
Cookie banner reject button: no harder than accept
At a glance
EU-03HighePrivacy Art. 5(3); GDPR Arts. 4(11), 7(3), 83(5)(a); EDPB Cookie Banner Taskforce report (2023)
Peeky looks at the cookie banner's first screen and counts how many steps it takes to say no compared with saying yes.
Last checked against the source:
The rule
No provision of EU law says in terms that a cookie banner must carry a reject button. The requirement is assembled from the consent rules.
Article 5(3) of the ePrivacy Directive allows information to be stored on, or read from, a user’s device only on condition that the user “has given his or her consent, having been provided with clear and comprehensive information”. Recital 66 of Directive 2009/136/EC, which inserted that text, adds that “the methods of providing information and offering the right to refuse should be as user-friendly as possible.”
The consent in Article 5(3) is the GDPR’s consent. Article 4(11) requires it to be a “freely given, specific, informed and unambiguous indication of the data subject’s wishes”. Recital 42 says consent “should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.” Article 7(3) adds that “it shall be as easy to withdraw as to give consent”. That last sentence is about withdrawal, but the EDPB reads it practically: when consent is given with one click, withdrawing must be equally easy (Guidelines 05/2020, para. 114).
The most direct statement from the European authorities is the Cookie Banner Taskforce report, adopted by the EDPB on 17 January 2023. By its own disclaimer the positions are a minimum threshold, not a greenlight for any banner, and each authority decides case by case.
On a banner with an accept button and no refuse option on any layer, a “vast majority” of authorities considered that this “is not in line with the requirements for a valid consent and thus constitutes an infringement”, although a few said Article 5(3) does not mention a reject option (para. 8). The taskforce also agreed that these examples do not lead to valid consent: a refusal offered only as a link in a paragraph of text without enough visual support, or placed outside the frame holding the accept buttons (para. 14). On colour and contrast, it declined to set a general standard, but treated a reject button whose text is unreadable to virtually any user as manifestly misleading (paras. 17 and 18). It also described a first screen that highlights acceptance with no refusal, which can lead the average user to believe there is no possibility to object (para. 20).
National authorities have put the point more bluntly. The CNIL, announcing its amended guidelines and its recommendation of 17 September 2020, states that “refusing trackers must be as easy as accepting them” and, in the recommendation, advises an interface with “not only an accept all button but also a reject all button” (our translation). The Italian Garante’s guidelines of 10 June 2021 take a different route: closing the banner with the X must leave the default, no tracking, in place, with a separate command for giving consent.
How this is enforced depends on where the page is aimed. The ePrivacy side is enforced under each Member State’s own law, which must provide penalties that are “effective, proportionate and dissuasive” (Art. 15a). The CNIL’s Google decision rests on Article 82 of the French Data Protection Act, the national text implementing Article 5(3). On the GDPR side, Article 83(5)(a) places “conditions for consent” in the upper fine tier, up to EUR 20 million or 4% of worldwide annual turnover. The EDPB’s Guidelines 03/2022 on deceptive design patterns are addressed to social media platforms; for banners, the relevant EDPB text is the taskforce report.
What PeekWell checks and how
EU-03 asks one question: on the banner’s first screen, is saying no about as easy as saying yes? The scan answers it from the rendered page, not from the consent tool’s settings.
The scan opens a public page in a fresh browser context with no saved choices. It finds the banner and lists the buttons and links on its first screen: is there an Accept all, is there a Reject all or an equivalent at the same level, and how do the two compare in size and in clicks needed. It then clicks the banner’s own controls as a visitor could, and counts the steps needed to refuse everything non-essential and the steps needed to accept. The click count is measured by code. Prominence is reported as measurements (size and click-depth as rendered), because where the line falls on prominence is a judgement that belongs to the reader and the authority, not to the scan.
A language model may help only where a button label is ambiguous, for example whether “Continue” means accept or refuse. It never decides the click count. The finding states what was seen, such as “Accept all on the first screen, no reject control until a second screen”.
This check shares its browser pass with EU-01, which looks at what loads before the banner is answered. EU-03 covers only the banner’s own design. The UK equivalent, with the Information Commissioner’s test, is UK-02.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. A banner shown only in some countries may not appear on one visit. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
This is a design fact anyone can see from outside, which is why it recurs in enforcement. In the account-creation flow, the CNIL’s Google decision of 1 September 2025 describes the effect in numbers: before October 2023, accepting personalised advertising cookies took two clicks and refusing took six. In October 2023 Google added a button making refusal as easy as acceptance, and the CNIL found that the lack of informed consent still persisted. It fined Google LLC EUR 200 million and Google Ireland Limited EUR 125 million, ordered changes within six months, and attached a penalty of EUR 100,000 per day of delay. The amount also covers advertisements placed between emails in Gmail, not the banner alone.
The Italian case is the same theme at a smaller scale. The Garante’s decision of 4 June 2025 on Confalonieri S.r.l., after an inspection of its website, records a banner that reappeared after a visitor clicked X and gave no warning that closing it left the default settings in place. There was no fine, but the Garante issued a formal warning and ordered the banner set up so visitors can give specific, informed consent to non-technical cookies.
The practical consequences come in three kinds. Consent that rests on a lopsided banner may not be valid, and under Article 7(1) the company has to show it was. What the tags collect afterwards is exposed too, because the taskforce takes the view that a failure under Article 5(3) means the later processing cannot be compliant (para. 24). And an authority needs no inside access to see the problem.
Smaller companies and larger companies
The rule has no size threshold, and a five-person shop and a global platform are judged on the same screen. What differs is how the asymmetry comes about.
