- Introduction
- How does the Privacy trigger work
- How to enable/disable the Privacy trigger
- How to change the position of the Privacy trigger
- How to change the colors of the Privacy trigger
- Override Privacy trigger configuration
- Adding a privacy settings link to your site
- FAQ
Introduction
The Cookiebot CMP Privacy trigger functions as a shortcut to the users' consent state information on your website. Showing a mini version of the cookie banner, it enables users to easily check or update their consent. This is in line with demands for more transparency and providing users control of their own data, as is required by various privacy legislations such as GDPR.
Key features of the widget include:
- Easier and more intuitive consent
- Seamless integration with our Swift banner design
- Customizable colors, text, and position
- Full mobile responsiveness
- WCAG (Web Content Accessibility Guidelines) compliance.
How does the Privacy trigger work
Your website users will encounter the cookie banner upon first visiting the website (or every time consent renewal is needed). After providing a consent state via the cookie banner, the Privacy trigger will appear as a small Cookiebot CMP icon, present on all pages in a placement of your choice. Clicking it opens a small window showing:
- Current consent state divided per cookie category:
- 🔒 Necessary (always enabled)
- ✔️ Preferences
- ✔️ Statistics
- ✔️ Marketing
- Date and time of when the current valid consent has been given
- Consent ID (an anonymous, random and encrypted key value, used for proof of consent)
- Option to withdraw consent (only necessary cookies will be allowed from then)
- Option to change consent (recalling the cookie banner)
How to enable/disable the Privacy trigger
The Privacy trigger is enabled by default, but you can disable and enable it as follows:
- Login into the Cookiebot CMP Admin
- Select "Configuration" in the left-hand menu
- Select the "Privacy" tab
- Click the toggle labeled "Show privacy button"
How to change the color of the Privacy Trigger
Three colored circles are displayed under the section "Icon color", selecting one of these applies the corresponding color.
You have the following options:
-
White
A black toggle logo on a white background. -
Black
A white toggle logo on a black background. -
Custom
The toggle logo will be displayed in either black or white, depending on which background color you select. This is applied automatically based on which color has the highest contrast with your selected color.
How to change the position of the Privacy trigger
The default position (10px from the bottom and 10px from the left) may not be optimal for your website. It's possible that the Privacy Trigger would obscure important elements, or just not look right in that position.
You can select in which corner of the screen the Privacy Trigger needs to be placed in the drop-down menu labeled "Position".
You can then adjust the offset in the two fields under "Distance from", which will correlate to the two sides adjacent to the corner you selected.
How to change the theme of the Privacy Trigger
When the Privacy Trigger is clicked, a small overview window expands from it. This window too can be adjusted to your needs in terms of colors.
As with the Privacy Trigger itself, you have the following options:
-
White
A black toggle logo on a white background. -
Black
A white toggle logo on a black background. -
Custom
The toggle logo will be displayed in either black or white, depending on which background color you select. This is applied automatically based on which color has the highest contrast with your selected color.
Overriding the Privacy trigger configuration
The Privacy trigger supports a number of script attributes which allows you to customize the placement and distance settings for each individual domain, effectively overriding the domain group settings.
| Attribute | Value |
data-widget-enabled |
true, false
|
data-widget-position |
top-left, top-right, bottom-left, bottom-right
|
data-widget-distance-vertical |
integer |
data-widget-distance-horizontal |
integer |
<script
type="text/javascript"
id="Cookiebot"
src="https://consent.cookiebot.com/uc.js"
data-cbid="01234567-89ab-cdef-0123-456789abcdef"
data-widget-enabled="false"
async
></script>
Adding a privacy settings link to your site
Even if you turn off the Privacy trigger icon, you can still give visitors a way to reopen the consent window — by adding a text link anywhere on your site, most commonly the footer.
You'll find this option in Cookiebot Admin → Privacy → Privacy trigger, under "Add privacy settings link to your site." This panel provides a ready-to-use code snippet:
<a onclick="window.Cookiebot.show()" href="#">Privacy settings</a>
Add this to your website footer's HTML to give visitors access to the privacy settings and let them adjust their consent choices at any time.
Please note
If you turn off "Show privacy button," Cookiebot Admin will display a warning that visitors then have no way to adjust their consent unless this link has been added to your site. If you disable the icon, make sure this snippet is live and visible somewhere, like your footer.
