
For a decade, these were "conversion tactics." Make "Accept" easy, make "Reject" a maze, and watch consent rates climb.
In 2026, they're something else: a line item in a fine.
France's CNIL alone issued 83 sanctions worth about €486.8 million in 2025 — including €325 million against Google and €150 million against SHEIN, both for exactly these cookie-banner tricks. The rule regulators now apply is blunt, and a user on r/gdpr summed it up perfectly: "you can't accept in 2 seconds and refuse with 30 clicks."
Here are the nine specific patterns that turn a banner into a liability — what each one is, why it's now fined, and how to fix it.
If you only read one thing: the test regulators use is whether refusing is as easy as accepting. Every pattern below fails that test.
What it is: "Accept all" sits right there on the first screen. To reject, you have to click "More options," dig through a settings panel, and toggle things off one by one.
Why it's fined: Unequal effort is the single most-enforced dark pattern. Refusal has to be as easy as acceptance. In 2022, CNIL fined Google €150 million and Facebook €60 million for exactly this — accepting took one click, refusing took several. A German court has since ruled that "Reject all" must appear on the first level, and the EU's cookie banner taskforce treats a missing first-layer "refuse all" as a breach.
The fix: Put "Reject all" on the first screen, one click, same size as "Accept all."
What it is: The consent toggles for analytics or ads are already switched on when the banner loads. Doing nothing counts as a yes.
Why it's fined: This one's settled law. In the 2019 Planet49 case, the EU's top court ruled that a pre-ticked box is not valid consent — consent requires an active choice. Every regulator now cites it. Non-essential cookies have to be off until the user turns them on.
The fix: Every non-essential category off by default. No pre-ticks, no exceptions.
What it is: The banner has a proper "Reject" button. You click it. The trackers fire anyway.
Why it's fined: This is the trick that produced the biggest cookie fine in history. In September 2025, CNIL hit SHEIN with €150 million and Google with €325 million — in part for consent flows where refusal didn't actually stop the tracking. In the US, California fined Healthline $1.55 million for banners that ignored opt-outs. Independent testing found the pattern everywhere: one study reported 55% of sites set cookies even after users declined.
The fix: Block non-essential scripts until consent, and make sure "Reject" genuinely stops them. Test it.
What it is: "Accept all" is a big, bright, high-contrast button. "Reject" is grey text, a faint outline, or a low-contrast link you barely notice.
Why it's fined: Regulators call it interface interference — using colour and contrast to steer the choice. CNIL described banners where it was "mathematically more difficult to refuse than to accept." California's privacy agency treats a bright "Accept" next to a hidden "Reject" as an illegal dark pattern, and its enforcement has already reached six figures against carmakers over non-compliant consent flows.
The fix: Give both buttons equal visual weight — same colour treatment, same size, same prominence.
What it is: A user rejects cookies. On the next visit, the banner is back. And the next. Refuse, and you get asked again forever, often behind content you're trying to read.
Why it's fined: Repeatedly pressuring someone who already said no undermines "freely given" consent. Belgium's data protection authority went after several news sites for this, threatening fines of €25,000 per day for banners that kept re-prompting and pressuring users to accept.
The fix: Store a refusal and respect it. Don't re-ask for months — the EU's proposed reform sets six months as the floor.
What it is: One button — "Accept all" — that lumps analytics, advertising, personalization, and data-sharing with dozens of vendors into a single yes. Granular control is missing or buried.
Why it's fined: Consent has to be specific. Bundling separate purposes into one click isn't a real choice. Amazon's €746 million fine in Luxembourg and Meta's €395 million fine in Ireland both turned on consent for ad tracking that users couldn't meaningfully refuse.
The fix: Let users consent by category — analytics separate from ads separate from personalization.
What it is: You open the settings, switch everything off, and feel safe. But a second set of toggles labeled "legitimate interest" was on the whole time — and you'd have had to turn each of those off separately.
Why it's fined: Regulators treat pre-enabled "legitimate interest" switches as pre-selection by another name — the same problem as pre-ticked boxes, just relabeled. For most ad-tracking, legitimate interest isn't a valid basis anyway, and hiding live tracking behind a second layer of on-by-default toggles is exactly the concealment DPAs are auditing.
The fix: Don't rely on legitimate interest for advertising cookies. If a toggle exists, it starts off.
