Hiding the reject button on a cookie banner raises the accept rate from 55% to 77%, a 22-percentage-point jump, according to a CHI 2020 field experiment that tested 8 banner designs on 40 participants. That single design choice moves more clicks than anything a visitor believes about privacy. The gap between what a banner is built to extract and what a compliant banner actually looks like is the story behind every number below.

How much does hiding the reject button change the accept rate?

A lot. Nouwens et al.’s CHI 2020 field experiment found that when the reject option was removed from the first screen of a banner, the accept rate rose from 55% to 77%, a jump of 22 percentage points. A second condition using a full-screen barrier notice instead of a banner produced a nearly identical 23-point increase. The same study scraped the five most common consent management platforms across the UK’s top 10,000 sites (n=680) and found only 11.7% met the minimal legal requirement of an equally prominent reject option.

Figure 1: Removing the reject button from the first screen raises accept rates by 22 points. Source: Nouwens, Liccardi, Veale, Karger, Kagal, “Dark Patterns after the GDPR,” CHI 2020.

Hiding the reject button lifts cookie banner accept rates by 22 points 77% accept rate when the rejectbutton is hidden, up from 55%,CHI 2020 field experiment

That 22-point swing is why regulators now treat a hidden reject button as a compliance red flag rather than a neutral design choice. A banner that makes rejecting harder than accepting is not measuring consent, it is measuring the path of least resistance.

Fewer than half. The CHI 2025 cross-country study by Nouwens et al. scraped 254,148 websites across 31 EU and ePrivacy-law countries and found only 45% of banners offered a reject option of any kind. Among the top 10,000 EU sites specifically, just 15% met the minimal bar of showing Accept and Reject with equal visual prominence, even though 67% displayed some kind of consent interface.

Compliance failureShare of non-compliant banners
No reject option at all56%
No granular purpose controls30%
Reject harder to see than accept24%

Source: Nouwens et al., CHI 2025, 254,148 sites analyzed.

Figure: No reject option at all is the single largest compliance failure, ahead of missing granular controls or a visually buried reject button. Source: Nouwens et al., CHI 2025.

For a site owner, the fastest way to close this gap is to pair a compliant banner with a cookie policy generator that lists the same categories the banner offers, so the disclosed cookie use and the clickable consent options actually match.

The pattern holds across five years of research: a reject button that exists in code but is visually buried counts as absent in practice, and most banners still take that shortcut.

How does button design change whether visitors click Accept or Reject?

Design decides the outcome more than user intent does. A published nudging experiment (Congiu, Moscati, Scacchi, Italian Economic Journal, 2025, n=358) tested a plain control banner against a salience nudge (making Reject more visible), a framing nudge (phrasing Reject as a negation), and both combined. The control banner produced a 27% reject rate. Combining both nudges pushed rejection to 80%, a 53-point swing from the same underlying population.

Figure 2: How two design nudges change the reject-click rate on an identical population. Source: Congiu, Moscati, Scacchi, “Digital Nudging and Cookie Rejection: An Experiment,” Italian Economic Journal, 2025.

Real-world sites show the same pattern outside the lab. In etracker’s benchmark of German cookie banners, sites with an equally visible Accept and Reject button averaged a 40% consent rate, while sites relying on subtler visual cues, still short of a dark pattern, averaged 54%. The click a visitor makes is less a decision about privacy and more a response to which button the layout points them toward.

This mirrors the accept-side design research covered in cookie consent statistics for 2026, where the same reject-button visibility gap shows up as a compliance failure rather than a UX preference.

Whichever button gets more visual weight gets more clicks, in both directions, which is exactly why regulators now test for equal prominence rather than for the mere presence of a reject option.

Does clicking Reject actually stop tracking cookies?

Not always. A 2025 preprint analysis of 14,000 sites found that 44% of EU sites and 83% of US sites set tracking cookies before a visitor clicks anything at all, and 92% of those cookies persist for more than 12 months. This paper has not yet completed peer review, so treat the figures as a strong signal rather than a settled number, but it lines up with the compliance gaps found in the peer-reviewed CHI studies above.

Figure 3: What a Reject click can and cannot undo. Source: 2025 dark-patterns preprint, 14,000 sites analyzed. Preprint, treat as directional.

If a banner sets cookies before the visitor makes any choice, the accept and reject rates recorded by that banner describe what people clicked, not what actually happened to their data. That distinction matters more with each enforcement cycle.

How has reject-button availability changed since GDPR took effect?

