A useful cookie banner explains the optional purposes, offers a clear choice and makes the website follow that choice. Good wording cannot compensate for tags that run too early or a rejection that the server ignores.
The examples below illustrate an ordinary EU website using consent for optional analytics and advertising. They are original examples to adapt, not a certified template or a substitute for assessing your actual processing. For the legal framework, start with our GDPR and ePrivacy cookie consent guide.
Example 1: the first layer of a cookie banner
Imagine a shop with necessary basket storage, optional audience analytics and personalised advertising. Its first layer could read:
Choose how this website uses cookies
We use necessary cookies to keep your basket and remember your privacy choices. With your permission, we and our partners also use cookies to measure website use and personalise advertising. You can accept optional uses, reject them or choose by purpose. Change your choice at any time through Cookie settings in the footer.
Reject optional cookies · Choose settings · Accept optional cookies
Cookie details and partners
These labels describe proposed controls; they are not live buttons. The details link should lead to the relevant notice and recipient information. Replace the example purposes with those your site actually uses. Do not mention advertising if there is none, or describe advertising measurement as necessary site operation.
| Element | Why it is included | What must happen behind it |
|---|---|---|
| Necessary functions | Explains what remains active | Only storage and processing justified for those functions remain |
| Optional purposes | Explains the choice before it is made | Each purpose maps to the correct tags and destinations |
| Reject optional cookies | Provides an immediate refusal route | Optional consent remains denied and the choice is saved |
| Choose settings | Allows a more specific choice | Opens purpose controls without granting permission |
| Accept optional cookies | Describes the scope of acceptance | Grants only the disclosed optional purposes |
| Cookie details and partners | Provides access to supporting information | Opens accurate information, including relevant recipients and lifetimes |
The CJEU's Planet49 judgment rejected preselected consent and addressed information about cookie duration and third-party access. A link to details is useful only when those details are complete and understandable. CJEU Planet49 summary
How prominent should Accept and Reject be?
Our recommended starting point is to put acceptance and rejection on the first layer with comparable readability, prominence and effort. Test the actual layout on small screens as well as desktop. Avoid placing rejection inside a paragraph that looks like ordinary explanatory text.
The EDPB taskforce reported that most participating authorities considered a missing rejection option on a layer containing acceptance inconsistent with valid consent. It also said colour and contrast require case-by-case assessment rather than one universal banner standard. Do not turn that report into a claim that EU law specifies identical button colours. EDPB Cookie Banner Taskforce report
For a French implementation, consult CNIL's national recommendations as well. Its examples favour choices that are equally easy to read and do not visually pressure acceptance. CNIL consolidated cookie recommendation
Practical review questions include whether a keyboard user can reach Reject, whether text stays readable when zoomed, and whether a mobile layout hides an option below the visible panel. Accessibility checks are part of making the choice usable; a consent notice should not create an obstacle to the rest of the site.
Example 2: a preference centre with separate purposes
A settings panel should explain the purpose before asking for a decision. “Improve your experience” is too vague to distinguish analytics from advertising.
| Purpose in this illustrative shop | Explanation | Initial control |
|---|---|---|
| Necessary functions | Maintain the basket, security and saved privacy choices | Informational, with the specific justification documented |
| Website analytics | Measure page use and journeys to help improve the site | Off until consent, for this example's consent-based setup |
| Personalised advertising | Use browsing information to personalise ads | Off until consent |
Use a Save my choices control that applies the displayed selection exactly. Give access to relevant vendor details and explain retention in the supporting notice. If purposes cannot be switched independently in the underlying integration, resolve that limitation before promising separate controls.
Illustrative outcome: a visitor enables analytics but leaves advertising off. The panel saves that selection; analytics follows its permitted configuration, while advertising destinations remain restricted. A general “accepted” flag that enables every vendor would fail this test.
The categories above are illustrative, not an official taxonomy. Map the actual purposes, recipients and data flows before deciding how many controls the interface needs. See our consent signal integration guide for the implementation layer.
Example 3: withdrawal after accepting
A persistent Cookie settings link should reopen the current choice, not start an unrelated form. Someone who previously accepted advertising must be able to turn it off and save without logging in or contacting support merely to change a browser preference.
A concise confirmation could read:
Your cookie preferences have been saved. You can change them again through Cookie settings.
Only display that message after the implementation has applied the choice. Avoid promising that all previously collected data has been deleted. Withdrawal, future processing controls and an erasure request are different operations.
GDPR Article 7 requires withdrawal to be as easy as giving consent and explains its effect on earlier lawful processing. GDPR Article 7
In testing, inspect subsequent requests, cookie reads, saved preferences and server forwarding. A changed toggle is insufficient evidence. CNIL's SHEIN decision illustrates the problem: cookies continued to be placed or read despite rejection or withdrawal. CNIL's SHEIN decision summary
Wording and behaviour to avoid
| Pattern | Problem to investigate | Better direction |
|---|---|---|
| “By continuing, you accept” | Navigation is treated as permission | Wait for an affirmative choice |
| “We only use cookies to improve your experience” | Purposes are unclear | Name the actual analytics or advertising use |
| A settings button that grants consent | Control behaviour contradicts its label | Opening settings leaves optional consent unchanged |
| “Reject all” while advertising still runs | The implementation contradicts the choice | Correct the relevant browser and server routes |
| Repeated prompts on every page | The saved choice is not respected | Persist the choice and investigate restoration faults |
| “Your data is anonymous” without assessment | Wording may misdescribe identifiers or matching | Explain the actual data and recipients |
These are review prompts. Investigate the specific design and implementation before concluding why a particular site fails.
Test the complete banner journey
For each case, record the browser, region, notice version and expected outcome. Use a clean profile for first visits and a separate profile for returning visitors.
- No interaction: optional consent-dependent storage and processing wait as designed.
- Rejection: the banner closes, the choice persists and optional purposes remain denied after navigation.
- Partial consent: only the selected purposes become permitted.
- Acceptance: intended events work without duplicate tags or a second contradictory banner.
- Withdrawal: later collection and forwarding reflect the updated choice.
- Returning visit: the saved choice is restored without an unintended temporary grant.
- Mobile and keyboard use: all choices and the settings link remain usable.
Record failures separately: wording, visual design, saved preferences, tag state and outgoing requests. This helps the right person fix the actual cause. For Google signal faults, use the Consent Mode troubleshooting guide.
FAQ
Can I copy this cookie banner wording?
Use it as a starting point. Replace purposes, functions, recipient information and the withdrawal route with accurate details. The deployed tags must match the adapted wording.
Must every site have analytics and advertising switches?
No. Include the purposes your site actually uses and assess them individually. A site without optional tracking should not invent optional categories merely to resemble another banner.
Is a close icon the same as Accept?
No. Closing the interface should not create consent. Define and test what closing does, keep consent-dependent processing blocked where no permission exists, and provide clear labelled choices.
How often should we ask again?
Set a documented policy based on the applicable rules and context. CNIL describes six months for remembering acceptance and refusal as a general good practice, not a universal EU deadline. Material changes need their own assessment; do not silently extend an old choice to new purposes.
Does matching this example prove GDPR compliance?
No. The notice, processing, applicable rules and actual implementation all matter. These examples help structure a review; they are not a legal certification.
Apply the examples to your site
Use our GDPR readiness assessment to identify broader gaps. For implementation help, explore cookie consent services or request a free consent audit.
