62.1% of the EU's top 500 websites per country displayed a cookie consent banner by the end of May 2018, days after GDPR's enforcement deadline, up from 46.1% five months earlier, according to a Ruhr-Universitat Bochum study of 6,759 sites published at the Network and Distributed System Security Symposium (NDSS) in 2019. That 16-point jump remains the clearest documented evidence of how a single regulation changed the visible face of the web almost overnight.

The number that gets less attention is the gap it leaves behind: even after the sharpest adoption jump on record, more than a third of major EU websites still displayed no cookie consent notice at all. Below is the country-by-country breakdown, what type of banner most sites actually chose, and how many went further than a notice to ask for real opt-in consent.

62.1 percent of EU websites display a cookie consent banner 62.1% of the EU's top 500 sites per countryshow a cookie consent banner

Cookie consent notices rose from 46.1% of the 6,759 EU top-500 websites researchers monitored in January 2018 to 62.1% by the end of May 2018, the month GDPR's two-year grace period expired, according to Degeling, Utz, Lentzsch, Hosseini, Schaub, and Holz's NDSS 2019 study "We Value Your Privacy... Now Take Some Cookies." The researchers scanned the 500 most popular websites in each of the 28 EU member states monthly from January to October 2018, using automated crawling combined with manual verification in 24 languages.

Adoption did not plateau the moment the deadline passed. By October 2018, five months after enforcement began, banner prevalence had climbed to 63.2%, a smaller but still real gain over the post-deadline figure. Measured by country-specific top-level domain instead of global popularity ranking, the pre-to-post jump was even larger: 50.3% to 69.9% across 4,125 domains, a 19.6 point swing.

EU cookie banner adoption by month, 2018 (n=6,759 sites) 020406080%Jan 2018May 2018Oct 201863.2%

Figure 1: Adoption rose sharply around GDPR's May 2018 enforcement date, then kept climbing more slowly through the rest of the year. Source: Degeling et al., "We Value Your Privacy... Now Take Some Cookies," NDSS 2019, 6,759 EU top-500 sites.

No comparable-scale academic re-measurement of banner presence across all 28 EU markets has been published since. More recent research, covered below, narrows in on compliance quality and specific countries rather than repeating this full cross-country census, which is itself a useful data point about how little independent auditing this space gets relative to how often it is cited.

Which country had the biggest jump in banner adoption?

Adoption gains varied enormously by country, both in starting point and in how far GDPR pushed each market. Grouped by each country's own top-500 list, the increase ranged from 20.2 percentage points in Slovenia to 45.4 points in Italy. Measured by national top-level domain instead, Ireland's .ie sites posted by far the largest jump of any group in the dataset: from 17.3% banner adoption in January 2018 to 87.5% in May, a 70.2 point swing that the researchers singled out as the single highest increase in cookie banner prevalence by TLD.

Largest cookie banner adoption jumps, Jan to May 2018 (percentage points) 020406080pp70.2Ireland (.ie)45.4Italy (top-500)29.6United Kingdom22.8Germany20.2Slovenia (top-500)

Figure 2: Ireland's .ie domain saw the largest single adoption jump on record, more than double the next-highest country group. Source: Degeling et al., NDSS 2019, Table III.

The United Kingdom's top-500 list rose from 37.4% to 67.0% adoption, a 29.6 point gain, while Germany's rose from 26.2% to 49.0%, a 22.8 point gain, leaving German sites among the lower-adoption group even after GDPR took effect. Two patterns explain most of the variance: countries and domains with the lowest starting adoption generally posted the biggest raw gains, and country-code domains (like .ie) moved further than global top-500 rankings dominated by large international sites that had already adjusted their compliance posture ahead of the deadline.

How does banner adoption compare across major EU markets?

The country-level detail matters more than the EU-wide average for any site owner benchmarking against a specific market, since the gap between the highest and lowest-adoption countries in the dataset was still more than 30 percentage points even after the May 2018 deadline.