Slowly, then quickly. Across 11,364 EEA websites tracked from 2018 to 2024, the share of banners offering both an Accept and a Reject button climbed from 2.94% to 30.66%, and consent management platform adoption rose from 11.60% to 40.29% over the same period. Enforcement accelerated the shift: after France’s CNIL acted against non-compliant banners in December 2021, French site compliance rose 16.08 percentage points within three months.

Figure 4: Reject-button adoption and enforcement milestones, 2018 to 2025. Sources: longitudinal EEA cookie banner study (2024 data); CNIL decisions, 2025.

The trend line is one-directional: every year since GDPR, both the share of banners offering a genuine reject click and the size of the fines for failing to offer one have grown.

France’s data protection authority, the CNIL, issued 83 sanctions in 2025 totaling 486.8 million euros, the large majority tied to just two decisions: a 325 million euro fine against Google and a 150 million euro fine against Shein, both for cookies set without valid consent and for reject controls that did not function as displayed. These are primary-source regulator decisions, the most reliable figures in this dataset because they come from the enforcement body’s own published rulings rather than a scraped sample.

Regulator actionAmountYearCited violation
CNIL fine, Google325 million euro2025Cookies set without valid consent
CNIL fine, Shein150 million euro2025Non-functional reject control
CNIL total sanctions486.8 million euro (83 sanctions)2025Cookies, tracking, and ePrivacy violations

Source: CNIL, “Sanctions and Corrective Measures: CNIL’s Actions in 2025.”

The Bottom Line

The most useful number in this dataset is not an average accept rate, it is the 22-point gap a single hidden button creates. A cookie banner is not a passive disclosure, it is a UI that predictably steers clicks in whichever direction its buttons are weighted toward, and regulators are now pricing that steering at nine figures per violation. Fewer than half of banners offer a real reject option, and even the ones that do sometimes set tracking cookies before the click lands. Site owners who pair equal-prominence Accept and Reject buttons with a current cookie policy generator reduce both the compliance risk and the gap between what the banner promises and what the code actually does.

Frequently Asked Questions

How much does hiding the reject button change cookie banner accept rates? Removing the reject button from the first screen raises accept rates from 55% to 77%, a 22 percentage point jump, according to a CHI 2020 field experiment with 40 participants across 8 banner designs by Nouwens et al.

What percentage of cookie banners actually offer a reject button? Only 45% of cookie banners across 254,148 websites offered a reject option as of the CHI 2025 cross-country study, and just 15% of the top 10,000 EU sites met the minimal bar of showing Accept and Reject with equal prominence.

Does clicking Reject actually stop cookies from being set? Not always. A 2025 preprint analysis of 14,000 sites found 44% of EU sites and 83% of US sites set tracking cookies before any click at all, meaning the click sometimes has no effect on what already loaded.

How much do cookie consent fines cost in 2026? France’s CNIL issued 83 sanctions totaling 486.8 million euros in 2025, including a 325 million euro fine against Google and a 150 million euro fine against Shein, both tied to cookies set without valid consent.

Sources and References

  1. Nouwens, Liccardi, Veale, Karger, Kagal. (2020). “Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence.” CHI 2020, ACM. Field experiment, n=40; CMP scrape, n=680 UK sites.
  2. Nouwens, Kristensen, et al.. (2025). “A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods for Scraping Them.” CHI 2025, ACM. Analysis of 254,148 websites across 31 countries.
  3. Congiu, Moscati, Scacchi. (2025). “Digital Nudging and Cookie Rejection: An Experiment.” Italian Economic Journal, vol. 11(1). Online experiment, n=358.
  4. etracker. “Cookie Consent: How Legally Compliant Consent Works.” Benchmark of German cookie banner consent rates.
  5. Singh, Jin, Kim. (2025 preprint). “Unveiling Evolving Dark Patterns in Cookie Consent Banners.” 14,000 sites, collected 2025. Not yet peer-reviewed.
  6. Longitudinal EEA cookie banner study. (2024 data). “A History of GDPR Cookie Banner Compliance.” 11,364 websites, 30 EEA countries, 2018 to 2024.
  7. CNIL. (2025). “Sanctions and Corrective Measures: CNIL’s Actions in 2025.” Official regulator report, 83 sanctions, 486.8 million euros total.

Note: All figures verified as of July 2026. Consent behavior and enforcement change quickly, so headline figures are refreshed at least twice a year. Preprint and rolling-source figures are flagged in-text and should be re-checked before each refresh.