose not to know<\/strong> about the consequences of their actions in order to obtain bonuses. It is known as \u201cinformation avoidance.\u201d People keep their heads in the sand and avoid information about how their behavior will affect their lives, even though on some level they know there are effects, which can be negative.<\/p>\n\n\n\n<p><em>\u201cEven people who are willing to pay to keep their Facebook data private also have a strong preference to avoid thinking about privacy in the first place\u201d<\/em>, <a href=\"https:\/\/www.nytimes.com\/2019\/06\/11\/opinion\/privacy-facebook-sexting.html?rref=collection%2Fseriescollection%2Fnew-york-times-privacy-project\" target=\"_blank\" rel=\"noreferrer noopener\">Dan Svirsky, the researcher behind the study said to the New York Times<\/a> and added that <em>\u201clots of people don't want to think about this stuff.\u201d<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"\/media\/3578\/kai-brame-258773-unsplash.jpg?width=434&amp;\" alt=\"Sign reading 'Please respect our neighbours' privacy' - Cookiebot\" width=\"770px\" height=\"516px\"\/><figcaption class=\"wp-element-caption\">The \u201cprivacy paradox\u201d makes it hard for us to keep our own privacy intact. Cookie notice texts and cookie agreement messages are real and concrete solutions here and now.<\/figcaption><\/figure>\n\n\n\n<p>In other words, the users of your website <em>do<\/em> care about their privacy, they just don't want to think about it all the time. This is an opportunity for companies to handle that work for users and build trust by doing so in a clear, easily accessible way.<\/p>\n\n\n\n<p>The <em>consent fatigue<\/em> <em>phenomenon<\/em> is a clear symptom of information avoidance. Your users just click at whatever pops up out of exasperation of constantly having to interact with cookie banners, especially when faced with confusing, noncompliant cookie messages and cookie texts.<\/p>\n\n\n\n<p>You, as the website owner, are undoubtedly aware of the weary and frustrated reaction of end users towards cookie banners online. <em>\u201cI just click accept, cause I'm so tired of seeing them\u201d<\/em>, is an all too common response in conversations on this subject matter.<\/p>\n\n\n\n<p>Cookiebot CMP saw this problem many years ago.<\/p>\n\n\n\n<p>That's why we developed the solution we have today. One that puts choice and control in the hands of users, but manages the complexities of data privacy for them.<\/p>\n\n\n\n<p><em>\u201cAnything that relies on people taking it upon themselves to protect their data is doomed\u201d<\/em>, <a href=\"https:\/\/www.nytimes.com\/2019\/06\/11\/opinion\/privacy-facebook-sexting.html?rref=collection%2Fseriescollection%2Fnew-york-times-privacy-project\" target=\"_blank\" rel=\"noreferrer noopener\">Svirsky argues to the New York Times.<\/a><\/p>\n\n\n\n<p>To respect the agency and autonomy of your users without putting the burden on them to protect themselves is not only the balance that ad blockers and private search browsers fail to strike, it's the very uniqueness of the Cookiebot CMP solution. The CMP not only enables data privacy compliance, it lies between website owners and visitors as an easily understandable badge of respect for privacy, transparency, and a demonstration of data compliance.<\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>What is a cookie text or cookie message? The cookie text or cookie message is the actual written content displayed by cookie consent banners that communicate to a website's users about its use of cookies. It's not the cookies\u2019 text files themselves that are referred to here. The cookie text is also not the same [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":12918,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1041","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2020\/10\/cookie_text_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1041","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=1041"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1041\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/12918"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=1041"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=1041"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=1041"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}