Skip to content

How to Improve Your Cookie Consent Rate (and Why It Decides Your Attribution)

If you run ads and you show a cookie banner, your cookie consent rate is a conversion rate, and it sits in front of every other conversion on your site. A visitor who clicks "Reject" and then buys something is a real sale, but to Google Ads, Meta, and your analytics tool it never happened. Most of the advice on this topic comes from the companies that sell cookie banners, and a lot of it is unsourced. My degree is in cognitive science, and a good chunk of it was human-computer interaction, which is the study of how people actually behave when a screen asks them to do something. A cookie banner is a great example of that, so I went through the actual field studies and pulled out what moves the number, where the legal gray areas are, and the two things you can do to get more attribution out of the people who already say yes.

What a declined visitor costs you

When someone declines marketing cookies, the ad pixel never fires for anything they do afterward. The click ID from the ad (gclid, fbclid, and the rest) doesn't get stored, so even if they come back tomorrow and buy, there's nothing to tie the purchase to the campaign. Enhanced conversions can't run, because there's no consent to send their email or phone number. And server-side tracking doesn't help here either. Sending a purchase to Meta or Google from your server for a visitor who said no is still tracking a visitor who said no, so a correct setup holds that back too.

Google fills in some of that hole with Google Consent Mode (version 2 is the current one), which sends cookieless pings for declined visitors and then models conversions from them. That's better than nothing, but it only works for Google Analytics and Google Ads. Meta, TikTok, LinkedIn, Pinterest, Microsoft, and every other platform get a blank for that visitor.

Conversion Bridge connects WordPress to 11 ad platforms and 19 analytics platforms, and it reads the consent choice from 14 cookie banner plugins, so the yes or no from your banner reaches every platform you use. See the supported cookie banners.

So every point of consent rate is a point of attribution, and if 45% of your EU visitors accept, your ad platforms are optimizing on roughly 45% of your real results (plus whatever Google models).

That turns into money in two ways. Google Ads and Meta decide who sees your ads and how much to bid based on the conversions they can see, so every sale they miss is a sale they can't learn from. Fewer visible conversions means the platform has less to work with when it picks the next person to show your ad to, and the audiences it builds for remarketing and lookalikes are built only from the people who said yes. The second way is in your own reporting. If half your real conversions are invisible, your cost per conversion looks twice as high as it is, and the campaign you pause because it "isn't working" may be the one that was paying for itself. Raising the consent rate from 35% to 50% doesn't change what happened on your site, but it changes what your ad platforms know about it, and that shows up as more conversions for the same spend.

The only broad benchmarks that exist come from the cookie banner companies themselves, pulled from their own customers' sites, so treat them as a ballpark rather than a study. By those numbers, a compliant banner with an equally visible reject option lands somewhere around 42% to 47% acceptance overall, with ecommerce a little higher at 45% to 55%. Individual sites range from about 4% to 85%, and almost all of that spread comes from how the banner is designed and where the visitor lives. US visitors accept far more often than EU visitors, partly because many US sites don't show a banner at all and I believe the audience has less privacy concerns.

One more number that sets expectations: a 2025 study in Computers in Human Behavior found that about two-thirds of people have a fixed habit. They either always accept or always reject, no matter what the banner looks like. Banner design only moves the remaining third. So if you're at 45% and hoping to hit 80% without doing anything questionable, that's not going to happen. Getting from 35% to 50% is realistic.

Most of what I'm confident about comes from two field studies: Utz and colleagues (2019) ran live experiments on a German site with more than 80,000 visitors, and Bielova and colleagues (2024) tested six banner designs on 3,947 people for the French privacy regulator (CNIL). The findings line up in a clear order of importance, and none of it surprised me, because the things that move a cookie banner are the same things that showed up in every HCI course I took: what's already selected, how many clicks something takes, and what stands out on the screen. People mostly take the path that requires the least effort and the least thought, and a banner is a decision they didn't ask to make on a site they came to for something else.

Four cookie consent examples, and how hard each makes it to reject

How hard it is to reject matters more than anything else about the banner, and it isn't close. In the CNIL study, a neutral banner with Accept and Reject side by side got 17% of people to refuse or customize. Move the reject option to a second screen (the "Manage settings" pattern) and refusals dropped to 4%. Highlight the reject button instead of the accept button and refusals doubled to 34%. Change the wording to spell out the consequences ("tracking") and refusals hit 47%. Same people, same site, and the refusal rate swung by more than 10x based on layout alone. Read from the site owner's side, that means every design that raises acceptance does it by making refusal harder or less obvious, and every design that regulators prefer does the opposite. Nothing in the data lets you have both.

