Your opt-in rate is a conversion rate: what moves it, legally
Which consent banner changes are legitimate design and which ones regulators have named. Plus the arithmetic for what a point of consent rate is worth.
Short answer: treat the banner like any other conversion surface — but the levers that survive a regulator's reading are timing, clarity, copy, layering and mobile layout, not friction. Making rejection harder does work; it is also the specific thing the EDPB and the ICO have written down as invalidating the consent you collect, which means every conversion you "recover" that way is built on a signal you can't defend. Fix the honest levers first, because most sites have never touched them. And before you chase a number, know that there is no reliable public benchmark for what a normal opt-in rate is — anyone quoting you one is quoting a vendor.
The one measured number on friction comes from a 40-person study
The advice circulating in advertising forums is that making it slightly harder to decline moves opt-in rates from around two-thirds to nearly ninety per cent. We went looking for where that comes from. The only peer-reviewed measurement of the effect is Nouwens et al., Dark Patterns after the GDPR, published at CHI 2020: removing the "reject all" button from the first page increased consent by 22–23 percentage points.
Read the method before you spend that number. It was a field experiment with 40 participants, mean age 26.1, all resident in the United States, recruited through an author's personal network and a university mailing list, shown pop-ups injected by a browser extension rather than real banners on real sites. The authors say so themselves: the sample "is by no means representative of the general population in the United States", and their results describe a best case, because these participants understood consent interfaces better than an average visitor.
So the direction is real and the magnitude is soft. Two other findings from the same paper are more useful and get quoted less. Showing granular per-purpose or per-vendor controls on the first page decreased consent by 8–20 percentage points. And notification style — a barrier that blocks the page versus a banner that doesn't — had no measurable effect on the answer at all.
The patterns regulators have already written down
Two public documents name the practices, so you don't have to guess where the line is.
The EDPB's Cookie Banner Taskforce report, adopted 17 January 2023 to coordinate handling of the NOYB complaints, works through them by letter. Type A is "no reject button on the first layer" — a vast majority of the authorities involved considered that the absence of a refuse option on any layer carrying a consent button is an infringement. Type B is pre-ticked boxes, which the members confirmed cannot produce valid consent. Type C is deceptive link design, where the only alternative to consenting is the word "refuse" buried in a paragraph of text, or placed outside the banner frame. Types D and E cover unequal button colours and contrast; the taskforce declined to impose a general contrast standard, but agreed that a reject button whose text is unreadable against its own background is manifestly misleading. Type H is the legitimate-interest layer, where refusing storage and objecting to processing are split so a user has to refuse twice.
The ICO's guidance, finalised on 29 April 2026, turns the same ground into a checklist. First item: "Our consent mechanism makes it as easy to refuse consent as it is to accept." Its bad-practice illustration is a banner offering "accept all" and "more options" with no reject. Its other bad-practice image is a purpose list with legitimate-interest toggles switched on by default next to consent toggles switched off.
The ICO is also explicit about re-prompting, which is the lever people reach for when the others stop working. You "should not repeatedly ask or prompt people to specify their preferences as a matter of course", and this applies "particularly" once someone has refused: "It is unfair to repeatedly request their consent just because you want them to respond differently." Its guideline for asking again after a decline is six months.
The legitimate levers, in the order most sites have neglected them
Every item here is a design change a regulator's own guidance points at, and none of them touch the cost of saying no.
Fix the mobile layout first. The ICO warns that a message box designed for a desktop browser "can be hard for the user to read or interact with when using a mobile device", and draws the consequence that consent obtained from those users may not be valid. If most of your traffic is mobile and your banner was styled on a laptop, this is both a compliance problem and the largest untouched lever you have.
Put bulk buttons on layer one and granularity on layer two. This is where the research and the rules agree. The ICO's own good-practice example is three equally prominent options — accept, reject, customise — with per-purpose toggles behind the third. Nouwens et al. measured the cost of doing it the other way: purpose and vendor lists on the first page dropped consent by 8–20 points. The same study found only 6.9% of participants ever clicked through to a second page, and put it bluntly — anything requiring interaction to access might as well not exist.
Cut the number of third parties before you cut the number of clicks. The ICO says consent is more likely to be valid where you have made an active choice to partner with a specific third party for a specific purpose, and that meeting the requirements "may be challenging" if you use a large number of them. A shorter vendor list is a shorter disclosure, which is a shorter decision.
