Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (2024)

After the General Data Protection Regulation or GDPR came into being in 2018, a lot of things changed on the internet. One of the after-effects is the prevalence of cookie popups and banners on websites. If you are looking to add a cookie popup to your website, you are in the right place!

With CookieYes, you can implement a custom cookie popup on your website in just minutes. You can choose a cookie consent popup from different layouts, themes, colours, in over 30 languages and curate a personalized consent experience for your user.

Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (1)

What is a cookie popup?

A cookie popup is a banner that is displayed on websites to ask visitors for consent for the use of cookies. That way, the user will be aware of the website’s cookie usage and provide active consent.

Cookie popups fulfil the GDPR requirement to obtain consent for setting cookies on a user’s device. Cookies fall under the category of personal data as per the GDPR. To process any personal data, businesses have to obtain consent from the user. This means, before dropping cookies on a user’s device, they should consent to it.

Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (2)Explore different cookie popup layouts

Cookie popup examples

Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (3)
Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (4)
Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (5)
Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (6)

Best practices for cookie popup

  • Provide the option to accept and reject cookies so users have an active choice. (Cookie walls are not GDPR compliant)
  • Ensure that the popup is mobile-responsive and is user-friendly on different devices.
  • Link your cookie policy or privacy policy on the cookie popup so that there’s clear information provided.
  • Block third-party cookies until the user gives consent.
  • If you have visitors outside the EU, you may geo-target the popup for users from the EU and UK alone.

Display cookie popup and
get GDPR compliant in no time

Try for free

14-day free trialCancel anytime

What is GDPR cookie consent?

To be GDPR compliant, consent should meet the standards as defined in the GDPR. Article 4(11) defines consent:

Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Freely given i.e. the user must have an active choice and consent should be voluntary i.e. consent should not be made conditional for using your website. This means the user should have the choice to accept and reject cookies.

Specific i.e. consent should be obtained for a specific purpose and cannot be vague, or ambiguous. Cookie consent cannot be bundled with other terms and conditions or privacy policies. You should obtain explicit consent prior to loading cookies on a user’s device.

Informed i.e. the user should be made aware of cookies on your website, their purpose and what they are consenting to.

Affirmative action indicates that the user has taken an action to give consent such as clicking on the accept button. This means implied consent is not valid. You cannot assume consent if a user continues browsing without taking an action on your cookie banner or popup.

How to add a cookie popup on a website?

You can easily generate a cookie popup or cookie banner with a consent management platform (CMP) like CookieYes. The CookieYes CMP is used by over 1 million websites, big and small, to comply with data privacy regulations across the globe. You don’t need knowledge of coding or time-consuming integrations to add a GDPR compliant cookie consent popup to your website.

Step 1. Sign up on CookieYes

The first step is to Sign up on CookieYes and start your 14-day free trial. You don’t need a credit card. All you have to do is fill in your email address, your website domain and password. You can start generating your cookie popup!

Step 2. Customize the cookie popup

On signing up, you will be directed to a setup screen. Here you can select a cookie popup template and fully customize it.

  • Layout: Select the cookie popup layout or other layouts such as box type or banner.
  • Content: Customize the cookie popup text, button texts, content of the audit table and also add a link to your privacy policy/cookie policy.
  • Languages: Choose from 30+ languages for an auto-translated cookie popup.
  • Colour: Customize the colour of the cookie popup as well as the text to match your site’s design.
  • Behaviour: Add a cookie widget to revisit consent, geo-target the banner for EU and UK users.
  • CSS customizations: Add CSS customizations to stylize the banner and modify its functionality.

Help Guide: How to add a cookie banner on your website

Step 3. Activate your cookie popup

After you are done with the customization of the cookie popup or banner, activate it on your website. Copy the script and paste it between the <head> and </head> tags on your website. (access the website platform or CMS setup guides for detailed instructions). You are all done! You now have a GDPR-compliant cookie popup on your website.

