Skip to main content
    Pritect
    All resources
    Data ProtectionGuide7 min readUpdated 24 Jun 2026

    Cookie consent and enforcement: what good looks like

    What regulators now expect from cookie banners, why dark patterns are a liability, and a practical standard for consent that holds up across the EU.

    By Magdalena Goralczyk·Data Protection Partner, White Label Consultancy

    Cookie banners look trivial and are anything but. They are the most public, most tested part of most organisations' data protection posture, and regulators across the EU have steadily converged on what an acceptable one looks like. Getting them wrong is both a compliance risk and a trust problem, because it is the first thing every visitor sees.

    The direction of travel is settled, even if the detail varies

    Following the European Data Protection Board's Cookie Banner Taskforce work, data protection authorities have published increasingly aligned positions. The headline expectation: users should find it as easy to refuse non-essential cookies as to accept them. Several of the most active authorities, including the French and Spanish regulators, take the strict view that a "reject all" control belongs on the first layer of the banner, alongside "accept all", not buried a click deeper.

    There is not yet perfect unanimity. Some authorities still tolerate "reject" on a second layer. But the active, enforcement-minded regulators have taken the strict line, and their practice tends to spread. Designing to the strict standard is the safe choice, and it is also the honest one.

    Three principles do most of the work:

    • Essential vs non-essential. Cookies strictly necessary for the site to function do not need consent. Analytics, personalisation, and advertising cookies do. So you need an accurate picture of what cookies you actually set and why.
    • Freely given and informed. Consent must be a genuine choice, clearly explained, and not bundled with terms and conditions. People should understand what they are agreeing to.
    • No dark patterns. Pre-ticked boxes, a glowing "accept" next to a greyed-out "reject", confusing wording, or extra clicks to refuse all undermine consent. Regulators increasingly treat these as making consent invalid.

    A compliant banner that still fires analytics and advertising tags before the user consents is not compliant. The banner has to actually gate what loads, record the user's choice, and let them change their mind later. That is a technical control, not just a design.

    A practical standard to hold yourself to

    If you want one checklist to design against:

    1. Maintain an accurate cookie inventory, categorised by purpose, and keep it current as tags change.
    2. Put "accept all" and "reject all" as equally prominent choices on the first layer.
    3. Default to no non-essential cookies until consent is given.
    4. Write the notice in plain language, separate from terms and conditions.
    5. Record consent, make withdrawal easy, and re-ask when the basis or scope changes.

    Meeting that standard is not just defensive. A clear, honest banner is a small but real signal that the organisation behind it treats people's data with respect, and that signal compounds.

    Connect consent to your wider data protection programme with Pritect and Pritect Beacon.

    Explore Data Protection