Naming requirements
The visible text of this link has different requirements depending on your audience:
- United States:
Several US privacy laws (including CCPA and CPRA) require this exact wording: "Do Not Sell or Share My Personal Information." This is a legal requirement, not just a recommended label. If your website is subject to these laws, you need to change the default "Privacy settings" text in the Admin to "Do Not Sell or Share My Personal Information."
-
Outside the United States:
There is no specific wording required by law. You can keep the default "Privacy settings" text shown in the Admin, or use other wording such as "Cookie Settings," "Manage Cookies," or "Privacy Preferences."
If your website serves both US and non-US visitors, you can either use the US wording for everyone or show different wording depending on the visitor's location.
When a DSR link is already present
If your website already has a "Do Not Sell or Share My Personal Information" link for Data Subject Requests (DSRs), you can use "Privacy Settings" for the Privacy Trigger instead.
Your website should have only one "Do Not Sell or Share My Personal Information" link. Depending on your setup, this link can:
- Open your DSR form, if you have one, or
- Reopen the Cookiebot CMP banner, if you don't have a DSR form.
This helps avoid having two links with the same name while still giving users an easy way to manage their privacy and consent settings.
For the full legal background on the US wording requirement, see [Using Cookiebot CMP for CCPA/CPRA compliance](https://support.cookiebot.com/hc/en-us/articles/360010952259).
FAQ
Is it mandatory to enable the Privacy trigger on my website according to GDPR?
Article 7(3) GDPR states that your website visitors should have the right to withdraw consent at any time and this withdrawal should be just as easy as it was to give consent in the first place. The Privacy trigger allows you to offer this possibility with minimal effort, offering a plug 'n play solution that can be enabled easily by checking the "Activate Privacy Trigger" box on your Cookiebot CMP account.
If you prefer not to activate the Privacy trigger on your website, the possibility to withdraw and/or change consent is still included in the Cookie Declaration. Alternatively, you can construct your own mechanism for allowing users to withdraw consent: How can the user change or withdraw a cookie consent?
Will there be a CCPA version of the widget?
The CCPA version of the Privacy trigger is still in development and will be released at a later time. This will include the extra "do not sell my personal information" option. You can find more information on CCPA here: California Consumer Privacy Act and How to set up your CCPA configuration.
Do I still need the cookie declaration on my website, if I activate the Privacy trigger?
The Privacy trigger can replace the cookie declaration as a means of complying with these key parts of GDPR art. 7(3): "The data subject shall have the right to withdraw his or her consent at any time" and "It shall be as easy to withdraw as to give consent."
Why is the date and consent key hidden?
To check the exact date and time and consent ID of the provided consent, you can click the "show details" link in the widget. These have been hidden behind a link in order not to clutter the users' view of the current consent state.
Mobile design: can we make the Privacy trigger smaller?
The size on mobile is full width, but only takes up the screen size it needs to show the content in its height. On older phones with smaller screens, this might end up in taking up the whole screen and your users having to scroll within. We can not really make it any smaller than it already is, because of usability.
Why is the preview not available in the manager?
The preview is not enabled for the Privacy trigger at this time, but will be enabled with a future release.
Why is it not possible to change consent from within the Privacy trigger?
In order to change an original consent state, users are presented with the cookie banner again, which provides the full overview of cookies and trackers in use. As users should be able to make a fully informed consent choice every time, the full cookie banner will re-appear upon clicking the "change consent" button in the Privacy trigger.
Is the Privacy trigger available for Free plans?
Yes, the Privacy trigger is also included in our Free plans, although customization options are only available in Premium accounts.
Will the Privacy trigger automatically be enabled for new domain groups?
The Privacy trigger will not be enabled automatically on existing domain groups. It will however be enabled by default on newly created domain groups. Disabling the Privacy trigger again can easily be done: How to enable/disable the Privacy trigger.
Can I remove the Cookiebot CMP branding from the Privacy trigger?
It is not possible to hide the Cookiebot CMP branding via your account's settings, but you can use CSS overrides in order to accomplish this. See also the Swift banner guide on how to do this: Remove Cookiebot CMP branding from Swift banner.
What Content Security Policy (CSP) directives are required to enable the Privacy trigger?
We retrieve the configuration for the Privacy trigger using XMLHttpRequests to https://consentcdn.cookiebot.com/, so you'll need to allow connect-src 'self' https://consentcdn.cookiebot.com. Please see our article on Cookiebot and CSP for more information.
If you have any questions regarding the Privacy trigger or are otherwise in need of assistance; feel free to reach out!
Comments
0 comments
Please sign in to leave a comment.