Country / groupSites measuredJan 2018May 2018Change
Ireland (.ie domains)10417.3%87.5%+70.2 pts
Italy (top-500 list)42321.3%66.7%+45.4 pts
United Kingdom (top-500)46337.4%67.0%+29.6 pts
Germany (top-500)45526.2%49.0%+22.8 pts
Slovenia (top-500)45143.9%64.1%+20.2 pts
All 28 EU states (top-500)6,35746.1%62.1%+16.0 pts

Table 1: Country-level cookie banner adoption before and after GDPR's May 2018 enforcement date. Source: Degeling et al., NDSS 2019, Table III.

Germany's comparatively modest 49.0% post-deadline figure is a useful check on the assumption that GDPR's home jurisdiction automatically leads on visible compliance. The researchers attributed the country-level spread to a mix of local enforcement posture, the share of small-business sites in each top-500 list, and how aggressively each country's regulator had already been pursuing cookie compliance before May 2018.

Do most websites build a custom banner or use an off-the-shelf platform?

Most do not use a recognized third-party platform. Of the EU websites displaying a cookie consent notice as of July 2018, only 15.4% used one of the 31 identified third-party consent libraries the NDSS 2019 researchers catalogued, meaning the large majority ran a custom-built or lightly-modified notice instead of a known commercial or open-source tool.

A separate, later study confirms the same pattern in a different market. Nouwens, Liccardi, Veale, Karger, and Kagal's CHI 2020 paper "Dark Patterns after GDPR" scraped the top 10,000 UK websites, ranked by the Tranco list, and found that only 680 sites, 6.8% of the total, used one of the five most popular consent management platforms (Quantcast, OneTrust, Cookiebot, TrustArc, and Crownpeak). Of those 680 sites running a recognized CMP, the researchers found only 11.8% met the minimal consent requirements they set based on European law.

How EU banners were built, among sites with a notice (Jul 2018) 84.6%15.4%Custom or unrecognized build84.6%Known third-party library15.4%

Figure 3: Roughly six in seven cookie notices in the EU dataset were not built on any of the 31 consent libraries researchers could identify. Source: Degeling et al., NDSS 2019.

The two studies used different populations, an EU-wide top-500 sample versus the UK's top 10,000, so their percentages are not directly interchangeable. Read together, they point at the same conclusion: recognizable commercial consent platforms cover a small minority of the sites that display a cookie notice, which means most of the compliance burden for banner wording and mechanics sits with whoever built the site, not a vendor.

Very few, even among sites that display a notice at all. The NDSS 2019 researchers identified just 37 websites, out of thousands analyzed in depth for cookie banner behavior, that implemented a genuine opt-in mechanism, blocking non-essential cookies by default and requiring an affirmative click before setting them. The rest relied overwhelmingly on implied consent, where continued use of the site after seeing the notice counts as agreement, a mechanism the researchers note does not meet Article 7 GDPR's requirements for valid consent.

Figure 4: Most banners never reach the opt-in step, even when they display a notice. Source: Degeling et al., NDSS 2019, Section VI.

The same research found a related but separate compliance signal worth noting: 147 websites stopped using third-party tracking libraries entirely between the pre- and post-GDPR crawls, a smaller but more durable form of compliance than adjusting banner wording. Together, the 37-site opt-in figure and the 147-site tracking removal figure suggest that most of GDPR's visible effect on cookie behavior came from adding a notice, not from redesigning how consent or tracking actually works underneath it. Getting the underlying disclosure right still starts with a privacy policy that accurately names what a site collects and why, since a banner and a privacy policy are required to describe the same data practices, not competing or conflicting ones.

Why does banner adoption keep climbing years later?

Regulatory pressure and a growing paid consent-management market both keep pushing adoption upward well past 2018's post-GDPR baseline. Cookie consent enforcement has escalated sharply since then, and the commercial tooling built to keep up with it has grown into a market Mordor Intelligence values at 1.07 billion dollars in 2026, projected to reach 2.34 billion dollars by 2031 at a 17.05% compound annual growth rate.

Figure 5: Two decades of cookie consent regulation compressed into five milestones, from directive to tooling market. Sources: EU Directive 2009/136/EC, Degeling et al. (2019), Nouwens et al. (2020), Mordor Intelligence (2026).

