14 min read

A cookie banner that loads on every page and offers an “Accept All” button looks compliant at a glance. Whether it actually is depends on things a quick look won't show: whether “Reject All” takes one click or three, whether a pre-checked box quietly opted someone in, and whether the banner honors an opt-out signal a browser sent before the page even finished loading. None of that shows up in a screenshot. All of it shows up in an audit.
A cookie banner is the pop-up or notice, sometimes called a cookie consent banner, that appears, usually on a first visit, to inform people about tracking cookies and collect their consent before using them. That part hasn't changed since cookie banners became standard. What has changed is the legal bar for what counts as a real, honored, provable choice, and it keeps moving.
A cookie banner exists to do three things at once: meet legal obligations under laws like the GDPR and a growing list of US state privacy laws, give people a genuine choice about their data, and disclose what's actually being collected and why. Vague language like “we use cookies to improve your experience” satisfies none of the three. A specific purpose, “to analyze traffic patterns” or “to remember your login,” satisfies all three at once.
Not every website needs one. Sites using only strictly necessary cookies, collecting no personal data, or genuinely not serving users in regulated regions may not be legally required to show one. But the reverse logic doesn't hold: having a banner doesn't automatically make a site compliant, and not having one doesn't automatically make it non-compliant. What matters is whether the underlying data practice matches what's disclosed and consented to.
In 2024, a handful of US states required some form of consent mechanism for cookies. As of 2026, roughly 20 states have comprehensive privacy laws in effect, including recent additions like Indiana, Kentucky, and Rhode Island, and more are expected to pass in the next two years. A cookie banner strategy built around five states is already out of date.
One requirement is spreading faster than the rest: honoring Global Privacy Control (GPC), a browser-level signal that communicates an opt-out preference automatically, without a person clicking through a banner at all. More than a dozen states now require businesses to recognize it. A banner that collects consent beautifully but ignores a GPC signal is non-compliant in every state that requires it, regardless of how the on-page experience looks.
Enforcement has kept pace with the legislation. California's Privacy Protection Agency reached a $1.1 million settlement with PlayOn Sports in 2026 over opt-out failures, and the agency has said publicly that fixing the problem before an enforcement action doesn't guarantee a reduced penalty. California's own per-violation fines were adjusted for inflation in 2025, rising to $2,663 for standard violations and $7,988 for intentional violations or those involving a consumer under 16. The GDPR's penalty ceiling, up to €20 million or 4 percent of global annual turnover, hasn't moved, and remains the highest exposure on the table for companies operating in the EU.
Cookie banner requirements vary by jurisdiction, but across them, a few show up consistently enough to treat as a baseline:
A banner can technically contain every element above and still manipulate the outcome. Vague wording that obscures what a cookie actually does, all-or-nothing choices that hide granular controls behind an extra click, and pre-ticked boxes that quietly assume consent are the three patterns regulators flag most often, and GDPR explicitly prohibits all three. The common thread is that each one produces a consent record that looks valid on paper while not reflecting what the person actually chose. That gap is precisely what an enforcement action exists to find.
Get the 5 Steps for Identifying an Effective CMP to evaluate whether your current setup can actually enforce what your banner promises.
Get the guideA compliant cookie banner is the output of a process, not a standalone design task. That process starts with an honest audit of every cookie and tracking technology actually running on a site, followed by a privacy policy that matches what the audit found, not what the company intended to be true. From there, the banner itself needs to reflect real choices: explicit consent captured correctly, purposes stated specifically, and a working link to manage preferences after the fact.
The step most companies skip is the last one: connecting that consent record to everything else that touches the same person's data. A cookie choice that lives only in the banner's own memory doesn't help when a data subject request comes in, when a new state law adds a GPC requirement, or when a regulator asks for proof that a specific opt-out took effect on a specific date. Consent management that's connected to the rest of a company's data stack turns that proof from a manual reconstruction into something the system already has on hand.
See how Privacy, Legal & Risk teams keep consent records audit-ready
See the solutionThe gap between a cookie banner that looks right and one that's actually defensible almost never shows up in the design. It shows up in what happens after someone clicks: whether the choice propagates everywhere it needs to, whether it's honored the moment a browser sends a GPC signal, and whether there's a record of it that would hold up if a regulator asked. Design gets a banner noticed. Enforcement is what gets a company through an audit.
Talk to Transcend about connecting your cookie consent to the rest of your privacy program.
Reach out