Cookie consent checklist

Using CookieYes, you can tick off the GDPR cookie consent checklist below!

  • Collect consent for using cookies on your website with a cookie popup or banner
  • Give users control to accept, decline or change cookie settings
  • Customize the cookie popup for content, colours, design
  • Display a responsive cookie popup for desktop and mobile devices
  • Show cookie table (name, type, purpose and duration) for full disclosure of cookies
  • Show auto-translated banner to users as per their browser language
  • Auto-block third-party cookies from loading till the user gives consent
  • Record all user consents for proof of compliance
  • Add a callback widget for the banner so users can revoke consent at any time

Cookie consent banners can come in different layouts and styles. You can use a layout as per your website’s design. Here are the different types that can be implemented using the CookieYes CMP. In terms of layout, the cookie banners should be simple and easy to use so that it does not interrupt the content or user experience of the website.

Popup

The cookie popup layout is designed to grab the user’s attention as they cannot access the website without taking any action on the popup. So, ensure that they are GDPR compliant and easy to use.

Banner

Footer or header banners are most commonly used by websites. In a study of consent banners in the EU, nearly 58% used bottom banners and 27% used top banners. Ensure that your banners don’t block elements like the navigation menu (in the case of a header banner).

Box-type

Box-type layouts are also often seen on websites and are placed in the left or right corner of the site. These types of banners are non-intrusive and can be aligned to the site’s aesthetic.

FAQ on cookie popup

Is a cookie popup necessary?

Yes, a cookie popup or banner is necessary if you are a website that functions in any of the EU countries and the UK or has visitors from these countries. Websites in the EU are also bound by the ePrivacy Directive or EU cookie law. (Read more on EU cookie law).

Data privacy laws and directives like the LGPD (Brazil), POPIA (South Africa), CNIL (French), CCPA (US) also have consent requirements. This meansif your website has visitors from these countries, you can be subject to the respective privacy regulations. Therefore, it is the best practice to add a compliant cookie popup or banner on your website.

What does GDPR say about cookies?

GDPR categorizes cookies and similar online identifiers as personal data. Since these identifiers can be used in combination to identify a user’s device and hence the user, they are considered as personal data.

Cookies are mentioned only once in the GDPR’s Recital 30, which states that:

“Natural persons may be associated with online identifiers … such as internet protocol addresses, cookie identifiers or other identifiers….This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.”

Why do websites warn about cookies?

Websites show cookie warnings and cookie notifications to obtain consent from users for dropping it on their devices. When we visit websites, cookies are loaded on our devices. In the EU, the use of cookies has been regulated by the ePrivacy Directive or the EU cookie law which requires websites to get consent for the use of cookies other than strictly-necessary ones.

After the arrival of GDPR, cookie consent requirements are legally binding. Hence websites use cookie consent banners or cookie popups to fulfil GDPR compliance regarding cookies.

What should cookie banner say?

A cookie banner should inform users about cookies on the website and their purposes in brief and ask for consent from the users. A banner should clearly provide users with the option to accept and reject cookies, and also to give granular consent through cookie settings. It should also provide detailed information on cookies by linking to the cookie or privacy policy.

Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes (2024)

FAQs

Cookie Popup for GDPR Cookie Consent: Best Practices - CookieYes? ›

Cookie banners should clearly state why cookies are used, the types of cookies in operation (including third-party cookies), and how users can accept, reject, or customize their preferences. It's also a best practice to provide a direct link to the website's cookie policy for users who wish to learn more.

What is the best practice of cookie consent banner? ›

Cookie banners should clearly state why cookies are used, the types of cookies in operation (including third-party cookies), and how users can accept, reject, or customize their preferences. It's also a best practice to provide a direct link to the website's cookie policy for users who wish to learn more.

Do I need a cookie consent popup? ›

Yes, if your website uses cookies.

GDPR and most other privacy laws require that you disclose to visitors what information you collect from them, such as their personal data and what you do with this information. If you use cookies to collect data from your site users, then you must have a cookie policy.

