This article helps you configure Cookiebot's CIPA/VPPA template so your consent banner blocks tracking tools until a visitor actively agrees, as required for California visitors under CIPA.
What is CIPA?
CIPA is a California state law passed in 1967, originally aimed at wiretapping and eavesdropping in phone calls. In recent years, plaintiffs' attorneys and activists have argued that website tools such as chat widgets, session replay software, and some analytics or advertising scripts fall under this law if they collect or share a visitor's information before that visitor has agreed to it. These claims are brought as private lawsuits, not by a regulator.
Who does this affect?
Any business with a website that California visitors can reach may be a target for a CIPA claim, regardless of where the business itself is based. Risk tends to concentrate around tools that capture what a visitor types, says, or does on a page before consent has been given.
How can prior consent (opt-in) help?
One argument used in this litigation is that a visitor who has clearly agreed, in advance, to a tool running has authorized it, which weakens a claim that the tool intercepted anything without permission. Configuring your consent banner so that non-essential tools stay switched off until a visitor actively agrees to them is one way to support that argument.
Does having a CMP configured for other U.S. state privacy laws protect against CIPA?
In general, no, because U.S. state privacy laws like the CCPA/CPRA use an opt-out consent model. Under those laws, in most cases you can collect personal data from website visitors without requiring their consent. You only need to inform them about data use and their rights, and enable them to opt out of certain data processing. CMP setups for most current U.S. laws won’t request consent before non-essential tools fire.
CIPA risk reduction: What your CMP setup should provide
- Tools blocked until consent is given. Non-essential scripts, including chat and analytics, should not run until the visitor has made an active choice.
- A clear opt-in and opt-out choice. Visitors need an equally easy way to decline as to accept. (Dark patterns are prohibited under the CCPA/CPRA.)
- A visible, working “Do Not Sell or Share My Personal Information” link. If you also handle CCPA/CPRA obligations on the same site, this link should let visitors opt out of the sale or sharing of personal information, or reopen the banner to review their choices.
- A way for a user to change or withdraw consent at any time, from any page.
CIPA: A Cookiebot guide
| This guide is not intended as legal advice and does not guarantee protection from CIPA claims. Consult your own legal counsel, who can assess your specific tools, disclosures, and risk. If your business is facing an active claim or demand letter, please consult an attorney before making changes or responding. |
Prerequisites
The following is needed to perform the steps in this guide:
- Admin access to your Cookiebot dashboard, with permission to edit banner settings.
- Optional: the URL of your Data Subject Request (DSR) form, if you have one.
Configure the CIPA/VPPA template in Cookiebot Admin
The following steps apply to you if you are using Cookiebot Admin. If you are on the previous user interface, Cookiebot Manager, then follow the steps in this article.
- Log in to Cookiebot Admin.
- Under Domains & Aliases, go to your domain group and add a domain, or edit an existing one.
- Go to the Configuration screen.
- Under Legislation Preset, select CIPA/VPPA.
- Click Apply Preset. Review the settings Cookiebot applies automatically. You don't need to change anything here. The template sets your banner to require active consent before any tracking starts, displays a bar at the bottom of your site, and applies these rules to all regions by default.
- Go to Design > Compliance and find the Data subject request form link section. Every California-compliant banner needs a "Do Not Sell or Share" option:
-
If you have your own Data Subject Request (DSR) form: check the box and enter its full URL.
-
If you don't have one: leave the box unchecked. Visitors see your consent banner again when they request to opt out. You can also add a footer link that reopens the banner. Copy its code snippet from the Privacy tab, and label it "Do Not Sell or Share My Personal Information".
-
If you have your own Data Subject Request (DSR) form: check the box and enter its full URL.
- Optional: on the Design tab, under Compliance, click Show additional settings to review which consent categories are checked by default and whether the banner shows a close icon.
- Click the Content tab to edit the banner heading, body text, button labels, and DSR link text.
If you skipped adding your own DSR form, paste the footer code snippet from the Privacy tab into your website footer. - Go to the Privacy tab and open the Privacy trigger section. The Show privacy button toggle controls a floating button that lets visitors update their consent at any time.
- If the toggle is off: copy the code snippet shown and paste it into your website footer.
-
If you turn the toggle on: customize the button's appearance using the options that appear. A backup code snippet is still available underneath.
- Click Save Changes.
Implement the banner on your website
If you haven't implemented the banner on your website yet, do it by following these steps:
- Go to Script Embeds in the left menu.
- Choose the blocking mode that fits your site (automatic or manual).
- Follow the standard installation instructions to add the script to your site.
After implementing Cookiebot with the CIPA template, visitors from California — and all other regions — will see the consent banner and must actively accept before any tracking tools run on your site.
Verify the implementation
Open your website in a private or incognito browser window, and confirm the consent banner appears before any cookies load, the "Do Not Sell or Share My Personal Information" link works, and any footer snippet you added reopens the banner correctly.
Once your setup is live, check your monthly scan report to confirm that non-essential scripts are correctly categorized and are not firing before a visitor has given consent. If a tracker is loading before consent, that gap undermines the setup described above, so it is worth correcting promptly.
Troubleshooting
The consent banner doesn't appear when I visit my site
Try a private or incognito browser window, which clears any existing cookie consent. If the banner still doesn't show, confirm you clicked Save Changes and that the CIPA/VPPA template is selected for the correct domain group.
The "Do Not Sell or Share My Personal Information" link doesn't appear on my site
Go back to the Design tab and confirm the Data subject request form link section is configured. If you skipped that step, return to step 6 and either enter a form URL or copy the footer code snippet from the Privacy tab.
Comments
0 comments
Please sign in to leave a comment.