Short answer: in the EU and the UK, if your cookie banner has an "Accept all" button, you should put a "Reject all" button (or an equally easy way to refuse) next to it on the first layer. No single EU law names a "Reject all" button, but regulators read the GDPR consent rules and the ePrivacy Directive as requiring that refusing cookies is as easy as accepting them. In January 2023 the EDPB Cookie Banner Taskforce reported that a vast majority of EU authorities consider a banner with no refuse option on the layer that has the consent button to be an infringement. France (CNIL), Germany (DSK), Spain (AEPD), the Netherlands (AP), Belgium (GBA) and Denmark (Datatilsynet) all expect refuse and accept at the same level. Italy (Garante) accepts a clearly visible "X" that closes the banner without consent. In the UK the ICO expects "Reject all" to be as prominent as "Accept all". It wrote to 53 of the top 100 UK websites in November 2023 and in 2025 reviewed the top 1,000.
Reject All button on cookie banners: rules by country
| Country | Regulator | Reject option on the first layer | Source |
|---|---|---|---|
| EU (common position) | EDPB | Expected: a vast majority of authorities treat a missing refuse option next to the consent button as an infringement | Cookie Banner Taskforce report, January 2023 |
| France | CNIL | Expected: refusing must be as easy as accepting; "Accept all" plus "Settings" is not enough | CNIL guidelines and recommendation (2020); fines on Google and Facebook (December 2021) |
| Germany | DSK and state authorities | Required in most cases: needed whenever users must interact with the banner to use the site | OH Digitale Dienste (November 2024); VG Hannover, 19 March 2025 |
| Italy | Garante | An "X" that closes the banner and keeps only technical cookies, with equal visual weight | Cookie guidelines, 10 June 2021 |
| Spain | AEPD | Required: accept and reject at the same level, applied since 11 January 2024 | Cookie guide updated July 2023 |
| Ireland | DPC | Required: a reject option with equal prominence to "Accept" | Cookie guidance, April 2020 |
| Netherlands | AP | Required: reject and accept on the same layer, no extra clicks to refuse | AP guidance on clear cookie banners |
| Belgium | GBA / APD | Required: "Reject all" next to "Accept all" on the first layer | Cookie checklist (October 2023); decision 113/2024 |
| Denmark | Datatilsynet | Expected: the first layer must let visitors actively say yes or no | Cookie guidance (May 2025) |
| United Kingdom | ICO | Expected: equally prominent "Reject all" and "Accept all" | ICO storage and access technologies guidance; letters to top sites 2023 and 2025 |
The EDPB set up the Cookie Banner Taskforce to coordinate the handling of cookie banner complaints filed by the privacy group noyb. Its report, adopted in January 2023, records that a vast majority of national authorities consider the absence of a refuse/reject option on any layer that contains a consent button to be incompatible with valid consent. The report also flags misleading button design: a reject link or button with such low contrast that it is barely readable is "manifestly misleading". The report is not binding guidance, so national rules still matter. That is why the country rules below are worth checking.
The CNIL says refusing cookies must be as easy as accepting them. Its recommended solution is a "Refuse all" button on the first layer, at the same level and with the same look as "Accept all". A banner that offers only "Accept all" and "Cookie settings" does not meet this standard. The CNIL has enforced this: on 31 December 2021 it fined Google €150 million and Facebook €60 million because google.fr, youtube.com and facebook.com did not make refusing cookies as easy as accepting them.
The German data protection authorities' guidance for digital services (OH Digitale Dienste, November 2024, updated for the TDDDG) says a reject option on the first layer is needed whenever users have to interact with the banner to keep using the site, which is the case for most common banners. A "Settings or reject" button that only leads to a second layer is not enough. In March 2025 the Administrative Court of Hannover (VG Hannover, 10 A 5385/22) backed the Lower Saxony regulator: a website with an "Accept all" option must offer a clearly visible "Reject all" button on the first layer.
The Garante's cookie guidelines of 10 June 2021 require an "X" command, usually at the top right of the banner, that closes it and keeps the default settings, so only technical cookies are used. The "X" must have the same visual weight as the other buttons, and continuing without consent must be as immediate and accessible as giving consent. Many sites also add a "Reject all" button, which meets the same goal.
The AEPD updated its cookie guide in July 2023 to follow the EDPB guidelines on deceptive design patterns. Accept and reject must now be presented at the same level, and refusing must not be harder than accepting. The old option of "Accept" plus a link to settings is no longer enough. The new criteria have applied since 11 January 2024.