What it is: The wording guilt-trips you. "Accept" is cheerful and green; the reject option reads "No, I don't want a better experience" or "I don't care about supporting this site."
Why it's fined: Regulators classify manipulative language as a dark pattern in its own right — framing refusal as harmful or shameful undermines a free choice. CNIL's formal notices call out ambiguous and misleading wording, and Belgium's action against news sites cited copy that pressured users into agreeing.
The fix: Neutral labels. "Accept all" and "Reject all." No editorializing on either button.
What it is: Accept all cookies, or you don't get in. Sometimes softened into "pay or consent" — agree to tracking, or pay a fee for the version without it.
Why it's fined: Consent isn't freely given if refusing costs you access. CNIL has long held that forcing cookie acceptance to use a site is rarely compatible with the GDPR, and Meta's €395 million fine turned on effectively forcing users to accept behavioural ads as the price of the service. "Pay or consent" is under active scrutiny across the EU right now.
The fix: Don't gate access on consent. If you offer a paid ad-free tier, make the free version usable without accepting tracking.
Notice what all nine have in common. Every one makes "yes" easier than "no."
That's the whole thing regulators are testing for now. Not whether you have a banner — whether your banner gives a real, equal choice. Asymmetry is the tell, and asymmetry is what gets fined.
The reassuring part: fixing these costs almost nothing. They're not features you buy. They're a banner that's honest by default — equal buttons, nothing pre-ticked, a "Reject" that actually rejects, and no guilt-trips. Do that, and none of the nine apply to you.
We built ConsentBit to be compliant by default — equal "Accept" and "Reject" on the first screen, non-essential scripts blocked until consent, nothing pre-ticked, consent logged, and the right rules applied by region. On Webflow, Framer, or any site, in minutes.
If you're not sure which of these nine your current banner is guilty of, we'll take a look. Let's talk.
Check your banner with ConsentBit →
1. What is a cookie banner dark pattern?
A cookie banner dark pattern is a design trick that steers people into accepting tracking they'd otherwise refuse — like burying the "Reject" button, pre-ticking consent boxes, greying out the refuse option, or using guilt-trip wording. Regulators treat these as evidence that consent wasn't freely given, which makes the underlying tracking unlawful. The common test: if refusing is harder than accepting, it's a dark pattern.
2. Can you really get fined for a cookie banner design?
Yes, and the fines are large. In 2025, France's CNIL fined Google €325 million and SHEIN €150 million over cookie-consent practices, and issued 83 sanctions worth roughly €486.8 million that year. Earlier fines include Google €150 million and Facebook €60 million (2022) for making refusal harder than acceptance, and Amazon €746 million in Luxembourg. In the US, California has fined companies for banners that ignored opt-out choices.
3. What makes a cookie banner compliant in 2026?
A compliant banner offers "Reject all" as easily and prominently as "Accept all" on the first screen, keeps non-essential cookies off until the user consents, makes sure "Reject" actually stops the tracking, avoids pre-ticked boxes and pre-enabled legitimate-interest toggles, uses neutral wording, doesn't re-prompt people who declined, and doesn't gate access behind consent. In short: refusing has to be as easy as accepting.
4. Is a buried "Reject" button illegal?
In the EU, effectively yes. Regulators and the EU cookie banner taskforce treat the absence of a first-layer "Reject all" — equal to "Accept all" — as a breach, and a German court has ruled that "Reject all" must appear on the first level. Making users click through extra screens to refuse is the single most-enforced cookie dark pattern, and it's what drove the 2022 fines against Google and Facebook.
5. Are pre-ticked cookie consent boxes allowed?
No. The EU's top court settled this in the 2019 Planet49 case: a pre-ticked box is not valid consent, because consent requires an active, affirmative choice. Non-essential cookies — analytics, advertising, personalization — must be switched off by default, and the same applies to pre-enabled "legitimate interest" toggles, which regulators treat as pre-selection under another name.
6. Are "pay or consent" cookie walls legal?
They're contested and under active scrutiny. Consent must be freely given, and regulators question whether that's possible when refusing tracking means losing access or paying a fee. CNIL has long held that forcing cookie acceptance to use a site is rarely GDPR-compatible, and Meta's €395 million fine in Ireland turned on forced consent for behavioural ads. Treat cookie walls as unsettled legal ground, not a safe tactic.