Write the copy for a person. The taskforce's requirement is that a user "should be able to understand what they consent to and how to do so", and that the banner must not imply consent is the price of reading the page. Say what the data is used for, in your own words.
Time it so it isn't interrupting something. The ICO asks that consent requests are "not unnecessarily disruptive" — while adding, fairly, that avoiding disruption never overrides validity. Given that the CHI study found barrier and banner formats produced no difference in the answer, the less intrusive format is close to free.
Check whether you need consent for analytics at all. In the UK the Data (Use and Access) Act added a statistical-purposes exception, and the ICO's own good-practice illustration shows an "analytics" category on by default with advertising and social tracking off. That is a change in what you have to ask for, not a trick — and we covered its limits in the piece on where the UK "consent or pay" line sits. It never extends to advertising tags.
The arithmetic, on your numbers not ours
For a site that doesn't qualify for Google's behavioural modelling — which is most sites, for reasons set out in what Consent Mode modelling actually recovers — the relationship is close to linear. Google's tags set no cookies when consent is denied; they send cookieless pings instead. So your observed conversions are roughly your true conversions multiplied by your consent rate, and one point of consent rate is one per cent of your conversion volume moving from invisible to visible.
Take a site with 400 conversions a month at a 60% consent rate. You see about 240. Ten points of consent rate is 40 more visible conversions a month. Put your own revenue per conversion against that, then set it against the cost of the work.
Two caveats decide whether that number means anything. These are not new conversions — they already happened, and what you're buying is measurement. Measurement is worth money because Smart Bidding trains on what it can see, and an algorithm shown 60% of your outcomes is optimising against a biased sample of them. The second caveat: if your traffic clears the modelling thresholds the relationship stops being linear, because Google fills part of the gap. Work out which of those two positions you're in before you model anything.
The arithmetic only works if the consent signal reaches Google in the first place. Our Google Ads consent checker loads your live site and reports whether the Consent Mode v2 parameters are actually being sent — which, on the sites we scan, is the failure that costs more than the opt-in rate does.
Nobody has published a trustworthy opt-in benchmark
If you want to know whether your consent rate is good, the honest answer is that no reliable public benchmark exists, and we're not going to invent one.
The figures that circulate come from CMP vendors reporting their own installed base, with no published method, no sampling frame, and an obvious interest in the result. The academic work doesn't fill the gap either: the accept and reject proportions in the CHI study came from pop-ups injected into a 40-person experiment, which measures interface effects, not what British visitors do on real websites.
The nearest thing to an official number measures something else entirely. On 29 April 2026 the ICO said that "99% of the UK's top 1,000 websites now meet compliance standards for cookie banners owing to focused ICO work with industry". That is a statement about banner compliance among the largest sites, not about opt-in rates, and the ICO doesn't publish the standard it was scored against. Treat it as evidence that enforcement attention is real, not as a number you can compare yourself to.
What's left is the only comparison that means anything: your own rate, measured the same way over time, against itself. Get that instrumented before you change the banner, or you'll never know which change did what.
What to do this week
Verify the consent signal reaches Google first, because an opt-in improvement on a site that isn't passing ad_user_data and ad_personalization correctly buys you nothing. Then check the banner on a phone. Then move granular controls to a second layer and give accept and reject the same visual weight — the one change that satisfies the ICO checklist and the CHI finding together. Then count your third parties.
Keep a record of what you changed and when. If a regulator asks, "we tested it" is a much better answer when the variants were layout and copy rather than the cost of refusing.
If you'd rather have the consent signal, the tag wiring and the Consent Mode defaults handled together, that's what we do.
Sources
- 1.ICO — Guidance on the use of storage and access technologies: 'How do we manage consent in practice?' (checklist of expectations for consent mechanisms, and the six-month re-prompt guideline) · Finalised 29 April 2026, checked 2026-07-29
- 2.ICO — 'Final storage and access technologies guidance published', quoting William Malcolm on the top 1,000 UK websites · 29 April 2026, checked 2026-07-29
- 3.EDPB — Report of the work undertaken by the Cookie Banner Taskforce (the lettered practice types) · Adopted 17 January 2023, checked 2026-07-29
- 4.Nouwens, Liccardi, Veale, Karger & Kagal — 'Dark Patterns after the GDPR', CHI 2020 (scrape of 680 CMP sites plus a 40-participant field experiment) · CHI 2020, checked 2026-07-29
- 5.Google Ads Help — About consent mode (what tags send when consent is denied) · Checked 2026-07-29