59% of website visitors accepted cookies and 39% refused them when shown a compliant banner with an equally visible reject button, according to CNIL's June 2022 study tracking 1,000 of France's most popular websites. That single number sits at the center of a much bigger shift: banner design, not user intent, now decides most consent outcomes, and regulators spent over 475 million euros in fines during 2025 alone making sure businesses cannot tilt that design in their favor.

What percentage of people accept cookies?

Acceptance sits close to a coin flip once a banner gives users a real, equally weighted choice. CNIL's monitoring of 1,000 popular French websites between January 2021 and August 2022 found a 59% acceptance rate and a 39% refusal rate by June 2022, with the remaining share leaving choices unset. That France-specific figure looks low next to a widely cited industry pattern showing US users accepting cookies more than 80% of the time, while French and German users accept fewer than 25% of the time, per Advance Metrics' cookie behavior research. The gap is regional regulatory culture as much as banner mechanics: US users see fewer cookie prompts overall and have less prior exposure to "reject" as a real option.

How visitors answer French cookie consent banners 59% 39% share of visitors acceptingversus refusing cookies,CNIL, June 2022

A separate 2022 Statista poll of French internet users adds a durable-preference angle to the same picture: only 5% of respondents said they never accept cookie banners, while 28% said they always accept, with the remainder deciding case by case. Read together, the CNIL and Statista data point at the same conclusion from two directions: roughly six in ten cookie decisions land on "accept," but that share is closer to even than the historical 80-to-90% acceptance rates recorded before regulators forced reject buttons onto banners.

Do reject buttons actually stop tracking?

No, not consistently. A 2024 study presented at USENIX Security by Ahmed Bouhoula and colleagues at ETH Zurich automatically analyzed cookie notices on 97,000 EU websites, drawn from Chrome UX Report data to represent real browsing traffic rather than a hand-picked sample. The study's most cited finding: 65.4% of websites offering a cookie rejection option collected user data anyway, despite the visitor's explicit refusal. The researchers also found that prior compliance studies, which typically restricted analysis to sites using the IAB Transparency and Consent Framework, produced results that diverge sharply from this broader, unbiased sample, meaning earlier compliance estimates likely understated the real scope of the problem.

Figure 1: Two out of three websites with a working reject button did not honor it. Source: Bouhoula et al., "Automated Large-Scale Analysis of Cookie Notice Compliance," USENIX Security 2024, 97,000 EU websites analyzed.

A working reject button is table stakes, not proof of compliance. Sites need server-side or tag-manager-level enforcement tied to the consent signal, not just a banner that visually records a choice while ad and analytics scripts keep firing regardless.

Enforcement against cookie violations has escalated well beyond the warning-letter phase CNIL used through 2022. CNIL issued 94 formal notices after roughly 300 targeted cookie audits in 2023, then moved to direct sanctions: 87 sanctions in 2024 and 83 in 2025, a rate of roughly one sanction every four to five days. The single largest cookie-specific enforcement day on record came on 1 September 2025, when CNIL fined Google 325 million euros (200 million against Google LLC, 125 million against Google Ireland Limited) and Shein 150 million euros, both for placing advertising cookies before obtaining consent and for consent flows that made accepting easier than refusing.

Figure 2: Cookie consent regulation moved from a directive to routine multi-hundred-million-euro fines in under two decades. Source: CNIL press releases 2022-2025, EU Directive 2009/136/EC.

For Google's case specifically, CNIL found that its account creation flow required six clicks to refuse personalized advertising cookies against just two clicks to accept them, the exact asymmetric-friction pattern regulators now treat as a standalone violation independent of whether a reject button technically exists.

Consent management platform pricing scales from free tiers for small sites to enterprise contracts running into six figures, but most small and mid-size businesses land in a narrow band. CookieYes prices per domain with page-view caps starting around 10 dollars a month, Cookiebot's Pro plan runs 29 dollars a month for two domains with 5 dollars per additional domain, and consentmanager.net's paid tiers start near 23 euros a month and scale to 219 euros a month for higher traffic and more domains. None of these figures include the cost of implementation time, legal review, or fixing the server-side enforcement gap the ETH Zurich study identified, which a banner subscription alone does not solve.

CMP tierStarting priceWhat it typically covers
Budget (CookieYes-tier)~$10/month1 domain, capped monthly page views
Mid-market (Cookiebot-tier)~$29/month2 domains, unlimited banner displays
Regional (consentmanager-tier)~€23 to €219/month1 to 10+ domains, granular consent logging
Enterprise (OneTrust-tier)Custom quoteMulti-brand, audit trails, legal-team workflows

Source: CookieYes, Cookiebot, and consentmanager.net published pricing pages, checked July 2026.

