88.2% of consent banners failed to meet the minimum legal requirements researchers set based on European law, according to a CHI 2020 study by Nouwens, Liccardi, Veale, Karger and Kagal that scraped 680 unique consent designs from the five most popular consent management platforms across the UK's top 10,000 websites. That leaves just 11.8% of banners tested passing the bar. The gap has not closed on its own since 2020: a newer, larger 2024 audit of 97,000 EU sites found the same underlying pattern, and regulators spent 2025 handing out some of the largest cookie consent fines on record.

Nearly nine in ten consent banners fail minimum legal requirements 88.2% of tested consent banners failedminimum GDPR legal requirements

11.8% is the pass rate, not the fail rate: 88.2% of the 680 consent designs Nouwens et al. scraped from the UK's top 10,000 websites in 2020 did not meet the minimal requirements the researchers defined from European law, covering things like an equally prominent reject option and no pre-checked consent boxes. The study remains the largest published audit of consent banner legal compliance at this scale, and no larger academic replication has been published since, though the newer studies below suggest the underlying design problem has persisted.

Consent banners meeting minimum GDPR requirements (Nouwens et al., CHI 2020) 88.2%11.8%Fails minimum requirements88.2%Meets minimum requirements11.8%

Figure 1: Fewer than one in eight of the 680 consent designs tested met the minimum bar researchers set from European law. Source: Nouwens, Liccardi, Veale, Karger and Kagal, "Dark Patterns after the GDPR," CHI 2020, top 10,000 UK websites.

Info

Nouwens et al.'s 2020 study is still the largest and most cited audit of consent banner legal compliance at this scale, but it is six years old as of this post. Treat 88.2% as the baseline finding rather than a live, continuously updated figure, and see the 2024 follow-up study below for evidence the pattern has not meaningfully improved.

The most common problem is not a missing reject button, it is a reject button that exists but is designed to be ignored. Matte, Bielova and Santos crawled 22,949 European websites using IAB Europe's Transparency and Consent Framework and then extensively tested 560 of them by hand, publishing their results at IEEE Security and Privacy in 2020. Overall, 54% of the 560 sites tested had at least one confirmed compliance violation.

Share of 560 tested consent banners with each violation type (Matte, Bielova & Santos, 2020) Nudges via pre-selected options42.1%Registers consent with no real choice25.2%Stores consent despite opt-out4.8%

Figure 2: The most common violation nudges users toward accepting, rather than skipping the reject option outright. Source: Matte, Bielova & Santos, "Do Cookie Banners Respect my Choice?," IEEE S&P 2020, 560 sites extensively tested.

Violation typeShare of 560 sites testedWhat it actually looks like
Nudges via pre-selected or highlighted options42.1%The accept button is bigger, brighter, or pre-ticked; reject is a small text link
Registers a positive consent with no real user choice25.2%The banner logs "accept" before or without the visitor clicking anything
Stores a positive consent despite an explicit opt-out4.8%The visitor clicks reject and the banner ignores it, storing acceptance anyway
At least one confirmed violation overall54%Majority of the 560 sites tested failed at least one of the checks above

Source: Matte, Bielova & Santos, IEEE S&P 2020.

A banner that visually offers a reject button is not the same thing as a banner that legally works. The gap between the two is where most of these violations live.

Do reject buttons actually stop data collection once clicked?

Not consistently, and the problem has not gone away in the years since the 2020 studies above. A 2024 study presented at USENIX Security by researchers at ETH Zurich automatically analyzed cookie notices on 97,000 EU websites, drawn from Chrome UX Report data to reflect real browsing traffic rather than a hand-picked sample. Their headline finding: 65.4% of websites offering a reject option collected user data anyway, despite the visitor's explicit refusal. Read the full acceptance and rejection breakdown, including how banner design shifts the numbers by country, in our cookie consent statistics for 2026.

A working reject button that a browser can click is table stakes, not proof of compliance. Enforcement, not banner design alone, is what closes that gap.

Researchers and regulators do not eyeball a banner and guess. Both the CHI 2020 and IEEE S&P 2020 studies above ran automated crawlers that clicked through each banner's actual options and inspected what the site stored and sent afterward, the same basic test a data protection authority runs during an investigation.

Figure 3: The same basic pass/fail test both academic audits and regulators apply to a consent banner. Source: methodology described in Nouwens et al., CHI 2020, and Matte, Bielova & Santos, IEEE S&P 2020.

A privacy policy generator built to match current cookie and consent disclosure rules closes the documentation side of this test automatically, though the banner mechanics themselves still need to pass the technical checks above independently. Getting the disclosure and the banner behavior aligned is what separates a banner that looks compliant from one that actually is. For how many sites run a banner at all before this test even applies, see how many websites use a cookie notice.

