Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Enforcement and Compliance

Cookie Banner Taskforce

Also known as: Cookie Banner Task Force, EDPB Cookie Banner Taskforce
Simply put

The Cookie Banner Taskforce is a group set up by the European Data Protection Board (EDPB) to help national data protection authorities respond to complaints about cookie banners in a more coordinated way. In January 2023 it published a report describing the issues it examined and offering guidance on what is generally expected of cookie banners and consent tools. Its work reflects the views of participating EU authorities rather than binding law, so specific outcomes may still depend on national interpretation.

Formal definition

The Cookie Banner Taskforce is an EDPB coordination body, reportedly established in September 2021, created to align the approaches of participating EU supervisory authorities in handling complaints concerning cookie banners and consent management practices. Its 18 January 2023 report, "Report of the work undertaken by the Cookie Banner Taskforce," set out common positions on minimum expectations for the transparency and design of cookie banners, addressing matters relevant to obtaining valid consent under the ePrivacy framework and the GDPR. The report expresses shared views and interpretive guidance from the taskforce rather than legally binding rules; enforcement and specific determinations remain the responsibility of individual national data protection authorities, and the evidence provided here does not detail the substantive requirements the report set out.

Why it matters

Cookie banners sit at the intersection of the ePrivacy framework, which governs the placing of and access to information on a user's device, and the GDPR, which governs any subsequent processing of personal data. Because complaints about banners have been filed across many EU member states, there was a risk that national data protection authorities would reach divergent conclusions on similar practices. The Cookie Banner Taskforce was created to reduce that fragmentation by helping participating EU supervisory authorities coordinate how they assess and respond to such complaints, which matters to organisations operating across multiple member states that need to anticipate how regulators may view their consent tools.

The Taskforce's January 2023 report is significant as a shared reference point on what participating authorities generally expect from cookie banners and consent management practices, particularly around transparency and design. For privacy officers and legal counsel, it offers insight into common interpretive positions that may inform enforcement, even though the report reflects the views of participating authorities rather than binding law. It is important to treat the report as guidance rather than a definitive rulebook, since specific outcomes can still turn on national interpretation and the facts of individual cases.

The evidence available here does not detail the substantive minimum requirements the report set out, so organisations should consult the report itself and relevant national guidance rather than rely on summary characterisations. Compliance decisions still require legal judgment applied to a specific banner, jurisdiction, and set of technologies, and the Taskforce's coordination does not replace the responsibility of individual authorities to make determinations.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for cookie consent programmes can use the Taskforce report as a reference for common expectations among participating EU authorities on banner transparency and design. Because the report reflects shared views rather than binding law, it should inform, but not substitute for, an assessment of applicable national guidance and the specific facts of a deployment.
Legal counsel and compliance teams
Lawyers advising on cookie consent across EU member states may find the Taskforce's coordination useful for anticipating how regulators could approach similar complaints. It remains important to note that enforcement and specific determinations sit with individual national authorities, and outcomes can still depend on national interpretation.
Web developers and marketing compliance teams
Teams that build and operate cookie banners and consent management tools can consult the report for guidance on transparency and design expectations relevant to obtaining valid consent under the ePrivacy framework and the GDPR. The evidence here does not detail the specific requirements, so implementation should be checked against the report itself and relevant authority guidance.
Organisations operating across multiple EU member states
Businesses that run websites or services in several member states are affected by the Taskforce's aim of reducing divergence in how authorities handle banner complaints. Coordination may help set common expectations, but organisations should not assume uniformity, as national interpretation can still shape specific outcomes.

Inside Cookie Banner Taskforce

Coordinated EDPB working group
The Cookie Banner Taskforce was a working group established under the European Data Protection Board to coordinate the response of national data protection authorities in the EU/EEA to complaints about non-compliant cookie banners. Its purpose was to promote a consistent approach rather than to issue binding law.
Origin in coordinated complaints
The taskforce was set up in response to a wave of complaints filed against numerous websites concerning their cookie consent interfaces. The complaints generally alleged that banner designs did not meet EU consent standards, though the specific outcomes for individual complaints fall outside the scope of this entry.
Focus on banner design practices
The taskforce examined recurring design patterns in cookie banners, such as the absence of a reject option at the same level as an accept option, the use of pre-ticked boxes, deceptive design or colour choices, and the classification of cookies. These practices are assessed against the GDPR requirement for consent that is freely given, specific, informed, and unambiguous, alongside the ePrivacy rules governing the placing of and access to information on a device.
Advisory, non-binding output
The taskforce worked toward a common position among participating authorities, but it did not create new legal obligations. Enforcement remains a matter for individual national supervisory authorities, and interpretations may continue to evolve.
Geographic scope
The taskforce operated within the EU/EEA framework combining the GDPR and national implementations of the ePrivacy Directive. Its work does not directly govern the UK or US state privacy regimes such as the CCPA and CPRA, which apply different standards and often rely on opt-out rather than opt-in.

Common questions

Answers to the questions practitioners most commonly ask about Cookie Banner Taskforce.

