Focus

User Consent in E-commerce: Everything to Know Before 2027

Alexandre Suon · 2026-09-26

Consent decides what your e-commerce site may track, test and personalise, and how much of your data you can trust. This Focus explains the rules in Europe, the UK and the US, what regulators fine, how banner design changes the answer, what consent does to your analytics, and what changes before and during 2027.

Executive summary

  1. Consent is now a data-quality issue as much as a legal one. In the EU, non-essential cookies, pixels and similar tags generally need consent before they run, with narrow exemptions. The share of shoppers who accept decides how much of your traffic, revenue and test results you can see, and the shoppers who accept are not typical: Google says consenting users are typically 2 to 5 times more likely to convert.
  2. Refusing must be as easy as accepting. European regulators have fined Google, Facebook and SHEIN for banners that made refusal harder or placed trackers before any choice. In the US, California now requires choices to be symmetrical and fines sites that ignore opt-out signals such as Global Privacy Control.
  3. Banner design is one of the biggest factors you control. In a CNIL-backed experiment with 3,947 people, only 4% refused or customised their choice when there was no reject button on the first screen, against 17% with a neutral design and 47% when the consequences were explained. Dark patterns raise consent and legal risk at the same time.
  4. Consent rates vary widely. Didomi's 2026 benchmark (vendor data) puts the consent rate among users who make a choice at 71% in France and 87% in the British Isles; across all banner displays, including ignored ones, only 56% to 68% led to an opt-in. Plan analytics and testing for the traffic you will not see.
  5. The rules will not relax in 2027. The EU's Digital Omnibus proposal would allow one-click refusal and some exemptions for audience measurement, but it was still being negotiated in September 2026. Current cookie rules are very likely to apply throughout 2027, while California's browser opt-out law and new US state laws take effect on 1 January 2027 and India's consent rules in May 2027.
  6. Treat consent as part of the customer experience. A clear, honest banner, a consent-aware data set-up and measurement that accounts for missing data protect revenue, lifetime value and trust better than a banner designed to trick people into clicking accept.

Section 1 · The basics

What is user consent in e-commerce?

User consent in e-commerce is a shopper's free, specific, informed and unambiguous agreement to let a website or app store and read information on their device, and to use their personal data, for purposes that are not strictly necessary to provide the service they asked for, such as analytics, A/B testing, personalisation and advertising.

Consent touches almost everything an online shop does beyond taking orders. An analytics tag, a testing tool, a recommendation engine, a Meta or TikTok pixel, a retargeting cookie and an email list used for ad targeting can all need it, depending on the country and the purpose. The consent banner is where these rules meet the customer, usually on the first page they see.

Three reasons make consent a board-level topic in 2026. First, fines have grown: the French regulator, the CNIL, fined Google €325M and SHEIN €150M in September 2025 alone. Second, consent shapes data: every shopper who refuses disappears from analytics, test results and advertising audiences, and those who remain are not representative. Third, consent is part of the customer experience: in Cisco's 2024 survey, 75% of consumers said they would not buy from companies they do not trust with their data.

What consent decidesExamplesWhat happens without it
AnalyticsGoogle Analytics, Adobe Analytics, Piano, session replayVisits and revenue go unrecorded or are estimated by models
ExperimentationA/B testing and feature-flag toolsTests run on consenting users only, a biased sample
PersonalisationRecommendations, returning-visitor experiences, lifecycle triggersDefault experience for visitors who refuse
AdvertisingMeta, Google Ads, TikTok and retargeting pixels; customer lists sent to ad platformsSmaller audiences, weaker attribution, legal risk if data is sent anyway
Email and SMS marketingNewsletters, promotionsIn the EU, prior consent is needed unless the soft opt-in for existing customers applies

For leaders. Ask two questions about your consent set-up: would a regulator see refusing as easy as accepting, and do your dashboards say how much of your traffic they cannot see? In our experience, many businesses cannot answer either.

Section 2 · The rules

Europe requires consent before tracking, the UK now exempts some low-risk uses, and the US lets shoppers opt out

The three largest markets for European and American e-commerce brands follow different models. What follows is a summary as of September 2026, not legal advice.

