How to create a compliant and user-friendly website cookie notice

Learn how to create a compliant, user-friendly website cookie notice under the ePrivacy Directive, GDPR, and CCPA, and see what belongs in a valid notice.

SA
Sam AlexanderKetch product and strategy team
Read time
6 min read
Last
Updated

Summarize this article with

A website cookie notice is the banner that informs visitors about a site's use of cookies and secures their consent before placing them. Cookie placement is governed by the ePrivacy Directive and national laws implementing it, not by GDPR directly; GDPR governs what happens to personal data once cookies collect it.

As companies and brands expand their online presence, they take on more exposure to privacy regulation, and cookies sit at the center of that exposure. Cookies are small data files that websites use to collect and store information about visitors. They improve the browsing experience in plenty of legitimate ways, but placing them on a visitor's device triggers specific legal notice-and-consent requirements that vary by jurisdiction.

A website cookie notice is the banner or notification that tells visitors a site uses cookies, explains what those cookies do, and lets them accept, reject, or customize their choice before non-essential cookies are placed. Getting the legal basis for that notice right requires understanding two separate layers of law, which the rest of this piece walks through.

Cookie compliance is often described as a single obligation, but it's really governed by two distinct legal frameworks that work together:

  • The ePrivacy Directive (2002/58/EC, as amended), implemented into national law by each EU member state (and by similar frameworks like the UK's PECR), governs the act of placing or reading information on a person's device, cookies included. This is the layer that actually requires prior consent before most cookies can be set.
  • GDPR governs what happens to personal data once it exists, including any personal data a cookie collects, transmits, or helps generate. GDPR doesn't directly regulate the act of placing a cookie on a device; it regulates the processing of the personal data that results.

In practice, a cookie banner has to satisfy the ePrivacy consent requirement before non-essential cookies load, and any personal data that flows from those cookies then falls under GDPR's rules for lawful basis, purpose limitation, and data subject rights. A cookie notice that only cites GDPR, without the ePrivacy consent requirement doing the actual gatekeeping, is missing the layer of law that governs the cookie itself. Getting both layers right, not just one, is what real cookie compliance looks like in practice.

You need a cookie notice if your website places cookies (or similar tracking technologies) on visitor devices, especially if you serve visitors in the EU/UK, California, or other jurisdictions with cookie-specific or comprehensive privacy laws. The notice has to inform visitors about what's being placed, secure valid consent where required, and give visitors a way to change their choice later.

Read more: Do I need a cookie policy on my website?

Want the fastest path to a compliant banner? Set up a free cookie banner and start collecting consent in minutes.

ePrivacy Directive and national implementations (EU/UK)

The ePrivacy Directive, and the national laws that implement it, require prior, informed consent before a website can place most cookies on a visitor's device. Consent has to come from a clear, affirmative action; continuing to browse the site doesn't count as valid consent. A compliant notice under this layer includes:

  • A clear accept option and an equally prominent reject option.
  • Plain-language information on what each cookie category does.
  • A link to granular cookie settings, so visitors can accept some categories and reject others.
  • Disclosure of any third parties that receive data through cookies.

Read more: What are some GDPR cookie consent examples?

GDPR (EU General Data Protection Regulation)

Once cookie consent is secured, GDPR governs the personal data those cookies collect or generate, such as an identifier used for analytics or advertising. A compliant program layers GDPR obligations on top of the ePrivacy consent flow: a documented lawful basis for the resulting processing, purpose limitation, and honoring data subject rights like access and erasure for any personal data the cookies touch.

CCPA (California Consumer Privacy Act)

CCPA takes an opt-out approach rather than the EU's opt-in model. It requires businesses to disclose what data they collect and to let California residents opt out of the sale or sharing of their personal information. Cookie notices built for CCPA need:

  • Clear disclosure of what data is collected through cookies and how it's used.
  • A "Do Not Sell or Share My Personal Information" option.

Read more: Is your cookie consent banner compliant with privacy laws?

Why the distinction matters in practice

France's data protection authority, CNIL, fined Orange €50 million after finding that the company continued reading cookies on users' devices even after they had withdrawn consent, a failure of the underlying consent mechanism the ePrivacy framework requires, not a GDPR processing violation on its own. Getting the two layers backward, treating GDPR consent language as sufficient for cookie placement, is exactly the kind of gap that leads to enforcement action.

  • Draft clear, informative text. Explain what cookies you use and why, in plain language a visitor doesn't need a law degree to follow.
  • Design the banner for real choice. Make accept and reject equally easy to find; a banner that buries "reject" behind extra clicks undermines the consent it's supposed to collect.
  • Implement the notice with a consent management platform. A platform that ties banner choices to actual enforcement (blocking cookies until consent is given, respecting rejections across sessions) closes the gap between what the notice promises and what the site actually does.
  • Test and maintain it. Cookie inventories drift as marketing and analytics tags change, so retest the banner and its enforcement periodically, not just at launch.

Read more: How to add cookie messages to your website

  • Use plain language. Avoid legal jargon that obscures rather than informs.
  • Offer a genuine choice. Visitors should be able to accept, reject, or customize cookie categories, not just accept.
  • Keep it visible without disrupting the experience. The notice should be noticeable but shouldn't block the page.
  • Update the notice as cookies and laws change. A stale cookie notice describing cookies you no longer use (or missing ones you've added) is itself a compliance gap.

Read more: What to look for in a cookie banner

Your cookie notice should explain what cookies are, what types are used, their purpose, and whether third parties have access to collected data. It should also inform users about their rights, how to manage or reject cookies, and link to your full cookie policy for more details.

A compliant cookie notice should include, at minimum:

Element Purpose
What cookies are and why the site uses them Basic transparency required under ePrivacy and GDPR
Cookie categories in use (essential, analytics, marketing, etc.) Lets visitors make an informed, granular choice
Whether third parties receive cookie data Required disclosure under both legal layers
Accept, reject, and customize options Satisfies the "active choice" requirement under ePrivacy
A link to the full cookie policy Gives visitors somewhere to find complete detail
A way to change cookie preferences later Required for ongoing compliance, not just first visit

Today, most, if not all, websites use cookie notices. This is vital in ensuring that they meet cookie compliance requirements under ePrivacy and GDPR. To meet these requirements, cookie notices should include the following elements:

  • The cookie notice must clearly inform users that the website uses cookies and why it uses cookies.
  • Cookie notice text must be in plain and easy-to-understand language.
  • It should allow users to accept or reject cookies based on their preferences.
  • The notice should offer a way for users to change their cookie preferences at any time.

A look at various website cookie notice examples can give us a clear picture of how they incorporate these elements into their cookie notices.

Google

Take, for example, Google's cookie banner. It provides a clear message about cookies and offers users options to customize or accept the default settings. This gives visitors control over their data, which is a principle both the ePrivacy consent requirement and GDPR's data subject rights are built around.

SeatGeek's website cookie notice example

Cookie notice and compliance go hand in hand. Website cookies enhance compliance by informing users about how the website collects and uses their data and giving users control by allowing them to decide whether or not to accept cookies.

Therefore, companies must strive to achieve cookie notice compliance by implementing cookie notice best practices and continuously updating their notices based on different data privacy laws.

Keep reading

FAQs

Next step

Retire your cookie banner for true compliance

Start free with the full-feature CMP, then expand into the full Permissioning layer, with consent collected, enforced, and audited everywhere.

Get Started Free

Get started in less than 5 min