Mock cookie banner with equal Refuse and Accept buttons side by side
Neutral banner, equal buttons: 17% refused or customized
Mock cookie banner with a filled Accept all button and a Manage settings link, no reject button
Reject moved to a second screen: 4% refused or customized
Mock cookie banner where the Refuse button is filled and the Accept button is grey
Refuse button highlighted instead of Accept: 34% refused or customized
Mock cookie banner that says it tracks your browsing and shows targeted ads, with equal Refuse and Accept buttons
Wording spells out tracking: 47% refused or customized

Pre-checked boxes and highlighted buttons

The Utz study tested category checkboxes, and with the boxes unchecked, fewer than 0.1% of visitors ticked every box. With the boxes pre-checked, about 30% of mobile visitors and 10% of desktop visitors accepted everything. That's why pre-ticked boxes were ruled invalid consent by the EU's top court in the Planet49 case back in 2019. Highlighting a button (color, size, contrast) has the same kind of pull in whichever direction you point it.

A simple first screen

Utz also found that a plain two-choice banner (accept or decline) gets far more full acceptance than a first screen full of categories and third-party names. Some cookie banner companies recommend per-category choices ("granular consent") as a way to raise the consent rate, but that only works if you count someone who allowed one category out of four as a yes. For attribution, the category that matters is marketing, and a wall of checkboxes on the first screen makes people less likely to allow it. Put the categories on the second screen behind a "Customize" link.

Position

The Utz study measured how many visitors interacted with the banner at all. A small notice in the bottom-left corner got 37.1% interaction. A bar across the top got 2.9%, and a bar across the bottom got 9.6%. Some cookie banner companies claim top-of-page placement raises consent, but I couldn't find data behind that. A centered modal that blocks the page forces interaction, which is why the banner companies like it, but it also drifts toward being a cookie wall.

Wording

Wording matters less than you'd think. Utz found that saying "cookies" instead of "your data" got slightly more people to interact but slightly fewer to accept. The CNIL study found that evocative words ("tracking") push people to refuse. No law requires the word "tracking", so there's no reason to use it. Plain, calm language that says what you measure and why is the right choice, but don't expect wording alone to move you more than a few points in either direction.

Where that leaves you

Ranked from most acceptance to least, the cookie banner design examples come out like this:

  • Reject hidden on a second screen. Highest acceptance (4% refused in the CNIL study). Fined in the EU.
  • Highlighted Accept next to a plain Reject. Raises acceptance above neutral. Legal gray area.
  • Equal Accept and Reject on the first screen. Middle of the range (17% refused). Accepted by every regulator.
  • Highlighted Reject, or wording that spells out "tracking". Lowest acceptance (34% and 47% refused). Nothing requires either one.

So the baseline I'd recommend to anyone is the clearly legal one: Accept and Reject on the first screen, same size, categories behind a Customize link, a small notice low on the page rather than a full-page block, short plain text, nothing pre-checked. It is not the highest-acceptance design, and I'm not going to pretend it is. It's the one you can defend anywhere, and it's the starting point that the gray-area choices below move you up from, at whatever risk level you're comfortable with.

The gray areas

Everything that moves acceptance above that baseline is a legal gray area. Most posts on this topic skip these choices, but site owners make them every day, so they belong in the open. The law (GDPR and the ePrivacy rules in the EU, plus a growing list of US state laws) says consent has to be freely given and as easy to refuse as to give. Regulators and courts have interpreted that unevenly, and enforcement is very different in France than it is in Texas.

None of what follows is legal advice. I'm not a lawyer, and this is my best understanding of the rules as they stood on the day this was published (the date is at the top of the post). Privacy law changes often, regulators issue new guidance, and a court decision can flip a gray area to black or white in an afternoon. Everyone has their own level of risk tolerance, and if a decision here could cost you real money, talk to a privacy lawyer who knows the countries you sell into.

These are the decisions I see site owners make, with what I know about each.

A highlighted Accept button next to a plain Reject button. Both buttons are on the first screen, but Accept is your brand color and Reject is a text link or a gray outline. The CNIL research shows this works in both directions, so it does raise acceptance. In Europe it really is a gray area. The CNIL guidance says refusing must have "the same degree of simplicity" as accepting, which reads as clicks rather than color, and many EU regulators have let this slide, while the EDPB's 2023 cookie banner task force has said misleading button contrast can invalidate consent. California is not a gray area on this one. Its regulations say plainly that "a choice where the 'yes' button is more prominent (e.g., larger in size or in a more eye-catching color) than the 'no' button is not equal or symmetrical" (11 CCR 7004(a)(2)(D)), and that rule applies whenever you ask a California visitor for consent. Honda's $632,500 fine was an asymmetry case, though it was about extra clicks rather than color. So this is the most common gray-area choice, and it is more of a gray area in Brussels than it is in Sacramento.