European UnionUnited KingdomUnited States
ModelOpt-in: consent before non-essential storage or trackingOpt-in, with new exemptions that need only an opt-outOpt-out: data may be used unless the shopper refuses
Main rulesePrivacy Directive Art. 5(3); GDPRPECR as amended by the Data (Use and Access) Act 2025; UK GDPRAbout 20 state privacy laws in force in 2026, led by California (CCPA)
AnalyticsConsent needed, except audience measurement meeting strict national conditions (e.g. CNIL)Exempt from consent for statistical purposes to improve the service, with clear information and an opt-out (since 5 Feb 2026)Generally no consent under state privacy laws; opt-out applies to sale and sharing; session replay and chat tools face wiretap (CIPA) lawsuits
Advertising and retargetingConsent neededConsent neededOpt-out of sale, sharing and targeted advertising; honour GPC in about a dozen states
Banner rulesRefusing as easy as accepting; no pre-ticked boxes; no trackers before a choiceRejecting as easy as accepting (ICO)California: symmetrical choices; closing a pop-up is not consent
Maximum finesUp to €20M or 4% of global turnover, whichever is higher, under the GDPR; national ePrivacy fines£17.5M or 4% of turnover (since 5 Feb 2026)California: per-violation penalties; CIPA lawsuits

European Union

Article 5(3) of the ePrivacy Directive says that storing or accessing information on a user's device is allowed only with consent, unless it is strictly necessary for a service the user explicitly requested. The GDPR defines what valid consent means: freely given, specific, informed and unambiguous, given by a statement or a clear affirmative action, and as easy to withdraw as to give. The Court of Justice confirmed in its 2019 Planet49 judgment that a pre-ticked box is not valid consent, and that the rule applies whether or not the information is personal data.

Regulators have spelled out what this means for banners. The European Data Protection Board's cookie banner taskforce reported in January 2023 that a vast majority of authorities consider the absence of a reject option on any layer that has an accept button to be an infringement, and that legitimate interest cannot replace consent for cookies. Its Guidelines 2/2023, finalised in October 2024, clarify that the rule also covers tracking pixels, tracking links and other identifiers, not just cookies.

United Kingdom

The Data (Use and Access) Act 2025 changed the UK rules on 5 February 2026. Consent is no longer needed for storage used only to collect statistics on how a service is used in order to improve it, where the information is shared only with those helping to make those improvements, or to adapt how the site looks or works to a user's preferences, provided users get clear information and a simple, free way to object. Advertising and cross-site tracking still need consent. Maximum fines rose from £500,000 to £17.5M or 4% of global turnover, and the Information Commissioner's Office (ICO) published its final guidance on storage and access technologies on 29 April 2026.

United States

There is no federal cookie-consent law. About 20 states had comprehensive privacy laws in force in 2026, using an opt-out model: businesses may use personal data but must let people refuse its sale, its sharing for cross-context behavioural advertising and targeted advertising, and most of these laws require opt-in consent for sensitive data (California instead gives consumers a right to limit its use). California goes furthest. Its regulations already required symmetrical choices; updates in force since 1 January 2026 add that a more prominent "yes" button is not symmetrical, that closing a pop-up without choosing does not count as consent, and that businesses must show whether they have processed an opt-out preference signal.

For marketers. If you sell in several regions, design for the strictest rule you face and adapt by region: an opt-in banner with an equally visible reject button in the EU, the lighter UK exemptions where they apply, and a clear "Do not sell or share" link plus automatic handling of Global Privacy Control in the US.

Section 3 · Enforcement

Regulators fine banners that make refusing harder than accepting, and trackers that fire before a choice

Consent enforcement is no longer theoretical. The largest fines have hit global platforms and retailers, and US regulators have begun fining ordinary consumer brands for broken opt-outs.

Two bar charts of consent-related fines. Europe, in millions of euros: Google €325M (CNIL, September 2025), Google €150M (CNIL, January 2022), SHEIN €150M (CNIL, September 2025), Facebook €60M (CNIL, January 2022), Criteo €40M (CNIL 2023, upheld March 2026), unnamed retailer €3.5M (CNIL, announced January 2026), American Express France €1.5M (CNIL, November 2025). United States, in millions of dollars: Disney $2.75M (February 2026), Healthline $1.55M (July 2025), Tractor Supply $1.35M (September 2025), Sephora $1.2M (August 2022), PlayOn Sports $1.1M (February 2026), Honda $0.63M (March 2025), Todd Snyder $0.35M (May 2025).
Exhibit 1. Selected consent and tracking fines in Europe and California, 2022–2026. Source: CNIL; PL&B; Conseil d'État; California Attorney General; California Privacy Protection Agency; Hintze Law; Holland & Knight. The Google €325M fine also covered ads in Gmail.

What this shows. European fines are larger, but US enforcement is growing fast and reaches mid-sized brands. The pattern is consistent: regulators punish trackers that fire before a choice or after a refusal, and choices that are harder to refuse than to accept.

