A compliant cookie banner does more than look good. It meets specific legal requirements that protect both the website owner and the visitor. Plenty of banners look professional but fail the compliance test. This guide covers real examples that get it right, what makes them legal, and the mistakes that put sites at risk.
What makes a cookie banner compliant

Photo by [Vyshnavi Bisani](https://unsplash.com/@vyshnavibisani) on Unsplash
The rules come from two main sources: the EU’s General Data Protection Regulation (GDPR) and the ePrivacy Directive. Together they set the standard most privacy laws reference.
A compliant banner needs these elements:
- Prior consent: Cookies (except strictly necessary ones) can’t load until the user agrees. This means no pre-checked boxes and no cookies firing before a click.
- Real choice: Users must be able to reject all non-essential cookies with the same ease as accepting them. A big green “Accept” button next to a tiny gray “Manage” link doesn’t cut it.
- Granular control: Visitors should pick categories (analytics, marketing, functional) rather than accepting everything or nothing.
- Easy withdrawal: Changing cookie preferences must be as simple as granting them. A persistent settings icon or footer link handles this.
- Clear language: The banner text must explain what cookies do in plain terms, not bury the details in legalese.
The UK’s Information Commissioner’s Office (ICO) and France’s CNIL have both issued detailed guidance on what they expect. CNIL went further in 2022 by requiring a visible “Refuse all” button on the first layer of every banner.
Example 1: The BBC’s layered approach

Photo by [Marshall W](https://unsplash.com/@knightwill) on Unsplash
The BBC uses a two-layer banner. The first layer appears at the bottom of the screen with a short explanation and two equally prominent buttons: “Yes, I agree” and “No, take me to settings.”
Clicking “settings” opens a second layer with toggle switches for each cookie category. Analytics and advertising cookies are off by default. The visitor turns them on individually if they choose.
Why it works: Equal button sizing, no pre-ticked boxes, and category-level control. The BBC also stores consent for 13 months and re-prompts after that period, which aligns with CNIL’s recommendation.
Example 2: The ICO’s own banner
The ICO practices what it preaches. Their site loads with a banner that offers three options: “Accept all cookies,” “Reject all cookies,” and “Cookie settings.” The reject button is just as visible as the accept button.
The settings panel lists four categories with descriptions written in plain English. Each category shows which specific cookies it includes and how long they persist.
Why it works: Symmetrical button design, transparent cookie inventory, and plain-language descriptions. It’s a textbook implementation of their own guidance.
Example 3: Decathlon’s CNIL-compliant banner

Photo by [Women’s Decathlon World Championships](https://commons.wikimedia.org/wiki/File%3AWomen%27s%20Decathlon%20World%20Championships.png) on Wikimedia Commons
After CNIL tightened its rules, Decathlon redesigned its French site banner. The first layer shows a brief explanation with two equally sized buttons: “Accept” and “Refuse.” There’s no “Manage” or “Customize” option on the first layer, which forces the site to make rejection as frictionless as acceptance.
A “Personalize my choices” link sits below both buttons for visitors who want granular control. The second layer opens category toggles with descriptions.
Why it works: It meets CNIL’s specific requirement for a visible refusal option on the first layer. The design doesn’t nudge users toward acceptance through visual hierarchy.
Example 4: IKEA’s regional adaptation

Photo by [Tdorante10](https://commons.wikimedia.org/wiki/File%3AIKEA%20Red%20Hook%20td%20%282025-03-04%29%20004e.jpg) on Wikimedia Commons
IKEA runs different banners depending on the visitor’s location. EU visitors see a GDPR-compliant banner with reject-all functionality. US visitors in states with privacy laws (California, Virginia, Colorado) see a banner with a “Do Not Sell My Personal Information” link, which is required under the CCPA/CPRA.
The cookie settings page lists every cookie by name, provider, purpose, and expiration date. It’s dense but thorough.
Why it works: Geographic targeting ensures the right banner appears for the right jurisdiction. The detailed cookie inventory gives visitors full transparency.
Common mistakes that break compliance

Photo by [Brett Jordan](https://unsplash.com/@brett_jordan) on Unsplash
These patterns show up on thousands of sites and each one creates legal exposure:
Pre-checked boxes. The GDPR explicitly bans this. Consent must be an affirmative action, not a default state. The Planet49 case at the Court of Justice of the European Union confirmed it in 2019.
Dark patterns. Making the “Accept” button bright and large while the “Reject” option is a small text link. CNIL fined Google and Amazon a combined 163 million euros in 2020 partly for this reason (CNIL decision).
Cookie walls. Blocking access to a site unless the visitor accepts all cookies. Most EU regulators consider this coercive and non-compliant. The EDPB’s Guidelines 05/2020 clarify that consent given under a cookie wall isn’t freely given.
No withdrawal mechanism. Some sites collect consent once and never offer a way to change it. The GDPR requires withdrawal to be as easy as giving consent. A footer link to cookie settings is the minimum standard.
Vague language. “We use cookies to improve your experience” without explaining which cookies, what data they collect, or who receives it. Regulators expect specificity.
How to check if a banner complies

Photo by [Al Amin Mir](https://unsplash.com/@alaminip) on Unsplash
A quick audit covers the basics:
Open the site in an incognito window and check if cookies load before any interaction.
Look for a “Reject” or “Refuse” button that’s as prominent as “Accept.”
Open the settings panel and verify that non-essential categories are toggled off by default.
Check if a footer link or icon lets visitors change their preferences later.
Read the cookie policy linked from the banner. It should list cookies by name, purpose, and duration.
Tools like Cookiebot and Cookie Assistant automate this scan across every page of a site. They flag cookies that load before consent and categorize them for the settings panel.
Building a banner that holds up

Photo by [Oscar Terrazas](https://unsplash.com/@oscar_terrazas) on Unsplash
The best cookie banners treat consent as a real choice, not a checkbox exercise. Equal button design, granular controls, and clear language are the foundation. Regional targeting adds another layer of protection for sites with international traffic.
Getting the banner right isn’t just about avoiding fines. Visitors who trust a site’s privacy practices stay longer and convert more often. A compliant banner is a business asset, not just a legal requirement.









