CookieHawk › Guides › What regulators actually look for in cookie banners
What regulators actually look for in cookie banners
There is a lot of talk about fines for cookie banners. There is also something more useful: a document where European regulators set out, jointly, which banner practices they consider unlawful. Here is what it says.
Everything here is drawn from the European Data Protection Board's own published report. We do not repeat figures or claims we cannot find at the source — including the various estimates circulating about how many websites are non-compliant.
The Cookie Banner Taskforce
In September 2021 the European Data Protection Board set up a taskforce to coordinate how national authorities handled complaints about cookie banners. The point was consistency: a banner should not be lawful in one EEA country and unlawful in the next.
The resulting report, adopted on 18 January 2023, examines eight practices that had been the subject of complaints, and records where the authorities agreed.
It is worth reading for one reason above all: it is not one regulator's opinion about one company. It is the common denominator among the regulators who would investigate you.
The points that matter most in practice
1. A missing reject option is an infringement
This is the clearest conclusion. A large majority of authorities took the view that the absence of a refuse, reject or “do not consent” option on any layer that carries a consent button does not meet the requirements for valid consent, and therefore constitutes an infringement.
In plain terms: if there is an accept button on a layer, there should be a way to decline on that same layer.
2. Pre-ticked boxes are not consent
Consent requires a clear affirmative action. A box already ticked when the banner appears is not an action by the visitor. This has been settled for some time, but it still shows up.
3. Design that steers the choice
The report addresses banner design directly. Deceptive layouts — colour, contrast and placement used so that accepting is the obvious path and declining is not — undermine whether consent is freely given. The banner can contain both options and still fail on this.
4. No way to withdraw
Withdrawing consent must be as easy as giving it. The absence of a withdrawal icon or an equivalent easily accessible mechanism was among the practices examined.
5. Calling things “strictly necessary” when they are not
The Board noted that some organisations classify as essential or strictly necessary cookies and processing that would not qualify as strictly necessary under Article 5(3) of the ePrivacy Directive. Labelling a category “necessary” does not make it exempt; what the cookie does decides that.
One consequence worth understanding
The report makes a connection that is easy to miss. Where Article 5(3) of the ePrivacy Directive is not complied with — in particular where no valid consent is obtained when one is required — the subsequent processing cannot be compliant with the GDPR either.
In other words, a defective banner does not stay a banner problem. It undermines the lawfulness of everything that follows from it, which is why these cases are rarely just about the banner when they are investigated.
What to take from it
- Put a reject option on every layer that has an accept button. This is the single clearest expectation, and it is cheap to fix.
- Give both options the same visual weight. Same size, same prominence. It removes the design argument entirely.
- Make withdrawal visible. A persistent small icon or a footer link is enough.
- Audit your “necessary” category. If analytics or advertising cookies are sitting in it, that is exactly what the Board flagged.
- Then check what is actually sent. Every one of these can be correct while scripts still load before the choice.
Common questions
Is the EDPB report legally binding?
It is not legislation. It records the common position of the data protection authorities that handle these complaints, so it tells you how the rules are being applied in practice across the EEA. National authorities remain responsible for their own enforcement decisions.
How large are fines for cookie banner problems?
There is no fixed rate, and outcomes vary widely between countries and cases. Many cookie banner cases end in a reprimand or an order to correct rather than a fine, particularly at first contact. Cases that involve unlawful transfers or sensitive data tend to be treated more severely.
Does the report mean my banner must have a reject button on the first layer?
It means a large majority of authorities consider that a layer offering consent should also offer refusal. Putting an equally prominent reject option on the first layer is the straightforward way to meet that expectation.
What should I do first if I am unsure?
Look at what your website actually sends before the visitor has chosen, and after a no. That observation is what everything else is built on, and it takes ten minutes to do yourself.
Want to know what your own website shares?
The free check shows which third parties your website contacts before the visitor has chosen, and what still happens after “Reject all”. It is the same observation an investigation would start from.
Check your website freeRead next
CookieHawk leveres av Webkompaniet AS · org.nr. 999 529 860 · Oslo · Vilkår · Personvern