How to create a CCPA compliant cookie banner in WordPress

How to Add CCPA/CPRA Cookie Consent Banner in WordPress?

Displaying a cookie consent banner under CPRA/CCPA is not mandatory, but it does require businesses to provide consumers with a way to opt out of the sale or sharing of their personal data, including data collected through cookies. To meet CPRA requirements, websites must offer a clear “Do Not Sell or Share My Personal Information” option that allows users to opt-out consent.

To enable a cookie consent banner for CPRA compliance, you can use a WordPress-native solution like the WebToffee GDPR Cookie Consent plugin, trusted by over 1.8 million website owners. The plugin makes it easy to display a CPRA-compliant cookie banner with just a few clicks.

In this guide, we will provide you with a detailed guide on how to create a CPRA-compliant cookie banner on your WordPress website.

📌

Key Takeaways

  • California Privacy Rights Act (CPRA) requires an opt-out consent mechanism for cookie compliance.
  • Websites should provide a “Do Not Sell My Personal Information” link on the cookie banner.
  • Complying with privacy laws is no longer a choice but a necessity for businesses to operate legally and maintain customer trust.
  • WebToffee GDPR Cookie Consent plugin deploys a cookie consent banner to comply with CPRA for WordPress websites.

Cookies are considered personal information under CPRA as they can be used to identify users or devices linked to them.

CPRA adopts an opt-out consent mechanism, which means websites can use cookies without asking for explicit consent but should provide users with an option to opt-out.

However, certain requirements must be met in order to use cookies, including cookie consent management. They are as follows:

  1. A clear and up-to-date privacy policy (or cookie policy) to disclose the use of cookies.
  2. Provide details on cookies, such as their name, purpose, source, and expiration date.
  3. Provide a “Do not sell my personal information” link or button to opt out of cookies.
  4. Manage, store, and secure personal data collected by cookies.
  5. Keep a consent log report with the details of cookies consent to, timeframe, etc.
  6. Allow cookie preferences to be accessed through a banner or button.

Now that you are aware of the CPRA cookie banner requirements, let’s dive into step by step guide on how to implement CCPA-compliant cookie banner in WordPress.

Our GDPR Cookie Consent Plugin will help you deploy a CPRA-compliant cookie banner on your WordPress website. In short, to create a CPRA cookie banner to manage cookie compliance in WordPress:

  • Step 1: Install GDPR Cookie Consent Plugin by WebToffee
  • Step 2: Enable US State Law cookie banner
  • Step 3: Choose a layout for CPRA banner
  • Step 4: Customize the cookie banner
  • Step 5: Preview the cookie banner

Now, let’s dive into the details of each step.

After purchasing the plugin, you can download the plugin zip file from the My account section.

  • Now, log in to your WordPress dashboard and go to Plugins > Add New Plugin.
  • Click on Upload Plugin to upload the plugin zip file.
  • Then, install and activate the plugin.
  • From your WordPress sidebar menu, go to Cookie Consent.
  • Choose consent law as US State Laws. This helps you comply with different US State privacy laws, such as CCPA/CPRA (California), VCDPA (Virginia), CTDPA (Connecticut), CPA (Colorado), and UCPA (Utah).
  • Check the Enable cookie banner checkbox.
  • If you want to restrict the cookie banner only to US citizens, choose the Geo-target option for United States.
  • Expand the advanced settings dropdown.
  • Enable the Respect Do Not Track and Global Privacy Control option to automatically hide the cookie banner for users who have these settings enabled in their browsers. When this option is active, the default consent status is set to “Denied.”
  • You can also hide the cookie banner on selected pages and define how long user consent should remain valid.
  • Enable the Reload page upon user consent option to refresh the page after users update their consent preferences.
  • Then, copy the Do not sell script and add it to your website footer to show a “Do not sell my personal information” link on your footer, helping you meet CPRA requirements.
Enable CPRA-compliant cookie banner

Now, let’s proceed to the next step.

Step 3: Choose a Layout for CPRA Banner

  • Go to the Layout tab in the Cookie Consent settings page.
  • Choose a layout and style for the cookie banner and preference center.
Choose a Cookie Banner Layout

Toggle the Banner Preview icon near the Update settings button to preview the cookie banner.

Go to the Content & Colors tab. The plugin will add the relevant message for the cookie banner per CPRA requirements. However, you can also edit or modify the text or title of the cookie banner.

You can also change the color of the background, border, and text. The plugin also allows you to add, edit, or modify additional elements on the cookie banner, like links to the cookie policy, consent preference center, revisit consent option, etc.

Customize CPRA cookie banner

After making the necessary changes, click on Update settings to save the changes.

Go to your website homepage, and you will see the banner we just created.

CPRA Cookie banner preview

Click on the Do Not Sell or Share My Personal Information link to opt out of cookies.

Opt-out consent preferences settings

You can then select the Do Not Sell or Share My Personal Information checkbox and click the Save My Preferences button.

Now, you have successfully deployed a CPRA-compliant cookie banner on your WordPress website.

Is a cookie banner required in California?

No, CPRA does not require websites to show a cookie banner. Instead, it requires websites to provide an opt-out mechanism for users to reject the collection and selling of their personal data using cookies. 

What is the difference between GDPR and CCPA cookie consent?

The GDPR mandates an opt-in consent mechanism, requiring websites to obtain explicit user permission before placing cookies on their devices. In contrast, the CCPA follows an opt-out consent mechanism, where websites can load cookies without prior consent but must provide users with the option to opt-out.

How can the GDPR Cookie Consent plugin help with CCPA compliance?

The WebToffee GDPR Cookie Consent plugin is a cookie compliance tool for WordPress websites. It helps you comply with the EU’s GDPR and other US State laws such as CCPA/CPRA (California), VCDPA (Virginia), CTDPA (Connecticut), CPA (Colorado), and UCPA (Utah).

Closing Thoughts

The steps outlined in this article will help you deploy a CPRA-compliant cookie banner on your WordPress website. It will manage your website’s cookie compliance with CPRA. However, to fully comply with CPRA, you should conduct a detailed audit of your data collection practices and seek legal advice from a professional.

Your website should also have a detailed and up-to-date cookie policy. If you don’t have one, the plugin discussed in this article will help you create one.

If you find this article helpful, drop your thoughts in the comments section below.

Article by

Content Writer @ WebToffee. With a background in journalism, I focus on eCommerce and data privacy. I've been writing about data protection and eCommerce marketing for over two years, crafting content that makes complex regulations easy to understand. I help businesses and individuals navigate evolving legal requirements and stay updated with the latest privacy standards.

Got any query? Please leave a comment or reach out to our support

Your email address will not be published. Required fields are marked *

Ensure GDPR & US Cookie Compliance for WordPress