Cookie consent is where privacy law meets a single click. In 2026, roughly 25% of website visitors accept all cookies the moment a banner appears, based on Advance Metrics’ analysis of more than 1.2 million visitors. Yet a peer-reviewed 2025 study of 254,148 websites found that only 15% of banners even meet the minimum bar for GDPR compliance. The gap between what sites ask for and what the law requires is the real story of the numbers below.
If you run a website, the takeaway is direct: the banner you show, and the buttons you offer, change your consent rate more than anything your visitors believe about privacy. Here is what the current data says, and where the sources are shaky enough that you should treat a figure as directional rather than settled.
What percentage of visitors accept cookies?
About 25.4% of visitors accept all cookies on their first interaction with a banner, and 33.6% ignore it completely, according to Advance Metrics’ study of over 1.2 million business-audience visitors (data collected in 2023). The remaining 41% reject or take some other action. These are observed first-click numbers, not survey self-reports, which makes them more reliable than the “average accept rate” figures that circulate on vendor blogs.
Figure 1: First-click banner behavior. Source: Advance Metrics, 1.2M+ visitors, 2023 data.
Warning
Treat any single “global accept rate” number with suspicion. Several roundups claim 45% to 60% accept rates, or that US visitors accept at over 80% versus under 25% in Germany and France. We could not trace those splits to a primary dataset, and the study those claims cite does not actually contain the country breakdown attributed to it. Consent depends on region, device, industry, and banner design, so a blended average hides more than it reveals.
The pattern that holds across studies is that most visitors never make a deliberate choice. They ignore, dismiss, or click the most prominent button. That is exactly why banner design carries more weight than user intent.
How many cookie banners are actually compliant?
Only 15% of the top 10,000 websites across 31 EU and ePrivacy countries run a minimally compliant banner, meaning one that presents Accept and Reject with equal prominence. This is the headline finding of Nouwens et al., “A Cross-Country Analysis of GDPR Cookie Banners,” published at CHI 2025 after analyzing 254,148 websites. A further 67% show some consent interface, but most fail the equal-prominence test.
The reasons for failure are specific and fixable:
| Compliance failure | Share of non-compliant banners |
|---|---|
| No reject option at all | 56% |
| No granular purpose controls | 30% |
| Reject harder to see than accept | 24% |
Compliance also varies sharply by country. Spain led the dataset at 28% compliant interfaces, while Slovenia sat at just 3%. The same study found little evidence that regulator guidance and fines had moved compliance rates at scale, a finding worth flagging as the authors’ own conclusion rather than a settled fact.
Figure 2: The minimum test a banner must pass to count as compliant. Source: CHI 2025 criteria.
Cookie banner trends: 2018 to 2026
The direction of travel is clear even where individual numbers are contested. Across 11,364 EEA websites tracked from 2018 to 2024, banners offering both Accept and Reject rose from 2.94% to 30.66%, and CMP adoption climbed from 11.60% to 40.29%. Enforcement can accelerate this: after France’s CNIL acted in December 2021, French site compliance rose by 16.08 percentage points within three months and by a further 21.69 points by September 2022.
Banner infrastructure now decides the result. The presence of a reject button depends heavily on which platform a site uses.
Figure 3: Reject-button availability by consent platform. Source: EEA longitudinal study, 2024 data.
If your banner does not offer a clear reject path, you are both risking a fine and inflating an accept rate that will not survive an audit. The fastest fix is to publish a clear, current cookie policy and pair it with a compliant banner. You can generate a compliant cookie policy in a few minutes and match it to the banner behavior your CMP supports.
Do dark patterns still shape consent?
A 2025 preprint analyzing 14,000 sites found that manipulative banner design remains widespread: 44% of EU sites and 83% of US sites set tracking cookies before any click, and 92% of cookies persist for more than 12 months. This paper is a preprint and not yet peer-reviewed, so treat these figures as strong signals rather than final numbers. The pattern is consistent with the compliance data above: when reject is buried or absent, “consent” is closer to inertia than agreement.
Figure 4: Pre-consent tracking by region. Source: 2025 dark-patterns preprint, 14,000 sites. Preprint, treat as directional.
