Cookie consent banners: what the evidence shows — ROR Labs cover showing 11.8% lawful.
|

Cookie Consent Banners: What the Evidence Shows

Key takeaways · 11 min read

  • European law requires consent for non-essential cookies, and refusing must be as easy as accepting.
  • Only 11.8% of 680 UK sites met minimal legal requirements in one study; 89% of banners in another violated the law.
  • Removing the reject button from the first page raised consent by about 22 points; banner design drives most choices.
  • Some sites recorded consent before users chose, or after they opted out.

Almost every website in Europe now greets visitors with the same small negotiation. A box slides up: this site uses cookies. There is a large bright button that says Accept all, and somewhere, sometimes, a smaller grey link that says Manage options. Most people click the bright button without reading a word, dozens of times a week, and few ever wonder what they have agreed to.

Those banners exist because of European law. Since 2009, sites have needed consent before storing most non-essential cookies on a device, and since 2018 the General Data Protection Regulation has set a strict standard for what consent means: freely given, specific, informed and unambiguous. The idea was to give people real control over tracking.

Researchers have now measured what the banners actually do. They have scraped thousands of them, tested them on tens of thousands of real visitors, and checked whether sites respect the choices people make. The results show that small design decisions change consent rates by tens of percentage points, that most banners do not meet the legal standard, and that some sites record consent that was never given. This article looks at that evidence and at what regulators have done about it.

A cookie is a small text file that a website stores in your browser. Some are essential: they keep you logged in or remember what is in your basket. Others exist mainly to recognise you again later, on the same site or across many sites, so that advertisers can build a profile of what you read and buy. The distinction that matters most is between first-party cookies, set by the site you are visiting, and third-party cookies, set by other companies whose code is embedded in the page.

A typical news or shopping site can load code from dozens of such companies. When you click accept, you are often agreeing on behalf of all of them at once, a list that may run to hundreds of named vendors hidden behind a settings link. The banner asks about cookies, but the same companies can also use other techniques, such as device fingerprinting, that do not rely on cookies at all and that a banner may not mention.

What the law requires

Two pieces of European law apply. The ePrivacy Directive, in its Article 5(3) as amended in 2009, requires consent before a site stores or reads information on a user’s device, unless it is strictly necessary for a service the user asked for. The GDPR defines what valid consent is, and its Article 7(3) adds that it must be as easy to withdraw consent as to give it.

The EU’s top court has filled in the detail. In the Planet49 case in 2019, the Court of Justice ruled that a pre-ticked checkbox is not valid consent. Regulators have since said that refusing should be as easy as accepting, that consent cannot be assumed from simply continuing to browse, and that the purposes of tracking must be stated clearly.

What researchers found when they looked

In a study presented at the CHI conference in 2020, Midas Nouwens and colleagues scraped the consent pop-ups of 680 UK websites among the top 10,000 that used the five most popular consent management platforms. These are third-party services that many websites install to handle consent. Only 11.8% met a minimal set of requirements based on European law: explicit consent, rejecting as easy as accepting, and no pre-ticked boxes.

The most common failure was simple. Only 12.6% of sites showed a ‘reject all’ button on the same page as ‘accept all’. For everyone else, saying no meant clicking through to another screen, sometimes several, and switching off purposes or vendors one by one.

Consent pop-ups on 680 UK websites

Sites using the five most popular consent management platforms, 2019.

11.8%met minimal requirements based on European law
12.6%offered ‘reject all’ on the first page

Nouwens M, Liccardi I, Veale M, Karger D, Kagal L, Proceedings of CHI 2020, 1–13.

A pointillist illustration: a large laptop screen on a desk at night showing a web page half covered by a pop-up with one bright amber button and a small grey link beside it.
A consent pop-up with one bright button. Design, not preference, drives most choices.

Design changes the answer

The same team then ran a field experiment with 40 participants, showing them different versions of the pop-up on sites they actually visited. Removing the ‘reject all’ button from the first page raised the probability of consent by about 22 percentage points. Putting more detailed choices about purposes or vendors on the first page lowered consent by between 8 and 20 points. Whether the notice was a banner or a barrier that blocked the page made no difference to the answer, but banners were ignored 3.6 times as often.

Larger experiments confirm the pattern. In 2019, Christine Utz and colleagues tested consent notices on more than 80,000 visitors to a German website. People were more likely to interact with notices in the lower left of the screen. Given a simple yes-or-no choice, more people accepted tracking than when they had to allow each category or company individually, and very few chose specific categories unless they were pre-selected. Nudges such as highlighted buttons and pre-ticked boxes had large effects.

A randomised field trial with 1,493 users, published in 2021 by Jan Michael Bauer, Regitze Bergstrøm and Rune Foss-Madsen, found that manipulating the banner’s design increased consent by 17 percentage points of the whole sample. The authors concluded that the ability of site owners to steer choices in this way is probably at odds with what the law intends.