The Data Protection Commission says that if a banner has an "Accept" button, a reject option (or a way to manage cookies by type) must have equal prominence. A banner with only an accept option, or with "OK, got it" buttons and no reject, is not compliant.
The Autoriteit Persoonsgegevens (AP) says the "reject" and "accept" buttons belong on the same layer, that only one of the two must not be offered on the first layer, and that declining must not take more clicks than accepting. The AP warned more than 200 websites about misleading banners and is now enforcing against those that did not fix them.
The Belgian Data Protection Authority (GBA / APD) published a cookie checklist in October 2023: an "Accept all" button should not appear on the first layer without an equally prominent "Reject all" button on the same layer. Its Litigation Chamber applied this in 2024, ordering the media group Mediahuis to add a "Reject all" option at the same level (decision 113/2024).
Datatilsynet says the first layer of the banner must let visitors actively say yes or no to cookies. Its May 2025 guidance, written with the Danish Agency for Digital Government, treats a banner that allows only acceptance as invalid. It also shows a bright green "Accept" button next to a barely visible "Reject" button as an example of nudging.
The UK ICO expects organisations to make it as easy to refuse non-essential cookies as to accept them. Its guidance on storage and access technologies gives "equally prominent options to accept all or reject all" as good practice and a banner with no "reject all" option as bad practice. In November 2023 the ICO wrote to 53 of the UK's top 100 websites and gave them 30 days to comply. By January 2024, 38 of them had changed their banners. In January 2025 it extended the review to the top 1,000 UK websites. In December 2025 it reported that 979 of the 1,000 met its checks, including whether rejecting advertising cookies was as easy as accepting them. It issued 17 preliminary enforcement notices along the way. For the full story, read UK ICO call for a Reject All button on cookie banners.
Every EU country applies the same GDPR consent standard and a national version of the ePrivacy Directive. If your local authority has no specific banner guidance, the EDPB Taskforce position is the safest baseline: a "Reject all" button next to "Accept all" on the first layer, with the same size, colour and contrast.
You can enable the Reject All button in the UniConsent CMP dashboard with one click. The UniConsent cookie banner shows "Accept all" and "Reject all" side by side with equal styling and blocks non-essential tags until the visitor chooses. It also supports Google Consent Mode v2 and IAB TCF. To check what your site does today, run a free scan with the cookie checker, and use the Consent Mode checker to confirm that a "Reject all" click sends denied consent signals to Google tags.
No EU law names a "Reject all" button, but regulators interpret the GDPR and ePrivacy rules as requiring that refusing is as easy as accepting. Spain, the Netherlands, Belgium and Ireland expect a reject option at the same level as "Accept", German courts and authorities require one on the first layer in most cases, and the CNIL and ICO treat an accept-only first layer as non-compliant. In practice, a "Reject all" button next to "Accept all" is the safest design.
Not for most EU regulators. The CNIL, the AEPD (since January 2024), the German authorities and the Belgian GBA all say a settings link or button that leads to a second layer does not make refusing as easy as accepting. Italy accepts an "X" that closes the banner without consent, as long as it is clearly visible.
The ICO's guidance expects an option to reject non-essential cookies that is as prominent as the option to accept them. Since 2023 it has written to the UK's most visited websites, and in 2025 it reviewed the top 1,000 sites against this standard and issued preliminary enforcement notices where needed.
The IAB TCF policies do not themselves require a reject button on the first layer, but they do not override national law. Publishers using the TCF still need to follow their local regulator, and UniConsent lets you show a TCF banner with "Reject all" on the first layer.
UniConsent is a part of Transfon User Experience Platform that serves tens of millions of users per day to provide a seamless privacy experience for both users and publishers in the age of post GDPR. Contact us to know more: hello@uniconsent.com
Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.
Activate Google Consent Mode UniConsent to enhance the accuracy of your Google Analytics and Google Ads conversion data.
Set up Google Consent Mode →Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up
IAB TCF 2.4 Deadline and How to Check Your Vendors
NFL.com CIPA Lawsuit: When Opting Out Doesn't Stop Tracking — How to Make Opt-Outs Actually Work

First-Party CMP Domain: Serve Your Consent Banner from Your Own Domain
UniConsent Is a Certified Microsoft UET CMP and Microsoft Clarity CMP

UK GDPR Right to Complain: Changes on June 19, 2026 and What Organisations Must Do

Prebid.js CMP Setup: Passing TCF, GPP, and CCPA Consent to Your Header Bidding Stack
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up