CCPA/CPRA
11 min read

CCPA Cookie Banner Requirements: What You Need to Know

By Safna|February 23, 2026
CCPA Cookie Banner Requirements: What You Need to Know

Tracking user behaviour online might sound technical, but for most websites, it’s just part of understanding what works- what pages people visit, what content they click, and how long they stay. These small insights help businesses improve, but they also come with big responsibilities when it comes to user privacy. That’s where the CCPA cookie banner requirements come in. More than just legal checkboxes, they’re an opportunity to show your visitors that you respect their choices and value their trust.

If your website welcomes visitors from California, this guide will break down what you need to know, without the jargon. Let’s make cookie compliance clearer, simpler, and better for everyone involved.

A cookie banner/cookie pop-up is a small notification that appears when someone visits your website. It tells users what cookies your site uses and gives them choices to accept, reject, or customise their cookie preferences.

Think of it as a front desk greeter for your site. Instead of tracking visitors silently, it introduces your data practices clearly, especially important under laws like CCPA/CPRA and GDPR.

CookieYes pre-built template for a CCPA cookie banner

The California Consumer Privacy Act does not explicitly require cookie consent for third-party cookies, nor a banner as such. However, websites must offer a simple, user-friendly, and symmetrical "opt-out" choice (Do not sell/share my personal information).

The CPPA, in ENFORCEMENT ADVISORY NO. 2024-02, advises that "The Enforcement Division reminds businesses to carefully review and assess their user interfaces to ensure that they are offering symmetrical choices and using language that is easy for consumers to understand when offering privacy choices. This includes user interfaces that businesses deploy through service providers, such as Consent Management Platforms (CMP).

CMP dashboard

This clearly means that the CPPA enforcers acknowledge cookie banners as a practical choice to perform their transparency and opt-out obligations regarding cookies.

Create a CCPA cookie banner for your website

Join CookieYes- Easy to use + no coding + advanced customisations

Create a banner
  • 14-day free trial
  • Cancel anytime

The California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), empower consumers to control how their personal data is collected, shared, and sold.

Unlike the GDPR, which focuses on opt-in consent, the CCPA emphasises the right to opt out, especially when it comes to selling or sharing personal information.

This difference makes CCPA cookie compliance unique. While some businesses try to cover both regulations with a single cookie banner for CCPA and GDPR, doing so without understanding the nuances can lead to compliance gaps and penalties.

In a room of 10 people, 9 would say online privacy is important to some degree

- Surfshark privacy survey

CCPA cookie notice obligations apply to for-profit businesses that:

  • Have annual gross revenues over $25 million,
     
  • Buy, receive, sell, or share the personal data of 100,000 or more California residents, or
     
  • Derive 50% or more of their annual revenue from selling or sharing personal information.

If your business falls under these criteria and uses cookies that collect personal data (especially for advertising or analytics), you must comply with the CCPA’s transparency and opt-out requirements.

The following are the must-haves in your CCPA cookie banner: 

A visible opt-out mechanism

The banner must include a direct link to the opt-out mechanism. This includes enabling users to reject the sale or share their data with third parties.

Therefore, your CCPA cookie banner must have a clear “Do Not Sell or Share My Personal InformationlinkThis opt-out option is central to CCPA cookie consent.

Visitors should also be able to manage their cookie preferences and data processing choices without any friction.

An example of an opt-out cookie banner as seen on AudioEye's website, with a "Do not track or share my personal information" link.

Transparent cookie categories

Split cookies into essential and non-essential types:

  • CCPA necessary cookies: These are required for core site functions (e.g., first-party session cookies).
     
  • Non-essential cookies: Include analytics cookies, social media trackers, and third-party cookies used for advertising or profiling.

Include clear descriptions so users know what they’re agreeing to—or opting out of.

Automatic cookie scans categorise cookies without manual effort.

Plain, user-first language

Avoid legalese. Tell users what you're collecting, why, and how they can control it. Explain terms like identifiers, tracking technologies, sale of personal information and how they affect consumers’ personal information in your cookie policy. Ensure that the policy is displayed prominently in your website footer or another prominent area on your website.

User-friendly design

A user-friendly CCPA cookie banner isn’t just about looks. It’s about function. Don’t block content with an aggressive pop-up. Instead, aim for less intrusive cookie banners that guide users gently toward informed decisions.

Social Talent

The Social talent's cookie banner explicitly provides a "Do not sell or share my personal information" link in a compliant and user-friendly manner.

Advocates for Human Potential (AHP)

AHP also uses an opt-out cookie banner. The banner is aligned to the bottom of the website.

Atlatt

The Atlatt example features an opt-out cookie banner with a 'Do not sell' link in brand colours.to match their brand colour.

Step 1: Audit your cookie usage

Identify which cookies your site uses and sort them into:

  • Essential (functionality-related)
     
  • Third-party cookies (e.g., ad trackers)
     

Call out whether any of them support data profiling or contribute to the sale of personal information.

Step 2: Use a Consent Management Platform (CMP)

A consent management platform like CookieYes simplifies the process of setting up a cookie banner for your website. Yes. It’s as simple as that.

CookieYes offers the following features, making it easy for businesses of all sizes:

  • Geotargeting for CCPA cookie banners (display banners only to California visitors)
     
  • Customisation options to match your website’s design and needs
     
  • Add a “Do Not Sell or Share My Personal Information” link directly to your banner
     
  • Full compliance with Google and Microsoft Consent Mode
     
  • Reliable technical support and comprehensive documentation
     
  • Easy setup with a beginner-friendly interface

Wish there was an autopilot for consent management?