Field tests of banner design

Experiments on real website visitors.

+17 ptsconsent gained by manipulating banner design, 1,493 users
80,000+visitors in the largest field test of consent notices

Bauer JM, Bergstrøm R, Foss-Madsen R, Computers in Human Behavior, 2021; Utz C et al, ACM CCS 2019.

How design changes consent

Effect of pop-up design on the probability of accepting, field experiment.

Design changeEffect on consent
Remove ‘reject all’ from first pageUp about 22 points
Show vendor choices on first pageDown about 20 points
Show purpose choices on first pageDown about 9 points
Banner instead of blocking barrierNo change; ignored 3.6× as often

Nouwens M et al, CHI 2020. Small sample: 40 participants.

Do sites respect the choice?

A banner is only the front of the system. Behind it, the consent decision is stored and passed on to advertising companies. In 2020, Célestin Matte, Nataliia Bielova and Cristiana Santos examined sites using the Transparency and Consent Framework, an industry standard run by the advertising trade body IAB Europe that many consent platforms follow.

A pointillist illustration: a small round cookie on a saucer beside a keyboard, with a tiny amber tag attached by a thread.
A cookie on a saucer. What is stored behind the banner matters more than its buttons.

Among 1,426 websites with such banners, they found 141 that registered positive consent before the user had made any choice, 236 that nudged users by pre-selecting options, and 27 that stored positive consent even after the user had explicitly opted out. In more detailed tests of 560 sites, at least one suspected violation appeared on 54%. The authors built a browser extension to help regulators and users detect such problems.

The wording of banners has problems too. Cristiana Santos and colleagues annotated around 400 banners on popular English-language websites visited from the EU and found that 89% violated applicable law in what they said. The most common problem, in 61%, was vague purposes such as ‘improving user experience’. In 30%, positive framing undermined the requirement that consent be freely given and informed.

What happens behind the banner

Sites using the IAB Europe Transparency and Consent Framework.

FindingSites
Positive consent registered before any choice141
Options pre-selected to nudge acceptance236
Positive consent stored after opting out27
At least one suspected violation, of 560 tested54%

Matte C, Bielova N, Santos C, 2020 IEEE Symposium on Security and Privacy, 791–809. 1,426 sites with such banners were found among 28,257 crawled.

What regulators have done

Enforcement has followed the research. In January 2022, France’s data protection authority, the CNIL, fined Google a total of €150 million and Facebook’s parent company €60 million because their sites made refusing cookies harder than accepting them: accepting took one click, refusing took several. The companies were ordered to offer an equally simple way to refuse.

The consent framework itself was challenged in Belgium. The Belgian data protection authority ruled in 2022 that IAB Europe’s framework infringed the GDPR, and in March 2024 the Court of Justice of the European Union, in case C-604/22, held that the coded string recording a user’s preferences can be personal data and that the organisation running such a framework can share responsibility for how it is used.

Regulators have also moved in the other direction on low-risk cookies. The United Kingdom’s Data (Use and Access) Act 2025 created exemptions from the consent requirement for some cookies considered low risk, such as certain analytics, reflecting a wider view that banners for everything had produced fatigue rather than control.

What banners say

About 400 banners on popular English-language websites, assessed against EU law.

89%of banners violated applicable law in their wording
61%described their purposes too vaguely to be valid

Santos C, Rossi A, Sánchez Chamorro L, and colleagues, Proceedings of the 20th Workshop on Privacy in the Electronic Society, 2021, 187–194.

Outside Europe

The European approach is based on opting in: nothing non-essential should happen until you agree. The United States has mostly taken the opposite route. California’s privacy law, as amended by the California Privacy Rights Act, gives residents the right to opt out of the sale or sharing of their personal information, and the state’s regulations require businesses to treat a browser-level opt-out signal, such as Global Privacy Control, as a valid request. Several other US states have since passed similar laws.

The practical result is a patchwork. Many international websites show a full consent banner only to visitors from Europe or the UK, a simpler notice to Californians and nothing at all to people elsewhere. The same site can therefore track two readers of the same article very differently depending on where they appear to be. For readers outside these jurisdictions, browser settings are often the only control available.

A pointillist illustration: a smartphone held in a hand on a train, its screen showing a pop-up with two buttons of equal size, one blue and one amber.
A pop-up with two equal buttons. When refusing is as easy as accepting, many more people refuse.

Are banners the right tool at all?

Critics on all sides agree that the banners have not worked as intended. People face so many that clicking accept has become a reflex. Utz and colleagues described ‘consent fatigue’ in 2019, and the finding that banners are ignored far more than barriers suggests many people simply work around them.

There is a counterpoint. The research also shows that when refusing is made as easy as accepting, many more people refuse. That suggests the banners measure design more than preference, and that a fair design would reveal a lower appetite for tracking than current consent rates imply. Some researchers and regulators have argued for moving the choice to the browser, so that a single setting such as the Global Privacy Control signal applies to every site, rather than asking on each page.