  • SHEIN, €150M (CNIL, September 2025). Advertising trackers were placed as soon as a user arrived on the site, before any interaction with the banner, and new trackers were still placed after users clicked "refuse all".
  • An unnamed retailer, €3.5M (CNIL, announced January 2026). It sent loyalty-programme members' email addresses and phone numbers to a social network for ad targeting without valid consent. The case matters for any retailer that uploads customer lists to advertising platforms.
  • Criteo, €40M (CNIL, 2023). France's highest administrative court upheld the fine on 4 March 2026, confirming the regulator's approach to consent for retargeting.
  • Disney, $2.75M, and PlayOn Sports, $1.1M (California, February 2026). Opt-outs were not applied across services or took many steps; PlayOn's banner offered only "Agree" and did not recognise Global Privacy Control.
  • Healthline, $1.55M (California, July 2025). Its consent banner did not stop tracking when users unticked options.

Enforcement also comes from complaints. The privacy group noyb filed 422 formal complaints about cookie banners in August 2021, and in May 2026 the European Data Protection Board required Belgium's regulator to examine one of them on its merits. In the UK, the ICO reviewed the cookie banners of the country's 1,000 most-visited websites and said in April 2026 that 99% now met its standards. Cookies are not one of the CNIL's named inspection priorities for 2026, but its 2025 report counted 21 cookie-related sanctions out of 83.

For leaders. The costliest breaches are simple to test: open your site in a private window, check which tags fire before you click anything, click "refuse all", and check again. Do this after every tag, app or template change, not once a year.

Section 4 · Banner design

Banner design is one of the biggest levers on the share of shoppers who accept

Research consistently shows that people's choices depend on how the question is asked. That gives businesses both an opportunity and a temptation.

Bar chart from an online experiment with 3,947 participants in France in 2022, showing the share who refused or customised cookies on first exposure by banner design: no reject button on the first layer 4%; neutral design 17%; accept button highlighted 18%; decline button highlighted 34%; three-colour design 38%; design explaining the consequences of each choice 47%.
Exhibit 2. Share of participants refusing or customising cookies on first exposure, by banner design, %. Source: Bielova et al., "The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions", USENIX Security 2024 (n = 3,947, France, 2022).

What this shows. Hiding the reject button cut refusals and customisations from 17% to 4%, which is why most European regulators treat it as an infringement. Designs that make the choice clearer, such as explaining the consequences, raised refusals to 47%. Earlier research points the same way: a 2020 study found that only 11.8% of UK sites using the five most popular CMPs met minimum legal requirements, and in its 40-person experiment, removing the reject option from the first page raised consent by 22 to 23 percentage points. A 2024 study of one CMP's data found that more than 60% of users refused when offered one-click "reject all", while about 90% accepted when opting out took more than one click.

What a compliant, customer-friendly banner looks like

  • Equal choices on the first screen. "Accept all" and "Reject all" (or "Continue without accepting") with the same size, colour and prominence, plus a way to customise.
  • Plain purposes. Say what you use data for in customer terms: measuring how the site is used, testing improvements, personalising recommendations, showing ads on other sites.
  • Nothing before a choice. Only strictly necessary storage runs before the shopper decides; everything else waits.
  • Easy to change later. A persistent link or icon lets shoppers withdraw or change consent as easily as they gave it.
  • Fast and accessible. The banner must not slow the page, hide key content on mobile or trap keyboard and screen-reader users.

A banner is also a moment of truth for the brand. It is often the first thing a new customer reads. An honest, well-designed banner costs some consent in the short term, but it avoids the legal risk and loss of trust that come with manipulation, and it produces data you can defend.

For marketers. Treat banner wording and layout as something to improve within the rules, not a trick to beat them. Test clearer wording, better placement and a stronger explanation of the value of personalisation, but never test away the reject button.

Section 5 · Consent rates

Consent rates range from about 70% to almost 90% of those who choose, and many visitors never choose

Consent rates vary by country, industry, device and banner format. Public benchmarks are scarce and mostly come from CMP vendors, whose customers and definitions differ, so treat them as ranges rather than targets.

Two horizontal bar charts of consent rates in Europe, 2025 data, from Didomi's 2026 benchmark. By region: Eastern Europe 89.3%, British Isles 87.3%, Northern Europe 84.8%, Southern Europe 82.5%, Western Europe 75.1%, France 71.0%. By industry: Media and publishers 82.7%, Home equipment 80.7%, Beauty and cosmetics 80.3%, Food, beverages and staples 78.3%, Fashion and jewellery 78.0%, High tech and telecom 75.4%, Finance 72.8%, Energy and utilities 69.6%. Consent rate is the share of users who accepted among those who made a choice.
Exhibit 3. Consent rate by region and by selected industries in Europe, 2025 data, %. Consent rate = share accepting among users who made a choice. Source: Didomi 2026 benchmarks (vendor data from Didomi's customer base).

What this shows. France, where the CNIL has enforced a first-layer reject option since 2021, has a lower consent rate than any European region in Didomi's data. Fashion and beauty sites sit in the middle of the range. The chart also hides a bigger gap: among all banner displays, including those ignored, only 55.7% to 67.6% led to an opt-in across regions. For a typical European shop, roughly a third to 45% of visitors may be missing from consent-based analytics and advertising.

