This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →
Data protection
Does clicking "Reject" in the cookie banner actually work?
Only a practical test can show that — and that's exactly what our check runs: it actually clicks the reject button, reloads the page, and measures whether tracking cookies are still set or tracking servers still contacted afterward. A banner whose rejection has no effect is worse than none at all, since it promises visitors a choice it doesn't honour.
The functional reject test, step by step
The checker opens your website in a fresh browser, finds the reject button on the first banner level, and clicks it — just as a real visitor would. Then it reloads the page and measures two things: what cookies are now in the browser, and what third-party servers get contacted. No tracking cookies should be created after a rejection, and no connections to tracking servers either. This acid test tells a functioning banner apart from a facade — settings on paper don't count, behaviour is what's measured.
Three possible outcomes of the measurement
The best result: after rejection, everything's quiet — no tracking cookies, no tracker contacts, full marks. The middle result: no more cookies are created, but the page still contacts tracking servers with cookieless signals, as Google Consent Mode provides for. The IP address is still transmitted then; the check awards half marks and recommends a manual review, since the legal classification is disputed. The worst result: tracking cookies are set despite rejection — the visitor's objection is technically ignored, and the rule counts as clearly failed.
An ineffective banner is worse than none at all
A website showing no banner at all promises nothing. One that shows a banner gives visitors its word: your decision counts. If the website still sets tracking cookies after a click on "Reject", it breaks exactly that word — and the visitor has no way of noticing. A common technical cause is a consent tool that stores the answer but isn't actually connected to the tracking scripts: the banner manages consent, while the scripts load regardless. The audit report makes this state visible so it can be fixed.
- Open your website in a private window, click "Reject", and check the browser settings for what cookies exist afterward.
- Reload the page after rejecting and watch the network tab (F12 key) for whether tracking servers are still contacted.
- Ask your agency to technically link every tracking script to the consent tool — the stored answer alone blocks nothing.
- Make a deliberate decision on whether cookieless signals after rejection (Consent Mode) are acceptable for you, and get legal advice on it.
- Repeat the test after every change to the banner or the integrated services.
FAQ
What is Google Consent Mode?
A mode in which Google services stop setting cookies after a rejection, but keep sending cookieless signals to Google servers. The visitor's IP address is still transmitted in the process. Our check recognises this pattern, awards half marks, and recommends a manual review — the legal classification is disputed and belongs with your legal counsel.
How can I test myself whether my cookie banner actually implements rejection?
Open the website in a private browser window, click "Reject", and reload the page. Then check the browser settings for stored cookies and the network tab (F12 key) for contacted servers. If names like "_ga" or connections to analytics servers show up there, the rejection isn't working.
My service provider says the banner is set up correctly — is that enough?
A setting is an intention, not an effect. The banner and the tracking scripts are separate building blocks; whether they actually work together only shows up in a measurement in the browser. That's why our check actually clicks "Reject" and measures afterward. The result is in the report — as confirmation for your service provider, or as a concrete task to fix.
What happens if the check can't click the reject button?
Then the report notes exactly that: a reject button was found but couldn't be triggered automatically — the effect needs manual review. If the first banner level offers no rejection at all, the effectiveness test doesn't happen either, and both banner rules count as unmet.