Mock cookie banner where the Accept button is filled in the brand color and the Refuse button is a grey outline
Highlighted Accept, plain Refuse: raises acceptance, legal gray area

Reject on the second screen. "Accept all" and "Manage settings," with no reject on the first screen. This is the pattern that dropped refusals to 4% in the CNIL study. France fined Google and Facebook over it in 2022, and the EDPB task force called it a violation. It's still everywhere, especially outside the EU, but in Europe it's the least gray of these options.

Mock cookie banner with a filled Accept all button and a Manage settings link, no reject button
Reject on the second screen: 4% refused in the CNIL study, fined in France

Button wording. "Accept all" vs "Continue without accepting" vs "Only necessary." No regulator has ruled that specific words are illegal as long as the meaning is clear, so this is mostly a design decision. Wording that makes rejecting sound like a loss ("Continue with a worse experience") starts to look like a dark pattern.

Opt-out instead of opt-in for US visitors. US state privacy laws run the other way around from the EU. You can track by default, and you have to give people a way to say no: a "Do Not Sell or Share My Personal Information" link, plus honoring the Global Privacy Control (GPC) signal a browser can send. No US state requires an accept-or-reject banner for ordinary ad and analytics tracking, so US traffic can run without one. Twelve states now make GPC legally binding, and that signal is the part sites trip over: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas.

Two things changed recently, and both cut against the older version of this advice that stops at "put a link in the footer." Every US privacy fine so far has been about an opt-out that didn't work rather than a missing banner: Honda ($632,500), Todd Snyder ($345,178), Healthline ($1.55 million), Tractor Supply ($1.35 million), Disney ($2.75 million) and Ford ($375,703). Two of those were banners that looked fine and quietly failed to turn anything off. And since January 1, 2026, California's rules say a business must display whether it has honored a visitor's opt-out signal, which a plain footer link doesn't do. Connecticut's attorney general went further in the 2025 enforcement report, published in February, and questioned whether an opt-out link sitting in the footer is "obvious" or "difficult to miss" at all.

So the accurate version is that you don't need a banner for US visitors, but you do need an opt-out that actually works, is easy to find, and shows the visitor when GPC has been honored. Everyone who doesn't opt out can be tracked, which beats an EU consent rate by a wide margin, though it isn't the 100 percent it sounds like. Somewhere around 5 to 10 percent of US browsers already send GPC, and that share grows every year.

The opt-in exceptions are wider than they were. Sensitive data such as health, precise location or race needs consent in most states. Minors are the bigger one now: Connecticut and Maryland ban targeted advertising and data sales for anyone under 18 no matter what consent you collect, Colorado requires consent under 18, and California requires opt-in under 16. Maryland also bans selling sensitive data at all, and Washington's My Health My Data Act sets separate rules for health data. For a US-heavy site this is still where the real money is, and it's the area that differs most from state to state, so it's worth a lawyer's hour if most of your traffic is American.

Geo-targeting the banner. The way to do the above in practice. Most banner plugins can show the opt-in banner to EU and UK visitors and run opt-out for everyone else from the same settings, so one setup covers both. Check the US side yourself, because this is where plugins differ: turn on GPC in your browser, load the site, and confirm the marketing scripts stay off and the page says the signal was honored.

Asking again. If someone rejects, how long before you show the banner again? CNIL says respect a refusal for at least six months. Other regulators haven't said, and some sites re-ask on every visit. Re-asking sooner will raise your consent rate and will annoy the people who already told you no.

Delaying the banner. Showing the banner after a few seconds, or on the second page, so the visitor has some context first. The rule that matters is that nothing non-essential fires before consent, whenever the banner shows. Some banner companies claim a short delay raises acceptance, but I haven't seen data either way.

The uncomfortable part, and the reason these are gray areas at all, is that the research that shows how to steer people toward a button is the same research regulators cite when they ban it. People click the button that stands out, and that works whether the one that stands out is Accept or Reject.

If you want my actual recommendation:

  • Start from the baseline: equal Accept and Reject on the first screen, categories behind Customize, nothing pre-checked.
  • Add geo-targeting so visitors outside the EU and UK aren't asked at all, and run opt-out for US visitors instead of a banner: an opt-out link that's easy to find, GPC honored, and a visible confirmation when it is.
  • Decide on a highlighted Accept button knowing it's a gray area in the EU and written down as asymmetrical in California.
  • Keep Reject on the first screen. Moving it is the one that has been fined.
  • Don't re-ask sooner than six months.

That gets you most of the acceptance that's available without much risk. Anything past it is a judgment call you should make on purpose rather than by default.

Make sure the yes reaches every platform

Once someone accepts the banner, it's worth checking that the yes actually turns on every platform you use, because that's a spot where attribution goes missing even on sites with a good consent rate.