  • Format matters. In Didomi's data, pop-up banners (used by 78.5% of sites) had a 69.9% consent rate, while rarely used header and full-screen formats reached 80.0% and 77.2%.
  • Device matters. Mobile users consented more (80.6%) than desktop users (77.8%), in the same data set.
  • Behaviour changes over time. In France, the share of people who say they configure cookies rose from 43% in November 2020 to 49% in June 2022, according to CNIL surveys, and 39% said they refuse. Between January 2021 and August 2022, the share of the 1,000 most-visited French sites setting six or more third-party cookies fell from 24% to 12%.

Section 6 · Measurement

Consent turns analytics into a partial view of your customers, so measure the gap and model it honestly

Every refusal removes a shopper from cookie-based analytics, attribution and advertising audiences. The effect is large enough to change decisions.

Bar chart of measured effects of privacy rules and Apple's App Tracking Transparency on recorded e-commerce and advertising data. GDPR: recorded page views minus 12% and recorded website revenue minus 12% across 1,084 firms (Goldberg, Johnson and Shriver, 2024); consumers observed by an online travel intermediary minus 12.5% and recorded searches minus 10.7% (Aridor, Che and Salz, 2023). Apple App Tracking Transparency: click-through rate of conversion-optimised Meta ads minus 37% (Aridor et al., 2025).
Exhibit 4. Measured effects of privacy rules on recorded data, % change. Source: Goldberg, Johnson and Shriver, American Economic Journal: Economic Policy (2024); Aridor, Che and Salz, RAND Journal of Economics (2023); Aridor et al., Management Science (2025). Part of each drop reflects lost measurement rather than lost sales.

What this shows. When people could refuse tracking, recorded activity fell by about 11% to 12.5% after the GDPR and ad performance fell sharply after Apple's App Tracking Transparency. Some of the fall was real and some was data that could no longer be seen. The same study of Apple's change found that revenue fell by 8% to 40% for firms most dependent on Meta advertising relative to others, and that smaller e-commerce firms bore most of the losses.

How Google Consent Mode fills the gap, and its limits

Google Consent Mode passes each visitor's choices to Google tags through four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. Google requires advertisers to collect consent from users in the European Economic Area and pass these signals to keep using its measurement, personalisation and remarketing features there. In basic mode, Google tags wait until the visitor chooses. In advanced mode, tags load with consent denied and send cookieless pings, which Google uses to build more detailed models.

  • Modeling needs volume. Google Analytics models the behaviour of users who refused only if a property collects at least 1,000 events a day with analytics consent denied for at least 7 days, and has at least 1,000 daily users with consent granted on at least 7 of the previous 28 days. Google Ads conversion modeling needs 700 ad clicks over 7 days per country and domain grouping.
  • Modeled data is an estimate. In 2021, Google reported that conversion modeling recovered more than 70% of ad-click-to-conversion journeys lost to consent choices, while warning that results vary widely by advertiser.
  • Consenting users are different. Google itself notes that consented users are typically 2 to 5 times more likely to convert than unconsented users. Conversion rates measured only on consenting users overstate the true rate.
  • Google changed the controls in 2026. From 15 June 2026, Google Analytics uses Consent Mode, via Google Ads, as the single control for advertising data, replacing the role that Google Signals played.

Other platforms have followed. Microsoft Advertising has enforced consent signals for traffic from the EEA, the UK and Switzerland since 5 May 2025, and Meta's pixel provides commands to revoke and grant consent. Publishers serving personalised Google ads to users in the EEA and UK have needed a Google-certified CMP using IAB Europe's TCF since 16 January 2024.

For marketers. Report three numbers side by side: observed data from consenting users, modeled data, and your consent rate. When the consent rate changes, for example after a banner redesign, your conversion rate and traffic will move for reasons unrelated to customers.

For leaders. Ask what share of revenue your analytics can see. If the answer is unknown, reconcile analytics revenue with order-system revenue every month; the gap is your measurement blind spot.

Section 7 · Testing, personalisation and server-side

A/B tests, personalisation and server-side tags all run inside the consent rules, not around them

Experimentation and personalisation teams often assume their tools are exempt. In most of Europe, the rules give them no specific exemption.

A/B testing

The CNIL allows analytics without consent only when it is strictly limited to audience measurement for the site's own use, producing anonymous statistics, with no cross-referencing and no transfer of identifiable data to third parties; it recommends cookie lifetimes of up to 13 months and data retention of up to 25 months. Its guidelines mention optimising a site's ergonomics among the permitted purposes, but they do not mention A/B testing, and the CNIL no longer publishes a list of exempt tools. The prudent reading is that A/B testing tools need consent in France unless a specific, documented configuration fits the exemption. In the UK, the new statistical-purposes exemption may cover some testing aimed at improving the service, with an opt-out; take advice before relying on it.

