Insight
Cookie banner design: why refusing must be as easy as accepting
Cookie banners are among the most visible compliance elements on a website, and regulators have fined large companies for making refusal harder than acceptance. The design principles are now fairly consistent across Europe, even though national enforcement differs.
The legal basis for cookie consent
In the EU, the ePrivacy Directive requires consent for storing information on, or accessing information from, a user’s device, unless it is strictly necessary to provide a service the user explicitly requested or for transmitting a communication. National laws implement this rule. In Germany, for example, the relevant law has been called the Telecommunications Digital Services Data Protection Act, TDDDG, since May 2024.
Where consent is required, it must meet the GDPR standard: freely given, specific, informed and unambiguous, given by a clear affirmative action. Pre-ticked boxes, continuing to browse and silence do not count as consent, as the Court of Justice confirmed in the Planet49 judgment in 2019. Consent must also be as easy to withdraw as to give.
Regulators and refusal
The most discussed issue has been the absence of a reject option on the first layer of a banner. Many banners offered a prominent accept button while refusal required opening settings and switching off categories one by one.
In January 2022, the French data protection authority CNIL fined Google 150 million euros and Facebook 60 million euros because their websites made refusing cookies more complicated than accepting them. CNIL has repeatedly stated that refusing should be as easy as accepting.
In January 2023, the European Data Protection Board adopted a report from its cookie banner taskforce, reflecting a common approach among authorities that examined complaints. Most authorities considered that the absence of a refuse option at the same level as the accept option was a violation, and they also addressed deceptive colours and contrast, pre-ticked boxes, misleading links and claims of legitimate interest for non-essential cookies.
Design principles that follow from the rules
A banner that meets these expectations does not have to be ugly or long. It needs to present a real choice clearly and then respect it technically.
- Equal first-layer options
- Accept and reject, or equivalent wording, available at the same level with comparable prominence.
- No deceptive design
- Avoid making the reject option look like plain text or hiding it through colour, size or contrast.
- No pre-selection
- Optional categories must be switched off until the user switches them on.
- Clear purposes
- Explain in plain language what analytics, advertising and other categories do, with access to a list of providers.
- Nothing before consent
- Non-essential cookies and tracking scripts must not load before the user agrees.
- Easy withdrawal
- A persistent link or button lets users change or withdraw consent at any time.
Where implementations fail technically
The most serious problems are often invisible in the banner design. Tags fire before consent, because a tag manager was configured without consent conditions or a script was added directly to the page template. Advertising pixels load on all pages regardless of the choice made.
Other issues include consent that is not stored correctly, so the banner reappears constantly or choices are not respected on other pages; rejection that stops cookies but still sends data to vendors through other identifiers; and subdomains or country sites that use separate, inconsistent consent tools.
Testing should check network requests and cookies before any choice, after rejection and after acceptance, on several templates and devices. Browser developer tools and privacy scanners make these checks practical.
Legitimate interest and strictly necessary cookies
Some banners list advertising or analytics cookies as based on legitimate interest, switched on by default with an option to object. Regulators have generally not accepted legitimate interest as a basis for non-essential cookies that require consent under ePrivacy rules.
Strictly necessary cookies, such as those keeping a shopping basket, maintaining a login session or storing the consent choice itself, do not require consent. The category should be used honestly: labelling marketing cookies as necessary is a common finding in audits.
Some national authorities have issued guidance allowing certain audience measurement without consent under strict conditions, but those exemptions are narrow and vary by country.
The business case for getting it right
Many companies fear that an equal reject button will reduce measured traffic and conversions. It often does reduce the share of users tracked. But a banner designed to push acceptance creates regulatory and reputational risk and produces consent that may not be valid, which undermines the data anyway.
A better approach is to measure what matters with the data you are allowed to collect, use aggregated and modelled reporting where available, send key conversions from backend systems, and design a banner that respects users. Trust shown on the first screen also affects how visitors see the rest of the site. This article is a general overview and not legal advice.
Questions
Must a cookie banner have a reject button?
European regulators generally expect refusal to be as easy as acceptance, which in practice usually means a reject option on the first layer.
Are pre-ticked cookie boxes allowed?
No. Pre-ticked boxes do not constitute valid consent, as confirmed by the Court of Justice in Planet49.
Why were Google and Facebook fined by CNIL?
In January 2022 CNIL fined them 150 million and 60 million euros because refusing cookies was more complicated than accepting them.
Can analytics cookies be based on legitimate interest?
Regulators have generally not accepted legitimate interest for non-essential cookies that require consent, though some countries allow narrow measurement exemptions.
Do strictly necessary cookies need consent?
No. Cookies strictly necessary for a service the user requested, such as a shopping basket, do not require consent.
How often should consent be asked again?
There is no single EU rule; authorities have suggested reasonable periods, and consent should be renewed when purposes or vendors change significantly.
How can we test whether our banner works?
Check cookies and network requests before any choice, after rejection and after acceptance across templates and devices.
Where this sits in what we do
This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.
- Digital Growth — The ongoing programme — strategy, content, paid, organic and reporting — run as one thing that answers to pipeline rather than to channel dashboards.
- The EU AI Act: what actually applies from 2 August 2026
- Belgium's B2B e-invoicing mandate: the January 2026 big bang
- Core Web Vitals after INP: what the three metrics measure and what usually needs fixing
- Customer care for logistics companies: proactive delay communication beats a bigger call centre
- All insight articles
Does your cookie banner actually block tracking?
We audit consent tools and tag configuration, fix scripts that load before consent and design banners that give visitors a real choice.
Get in touch