Is the Cookie Banner Taskforce's report legally binding on organizations that display cookie banners?
No. The Cookie Banner Taskforce was a coordination body established under the European Data Protection Board (EDPB) framework to promote a common approach among national data protection authorities responding to complaints about cookie banners. Its output typically takes the form of a report reflecting common denominators among participating authorities rather than binding law. Enforcement remains with individual national authorities, and their interpretations may differ. Treat the Taskforce's conclusions as an indication of regulatory thinking, not as a definitive legal standard that automatically applies in every EU jurisdiction.
Does the Taskforce address every aspect of cookie compliance, including the GDPR processing that follows consent?
Not necessarily. The Taskforce's work generally focused on specific, recurring design and practice issues raised in coordinated complaints about cookie banners, such as banner design patterns and how consent is presented or withdrawn. It should not be read as a comprehensive guide to all cookie-related obligations. In particular, the placing of and access to information on a device is governed by the ePrivacy Directive and its national implementations, while the subsequent processing of personal data is governed by the GDPR. A banner practice consistent with the Taskforce's observations does not, by itself, resolve every downstream GDPR obligation.
How should we treat the Taskforce's positions when designing a cookie banner across multiple EU member states?
Use the Taskforce's report as a baseline reflecting areas of convergence among participating authorities, but verify the position of each relevant national authority. Because the Taskforce reflected common denominators rather than a fully harmonized rule, individual authorities may apply stricter or differing expectations, and national ePrivacy implementations vary. Where you operate across several member states, it is generally advisable to document which authority's guidance you relied on for each design choice and to seek legal advice where positions diverge.
Can we rely on Taskforce commentary about specific banner design elements, such as reject options, to guide our own banner?
The Taskforce commented on recurring design questions raised in complaints, which can usefully inform your banner design. However, its observations should be read alongside the underlying legal requirement that consent under the GDPR be freely given, specific, informed, and unambiguous, and given through a clear affirmative action. Design choices should be assessed against those standards and against the applicable national implementation, not solely against Taskforce phrasing. Where the report leaves a question open or notes differing views among authorities, treat that as an unresolved area requiring your own legal judgment.
Does aligning our consent management platform (CMP) with Taskforce observations make our banner compliant?
No tool or configuration guarantees compliance. A CMP can help implement and record consent choices in line with regulatory expectations, including those reflected in the Taskforce's report, but it does not replace a legal assessment of whether your specific banner meets the applicable ePrivacy and GDPR requirements in each jurisdiction where you operate. Configuration decisions, the categories of cookies and similar technologies in scope, and your consent records all require review beyond simply adopting a CMP template.
How does the Taskforce's work relate to cookie practices outside the EU, such as under US state privacy laws?
The Taskforce operated within the EU regulatory framework, so its observations address EU cookie consent expectations and do not govern practices under other regimes. Requirements differ elsewhere; for example, several US state privacy laws such as those in California often rely on an opt-out model rather than the prior opt-in consent generally expected in EU jurisdictions. If you serve users across multiple regions, you should not assume the Taskforce's conclusions extend to those other regimes and should assess each applicable framework separately.

Common misconceptions

The Cookie Banner Taskforce issued binding rules that all EU websites must follow.
The taskforce was a coordination mechanism among data protection authorities intended to encourage a consistent approach. It did not itself create binding law; legal obligations flow from the GDPR and national ePrivacy implementations, and enforcement rests with individual national authorities whose positions may differ.
The taskforce's positions apply worldwide to any cookie banner.
The taskforce operated within the EU/EEA context and does not govern jurisdictions such as the UK or US states. Requirements differ elsewhere, with several US state laws relying on opt-out mechanisms rather than the opt-in, affirmative-action consent standard emphasised in the EU.
Following the design patterns discussed by the taskforce guarantees that a banner is compliant.
Addressing the practices examined by the taskforce may reduce risk, but compliance depends on the full context of a site's data processing and the interpretation of the competent authority. Design guidance supports compliance but does not replace legal judgment, and unresolved interpretive questions remain.

Best practices

Offer users a clear way to reject non-essential cookies that is as easy to find and use as the option to accept, since imbalanced choices are among the practices the taskforce scrutinised in the EU/EEA context.
Avoid pre-ticked boxes and reliance on implied consent from continued browsing, as these generally do not meet the GDPR standard of consent given through a clear affirmative action.
Ensure only strictly necessary cookies are set before consent, and obtain prior consent for analytics, advertising, and functional cookies, as well as comparable technologies such as pixels, local storage, SDKs, and fingerprinting.
Review banner design for deceptive patterns, such as misleading colour contrast or wording, that could undermine whether consent is freely given and informed.
Maintain records of consent to support accountability, while recognising that logging supports compliance but does not by itself establish that consent was valid.
Confirm the geographic scope of your obligations and tailor consent mechanisms accordingly, since the EU/EEA approach reflected in the taskforce's work differs from UK requirements and from opt-out-based US state regimes such as the CCPA and CPRA.
Promotional banner for the Penetration Report Template Kit