The market those subscriptions sit inside keeps expanding regardless of tier. The global consent management platform market is worth 1.07 billion dollars in 2026, according to Mordor Intelligence, and is forecast to grow at a 17.05% compound annual rate to reach 2.34 billion dollars by 2031. North America holds the largest regional share at 36.2% of 2025 revenue, while Asia-Pacific is the fastest-growing region at a 17.4% compound annual rate through 2031, driven by newer national privacy laws following the GDPR and CCPA template. If your site collects data from EU or UK visitors, a privacy policy generator built around current cookie disclosure requirements is the lower-cost half of the compliance stack, since a compliant policy and a compliant banner have to say the same thing about what you collect and why.

Figure 3: The consent management market compounds at 17.05% annually through 2031. Source: Mordor Intelligence, Consent Management Market report, 2026.

How do visitors actually behave at the banner?

Behavior splits three ways rather than defaulting to a single dominant choice once a banner offers a genuine option. A 2025 Pollfish survey of 1,000 US adults, commissioned by All About Cookies, found 24% blindly accept all cookies when prompted, 25% reject all optional cookies by default, and 27% manually select specific categories, with the remainder unsure or inconsistent. The same survey found that fewer than 40% of respondents understood what cookies actually are and do, and only 11% could correctly identify all the real uses of cookies from a list of options, which helps explain why so many users default to whichever button is visually easiest rather than reasoning through the choice.

Figure 4: No single behavior dominates once a real choice is offered. Source: All About Cookies / Pollfish survey, 1,000 US adults, August 2025.

That three-way split also explains why acceptance-rate figures vary so widely across studies: a banner that makes "accept" the only prominent button pushes nearly everyone into that 24% blind-accept bucket, while a banner with equally weighted buttons lets the reject-leaning 25% and customize-leaning 27% actually register their real preference.

What decides whether a visitor accepts or rejects?

Banner mechanics decide the outcome more than any stated privacy preference does. The compliance test regulators apply comes down to whether accepting and refusing require the same number of steps and the same visual weight.

Figure 5: Two separate failure points, banner asymmetry and unenforced backend logic, both distort the real consent rate. Source: CNIL (2022), Bouhoula et al. USENIX Security 2024.

Google's own September 2025 CNIL fine is a direct example of the first failure point: a six-click path to refuse against a two-click path to accept, which by itself pushed outcomes toward acceptance regardless of what users actually preferred.

The Bottom Line

Cookie consent in 2026 is no longer a simple accept-or-decline moment. The headline 59% acceptance rate from CNIL's French study only holds when a banner gives users a genuinely equal choice, and the 65.4% of EU sites still collecting data after a refusal shows that even a technically working reject button is not the same as an enforced one. Regulators are treating both failures as the same underlying violation: France's CNIL alone moved 475 million euros in fines through Google and Shein in a single day in September 2025, and issued sanctions at a pace of roughly one every four to five days across the year. A 1.07-billion-dollar consent management market exists to solve the banner half of this problem, but the server-side enforcement gap the ETH Zurich researchers documented means a subscription to a consent platform is necessary and not sufficient on its own.

Frequently Asked Questions

What percentage of people accept cookies? 59% of visitors accepted cookies and 39% refused them when shown a compliant banner, according to CNIL's June 2022 study of 1,000 popular French websites. Acceptance rates vary sharply by country and banner design, from under 25% in France and Germany to over 80% in the United States.

Do cookie rejections actually stop data collection? Not always. A 2024 USENIX Security study of 97,000 EU websites by researchers at ETH Zurich found that 65.4% of sites offering a reject option collected user data anyway despite the explicit refusal.

How big is the cookie consent management market in 2026? The global consent management platform market is worth 1.07 billion dollars in 2026, according to Mordor Intelligence, and is projected to grow at a 17.05% compound annual rate to reach 2.34 billion dollars by 2031.

How much have regulators fined companies over cookie consent? France's CNIL alone fined Google 325 million euros and Shein 150 million euros in a single day in September 2025 over cookie consent violations, and issued 83 separate sanctions across 2025.

Where the Numbers Come From

  1. CNIL. (2022). "Evolution of Practices on the Web Regarding Cookies." 1,000 top French websites monitored January 2021 to August 2022; 59% acceptance, 39% refusal as of June 2022.
  2. USENIX Security 2024 / Bouhoula, Kubicek, Zac, Cotrini, Basin (ETH Zurich). "Automated Large-Scale Analysis of Cookie Notice Compliance." 97,000 EU websites analyzed; 65.4% collected data despite explicit refusal.
  3. Mordor Intelligence. (2026). "Consent Management Market Size and Share Analysis." 1.07 billion dollar 2026 market size, 17.05% CAGR to 2.34 billion dollars by 2031.
  4. CNIL. (2025). "Cookies Placed Without Consent: SHEIN Fined 150 Million Euros by the CNIL." 1 September 2025 decision.
  5. All About Cookies. (2025). "Cookies Survey." Pollfish survey of 1,000 US adults, conducted August 2025; 24% blindly accept, 25% reject all, 27% customize.

Note: All figures verified as of July 2026. CNIL sanction counts and CMP market forecasts are refreshed at least twice a year as new enforcement decisions and market reports are published; the ETH Zurich compliance figure reflects the study's 2024 data collection window and has not been re-measured at the same scale since.