Testing vendors provide consent options. Kameleoon, for example, can run only experiments tagged as technical until consent is given, or display experiments while holding data in memory until the visitor decides. AB Tasty can hand consent to a CMP or to its own tag and erases a visitor's data if consent is withdrawn. Optimizely offers an opt-out setting that keeps its snippet inactive until the visitor opts in.

  • Tests become samples of consenting users. Results describe people who accept cookies, who convert more than average. Check whether the winning variation is likely to behave differently for everyone else.
  • Watch for sample ratio mismatch. If consent is collected after a variation loads, or the banner interacts with the test, visitors can drop out unevenly between versions. Check the split before trusting a result; our essential guide to A/B testing explains how.
  • Do not test the banner into non-compliance. Testing banner wording is legitimate; removing or hiding the reject option is not.

Personalisation

Personalisation that relies on cookies or on profiles built from browsing generally needs consent in the EU. In the UK, the new exemption covers adapting how a site looks or works to a user's preferences, with an opt-out, but profiling for recommendations or advertising is not clearly covered; take advice before relying on it. Design a good default experience for visitors who refuse, and use data customers give you directly, such as preferences and account settings, with a clear explanation. Our essential guide to personalisation covers this in depth.

Server-side tagging

Server-side tagging sends data to a server you control before it reaches analytics and advertising vendors. It gives more control over what each vendor receives, but it does not bypass consent. The ICO states that the storage and access rules apply whether in a first-party or third-party context and describes server-side tag management explicitly, and the EDPB's Guidelines 2/2023 confirm that the consent rule covers pixels and tracking links. Google's server-side tagging passes the consent choices collected on the page to its own tags; other vendors' tags need to be configured to respect them. Our Focus on server-side Google Tag Manager covers this in detail.

For marketers. List every tool that runs on your site, its purpose and whether it waits for consent. Ask each testing and personalisation vendor how its consent mode works and what data it stores before a choice.

Section 8 · 2026–2027

Through 2027, the rules tighten in the US and India while Europe debates simpler banners

Several changes will affect e-commerce sites between now and the end of 2027. The EU's reform is the most discussed, but it is also the least certain.

Timeline of consent changes from 2024 to 2027. Already in force: Google requires consent signals, and a certified CMP for personalised ads in the EEA and UK (2024); Microsoft Advertising enforces consent signals (5 May 2025); Chrome keeps third-party cookies and retires most Privacy Sandbox tools (17 October 2025); California's updated CCPA regulations apply (1 January 2026); UK exemptions for statistics and preferences take effect (5 February 2026); IAB TCF 2.3 becomes mandatory (28 February 2026); Google Analytics uses Consent Mode as the single control for ad data (15 June 2026). Coming: EU Digital Fairness Act proposal expected (Q4 2026); EU Digital Omnibus negotiations, target of a deal by end of 2026; India consent manager registration (November 2026); California browsers must offer an opt-out signal, ADMT rules apply, and Louisiana and Oklahoma privacy laws take effect (1 January 2027); Alabama privacy law (1 May 2027); India DPDP consent obligations apply (May 2027); California risk assessments due (31 December 2027).
Exhibit 5. Consent-related changes for e-commerce, 2024–2027. Source: Google; Microsoft Advertising; Privacy Sandbox blog; California Privacy Protection Agency; legislation.gov.uk; IAB Europe; European Parliament Legislative Train; Venable; Press Information Bureau of India; Henkan & Partners analysis.

What this shows. Most of what is certain for 2027 happens outside the EU: California's browser opt-out law, new US state laws and India's consent rules. The EU reform could simplify banners, but not in time to change what sites must do in 2027.

The EU Digital Omnibus

On 19 November 2025, the European Commission proposed moving the cookie rules, where personal data is involved, from the ePrivacy Directive into the GDPR. As proposed, consent would remain the rule, but aggregated audience measurement for the site's own use and security would not need consent; users would be able to refuse with a single click; a site could not ask again for the same purpose for at least six months after a refusal; and sites would eventually have to honour automated, machine-readable choices sent by browsers. As of late September 2026, the Council had not agreed its position, a June 2026 Council compromise text had removed the browser-signal article, and the Parliament committees had not voted. The target is a political agreement by the end of 2026.

Our reading is that current national cookie rules, such as the CNIL's, will apply throughout 2027 whatever happens, because the new rules would start only after adoption and, for browser signals, only 24 to 48 months after entry into force. The Commission also plans to propose a Digital Fairness Act in late 2026, which is expected to address dark patterns.