That growth curve does not mean banner adoption is now universal. It means the gap the 2018 data documented, roughly a third of major EU sites with no banner at all, has almost certainly narrowed further, even though no equivalent full-scale academic re-measurement has confirmed by how much.

The Bottom Line

Cookie consent banners went from a minority feature to a majority one in the space of five months around GDPR's May 2018 deadline, rising from 46.1% to 62.1% of the EU's top websites and continuing to 63.2% by October. That headline number, though, hides two harder truths: adoption still varied by more than 30 percentage points between the highest and lowest-adoption countries even after the deadline, and only a small minority of banners, 15.4% built on a known library in the EU dataset and 6.8% on a leading commercial CMP in the UK, came from recognizable third-party tooling rather than a custom build. Fewer than 40 sites out of thousands studied in depth implemented genuine opt-in consent rather than the implied-consent pattern regulators have since ruled inadequate. For a site owner, the practical read is that displaying a banner was never the finish line: the underlying privacy policy and the banner have to describe the same data practices accurately, which is the part a generator handles more reliably than a one-off custom build.

Frequently Asked Questions

What percentage of websites show a cookie consent banner? 62.1% of the EU's top 500 websites per country displayed a cookie consent banner by the end of May 2018, shortly after GDPR took effect, up from 46.1% in January 2018, according to a Ruhr-Universitat Bochum study of 6,759 sites published at NDSS 2019. That share climbed further to 63.2% by October 2018 and is the most recent cross-country academic measurement at this scale.

Which country saw the biggest jump in cookie banner adoption? Ireland's .ie domains saw the largest single jump, rising from 17.3% to 87.5% banner adoption around GDPR's enforcement date, a 70.2 percentage point increase, according to the same NDSS 2019 study. Among country-specific top-500 lists, Italy rose the most, up 45.4 percentage points, while Slovenia rose the least among the largest movers, up 20.2 points.

Do most websites build their own banner or use an off-the-shelf CMP? Most build custom or lightly-configured banners. Only 15.4% of EU websites displaying a cookie notice used one of 31 identified third-party consent libraries as of July 2018, per the NDSS 2019 study. A separate CHI 2020 study by Nouwens et al. found only 6.8% (680 of 10,000) of the UK's top websites used one of the five leading commercial consent management platforms.

How many websites actually ask for real opt-in consent before setting cookies? Very few, even among sites with a visible banner. The NDSS 2019 researchers identified just 37 websites, out of thousands analyzed in depth, that asked for explicit consent before setting any cookies. Most banners instead relied on implied consent, where continued browsing counts as agreement.

Where the Numbers Come From

  1. Degeling, Utz, Lentzsch, Hosseini, Schaub, Holz (Ruhr-Universitat Bochum / University of Michigan): "We Value Your Privacy... Now Take Some Cookies: Measuring the GDPR's Impact on Web Privacy," NDSS 2019. Monthly crawls of the 500 most popular websites in each of the 28 EU member states, January to October 2018, 6,759 unique domains; source of the 46.1%, 62.1%, 63.2%, country-level, library-share, and opt-in figures.
  2. Nouwens, Liccardi, Veale, Karger, Kagal: "Dark Patterns after GDPR: Scraping Consent Pop-ups and Demonstrating their Influence," CHI 2020. Scraped consent designs across the UK's top 10,000 websites (Tranco list); source of the 680-site (6.8%) leading-CMP adoption figure and the 11.8% minimal-compliance figure among those.
  3. Mordor Intelligence: "Consent Management Market Size and Share Analysis," 2026. Source of the 1.07 billion dollar 2026 market size and 17.05% CAGR to 2.34 billion dollars by 2031, used here as context for continued adoption growth since the 2018 and 2020 studies above.

Note: All figures verified as of August 2026. The 46.1%/62.1%/63.2% cross-country adoption figures remain the most recent large-scale, peer-reviewed measurement at this scope; no equivalent full 28-country academic re-crawl has been published since NDSS 2019, so treat the 2018 baseline as a floor that has likely risen further given the consent management market's growth documented above, not as a current-day census.