Yes, in practice: EDPB guidance and DPA practice require that rejecting cookies be as easy as accepting them. That means a visible "Reject all" button on the first layer of the banner, next to "Accept all" — not buried two clicks deep in "Settings". A banner that offers only "Accept" or hides the reject option makes consent invalid and invites complaints. Below: what a compliant first layer looks like and what happens to your data when visitors reject.
What the law requires: rejecting as easy as accepting
GDPR requires consent to be "freely given" — and consent obtained because rejecting is hard to find isn't free. Guidance from the European Data Protection Board (EDPB) is explicit on this point: rejecting must be as easy as accepting.
In DPA practice, including that of Romania's ANSPDCP, this translates simply: if "Accept all" is a button on the first layer, then "Reject all" must be a button on the first layer too, equally visible. It isn't about a mandatory wording, but a symmetry principle:
- Rejecting cannot take more clicks than accepting.
- The reject button cannot be visually hidden (grey on grey, below the fold, in a submenu).
- "Continue without accepting" or a closing "X" do not replace a clear reject unless they actually stop the trackers.
A banner without a reject button on the first layer isn't just risky — it makes the consent you collect invalid from the start.
What a compliant first layer looks like
The first layer (what the visitor sees before any click) should offer three balanced choices:
| Element | Right | Wrong (invalidates consent) |
|---|---|---|
| Accept all | Clear button, on the first layer. | — |
| Reject all | Equally visible button, on the first layer. | Hidden in "Settings" or missing entirely. |
| Customize / Settings | Link to per-category choices. | The only way to reject anything. |
| Visual design | Buttons balanced in size and contrast. | "Accept" brightly colored, "Reject" grey and barely visible. |
Color imbalance between buttons is one of the practices regulators flag as manipulative. See cookie banner dark patterns for the full list of patterns that make consent invalid even when you do have a banner.
What happens to your data when visitors reject
The main fear for site owners is "if everyone rejects, I lose all my data". Not quite. With Google Consent Mode v2 configured correctly, even after a reject Google receives cookieless pings — aggregated signals with no persistent identifiers — which it uses for conversion modeling.
Concretely, when a visitor rejects:
- The four Consent Mode v2 signals (
ad_storage,analytics_storage,ad_user_data,ad_personalization) switch todenied. - Trackers set no persistent cookies and collect no personal data.
- Google still receives aggregated, anonymous signals for conversion estimation.
The result: legally valid data, instead of illegally collected data that wouldn't survive a complaint anyway. See the Consent Mode v2 in Romania guide for setup.
The honest trade-off: lower opt-in, but valid data
Let's be direct: a visible reject button will lower your acceptance rate compared to a banner that nudges toward "Accept". That's the reality. But the trade-off is in your favor:
- Valid data vs. data at risk. A 60% opt-in on real consent beats a 95% obtained through manipulation, which collapses at the first complaint.
- GDPR risk is disproportionate. Fines run up to €20 million or 4% of global turnover; any visitor can file a free complaint with ANSPDCP.
- Consent Mode covers the gap. With cookieless pings, you aren't even blind on conversions.
A well-built CMP gives you the correct reject button out of the box, with nothing to configure by hand. FewCookies shows "Accept" and "Reject" balanced on the first layer and sends all four Consent Mode v2 signals. Check what your current banner does with a free scan — if trackers fire before the click or the reject option is missing, you have something to fix. See also what you risk without consent in Romania.
Frequently asked questions
Can I put the "Reject" button only in the settings menu?
Not advisable. EDPB guidance requires rejecting to be as easy as accepting; if "Accept all" is on the first layer while "Reject" is hidden behind a click into "Settings", the asymmetry makes consent invalid and is exactly the pattern regulators flag. Put both buttons on the first layer.
Does the closing "X" on the banner count as a reject?
Only if closing actually stops all non-essential trackers, the same as a "Reject all". If the banner closes but scripts run anyway, you don't have a reject — you have a decorative banner. The safest option is an explicit "Reject all" button, and you verify the behavior with a scan.
Do I lose all my analytics data if I add a reject button?
No. With Google Consent Mode v2 configured correctly, even after a reject Google receives cookieless pings — aggregated, anonymous signals — used for conversion modeling. You lose the persistent identifiers, but you keep a valid estimate, instead of illegally collected data.
Want to see which cookies and trackers fire on your site before consent? The scan is free and needs no account. Check your site for free →