Yes, and 2025 produced some of the largest cookie-specific penalties on record. France's data protection authority, the CNIL, fined Google 325 million euros and Shein 150 million euros on the same day in September 2025, both decisions explicitly citing cookies placed without valid consent. The CNIL issued 83 separate sanctions across 2025 overall, a pace that shows enforcement following directly from the kind of violations the academic audits above documented years earlier.

Figure 4: Academic audits identified the compliance gap years before enforcement caught up to it at scale. Sources: CHI 2020, IEEE S&P 2020, USENIX Security 2024, CNIL 2025 decisions.

How do the major compliance studies compare?

StudySampleYearWhat it measuredResult
Nouwens et al. (CHI)10,000 UK sites, 680 CMP designs2020Meets minimum GDPR requirements88.2% fail
Matte, Bielova & Santos (IEEE S&P)560 sites tested in depth, from 22,949 crawled2020At least one confirmed violation54% fail
Bouhoula et al. (USENIX Security)97,000 EU sites2024Collects data despite reject65.4% fail
Share of sites failing each study's compliance test 0255075100%88.2Nouwens 2020 (n=10,000)54Bielova 2020 (n=560)65.4Bouhoula 2024 (n=97,000)

Figure 5: Three different tests, three different samples, the same conclusion: most consent banners fail at least one compliance check. Sources: CHI 2020, IEEE S&P 2020, USENIX Security 2024.

No two studies test the exact same thing, so these numbers are not directly interchangeable, but every large-scale audit published since GDPR took effect has found a majority-to-supermajority failure rate. That consistency across independent research teams, sample sizes, and years is itself the strongest evidence that banner non-compliance is systemic rather than a handful of bad actors.

The Bottom Line

88.2% is six years old, but nothing in the newer research contradicts it. A 97,000-site audit in 2024 found essentially the same behavior, and regulators spent 2025 fining companies hundreds of millions of euros for the exact violation types the 2020 studies documented: pre-selected accept buttons, banners that log consent without a real choice, and reject clicks that get ignored. For a site owner, the fix is not complicated even if the industry-wide numbers are bad: an equally weighted reject option, no tracking before a real click, and enforcement that actually stops the scripts when a visitor declines. Most of the sites in these audits failed on the first or third of those three things, not on some obscure technicality.

Frequently Asked Questions

What percentage of cookie consent banners violate GDPR? 88.2% of the consent banners tested failed to meet the minimum legal requirements researchers set based on European law, according to a CHI 2020 study by Nouwens et al. that scraped 680 consent designs across the UK's top 10,000 websites. Only 11.8% passed.

What are the most common consent banner violations? Nudging users toward accepting through pre-selected or visually emphasized options was the most common issue, found on 42.1% of the 560 sites tested in depth by Matte, Bielova and Santos (IEEE S&P, 2020). 25.2% registered a positive consent even though the visitor made no choice at all, and 4.8% stored a positive consent despite an explicit opt-out.

Do reject buttons actually stop data collection once clicked? Not consistently. A 2024 USENIX Security study of 97,000 EU websites by researchers at ETH Zurich found that 65.4% of sites offering a reject option collected user data anyway after the visitor declined.

Have regulators fined companies over non-compliant consent banners? Yes. France's CNIL fined Google 325 million euros and Shein 150 million euros on the same day in September 2025, both explicitly over cookie consent banner failures, and issued 83 separate sanctions across 2025.

Where the Numbers Come From

  1. Nouwens, Liccardi, Veale, Karger & Kagal. (2020). "Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence." ACM CHI 2020. 680 consent designs scraped from the UK's top 10,000 websites; 11.8% met minimum requirements.
  2. Matte, Bielova & Santos. (2020). "Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent Framework." IEEE Security and Privacy 2020. 560 sites extensively tested from a crawl of 22,949; 54% had at least one confirmed violation.
  3. USENIX Security 2024 / Bouhoula, Kubicek, Zac, Cotrini, Basin (ETH Zurich). "Automated Large-Scale Analysis of Cookie Notice Compliance." 97,000 EU websites analyzed; 65.4% collected data despite explicit refusal.
  4. CNIL. (2025). "Cookies Placed Without Consent: SHEIN Fined 150 Million Euros by the CNIL." 1 September 2025 decision, issued alongside a 325 million euro fine against Google over the same underlying violation type.

Note: All figures verified as of August 2026. The Nouwens et al. and Matte, Bielova & Santos figures reflect their original 2020 data collection windows and have not been re-measured at the same scale since; the ETH Zurich figure reflects its 2024 collection window. CNIL sanction counts are refreshed at least twice a year as new enforcement decisions are published.