Just the Facts · Article
Your cookie banner probably isn't doing anything
Almost every site we scan has a banner. On roughly three in four, the trackers have already fired by the time it appears — which means the banner is decoration, not protection. Here is the one difference that matters.
You added a cookie banner. You reasonably assumed that dealt with it. The measured reality: among websites that display a cookie notice, 73.4% load non-essential trackers before the visitor touches the banner at all — and of the sites that do offer a reject button, roughly two-thirds keep tracking anyway after someone clicks it.
Notice versus consent — the whole article in two sentences
A notice-only banner announces that cookies are in use and asks you to acknowledge it. A prior-consent banner blocks every non-essential tracker from loading until the visitor affirmatively opts in. Only the second one is a defence, because only the second one changes what actually happens.
The distinction is invisible from the front of the site. Both look like a bar at the bottom of the page with a button. The difference is entirely in what already ran before you saw it.
Why notice-only stopped being enough
In Europe this is not a matter of interpretation. The ePrivacy Directive originally required only that users be offered a right to refuse — a notice-and-opt-out rule. A 2009 amendment replaced that language with a requirement of consent: storing or accessing information on a user's device is permitted only on condition that the user has given consent, having been given clear and comprehensive information first. Notice-only banners have been insufficient in the EU since that change took effect.
In 2019 the Court of Justice of the EU held in Planet49 that a pre-ticked box the user must deselect is not valid consent — and, importantly, that the rule applies whether or not the information involved is personal data. In 2023 the European Data Protection Board's cookie taskforce put it plainly: no cookies requiring consent may be set without consent, and that consent must be expressed by a positive action.
The United States works differently, and the difference matters
California is not a prior-consent regime. Under the CCPA as amended, trackers may run by default for adults, provided a genuine opt-out exists. But three things are required and are routinely missing:
- The opt-out must actually work. California's privacy agency fined a retailer $345,178 in 2025 after a misconfigured privacy portal failed to process opt-out requests for 40 days.
- Rejecting must not be harder than accepting. California regulation requires that the path to the more privacy-protective option is no longer or more difficult than the path to the less protective one. Honda was fined $632,500 in March 2025 for exactly this: accept all in one click, opt out in at least two.
- The Global Privacy Control signal must be honoured — automatically, with no banner interaction at all. That is a separate article, and a separate finding on your report.
The enforcement record on pre-consent tracking specifically
- France's CNIL fined Google €100m and Amazon €35m in December 2020 for depositing cookies on arrival, before any user action. Amazon appealed; the Conseil d'État upheld the penalty in 2022.
- CNIL fined Facebook Ireland €60m at the end of 2021 for a banner requiring one click to accept and three actions to refuse, calling it "particularly counter-intuitive to have to click on a button entitled 'Accept cookies' to actually refuse."
- CNIL fined SHEIN €150m in September 2025 — advertising cookies placed as soon as visitors arrived, before any interaction with the banner, and new cookies still placed after the visitor clicked "Refuse all."
The connection to demand letters in the US
This is where it stops being a European story. California's CIPA pen-register theory turns almost entirely on tracking that fires before any consent interaction. The pattern in every one of these demand letters is identical: an automated scan captures a third-party request made on page load, before the visitor clicked anything. In the real letter published as Exhibit B on our demand-letter article, the plaintiff's entire case was a single Google Analytics request that fired before the consent banner appeared.
A consent banner shown after tracking has already begun is disclosure, not consent. That single sentence is the difference between a banner that protects you and one that simply documents the violation.
What to actually check on your own site
- Open your site in a private window with the browser's network tab recording, and look at what fires before you touch the banner. Requests to analytics, ad platforms, tag managers, embedded fonts, maps and video players are the usual culprits.
- Click reject, then reload and look again. If the same requests fire, your reject button is cosmetic.
- Count the clicks. If accepting is one click and rejecting is two or more, fix that first — it is the most frequently enforced defect in the US.
- Check that consent is actually recorded and can be withdrawn as easily as it was given.
Educational information, not legal advice. Requirements differ substantially by jurisdiction; what is mandatory in the EU is not necessarily required in the US, and vice versa.
Sources
- Bouhoula et al., Automated Large-Scale Analysis of Cookie Notice Compliance — 33rd USENIX Security Symposium (2024), 97,090 sites
- Nouwens et al., Dark Patterns after the GDPR — CHI 2020: only 11.8% of 680 UK banners met minimal legal requirements
- ePrivacy Directive 2002/58/EC, Article 5(3), as amended by Directive 2009/136/EC
- CJEU, Planet49, C-673/17 (1 October 2019)
- EDPB — Report of the Cookie Banner Taskforce (17 January 2023)
- CNIL — SHEIN fined €150m for cookies placed without consent (September 2025)
- CNIL — Deliberation SAN-2021-024, Facebook Ireland (31 December 2021)
- CPPA — Order, American Honda Motor Co. (7 March 2025)
- CPPA — Todd Snyder, Inc. enforcement action (May 2025)
More from Just the Facts
- Is Any of This Actually Real?
- How Real Is the Threat? A By-the-Numbers Risk Assessment
- Who's Really Suing — CIPA Website-Wiretap Filers
- When the Court Reins One In: the Vivek Shah Vexatious-Litigant Ruling
- The Demand-Letter Economy
- Verifying Licensed Images, Fonts & Video
- Copied Content: Plagiarism, Copyright & the Hidden SEO Risk
- Passwords, Backups & VPNs: the security that decides whether a breach sinks you
- Website accessibility is the most-sued thing on the internet
- The instructions your website isn't giving the browser
- Three real demand letters, eighteen years apart
- The privacy signal your site is ignoring
- Code you didn't write, running on your site tonight
- Three documents nearly every site gets wrong
- What an accessibility statement is actually for
- Cookies without locks
- Anyone can send email as you