The stakes for publishers explain why the fight over design is so intense. Many free websites earn most of their revenue from advertising, and personalised adverts usually sell for more than untargeted ones. Every percentage point of consent therefore has a price, which gives sites a strong incentive to make accepting easy and refusing tedious. The research suggests that the design of the banner, rather than what readers actually want, often decides the outcome.

What you can do

For individuals, the practical steps are modest but real. Look for a reject or ‘necessary only’ option before accepting; on sites that follow the rules, it should be on the first screen. Browser settings that block third-party cookies, and extensions that answer banners automatically with a refusal, reduce the number of choices you have to make. Clearing cookies from time to time removes identifiers that have built up, and private browsing windows discard them when you close the window.

Cookies are only one tracking method among many. We looked at how location data from phones is collected and sold in our article on data brokers, and at the wider tricks of manipulative design in our article on dark patterns.

Questions people ask

Do I have to accept cookies?

No. Under EU law, non-essential cookies need your consent, and refusing should be as easy as accepting. Strictly necessary cookies do not need consent.

How many cookie banners follow the law?

Few. One study found only 11.8% of 680 UK sites met minimal requirements; another found 89% of about 400 banners violated the law in their wording.

Does rejecting cookies actually work?

Usually, but not always. One study found 27 sites that stored positive consent even after users opted out.

Are cookie walls allowed?

Regulators have generally said that access to a site should not depend on accepting all tracking, though some accept a paid alternative. The rules and their interpretation are still being argued over.

Why is the accept button always bigger?

Because design changes behaviour. Removing the reject button from the first page raised consent by about 22 percentage points in one experiment.

Have regulators fined companies over cookie banners?

Yes. In 2022 France fined Google €150 million and Facebook’s parent €60 million for making refusal harder than acceptance.

The short version

  • European law requires consent for non-essential cookies, and refusing must be as easy as accepting.
  • Only 11.8% of 680 UK sites met minimal legal requirements in one study; 89% of banners in another violated the law.
  • Removing the reject button from the first page raised consent by about 22 points; banner design drives most choices.
  • Some sites recorded consent before users chose, or after they opted out.
  • Regulators have fined Google and Facebook, and the EU court has tightened rules on consent frameworks.

This article summarises published research and regulatory decisions about cookie consent. It is not legal advice for website owners or users. Rules differ between the EU, the UK and other countries and continue to change.

Further reading. Nouwens and colleagues, ‘Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence’, CHI 2020, is open access and readable. Matte, Bielova and Santos, IEEE Symposium on Security and Privacy, 2020, looks behind the banner.

Three books
  • Means of Control, Byron Tau (2024). A journalist on how data collected through apps and websites flows to brokers and governments.
  • Privacy Is Power, Carissa Véliz (2020). A philosopher on why personal data matters and what individuals and societies can do.
  • Breached!, Daniel J. Solove and Woodrow Hartzog (2022). Two law professors on why privacy and data security law keeps falling short.

Sources

  1. Nouwens M, Liccardi I, Veale M, Karger D, Kagal L. Dark patterns after the GDPR: scraping consent pop-ups and demonstrating their influence. Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems, 1–13. doi:10.1145/3313831.3376321.
  2. Utz C, Degeling M, Fahl S, Schaub F, Holz T. (Un)informed consent: studying GDPR consent notices in the field. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 973–990. doi:10.1145/3319535.3354212.
  3. Bauer JM, Bergstrøm R, Foss-Madsen R. Are you sure, you want a cookie? The effects of choice architecture on users’ decisions about sharing private online data. Computers in Human Behavior, 2021;120:106729. doi:10.1016/j.chb.2021.106729.
  4. Matte C, Bielova N, Santos C. Do cookie banners respect my choice? Measuring legal compliance of banners from IAB Europe’s Transparency and Consent Framework. 2020 IEEE Symposium on Security and Privacy, 791–809. doi:10.1109/SP40000.2020.00076.
  5. Santos C, Rossi A, Sánchez Chamorro L, and colleagues. Cookie banners, what’s the purpose? Analyzing cookie banner text through a legal lens. Proceedings of the 20th Workshop on Privacy in the Electronic Society, 2021, 187–194. doi:10.1145/3463676.3485611.
  6. Directive 2002/58/EC (ePrivacy Directive), Article 5(3), as amended by Directive 2009/136/EC.
  7. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4(11) and 7(3).
  8. Court of Justice of the European Union. Case C-673/17, Planet49, 1 October 2019; Case C-604/22, IAB Europe, 7 March 2024.
  9. Commission nationale de l’informatique et des libertés (CNIL). Deliberations on Google LLC, Google Ireland Limited and Facebook Ireland Limited, 31 December 2021, announced January 2022.

Similar Posts