Having a Cookie Banner Doesn’t Mean Your Website Is Compliant

by | Aug 30, 2026 | Uncategorized | 0 comments

For many companies, cookie compliance feels like a box that has already been checked.

A consent platform such as OneTrust, Cookiebot, CookieYes, or another CMP has been installed. A banner appears when someone visits the website. Visitors can accept or reject cookies.

Everything must be working correctly, right?

Not necessarily.

Recent research suggests there is a significant gap between having a consent solution installed and having that solution configured correctly. In many cases, websites continue to fire tracking technologies before consent, fail to honor a visitor’s choice, or have technical configurations that don’t behave the way the company expects.

And that’s an important distinction: the presence of a cookie banner tells you very little about what is actually happening behind it.

The numbers show how common the problem is

A 2025 peer-reviewed study published in the Journal of Network and Computer Applications analyzed more than one million websites under European GDPR requirements.

The researchers found that nearly half of the websites used tracking cookies without valid user consent, while more than half employed pixel tracking without consent.

Another large-scale study presented at the 2025 CHI Conference analyzed more than 254,000 website observations across 31 countries. Researchers found that 67% used a consent interface, but only 15% were considered minimally compliant under the study’s criteria.

That’s a pretty big difference between:

“We have a cookie banner.”

and

“Our consent implementation is actually working.”

What about companies that already use a consent platform?

This is where the data gets particularly interesting.

A 2026 study from ConsentStack specifically looked at 912 live websites that were already running one of four common consent platforms: OneTrust, Cookiebot, Ketch, or CookieYes.

In other words, these weren’t websites that had simply ignored cookie consent altogether. They had already implemented a CMP.

Researchers reported that 91% fired at least one third-party tracker before the visitor interacted with the banner. Among sites where the scanner could click Reject, 24% continued firing a tracker after rejection. Only 6% of the 912 sites passed both the study’s EU and U.S. tests.

That doesn’t mean 91% of every company using these platforms is legally noncompliant. The study used its own technical testing methodology, and legal requirements vary by jurisdiction and implementation.

But it demonstrates something important:

Installing a consent management platform does not automatically mean the website’s tracking has been configured correctly.

A “Reject” button doesn’t necessarily stop tracking

Another large-scale study presented at USENIX Security 2024 examined approximately 97,000 websites popular in the EU.

Researchers found that 65.4% of websites offering a cookie rejection option likely continued collecting user data despite the visitor explicitly rejecting consent.

More recent testing has found similar problems.

ConsentStack tested 949 websites with functioning Reject buttons in 2026 and examined what happened to tracking cookies after visitors selected Reject All. Of the tracking cookies observed in its test, 43.4% remained in the browser after rejection, and nearly all of those surviving cookies had been created before the visitor made a consent choice.

Again, the takeaway isn’t simply that “cookie banners don’t work.”

It’s that the banner is only one piece of the implementation.

Why does this happen?

Modern website tracking is complicated.

A company might be running Google Analytics 4, Google Tag Manager, Google Ads, Meta, LinkedIn, HubSpot, Microsoft Advertising and numerous other marketing technologies.

Then a consent management platform is added on top of that.

Those systems have to work together.

For example, a company may configure its cookie banner correctly but still have a Google Tag Manager tag that fires before the visitor’s consent state has been established.

Or the opposite can happen. Tracking may be blocked too aggressively, resulting in legitimate measurement being lost even when the company’s consent configuration would allow it.

Google Consent Mode adds another layer. Consent defaults, consent updates, regional settings and the consent requirements assigned to individual tags all affect what happens when the page loads.

A website can therefore have a perfectly functional-looking banner while the underlying implementation is doing something entirely different.

Cookie compliance and marketing measurement are connected

There’s another side to this problem that receives less attention.

An incorrectly configured consent implementation doesn’t just create a potential privacy issue.

It can also create a measurement problem.

Suppose a company changes its consent platform and GA4 suddenly reports 25% fewer users.

Did website traffic actually decline 25%?

Maybe.

But it’s also possible the website simply stopped measuring a portion of its traffic because of the way GA4, Google Tag Manager and the consent platform were configured.

The same thing can happen with Google Ads conversions, form submissions, remarketing audiences and other marketing data.

Suddenly the business is making budget decisions using numbers that changed because of its tracking implementation rather than because customer behavior changed.

That’s why consent shouldn’t be reviewed in isolation.

The real question isn’t whether you have a cookie banner

Most established companies already know whether they have a consent platform.

The better questions are:

  • What happens before someone makes a choice?
  • What happens after they click Accept?
  • What happens after they click Reject?What consent signals are being sent to Google?
  • Which tags are actually firing in Google Tag Manager?
  • Are GA4 and advertising platforms receiving the data you expect them to receive?
  • Does the behavior change correctly based on the visitor’s region?

Those questions can’t be answered by looking at the banner.

You have to test the implementation.

A consent platform is a tool, not a guarantee

OneTrust, Cookiebot, CookieYes and other consent management platforms can provide the technology needed to manage user consent.

But the platform still has to be configured correctly and integrated with the rest of the website’s marketing technology.

The growing body of research around cookie consent makes one thing increasingly clear:

Having a consent platform installed is not the same thing as having a consent implementation that works correctly.

And because consent now sits directly between the visitor and tools like GA4, Google Tag Manager and advertising platforms, mistakes can affect both privacy and the accuracy of your marketing data.

That’s why it’s worth testing what’s actually happening rather than assuming everything is working because the banner appears.

Not sure if your setup is working correctly?

A Consent Audit reviews how your consent platform works with Google Tag Manager, GA4, Google Consent Mode and your advertising tags. We test what happens before and after a visitor makes a consent choice and identify configuration issues that could be affecting your tracking or consent setup.