Skip to content

This translation has not been editorially reviewed yet. The German version is authoritative. Deutsche Fassung →

Data protection

Does "Reject" belong on the first level of the cookie banner?

Yes — rejection should be just as easy to reach on the banner's first level as acceptance. A "Reject" that's hidden behind "Settings" or in a submenu isn't an equal choice. Our check reads the buttons on the first banner level and determines whether one of them offers rejection.

An equal choice at a glance

A banner asks a question, and a question needs two equally reachable answers. In practice, it often looks different: a large, coloured "Accept all" button — and next to it an inconspicuous link to "Settings", behind which rejection is hidden several steps deep. Accepting takes one click; rejecting takes three. For this pattern, the audit report points to the requirements around the voluntariness of consent. The assessment itself stays a technical finding: a reject button is missing on the first level.

How the check recognises the buttons

The checker reads out the labels of every button on the first banner level and matches them against known phrasings. Wording that counts as rejection includes "Reject", "Only necessary cookies", "Only required", "Decline", or "Continue without consent" — including German equivalents such as "Ablehnen" or "Nicht zustimmen". The report lists the button texts found, word for word. That way you see in black and white exactly what choice your banner actually offers visitors in that first moment — and whether rejection is among them.

Without a reject button, the effectiveness test fails too

This rule has a knock-on effect: our check tests, in a further step, whether rejection actually works — it clicks the button and measures afterward. If the reject option is missing on the first level, this test can't happen at all, and the follow-up rule stays unmet too. So a missing button costs twice. Conversely: a website with no consent-requiring services and no banner at all satisfies both rules automatically, since where there's nothing to reject, no button is needed for it either.

  • Open your website in a private browser window and count the clicks: one to accept, how many to reject.
  • Ask your agency to put a reject button on equal footing next to the accept button.
  • Look for clear labels like "Reject" or "Only necessary cookies" instead of hidden menu links.
  • Compare the design of both buttons — same size, same visibility, no greyed-out colours for the reject option.
  • Check after every update to the consent tool whether the first level still offers both routes.

FAQ

Is a "Settings" link enough instead of a reject button?

Not in the check. It assesses only the first banner level, since that's where most visitors make their decision. A rejection that's only reachable after further clicks in a submenu counts as missing in the check — the report then shows, word for word, what buttons the first level offers instead.

What labels does the check recognise as rejection?

Among others: "Reject", "Only necessary cookies", "Only required", "Decline", "Continue without consent", as well as German forms like "Ablehnen", "Nicht zustimmen", or "Nur notwendige Cookies". Detection works with text patterns tuned to common consent tools. If your button has an unusual label, it's worth checking the report — it lists every button text found.

Why must rejecting be just as easy as accepting?

Because consent only counts if it's given voluntarily — and voluntariness requires a genuine choice. If accepting is one click and rejecting is a multi-click path, the design steers the outcome. The check establishes this difference as a technical finding; the legal assessment for your specific case belongs with your legal counsel.

My banner comes from a well-known provider — is the first level automatically correct then?

No, since most consent tools can be configured either way: with or without a reject button on the first level. What matters is the chosen configuration, not the provider's name. The check measures the actual state in the browser and shows the first level's buttons word for word in the report.

Deutsche Fassung dieser Seite