If your website uses cookies and other technology to monitor users, provide them with a cookie notification message on your cookie banner informing users about what cookies are active on your website and why.
Read on to learn more about cookie messages, when you need them, and how to create one to add to your website.
Don’t want to deal with all this stuff? Let us manage your cookies for you!
What Is a Cookie Message?
Cookie messages on websites refer to the text in the pop-ups or banners that users receive when they go on websites with cookies.
These cookie messages remind users that a website uses cookies and that they may have the right to opt into or out of cookies.
These messages are impacted by certain privacy and cookie laws, such as the General Data Protection Regulation (GDPR).
You can read our in-depth cookie guide for more information on cookies in general.
How to Create a Cookie Message to Add to Your Website
Here are some ways you can create a cookie message for your website.
Use a Managed Solution to Make Your Cookie Message
The easiest way to make a cookie message for your website is to use a managed solution or automatic generator.
For example, you can use Termly’s Cookie Consent Manager to save time while easily aligning your site with various cookie requirements.
Powerful yet easy to use, our Cookie Consent Manager is a browser-based tool that requires minimal effort on your part.
Use Termly to Create a Cookie Notification

To use it, just follow these simple steps:
- Enter your website URL into Termly’s scanner,
- Our tool scans your site and categorize the majority of your cookies,
- It then generates your cookie policy & customizable cookie notification banner!
All you have to do is enter your website’s information and press the button!
We’ll then scan your website for cookies, organize them into appropriate categories, write a custom cookie policy for your company, and generate a cookie consent banner that you can display on your site with ease.
Use a Plugin To Create a Cookie Message for Your Site
If you’re the owner of a WordPress site, consider downloading a cookie consent plugin for WordPress to automate the process of displaying a cookie message.
These tools will give you customizable cookie messages and pop-ups that will help you comply with cookie requirements.
Unlike DIY or templates, plugins already come with coding, colors, WordPress page synchronization, and formatting, so all you have to do is change the text and look to fit your brand.
Try a DIY Solution To Make a Cookie Message (Not Recommended)
You can also try the do-it-yourself method and try to create your cookie message and manage user consent from scratch.
However, this option involves writing up the required legalese and coding the notification message display and function by yourself.
It is not recommended if you’re not very familiar with data privacy laws and coding.
If you choose this option, consider using a cookie policy template to streamline the process of cookie compliance.
Cookie notification messages are heavily impacted by laws like the GDPR, CCPA, and even the CIPA.
As such, you need to get together with your team and choose a cookie notification message solution that will help you comply with the privacy laws that apply to your website’s users.
Why Do You Need a Cookie Message?
There are many reasons you need a cookie message on your website.
It may be required by laws like the GDPR, the CCPA, or even the CIPA. For example, you may need to comply with the GDPR if you target consumers from the European Economic Area (EEA), even if your company and website server are US-based.
Modern consumers also care about their privacy online and want to know what cookies you’re placing on their browsers or devices and why.
Having an adequate cookie notification message helps keep them transparently informed, which can help improve your overall relationship with your consumers.
What Privacy Laws Impact Cookie Notification Messages?
Several privacy laws exist around the world that impact how your cookie notification message should appear to users, for example:
- General Data Protection Regulation (GDPR): Also known as the world’s strictest cookie law, the GDPR applies to all websites targeting European consumers. The GDPR makes it mandatory for websites to get consent from users before putting cookies on their browsers. For consent to be valid, it must be specific, freely given, informed, which means the site must inform the user about cookies before placing them on their browser, and expressed through explicit, affirmative action.
- California Consumer Privacy Act (CCPA): The CCPA protects Californian users’ data from privacy violations. It doesn’t require an organization to obtain user consent for collecting and processing their personal information. However, the organization must give users the right to opt out of the sale of personal information if it collects and sells users’ personal information to third parties. Consent is also required for specific circumstances like collecting and using the personal information of minors under 16 and information transfer.
- Children’s Online Privacy Protection Act (COPPA): COPPA protects minors’ right to privacy. It applies to all websites and online businesses that collect, use, or disclose personal information from children and requires you to give direct notices to parents about cookie collection.
- ePrivacy Regulation: The ePrivacy Regulation is a revised version of the current ePrivacy Directive (the Cookie Law). It’s intended to work with the GDPR to establish the EU’s reformed data protection framework, but it still hasn’t come into effect. If finalized, it will expand on the GDPR and establish more straightforward rules for cookies. The European Commission has stated that no consent will be needed for cookies that don’t intrude on privacy. These include cookies that improve user experience, such as those used to remember shopping cart history.
- Canada’s Anti-Spam Law (CASL): Cookie regulation is part of Canada’s anti-spam and privacy laws. According to Canada’s federal , it’s illegal to install any program or software on another person’s computer during commercial activity without first obtaining their express consent.
- Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA): generally requires consent to collect, use, and disclose personal information. The safest way to obtain this consent is through express, informed consent, such as cookie notifications.
- Singapore’s Personal Data Protection Act (PDPA): The PDPA regulates the handling of personal data and marketing in Singapore. It establishes how organizations use, collect, and dispose of Singaporeans’ personal data. Singapore’s PDPA is more similar to Canada’s CASL than it is to the GDPR since it accepts implied or deemed consent.
What Needs to Be in a Cookie Message?
Your cookie message should include the following details:
- Inform users that the website uses cookies.
- List the types of cookies that are present on the website (e.g., essential, functional, marketing)
- Give users more information about how the website uses cookies by including links to the site’s privacy policy or cookie policy.
- Contain information about how users can opt out of cookies or change their cookie settings.
- Get users’ active consent to use cookies.
Including all of this information can help your website align with privacy laws like the GDPR and the CCPA.
Example of a Good Cookie Notification Message
For a good example of a cookie notification message, check out the screenshot below that features one used by The Guardian, a news publication.

The Guardian’s banner does all of the steps mentioned previously, for example, it:
- Informs users that the site uses cookies. It uses a large, eye-catching font for “It’s your choice.” This prompts the user to read out to find out why there’s a banner and what choice it’s referring to.
- It gives users information about how The Guardian uses cookies. The details are under “It’s your choice.”
- Gets users’ active consent to use cookies. It does this through the “Yes, I’m happy” and “Manage my cookies” buttons.
Try using their cookie notification message as an example to inspire you as you go to create your own.
Where Should I Display My Cookie Message?
You should display your cookie message every time your cookie consent banner pops up.
Because new users can end up anywhere on your site, you might need to include your cookie message on every page of your website.
If multiple privacy laws apply to your website, then your cookie message should also adapt based on where your users are located.
Using Termly’s cookie consent solution can help you align with this requirement because it has regional consent settings available.