United States and India

  • California, 1 January 2027. Under the Opt Me Out Act (AB 566), browsers must offer a built-in setting that sends an opt-out preference signal, so many more shoppers will be able to switch one on once and have it apply to every site. Rules on automated decision-making technology also apply from that date, and risk assessments for existing processing must be completed by 31 December 2027.
  • New state laws. Louisiana and Oklahoma privacy laws take effect on 1 January 2027 and Alabama's on 1 May 2027; Vermont's follows on 1 January 2028.
  • India, May 2027. The Digital Personal Data Protection Rules, notified in November 2025, phase in over 18 months: registration of consent managers from November 2026, and notice and consent obligations from May 2027.

For leaders. Budget for consent as a permanent capability, not a one-off project. Rules, browsers and platform requirements changed several times in 2024–2026 and will change again in 2027.

Section 9 · Building it right

Every team can run consent well, from a small shop using its platform's banner to a multi-market retailer

Good consent management does not require a large team. It requires clear ownership, a correct set-up and regular checks.

TeamSet-upChecksOwner
One or two people (small shop)The platform's built-in banner (e.g. Shopify or Shopware) or an entry-level CMP; Google Consent Mode; consent settings in every app and pixelPrivate-window test after each new app or tag; review banner wording yearlyThe e-commerce or marketing lead
Growing digital, CRO or data teamA CMP integrated with the tag manager; consent modes configured in analytics, testing and advertising tools; region-specific bannersMonthly tag audit; consent-rate and analytics-gap dashboard; test results checked for consent biasA named owner in analytics or CRO, with legal sign-off
Multi-brand or international retailerEnterprise CMP across sites and apps; server-side tagging with consent enforced per vendor; TCF where you sell ads; GPC handling in the USAutomated scans for trackers firing before consent; quarterly legal review; incident processA privacy and data governance group spanning legal, data, marketing and IT

Built-in tools cover more than many teams realise. Shopify offers a cookie banner that is configured automatically for visitors from the UK and EEA when those markets are active and controls Shopify's own tools and pixels, although third-party pixels added manually or by apps may need their own handling. Shopware 6 includes a cookie consent manager with opt-in by default. Larger businesses usually add a dedicated CMP to cover several sites, apps and regions.

Consent as part of the customer experience

The banner is part of your brand. In Cisco's 2024 survey of 2,600 consumers in 12 countries, 75% said they would not buy from companies they do not trust with their data, and 51% of the most privacy-active consumers had switched companies over data practices. In Twilio's 2025 survey of 7,640 consumers (vendor data), only 15% said they absolutely trust brands with their data and 84% wanted control over personalisation. A clear choice, honestly explained, is a small but visible proof that you respect your customers.

For leaders. Put consent in the same governance as payments and security: a named owner, documented configuration, regular audits and a plan for incidents. The cost is small compared with a fine or a year of unreliable data.

Section 10 · What to do next

Five moves to make before 2027

1. Audit what fires before and after a choice

In a private window, record which cookies, pixels and requests fire on arrival, after "accept all" and after "reject all", on desktop and mobile, in each market. Fix anything that fires without consent.

2. Make refusing as easy as accepting

Put accept and reject options with equal prominence on the first screen, explain purposes in plain words, and add a persistent way to change choices. In the US, add a clear opt-out link and honour Global Privacy Control automatically, ready for more browsers sending it from 2027.

3. Connect consent to every tool

Configure Google Consent Mode and the consent settings of your analytics, testing, personalisation, advertising and email tools, including customer lists sent to ad platforms. Document which purpose each tool serves.

4. Measure the gap

Track your consent rate by market and device, reconcile analytics revenue with order data each month, and label modeled figures in reports. Check A/B test results for consent bias before rolling out winners.

5. Assign an owner and a review cycle

Name one owner, review the set-up every quarter and after every major site or tag change, and follow the EU Digital Omnibus, the Digital Fairness Act and US state laws through 2027.

Our view. Consent is not an obstacle to growth. It is the permission that makes analytics, testing and personalisation legitimate. Businesses that ask clearly, respect the answer and measure what they cannot see will make better decisions and keep customers' trust.

FAQ

Frequently asked questions about user consent in e-commerce

Frequently asked questions

Do I need cookie consent for Google Analytics?

In the EU, generally yes: Google Analytics sets cookies and sends data to Google, so it needs consent unless it is configured to meet strict national exemptions, which standard set-ups do not. In the UK, since 5 February 2026, analytics used only to improve your service may run without consent if you give clear information and an easy opt-out, and the data is not shared beyond those helping you improve the service; check your analytics vendor's data-sharing settings and take advice before relying on it. In the US, consent is not required, but opt-out rules apply to the sale and sharing of data.

Is a cookie banner without a reject button legal?