Cookie banners handle this in two ways. For Google, most of them speak Google Consent Mode: the Google tags load right away in a denied state, and the banner flips them to granted when the visitor accepts. For everything else, the banner blocks the script entirely until consent and then releases it. Blocking works, but only for scripts the banner knows about, so a pixel the banner's auto-blocker doesn't recognize, or one you added without registering it, either loads before consent or never loads at all. And a blocked-then-released script misses out on the platform's own consent features. Meta, TikTok, Microsoft, and others have consent signals of their own, similar to Google's, that let the tag load early and only start sending data once consent is given, and a banner that just blocks the script never uses them.

Conversion Bridge listens to the choice your banner records, then handles each platform the way that platform expects. Where a platform has its own consent signal (Google, Meta, TikTok, Microsoft, and a few more), Conversion Bridge loads the tag and sends that signal, in that platform's own format. Where a platform has no such signal, Conversion Bridge tags the script with its consent category so your banner can block and release it correctly.

Using each platform's own consent signal instead of blocking the script matters for different reasons on different platforms:

  • Google, Microsoft Advertising, and Microsoft Clarity require it. Google has needed Consent Mode v2 signals since March 2024 before it will use EEA visitors' data for audiences and remarketing. Microsoft Advertising has required UET consent mode for EEA, UK, and Swiss traffic since May 2025, and without it stops counting conversions and updating remarketing lists. Clarity has required a consent signal for the same regions since October 2025. A banner that blocks and releases these scripts without sending the signal collects data from visitors who accepted, and the platform then won't use all of it.
  • Declined visitors still count for something. With the signal set to denied, Google models conversions from cookieless pings and Clarity keeps running in a limited no-cookie mode. A blocked script sends nothing at all.
  • One script, two purposes. GA4 and Google Ads share one gtag script. Blocking treats it as a single yes or no, while the consent signal can grant analytics and deny ads, which is the most common partial choice visitors make.
  • Nothing is lost at the moment of acceptance. Meta's and TikTok's consent APIs let the pixel load right away and hold everything until consent, so when the visitor clicks Accept, the page view and any event that already happened go out. Conversion Bridge does the same with its own conversion events, holding each one until consent and releasing it once, so a form submitted a second before the click still gets tracked. A blocked script has to be fetched and run after the click, and anything from before that point is gone.

Since June 15, 2026, Google uses the Consent Mode ad_storage signal as the only control over whether advertising data flows from Google Analytics to a linked Google Ads account. A missing or wrong signal can send visitor data to Google Ads against their choice, or block data they agreed to share. The Consent Signal Ownership doc walks through the setup.

The test is to accept the banner in a private window, then check that each platform's pixel actually fired for a conversion, not just Google's. On a lot of sites, that check is the biggest attribution improvement available, and it costs nothing in consent rate.

Ask for less so more people say yes

The other thing you can change without touching the banner design is how much you need consent for, and cookieless analytics is the easiest place to do that. Cookieless analytics means a tool that measures visits without setting a cookie or building a profile of the visitor. Tools like Fathom, Plausible, Pirsch, and the other cookieless analytics platforms Conversion Bridge supports don't set cookies or build a profile of the visitor, and the common reading of GDPR is that they can run for every visitor, accepted or not. Conversion Bridge knows which platforms are cookieless and doesn't hold them behind the banner. If you run one of these for analytics, your banner only has to ask for marketing, which means a shorter banner with fewer categories, which the Utz research says gets more full acceptance.

This is one more gray area, and not every banner agrees. Borlabs Cookie, for example, treats any connection to an outside server (your IP address plus a timestamp) as personal data, so it wants consent for cookieless tools too, and Conversion Bridge follows that policy when Borlabs is your banner. Under every other supported banner, cookieless analytics runs for everyone.

It also fixes a second problem: when analytics is behind the banner, your own traffic numbers are only as complete as your consent rate. Cookieless analytics gives you a full picture of visits and conversions to measure your consent rate against, which is the only way to know whether your changes are working.

Measure it like any other conversion

Your banner plugin almost certainly reports its consent rate. Look at it monthly, split by region if it can, and change one thing at a time, so if you move the banner this month, give it a couple of weeks before you also restyle the buttons. The studies tell you which changes are big and which are small, but your audience and your traffic mix decide the actual numbers. A B2B site with mostly desktop US traffic and an ecommerce store with mostly mobile EU traffic will land in very different places with the same banner.

Where to start

If you already use one of the supported cookie banners, Conversion Bridge picks up its choices automatically, and the Consent Signal Ownership doc covers the one setting worth checking. If you're choosing a banner, the cookie banner integrations list shows which ones connect. Either way, start from the legal baseline, decide on the gray areas on purpose (with a lawyer if the stakes are high), and make sure every yes reaches every platform.

Happy tracking!

Derek Ashauer
Derek Ashauer is the lead developer of the Conversion Bridge WordPress plugin. He has been involved with WordPress since 2005 and has worked with hundreds of clients to build custom websites. He now uses that experience to build highly-rated and helpful WordPress plugins.