Cookie Banner Examples That Actually Comply

A compliant cookie banner does more than look good. It meets specific legal requirements that protect both the website owner and the visitor. Plenty of banners look professional but fail the compliance test. This guide covers real examples that get it right, what makes them legal, and the mistakes that put sites at risk.

What makes a cookie banner compliant

Minimal Cookie Shot

Photo by [Vyshnavi Bisani](https://unsplash.com/@vyshnavibisani) on Unsplash

The rules come from two main sources: the EU’s General Data Protection Regulation (GDPR) and the ePrivacy Directive. Together they set the standard most privacy laws reference.

A compliant banner needs these elements:

  • Prior consent: Cookies (except strictly necessary ones) can’t load until the user agrees. This means no pre-checked boxes and no cookies firing before a click.
  • Real choice: Users must be able to reject all non-essential cookies with the same ease as accepting them. A big green “Accept” button next to a tiny gray “Manage” link doesn’t cut it.
  • Granular control: Visitors should pick categories (analytics, marketing, functional) rather than accepting everything or nothing.
  • Easy withdrawal: Changing cookie preferences must be as simple as granting them. A persistent settings icon or footer link handles this.
  • Clear language: The banner text must explain what cookies do in plain terms, not bury the details in legalese.

The UK’s Information Commissioner’s Office (ICO) and France’s CNIL have both issued detailed guidance on what they expect. CNIL went further in 2022 by requiring a visible “Refuse all” button on the first layer of every banner.

Example 1: The BBC’s layered approach

low angle photo of BBC Scotland building under blue sky

Photo by [Marshall W](https://unsplash.com/@knightwill) on Unsplash

The BBC uses a two-layer banner. The first layer appears at the bottom of the screen with a short explanation and two equally prominent buttons: “Yes, I agree” and “No, take me to settings.”

Clicking “settings” opens a second layer with toggle switches for each cookie category. Analytics and advertising cookies are off by default. The visitor turns them on individually if they choose.

Why it works: Equal button sizing, no pre-ticked boxes, and category-level control. The BBC also stores consent for 13 months and re-prompts after that period, which aligns with CNIL’s recommendation.

Example 2: The ICO’s own banner

The ICO practices what it preaches. Their site loads with a banner that offers three options: “Accept all cookies,” “Reject all cookies,” and “Cookie settings.” The reject button is just as visible as the accept button.

The settings panel lists four categories with descriptions written in plain English. Each category shows which specific cookies it includes and how long they persist.

Why it works: Symmetrical button design, transparent cookie inventory, and plain-language descriptions. It’s a textbook implementation of their own guidance.

Example 3: Decathlon’s CNIL-compliant banner

Women's Decathlon World Championships

Photo by [Women’s Decathlon World Championships](https://commons.wikimedia.org/wiki/File%3AWomen%27s%20Decathlon%20World%20Championships.png) on Wikimedia Commons

After CNIL tightened its rules, Decathlon redesigned its French site banner. The first layer shows a brief explanation with two equally sized buttons: “Accept” and “Refuse.” There’s no “Manage” or “Customize” option on the first layer, which forces the site to make rejection as frictionless as acceptance.

A “Personalize my choices” link sits below both buttons for visitors who want granular control. The second layer opens category toggles with descriptions.

Why it works: It meets CNIL’s specific requirement for a visible refusal option on the first layer. The design doesn’t nudge users toward acceptance through visual hierarchy.

Example 4: IKEA’s regional adaptation

IKEA Red Hook td (2025-03-04) 004e

Photo by [Tdorante10](https://commons.wikimedia.org/wiki/File%3AIKEA%20Red%20Hook%20td%20%282025-03-04%29%20004e.jpg) on Wikimedia Commons

IKEA runs different banners depending on the visitor’s location. EU visitors see a GDPR-compliant banner with reject-all functionality. US visitors in states with privacy laws (California, Virginia, Colorado) see a banner with a “Do Not Sell My Personal Information” link, which is required under the CCPA/CPRA.

The cookie settings page lists every cookie by name, provider, purpose, and expiration date. It’s dense but thorough.

Why it works: Geographic targeting ensures the right banner appears for the right jurisdiction. The detailed cookie inventory gives visitors full transparency.

Common mistakes that break compliance

scrabble, scrabble pieces, lettering, letters, wood, scrabble tiles, white background, words, quote, letters, type, typography, design, layout, focus, bokeh, blur, photography, images, image, get over it, move on, press on, don't mope, mither not, no regrets, start again, learn from your mistakes, mindfulness, life will not wait, keep going, take initiative, be a self starter, do it now, don't wait forever, procrastination, excuses, don't make excuses, learn from failure,

Photo by [Brett Jordan](https://unsplash.com/@brett_jordan) on Unsplash

These patterns show up on thousands of sites and each one creates legal exposure:

Pre-checked boxes. The GDPR explicitly bans this. Consent must be an affirmative action, not a default state. The Planet49 case at the Court of Justice of the European Union confirmed it in 2019.

Dark patterns. Making the “Accept” button bright and large while the “Reject” option is a small text link. CNIL fined Google and Amazon a combined 163 million euros in 2020 partly for this reason (CNIL decision).

Cookie walls. Blocking access to a site unless the visitor accepts all cookies. Most EU regulators consider this coercive and non-compliant. The EDPB’s Guidelines 05/2020 clarify that consent given under a cookie wall isn’t freely given.

No withdrawal mechanism. Some sites collect consent once and never offer a way to change it. The GDPR requires withdrawal to be as easy as giving consent. A footer link to cookie settings is the minimum standard.

Vague language. “We use cookies to improve your experience” without explaining which cookies, what data they collect, or who receives it. Regulators expect specificity.

How to check if a banner complies

Blank 3D Vertical Banner Mockup A high-quality 3D render of a blank vertical display banner stand (often called an X-Banner or Roll-Up Banner). Ideal for graphic designers and marketers needing to present corporate branding, event advertising, or product promotion designs in a realistic setting.

Photo by [Al Amin Mir](https://unsplash.com/@alaminip) on Unsplash

A quick audit covers the basics:

Open the site in an incognito window and check if cookies load before any interaction.

Look for a “Reject” or “Refuse” button that’s as prominent as “Accept.”

Open the settings panel and verify that non-essential categories are toggled off by default.

Check if a footer link or icon lets visitors change their preferences later.

Read the cookie policy linked from the banner. It should list cookies by name, purpose, and duration.

Tools like Cookiebot and Cookie Assistant automate this scan across every page of a site. They flag cookies that load before consent and categorize them for the settings panel.

Building a banner that holds up

a large building with graffiti on the side of it

Photo by [Oscar Terrazas](https://unsplash.com/@oscar_terrazas) on Unsplash

The best cookie banners treat consent as a real choice, not a checkbox exercise. Equal button design, granular controls, and clear language are the foundation. Regional targeting adds another layer of protection for sites with international traffic.

Getting the banner right isn’t just about avoiding fines. Visitors who trust a site’s privacy practices stay longer and convert more often. A compliant banner is a business asset, not just a legal requirement.