Tracking cookies: what the consent banner actually changes

Consent banners don’t “turn off the internet.” Here’s what accepting or refusing really changes, what it doesn’t, and how to stay in control.

The short version

The “Accept / Reject” banner isn’t decoration. In the EU (and similar regimes), non-essential cookies — ads, detailed analytics, personalization — generally need freely given, informed, specific consent. Rejecting should be as easy as accepting. But “reject” doesn’t mean “no tracking anywhere,” and many interfaces still add friction on purpose so the tired click is “Accept all.”

What consent actually changes

When you refuse properly:

  • non-essential cookies/trackers for ads and advanced tracking shouldn’t be set (or activated),
  • the site can still use technical cookies (cart, session, security; limited measurement in some cases),
  • your choice should be remembered for a reasonable period without constant re-prompts.

When you accept: you allow broader tracking, often shared with partners. It’s rarely “one cookie” — it’s an ecosystem of identifiers, pixels, and ad auctions you never see.

Compliant banner vs deceptive banner (concrete examples)

More compliant example (what regulators aim for in spirit):

  • two equal buttons: “Accept all” and “Reject all” (same size, same contrast, same one-click path),
  • an optional “Customize” path — not required to say no,
  • partner boxes unchecked by default,
  • clear purposes (ads, measurement, personalization),
  • the site still works if you refuse (maybe more contextual ads or fewer recs, but not a wall).

Deceptive example (classic dark pattern):

  • big green “Accept all”; reject is a gray “Continue without accepting” link, or buried under “Manage” → 3 screens → 40 partners → “Save”,
  • pre-ticked “partners” / “personalization” boxes,
  • “Reject” that actually opens a paywall or guilt screen,
  • “Legitimate interest” waved at targeted ads when consent was required,
  • banner again on every visit until you give in.

The first respects a real choice. The second turns the banner into an acceptance funnel. Same word (“cookies”); opposite intent.

If you’re unsure which one you’re looking at, zoom out from the legal text and look at effort asymmetry: equal effort to accept/refuse is the core compliance idea in EU guidance; everything else is decoration. When “Reject all” finally appears after a maze, you didn’t get a real choice — you got a conversion funnel with privacy cosplay.

What the banner doesn’t fix

  • Beyond cookies: browser fingerprinting, mobile ad IDs, shared login across sites.
  • Rejecting on site A doesn’t erase your profile elsewhere.
  • A banner is a gate for that site’s non-essential trackers — not a global privacy switch.

Think of the banner as a local contract, not a privacy operating system. You can refuse diligently on news sites and still be tracked through an app login, a “Sign in with Google” button, or a pixel loaded before the banner even appears (illegal in many cases — still happens). Regulators care about that gap; your job as a reader is mainly not to reward the worst interfaces with an automatic “Accept all.”

A quick side-by-side mental test helps: if saying yes takes one click and saying no takes a scavenger hunt, treat the design as hostile until proven otherwise. That heuristic won’t make you a lawyer, but it will save you from the most common traps without reading forty partner names.

Useful habits

  1. Hit Reject / “reject all” when it’s clearly available.
  2. Be wary of “Customize” flows that need twenty clicks to say no.
  3. Add browser settings / blockers if you want another layer.
  4. Be stricter on sensitive services (health, banking, government).
  5. Periodically clear site data for places you don’t trust — consent fatigue is real.
  6. Prefer browsers and settings that block third-party cookies / known trackers by default — banner hygiene + technical hygiene stack better than either alone.
  7. On a site you visit weekly, take thirty seconds once: refuse, confirm the choice stuck on reload, then move on. Recurring friction is often intentional.

None of this requires becoming a privacy maximalist. It’s closer to locking your door: boring, unevenly effective against professionals, still worth doing against casual opportunism.

Going further

Sources

Found an error? Email us — we correct factual mistakes and note significant updates on the article. Contact us

Keep exploring

France Identité: useful tool or trap?

Official app tied to France’s credit-card-format ID, NFC, one-time ID proofs, FranceConnect / FranceConnect+, town-hall certification: what it really changes — and the risks (phone theft, dependency, exclusion).

Read the article