Do browser extensions and auto-consent signals change the numbers?
A growing share of consent decisions are never made by a person at all. Extensions like “I don’t care about cookies” (now owned by AdGuard) and the academic project Consent-O-Matic accept or reject banners automatically before a user sees them. Global Privacy Control, a browser-level signal now enforceable under California law and several other US state privacy laws, tells sites not to sell or share data with no click at all.
We could not find a reliable, current figure for how many consent choices these tools make on a person’s behalf, and the compliance studies above do not isolate automated agents from human clicks. Treat that as a real blind spot. The observed accept and reject rates in this article mix deliberate human choices with extensions and signals acting silently in the background, so as adoption of Global Privacy Control and auto-consent tools grows, the “ignored” and “accepted all” buckets increasingly include machines, not people. We will refresh this section when defensible numbers exist.
What is happening with enforcement and third-party cookies?
Regulators moved from guidance to penalties in 2025. France’s CNIL issued a 325 million euro fine to Google and a 150 million euro fine to Shein, both tied to cookies set without valid consent and to non-functional reject controls. These are primary-source regulator decisions, the most reliable figures in this article.
The technical ground shifted too. In April 2025 Google confirmed it will not ship a separate third-party cookie prompt in Chrome, and will not force deprecation. Third-party cookies remain on by default with an opt-out in settings. Safari, Firefox, and Brave already block them by default. The result is a split web where consent, not deprecation, remains the compliance battleground.
Figure 5: Key enforcement and platform milestones. Sources: CNIL decisions, Google Privacy Sandbox.
The Bottom Line
The single most useful number in 2026 is not the accept rate, it is the 15% compliance rate. Most banners are not built to record a lawful choice, so most “consent” is fragile. Around 25% of visitors accept everything on first click, but that figure is a product of design, not agreement. Fix the banner, offer a genuine reject, and publish a current cookie policy, and both your compliance and the trustworthiness of your consent data improve at once.
Frequently Asked Questions
What percentage of people accept cookies? About 25.4% of visitors accept all cookies on first interaction with a banner, based on Advance Metrics’ 2023 study of 1.2 million visitors. Around 33.6% ignore the banner entirely, so most users never make an active choice.
Are most cookie banners GDPR-compliant? No. A CHI 2025 study of 254,148 websites found only 15% of the top 10,000 EU sites run a minimally compliant banner with Accept and Reject shown equally. 56% of non-compliant banners lack a reject option altogether.
Does banner design change the consent rate? Yes, significantly. In 2024 EEA data, 55.16% of Cookiebot banners offered a reject button versus 13.39% of generic plugin banners. The platform and layout you choose affects both accept rates and legal exposure.
Are third-party cookies being phased out? Not by Chrome. In April 2025 Google confirmed it will keep third-party cookies on by default with a user opt-out. Safari, Firefox, and Brave continue to block them by default.
Sources and References
- Nouwens, Kristensen, et al.. (2025). “A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods for Scraping Them.” CHI 2025, ACM. Analysis of 254,148 websites across 31 countries.
- Advance Metrics. (2024). “Cookie Behaviour Study, 5 Years After GDPR.” Observed first-click behavior of 1.2M+ visitors, data period 2023.
- Longitudinal EEA cookie banner study. (2024 data). “A History of GDPR Cookie Banner Compliance.” 11,364 websites, 30 EEA countries, 2018 to 2024.
- CNIL. (2025). “Cookies Placed Without Consent: Shein Fined 150 Million Euros.” Official regulator decision.
- CNIL. (2025). Google cookie consent decision, 325 million euro total. Official regulator decision.
- Singh, Jin, Kim. (2025 preprint). “Unveiling Evolving Dark Patterns in Cookie Consent Banners.” 14,000 sites, collected 2025. Not yet peer-reviewed.
- Google Privacy Sandbox. (2025). Update on the plan for third-party cookies in Chrome.
Note: All figures verified as of July 2026. Consent behavior and enforcement change quickly, so headline figures are refreshed at least twice a year. Preprint and rolling-source figures are flagged in-text and should be re-checked before each refresh.