Skip to main content
The state of ai impact assessment
Category: Consent Interfaces

Continue Without Accepting

Also known as: Continue Without Accepting Cookies, Reject and Continue
Simply put

"Continue Without Accepting" is a button or link on a cookie consent banner that lets you use a website without agreeing to non-essential cookies. Clicking it generally means the site will not set optional cookies, such as those used for analytics or advertising, though the site may still use cookies that are strictly necessary for it to function. Some websites may behave differently or work less fully depending on how they are built.

Formal definition

"Continue Without Accepting" refers to a consent-banner control that allows a user to proceed to a website while declining consent to non-essential cookies and similar technologies (for example analytics, advertising, and functional cookies, as well as pixels, local storage, or SDKs subject to the same rules). It is frequently presented as an interface mechanism intended to give a refusal option that is as accessible as an "Accept All" option, addressing the concern that unequal prominence between accepting and rejecting may undermine consent that is freely given. Under EU frameworks, valid consent must be freely given, specific, informed, and unambiguous through a clear affirmative action; a "Continue Without Accepting" control is generally treated as an expression of refusal rather than consent, and typically only strictly necessary cookies (which are generally exempt from consent under the ePrivacy Directive as implemented nationally) should be placed after it is used. The evidence packet does not establish uniform technical behavior, DPA guidance on banner design, or the treatment of this control outside the EU (including under UK rules or US state privacy laws such as the CCPA/CPRA, which often rely on opt-out mechanisms); whether any specific implementation satisfies legal requirements depends on facts and jurisdiction-specific interpretation not covered here.

Why it matters

The way a cookie banner presents its choices directly affects whether any consent it collects can be considered valid. Under EU frameworks, consent must be freely given, specific, informed, and unambiguous, and a common concern is that giving an "Accept All" button far greater prominence than a refusal option may undermine the "freely given" requirement. A "Continue Without Accepting" control is often introduced precisely to offer a refusal path that is as accessible as acceptance, so that users are not effectively steered toward consenting simply because rejecting is harder to find or requires more clicks.

The control also matters because of what should happen after it is clicked. It is generally treated as an expression of refusal rather than consent, which means that in most EU jurisdictions only strictly necessary cookies (generally exempt from consent under the ePrivacy Directive as implemented nationally) should be set once a user chooses it. Optional cookies such as those used for analytics or advertising should not follow. The commercial incentive to obtain broad consent is real, since data tied to advertising can be valuable, and this incentive is part of why the balance and behavior of consent controls attracts scrutiny.

For users and site operators alike, behavior is not uniform. Some sites may function fully after a refusal, while others may work less completely depending on how they were built, and simply clicking out of a banner without making a choice can leave a site behaving unpredictably. Because the evidence here does not establish standardized technical behavior or specific regulatory guidance on banner design, whether any given implementation is compliant depends on facts and jurisdiction-specific interpretation.

Who it's relevant to

Privacy officers and data protection professionals
This control is central to assessing whether a consent banner treats acceptance and refusal with comparable prominence, a factor relevant to whether consent is freely given under EU frameworks. Professionals should verify that clicking it results in optional cookies not being set, though whether a specific design meets legal requirements depends on jurisdiction-specific interpretation not settled by the evidence here.
Web developers and engineers
Developers implement the logic that determines what happens after a user selects "Continue Without Accepting," including ensuring only strictly necessary cookies are placed and that the site remains usable. Because behavior can vary by implementation and some sites work less fully after refusal, testing the refusal path is important, but technical implementation alone does not resolve legal compliance questions.
Legal counsel and compliance teams
Counsel advising on banner design need to consider whether the control functions as a genuine, accessible refusal option consistent with EU consent standards. The evidence does not cover how this control is treated under UK rules or US state privacy laws such as the CCPA/CPRA, which often rely on opt-out mechanisms, so scope and jurisdiction should be assessed case by case.
Marketing and analytics teams
Teams relying on analytics or advertising cookies should understand that users who choose this control are declining those technologies, which affects data collection. While there is a commercial incentive to maximize acceptance, steering users away from a fair refusal option raises the concern that resulting consent may not be freely given.

Inside Continue Without Accepting

Reject option parity
A 'Continue Without Accepting' mechanism is intended to give users the ability to decline non-essential cookies as easily as they can accept them. Several EU data protection authorities have taken the position that the option to refuse should be presented with comparable prominence and require no more effort than the option to consent, though the precise design expectations can vary between jurisdictions and evolving guidance.
Relationship to valid consent
The presence of a clear refusal path supports the requirement under the GDPR that consent be freely given, since users must have a genuine choice to decline non-essential processing without detriment. It relates to the placing of and access to information on the user's device governed by the ePrivacy Directive and its national implementations, as well as any subsequent personal data processing governed by the GDPR.
Effect on cookie placement
When a user selects a refusal option, non-essential cookies and similar technologies (such as pixels, local storage, SDKs, and fingerprinting) generally should not be set. Strictly necessary or essential cookies may continue to operate because they are typically exempt from consent under EU law.
Interaction with the consent banner design
This mechanism is usually implemented as a button or link within a first-layer cookie banner. It is one design element among others, such as accept-all buttons and granular preference controls, and its wording and placement are commonly scrutinised as part of the overall assessment of whether consent is freely given, specific, informed, and unambiguous.
Geographic and legal scope
The relevance of a 'Continue Without Accepting' option is most pronounced in the EU and, comparably, the UK, where opt-in consent for non-essential cookies is generally required. Under many US state privacy frameworks that rely on opt-out mechanisms rather than opt-in, the design considerations differ, so this concept should not be treated as a universal requirement.