What is the GDPR compliant cookie consent banner? ›

To be compliant with the GDPR, your cookie banner must provide information about the cookies used on the website, use clear and concise language, link to your Privacy Policy, be responsive, provide granular cookie consent control, and do not diminish the user experience.

Does GDPR require a cookie banner? ›

Even if your website is not based in the EU, but caters to users from the EU, you will have to comply with the GDPR. This means that your website is required to display a cookie consent banner.

What is the best practice for cookie pop up? ›

Best Practices for Cookie Popup Design

This can be done through a banner or a popup window. Secondly, cookie popups should provide clear and concise information about the types of cookies used and their purposes. It is important to use plain language that is easily understandable by the average user.

What is the cookie consent strategy? ›

There are a few different ways to obtain cookie consent, but one of the most common methods is to display a notice on your website that explains what cookies are and why you're using them. Visitors can then choose to accept or reject the use of cookies.

How do I create a cookie consent pop up? ›

How to Create Cookie Consent Popup?
  1. Choose a positioning that you want to present your cookie consent popup. ...
  2. Decide on the colors of your cookie consent.
  3. Edit the text of it. ...
  4. Set a display time for the cookie consent.

What are the different types of cookie consent banners? ›

There are three primary types of cookie banners: notice-only, opt-in, and opt-out. While there are variations within each type, these broadly represent the general approaches to obtaining user consent for the use of cookies on a website.

What are the guidelines for cookie consent? ›

The rules state that users must be made aware of what their data will be used for and that they must give informed consent before their data can be stored. Users have to be told exactly why they need to accept cookies and what (if any) benefit they will gain from doing so.

How do I use GDPR cookie consent? ›

How do you set GDPR cookie consent? You need to implement a cookie banner and obtain consent for cookie use to set GDPR cookie consent on your website. This involves collecting valid consent (freely given, specific, informed and unambiguous), recording proof of consent and providing the ability to withdraw consent.

What is the difference between GDPR and CCPA cookie consent? ›

The GDPR requires websites to obtain explicit consent from users before placing cookies on their devices. If your website targets visitors in California, you must comply with the CCPA/CPRA. The CCPA/CPRA requires businesses to provide California residents with access to their personal data and allow them to delete it.

Which countries require cookie banners? ›

The countries and regions that have specific cookie requirements are the European Union, Canada, the UK, and the United States. As a general rule, it's best to meet the expectations for each requirement regardless of whether your business is physically located in those jurisdictions or not.

What should cookie consent say? ›

This website collects cookies to deliver better user experience” “We collect cookies to analyze our website traffic and performance; we never collect any personal data” “Cookies help us display personalized product recommendations and ensure you have great shopping experience”

What is the best practice for cookie session? ›

Website owners should follow best practices such as providing clear and concise cookie policies, using secure cookies, and minimizing the amount of information stored in cookies. They should also provide users with the ability to opt-out of certain types of cookies. Privacy tip: Take control of your online data!

How do you give consent to cookies? ›

Consents must be freely given, i.e. not nudged or coerced in any way. Consent must be informed, i.e. users must have access to relevant cookie information and know what they are consenting to. Visitors must be able to change or withdraw consent as easily as they gave it.

Top Articles
Latest Posts
Article information

Author: Margart Wisoky

Last Updated:

Views: 6303

Rating: 4.8 / 5 (58 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Margart Wisoky

Birthday: 1993-05-13

Address: 2113 Abernathy Knoll, New Tamerafurt, CT 66893-2169

Phone: +25815234346805

Job: Central Developer

Hobby: Machining, Pottery, Rafting, Cosplaying, Jogging, Taekwondo, Scouting

Introduction: My name is Margart Wisoky, I am a gorgeous, shiny, successful, beautiful, adventurous, excited, pleasant person who loves writing and wants to share my knowledge and understanding with you.