Very unlikely in the EU or the UK. European regulators require refusing to be as easy as accepting, and most consider the absence of a reject option on a layer with an accept button an infringement. The CNIL has fined companies including Google and Facebook for this. In California, choices must also be symmetrical.

What is Google Consent Mode v2?

It is Google's way of passing consent choices to its tags. Version 2 added the ad_user_data and ad_personalization signals. Google requires consent signals for users in the European Economic Area to keep using its measurement, personalisation and remarketing features there, and uses them to model activity from users who refuse.

Does server-side tagging remove the need for consent?

No. Server-side tagging changes where data is processed, not whether you need permission. The UK ICO says the rules apply in first-party and third-party contexts and mentions server-side tag management, and the EDPB's guidelines confirm that the consent rule covers pixels and tracking links.

Do A/B testing tools need consent?

In France, and very likely in most of the EU, yes for standard set-ups. The CNIL's exemption covers audience measurement strictly for the site's own use and does not mention A/B testing. Most testing tools offer consent modes that wait for or respect the visitor's choice. In the UK, the new statistical-purposes exemption may cover some testing; take advice before relying on it.

What is a good cookie consent rate?

It depends on the country, sector and banner. Didomi's 2026 benchmark (vendor data) shows consent rates among users who choose ranging from 71% in France to 89% in Eastern Europe, with fashion and beauty around 78% to 80%. Among all banner displays, including those ignored, opt-in rates were 56% to 68%.

Will cookie banners disappear in 2027?

No. The EU's Digital Omnibus proposal would allow one-click refusal, exempt some audience measurement and eventually require sites to honour browser signals, but it was still under negotiation in September 2026 and would take time to apply. In our reading, current rules will apply throughout 2027.

Key terms

Consent
Under the GDPR, a freely given, specific, informed and unambiguous indication of a person's wishes, given by a statement or a clear affirmative action. Silence, pre-ticked boxes and inactivity do not count.
ePrivacy rule (Article 5(3))
The EU rule that storing or reading information on a user's device needs consent, unless it is strictly necessary for a service the user asked for. It covers cookies, pixels, local storage and similar technologies, whether or not the data is personal.
Strictly necessary
Storage the site cannot work without, such as a shopping basket or login session. It needs no consent, but the category is interpreted narrowly.
Consent management platform (CMP)
Software that shows the cookie banner, records each visitor's choices and passes them to tags and tools. Examples include Didomi, OneTrust, Usercentrics (Cookiebot) and Axeptio.
Consent rate
The share of users who accept, among those who make a choice. The opt-in rate among all visitors is lower, because many people ignore the banner.
Dark pattern
A design that pushes people towards a choice they would not otherwise make, such as hiding the reject button or making it grey and small. Regulators treat many of these as invalid consent.
Google Consent Mode
Google's system for passing consent choices to its tags. Version 2 added two signals, ad_user_data and ad_personalization, that Google requires for EEA traffic.
Behavioural and conversion modeling
Google's estimates of the activity of users who refused consent, based on the behaviour of those who accepted. They fill gaps in reports but are estimates, not observed data.
Opt-out model
The US approach: companies may use data by default but must let people refuse the sale or sharing of their data and targeted advertising.
Global Privacy Control (GPC)
A browser signal that tells sites the user opts out of the sale or sharing of their data. About a dozen US states, including California, require businesses to honour such signals.
Transparency and Consent Framework (TCF)
IAB Europe's standard for passing consent choices to advertising vendors. Version 2.3 became mandatory at the end of February 2026.
Consent or pay
Offering users a choice between accepting tracking and paying for access. Regulators accept it only under strict conditions, such as a fair price and an equivalent service.
Server-side tagging
Sending data to your own server first, which then forwards it to analytics and advertising tools. It improves control over data but does not remove the need for consent.

Sources

Laws, regulator decisions and guidance, platform documentation and research were checked against the original publications or publishers' pages where available on 26 September 2026; where a primary text could not be opened or a regulator no longer publishes a decision, a reputable secondary source is cited. Consent-rate benchmarks and some consumer surveys come from vendors (Didomi, Twilio) and are labelled as such. The regulatory summary is not legal advice. The comparison tables, the programme by team size and the recommendations are Henkan & Partners' own analysis.