Common questions

Answers to the questions practitioners most commonly ask about Continue Without Accepting.

Does offering a 'Continue Without Accepting' option automatically make my cookie banner compliant?
No. A 'Continue Without Accepting' option addresses one common criticism of cookie banners, namely that rejecting cookies should be as easy as accepting them, which several EU data protection authorities have emphasized. However, providing this option does not by itself guarantee compliance. The banner must still meet the broader standard for valid consent under the GDPR (freely given, specific, informed, and unambiguous) and the requirements of the applicable ePrivacy rules, and it must handle the actual placing of and access to cookies correctly. Whether a given implementation is compliant depends on the full design, the information provided, and how consent choices are respected and logged. Tools and design patterns support compliance but do not replace legal judgment, and enforcement positions continue to evolve.
Does clicking 'Continue Without Accepting' mean the user has consented to non-essential cookies?
Generally no, at least in most EU jurisdictions. 'Continue Without Accepting' is typically intended to signal that the user declines consent to non-essential cookies (such as analytics, advertising, and certain functional cookies) while still being able to use the site. Treating a user's decision to continue without accepting as if it were consent would run counter to the GDPR requirement for a clear affirmative action and to the widely held view that implied consent from continued browsing is not valid in the EU. Strictly necessary or essential cookies may still be set because they are generally exempt from consent. The precise meaning depends on how the option is labeled and configured, and requirements differ under other frameworks, such as US state privacy laws that often rely on an opt-out model.
Where should the 'Continue Without Accepting' option be placed on the banner?
As a practical matter, many organizations place a 'Continue Without Accepting' or equivalent reject option at the same level of prominence as the accept option, typically on the first layer of the banner. Several EU data protection authorities have stressed that rejecting cookies should be as easy as accepting them, which in practice tends to mean an equally visible and accessible control rather than one buried in a secondary menu. The exact placement that will satisfy a given authority is not fixed by this definition, and expectations vary by jurisdiction and evolve over guidance, so the specific layout should be assessed against current local guidance and legal advice.
What should happen technically when a user selects 'Continue Without Accepting'?
In a typical implementation, selecting this option should prevent non-essential cookies and similar technologies (including pixels, local storage entries, SDKs, and fingerprinting techniques, which fall within the same consent rules even though they are not literally cookies) from being placed or accessed. Only strictly necessary cookies, which are generally exempt from consent, should be set. The consent management platform should also record the user's choice so that non-essential tags and scripts remain blocked until and unless consent is later given. The specific behavior depends on how the CMP and tag management are configured, and this definition does not prescribe a particular technical architecture.
Should a user's selection of 'Continue Without Accepting' be logged?
Recording a user's cookie choice, including a decision to continue without accepting, is generally consistent with the record-keeping and accountability expectations associated with consent management, particularly in the EU where controllers are expected to be able to demonstrate the basis on which cookies were or were not set. In practice, consent management platforms often log the choice, its timestamp, and the configuration presented. The precise scope of any logging obligation depends on the applicable legal regime and on facts not covered by this definition, and organizations should confirm requirements against current guidance rather than assume a single standard applies everywhere.
How does 'Continue Without Accepting' interact with US opt-out frameworks like those in California?
The 'Continue Without Accepting' pattern is most closely associated with EU-style opt-in consent, where non-essential cookies should not be set before the user takes a clear affirmative action. Under several US state privacy laws, such as the CCPA and CPRA in California, the model often relies on opt-out rather than opt-in, and may focus on mechanisms such as respecting Global Privacy Control signals and offering the ability to opt out of certain sale or sharing of personal information. A single banner may need to accommodate different requirements depending on where the user is located. This definition does not resolve how any specific multi-jurisdiction banner should be configured, and such design choices should be made with reference to the applicable frameworks and legal advice.

Common misconceptions

Adding a 'Continue Without Accepting' button automatically makes a cookie banner compliant.
No single design element or tool guarantees compliance. The option supports the requirement that consent be freely given, but compliance depends on the banner as a whole, the categories of cookies used, accurate information provided, proper suppression of non-essential technologies on refusal, and the applicable legal regime. A consent management platform can facilitate this but does not replace legal judgment.
Clicking 'Continue Without Accepting' means no cookies at all are placed.
Selecting refusal generally prevents non-essential cookies and similar technologies from being set, but strictly necessary or essential cookies may still operate because they are typically exempt from consent under EU law.
The refusal option is required in the same way everywhere.
The emphasis on an easily accessible refusal path is most closely associated with EU and UK expectations around opt-in consent. Many US state frameworks such as the CCPA and CPRA rely on opt-out approaches, so obligations and appropriate design differ by jurisdiction, and authority guidance on prominence and equivalence continues to evolve.

Best practices

Present the refusal option with prominence and effort comparable to the accept option, in line with the position taken by several EU data protection authorities that declining should be as easy as consenting.
Ensure that when a user declines, non-essential cookies and similar technologies (pixels, local storage, SDKs, fingerprinting) are not set, while limiting continued operation to strictly necessary or essential cookies.
Assess the banner as a whole against the standard that consent be freely given, specific, informed, and unambiguous, rather than relying on the refusal button alone as evidence of compliance.
Tailor the mechanism to the applicable legal regime, recognising that opt-in expectations in the EU and UK differ from opt-out approaches under many US state privacy laws, and document the geographic scope of your configuration.
Use a consent management platform to support implementation and consent record-keeping, but treat its output as a support for compliance and confirm design choices with legal judgment rather than assuming any tool guarantees lawfulness.
Monitor evolving guidance from relevant data protection authorities, since positions on the prominence and wording of refusal options continue to develop and may require design updates over time.
Promotional banner for the Penetration Report Template Kit