That's us- Join and see why we are #1 CMP choice

Create a banner
  • 14-day free trial
  • Cancel anytime

Ensure your California policy updates reflect:

  • The types of cookies used
  • Whether data is sold or shared
  • Opt-out processes
  • Your alignment with CCPA/CPRA and other data privacy laws
  • Consumer privacy rights and how to exercise them

Ignoring opt-out functionality

CCPA mandates opt-out, not suggesting it. Failing to offer a clear “Do Not Sell” option could lead to CCPA penalties.

Confusing GDPR and CCPA

CCPA vs GDPR cookie banner standards differ. GDPR needs explicit consent (opt-in), while CCPA allows tracking unless the user opts out

Using a GDPR-only approach may cover the basics, but it often misses key CCPA requirements, especially around opt-outs.

Overdoing the pop-up

Your banner shouldn’t interrupt or annoy. Avoid full-screen overlays on your homepage. Choose a design that feels like a helpful guide, not an obstacle.

With a CMP, you can easily address this and ensure that your banner is top-notch like this one:

An example of a CCPA Cookie banner aligned to the bottom-left as seen on Grow with Geistlich's website.

User experience and compliance

Balancing legal requirements with a positive user experience is crucial. Adopt best practices like allowing users to easily customise cookie preferences using a cookie widget/cookie consent icon, clearly providing an opt-out of sale link.

A well-designed, user-friendly CCPA cookie banner significantly enhances visitor trust and retention.

Websites with user-friendly cookie banners may experience a higher user retention rate than those employing complex or intrusive banners.

Change in cookie banner behaviour between 2018 and 2023 based on a study by Advance Metrics

Compliance check:

Penalties under CCPA can reach $2,500 per unintentional violation and $7,500 per intentional one.

Several cookie banner compliance tools and CCPA cookie banner plugins streamline the compliance process.

CookieYes, for instance, provides user-friendly and fully customisable cookie consent banners specifically tailored to meet both GDPR and CCPA/CPRA standards effortlessly.

For businesses juggling multiple privacy laws and limited tech resources, it’s a practical way to stay compliant without compromising the user experience.

Still thinking?

Save time and ensure compliance with customisable banners tailored to CCPA using CookieYes

Get started for free
  • 14-day free trial
  • Cancel anytime

Does the CCPA require a cookie banner or consent pop-up?

Yes, the CCPA require a cookie banner or a consent pop-up to inform users at or before the point of data collection about the categories of personal information being collected and their rights, including the right to opt out of the sale or sharing of their personal data.

A cookie banner is a practical way to deliver this “notice at collection” and provide an opt-out option, especially for tracking technologies like cookies.

What are the CCPA cookie consent requirements for websites?

Under the CCPA (and the amended CPRA), websites must:

  • Disclose what categories of personal information are being collected through cookies.
  • Inform users about their rights, including the right to opt out of the sale or sharing of their data.
  • Provide a “Do Not Sell or Share My Personal Information” link in the banner or prominently elsewhere (like the footer).
  • Honour Global Privacy Control (GPC) signals as valid opt-out requests.
  • Explicit opt-in consent is not required under CCPA under general circumstances, but websites must offer clear opt-out mechanisms for non-essential cookies involved in data selling or sharing.

Is “Do Not Sell My Personal Information” required on a CCPA cookie banner?

Yes, if your website sells or shares personal information collected via cookies or other tracking technologies, you must include a “Do Not Sell or Share My Personal Information” link.

This link can be placed directly on your cookie banner or made easily accessible (e.g., in the website footer). The CPRA expands this requirement to include sharing for cross-context behavioural advertising, making the opt-out link even more important.

How is CCPA cookie compliance different from GDPR cookie consent?

The GDPR requires opt-in consent before placing any non-essential cookies (such as those used for analytics or advertising). In contrast, the CCPA follows an opt-out model, meaning businesses can use cookies by default, but must:

  • Inform users clearly
  • Allow them to opt out of the sale or sharing of personal data.

This fundamental difference means that GDPR banners ask for consent upfront, while CCPA banners offer a way to reject data selling/sharing after the fact.

Do I need to obtain opt-in cookie consent under CCPA or CPRA?

In general, no. The CCPA/CPRA does not require opt-in consent for most cookies. However, there are exceptions:

  • If your website collects personal data from children under 16, you must obtain opt-in consent (or parental consent if under 13).
  • If your business operates in other jurisdictions (like the EU), you may need opt-in consent to comply with those laws (e.g., GDPR).

In California, your focus should be on providing a notice of collection and an opt-out mechanism for selling or sharing data.

What is a CCPA “notice at collection” for cookies?

A “notice at collection” is a disclosure that informs users, at or before the time personal information is collected, about:

  • The categories of personal data collected (including through cookies)
  • The purposes for which the data is used
  • How users can opt out of the sale or sharing of their information.

You can implement this notice through a cookie banner, a cookie policy linked from the banner, or another interface that appears when a user first visits the site. This ensures users are aware of data collection practices before any non-essential cookies are deployed.


 Safna

Safna

CIPP/E from the International Association of Privacy Professionals (IAPP) | Data privacy writer at CookieYes.