  1. Directive 2002/58/EC (ePrivacy), Article 5
  2. Directive 2002/58/EC (ePrivacy), Article 13
  3. GDPR Article 4
  4. GDPR Article 7
  5. CJEU press release, Planet49 judgment (C-673/17), October 2019
  6. EDPB, Report of the Cookie Banner Taskforce, January 2023
  7. Hunton, EDPB adopts guidelines on the technical scope of Art. 5(3) ePrivacy, October 2024
  8. PL&B, CNIL fines Google €150 million and Facebook €60 million, January 2022
  9. CNIL, Google fined €325 million, September 2025
  10. CNIL, SHEIN fined €150 million, September 2025
  11. CNIL, sanction for sending data to a social network for advertising, January 2026
  12. CNIL, sanctions list
  13. CNIL, 2025 sanctions report
  14. CNIL, 2026 inspection priorities
  15. Next.ink, Conseil d'État upholds Criteo's €40 million fine, March 2026
  16. noyb, 422 formal complaints about cookie banners, August 2021
  17. EDPB, Belgian DPA must handle noyb cookie banner complaint, 2026
  18. CNIL, cookies FAQ
  19. CNIL, audience measurement tools exempt from consent
  20. CNIL, evaluation programme for exempt audience measurement, July 2025
  21. CNIL, guidelines on cookies and other trackers, 2020
  22. CNIL, evaluation of its cookie action plan, 2023
  23. Data (Use and Access) Act 2025, section 112
  24. Data (Use and Access) Act 2025, Schedule 12
  25. Clifford Chance, key aspects of the Data (Use and Access) Act take effect, February 2026
  26. ICO, final storage and access technologies guidance published, April 2026
  27. ICO, what are storage and access technologies?
  28. ICO, action secures increased cookie compliance, December 2025
  29. MultiState, comprehensive privacy laws taking effect in 2026
  30. Venable, 2026 mid-year state privacy law update
  31. California Privacy Protection Agency, CCPA regulations
  32. Greenberg Traurig, revised CCPA regulations effective 1 January 2026
  33. Hunton, CPPA finalises regulations on ADMT, risk assessments and audits
  34. California Privacy Protection Agency, Tractor Supply decision, September 2025
  35. California Attorney General, Healthline settlement, July 2025
  36. Clifford Chance, the first CCPA fine (Sephora), 2022
  37. Hintze Law, Disney CCPA settlement, February 2026
  38. Holland & Knight, PlayOn Sports fined $1.1M, March 2026
  39. California Privacy Protection Agency, Opt Me Out Act signed, October 2025
  40. European Parliament Legislative Observatory, Digital Omnibus summary
  41. Simmons & Simmons, Digital Omnibus update
  42. PPC Land, EU Council drops cookie signal article, 2026
  43. Tech Times, EU Council nears Digital Omnibus deal, September 2026
  44. European Parliament Legislative Train, Digital Fairness Act
  45. Press Information Bureau of India, DPDP Rules notified, November 2025
  46. Shardul Amarchand Mangaldas, enforcement of the DPDP Act and Rules
  47. Nouwens et al., Dark Patterns after the GDPR, CHI 2020
  48. Bielova et al., The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions, USENIX Security 2024
  49. Jha et al., Privacy Policies and Consent Management Platforms: Growth and Users' Interactions over Time, 2024
  50. Didomi, average consent rate in Europe (2026 benchmark)
  51. Didomi, consent rate by industry in Europe, 2026
  52. Didomi, best consent banner format in Europe, 2026
  53. Didomi, consent rate by device
  54. Google for Developers, consent mode overview
  55. Google Ads Help, updates to consent mode for EEA traffic
  56. Google Analytics Help, behavioural modeling for consent mode
  57. Google Ads Help, about consent mode modeling
  58. Google, conversion modeling through Consent Mode in Google Ads, April 2021
  59. Google Analytics Help, Consent Mode as the single control for data, 2026
  60. Microsoft Advertising, providing user consent signals by 5 May 2025
  61. Meta for Developers, Meta Pixel and GDPR
  62. Google AdSense Help, consent management requirements for the EEA, UK and Switzerland
  63. IAB Europe, transition to TCF v2.3
  64. Google for Developers, consent mode with server-side tagging
  65. Privacy Sandbox, update on plans for Privacy Sandbox technologies, October 2025
  66. Kameleoon Developers, consent management
  67. AB Tasty Docs, consent policy
  68. Optimizely Support, opt-in options for cookies and local storage
  69. Goldberg, Johnson and Shriver, Regulating Privacy Online: An Economic Evaluation of the GDPR, 2024
  70. Aridor, Che and Salz, The Effect of Privacy Regulation on the Data Industry: Empirical Evidence from GDPR
  71. Aridor et al., Evaluating the Impact of Privacy Regulation on E-Commerce Firms: Evidence from Apple's App Tracking Transparency
  72. Shopify, Customer Privacy API
  73. Shopify Help Center, customer privacy settings
  74. Shopware, cookie consent management
  75. Cisco, 2024 Consumer Privacy Survey
  76. Twilio, 2025 State of Customer Engagement Report
  77. Henkan & Partners, The Essential Guide to A/B Testing
  78. Henkan & Partners, Server-Side Google Tag Manager for E-commerce
  79. Henkan & Partners, The Essential Guide to Personalisation