In a smaller company the banner usually comes from a plugin or a hosted builder, and the asymmetry is an unchanged default. The tool ships with Accept all as a bright button and Settings as a grey link, and the Reject all button is switched off. The Italian case began with an inspection of an ordinary company website and ended in a warning and an order, not a fine.
In a larger company the asymmetry tends to be a product decision. A flow such as account creation or checkout gets its own consent screen, built by a team that measures opt-in rates, and the version with the most acceptances can win. The Google decision turned on that kind of flow. With several domains and apps, the main site’s banner may be fixed while another property keeps the old design.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Google LLC and Google Ireland Limited
The CNIL found that when users created a Google account, it was more difficult to refuse cookies linked to personalised advertising than to accept them. It also found advertisements displayed between emails in Gmail without prior consent.
Read the CNIL (France) publication about Google LLC and Google Ireland Limited
Smaller companies
Confalonieri S.r.l.
The Garante inspected the company's website. It found a cookie banner that came back after a visitor clicked X and did not let users give specific, informed consent to non-technical cookies. It issued a formal warning and an order to bring the banner into line.
Read the Garante (Italy) publication about Confalonieri S.r.l.
How to fix it
The aim is a first screen where yes and no take one action each. These steps fit most consent tools.
- Look at the first screen as a visitor. Open the site in a private window and count the clicks to accept everything and to refuse everything non-essential. If the numbers differ, that is the gap a scan will report.
- Put Reject all next to Accept all. Most consent tools have a setting for a reject button on the first layer. Switch it on. Use the same kind of control for both, the same size, in the same row.
- Keep the wording plain. Use labels that say what the buttons do, such as Accept all and Reject all. Avoid Continue or Got it, and avoid a refusal that exists only as a link inside a paragraph.
- Match colour and contrast. The reject text must be readable, and matching the buttons removes the argument about prominence.
- Make closing the banner mean no. If the banner has an X, closing it should leave non-essential tags off and should not bring the banner back on every page, as in the Italian case.
- Check the second layer too. Pre-ticked boxes in the settings view do not count as consent, as the taskforce confirmed (para. 10). Leave non-essential categories off until the visitor switches them on.
- Re-scan. Clear cookies and storage, reload, and run a scan again. The finding should show the same number of clicks for accepting and refusing.
Whether a design meets the rule in a given country is a question for your legal adviser. Peeky reports the buttons and clicks it saw.
Questions
Does a cookie banner need a reject button?
The directive does not use the words reject button, but regulators expect a clear way to say no. In 2023 the European data protection authorities' cookie banner taskforce reported that a vast majority of them treated a banner with no refuse option on any layer that carries a consent button as not in line with valid consent. The CNIL goes further and recommends an Accept all and a Reject all button side by side.
Can the reject option sit behind a settings button?
It can, but regulators have criticised it. The taskforce describes banners with Accept on the first screen and no refusal there, and says they may lead people to believe they have no choice. In the CNIL's Google decision, before October 2023, accepting took two clicks and refusing took six, and the CNIL treated that gap as discouraging refusal.
Do the accept and reject buttons have to look the same?
No, the authorities have not set one standard for colour or size. The taskforce says banners are judged case by case and gives one clear example of trouble: a reject button whose text is unreadable because the contrast is so low. The safer line is two buttons of the same kind, in the same place, with text anyone can read.
What counts as a dark pattern on a cookie banner?
Any design that steers the visitor towards Accept. The taskforce lists a refusal hidden in a text link, pre-ticked boxes, and button colours that make Accept stand out. The EDPB's separate guidelines on deceptive design patterns are written for social media platforms, but they describe the same habits of nudging and making a refusal tiring.
How does Peeky check the reject option?
Peeky opens your public page, finds the banner, and lists the buttons on its first screen. It then counts the clicks needed to refuse everything non-essential and compares them with the clicks needed to accept. It signs in nowhere and fills in no forms. How a scan works has the full path.
Filed with
The rule
ePrivacy Directive 2002/58/EC, Art. 5(3), as amended by Directive 2009/136/EC (recital 66)
Read the rule (ePrivacy Directive 2002/58/EC, Art. 5(3), as amended by Directive 2009/136/EC (recital 66))A case
Google LLC and Google Ireland Limited
Read the decision (Google LLC and Google Ireland Limited)Sources
- Directive 2009/136/EC, Official Journal L 337, Art. 2(5) and recital 66 (replaces Art. 5(3) of Directive 2002/58/EC and adds Art. 15a)
- Regulation (EU) 2016/679 (GDPR), Official Journal L 119
- EDPB, Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, adopted 4 May 2020
- EDPB, Report of the work undertaken by the Cookie Banner Taskforce, adopted 17 January 2023
- EDPB, Guidelines 03/2022 on deceptive design patterns in social media platform interfaces, version 2.0, adopted 14 February 2023
- CNIL, Cookies et autres traceurs: lignes directrices modificatives et recommandation (deliberations of 17 September 2020)
- CNIL, Cookies and advertisements inserted between emails: Google fined 325 million euros by the CNIL (1 September 2025)
- CNIL, Deliberation SAN-2025-004 of 1 September 2025 (Google LLC and Google Ireland Limited), English version
- Garante per la protezione dei dati personali, Provvedimento del 4 giugno 2025 [10152729] (Confalonieri S.r.l.)
- Garante per la protezione dei dati personali, Linee guida cookie e altri strumenti di tracciamento, 10 June 2021
Last checked against the source:
For information only. Not legal advice.


