Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Consent Interfaces

First Layer

Also known as: First-Layer Notice, Top Layer of a Cookie Banner, Initial Consent Layer
Simply put

In cookie consent, the 'first layer' is the initial screen or banner a user sees when they arrive on a website, before any non-essential cookies are set. It typically presents a short summary of what cookies are used and the main choices, such as accepting or rejecting, with the option to view more detail on a further layer. It is part of a 'layered' approach to giving people information about cookies, and should not be confused with the unrelated 3D-printing term of the same name.

Formal definition

The first layer is the top-level component of a layered (multi-tiered) information and consent interface used to inform users about the placing of, and access to, cookies and similar technologies on their device and to obtain any consent required. In EU practice, the first layer generally carries the core notice and the primary consent controls, while additional detail (for example, purpose-by-purpose descriptions, vendor lists, and retention information) may be provided on subsequent layers. The device-access aspect is governed by the ePrivacy Directive as implemented in national law, while any processing of personal data that follows is governed by the GDPR; consent obtained at the first layer must, where the GDPR applies, meet the standard of being freely given, specific, informed, and unambiguous through a clear affirmative action. Data protection authorities and the EDPB have scrutinised first-layer design in particular, for example, whether a means to refuse non-essential cookies is presented at the same level as the means to accept them, though specific enforcement positions vary by jurisdiction and continue to evolve. This entry describes the concept of the first layer as a design and compliance construct; it does not prescribe a definitive layout that is lawful in all jurisdictions, and requirements differ between the EU, the UK, and US state regimes (which often rely on opt-out mechanisms rather than the EU's prior opt-in model). The precise adequacy of any given first layer depends on facts not covered by this definition and on current regulatory guidance.

Why it matters

The first layer is the moment where cookie compliance either succeeds or fails, because it is the interface most users actually see and interact with. Under EU practice, the design of this initial screen determines whether any consent obtained can meet the GDPR standard of being freely given, specific, informed, and unambiguous. Data protection authorities and the European Data Protection Board have paid particular attention to first-layer design, for example, examining whether a means to refuse non-essential cookies is presented at the same level as the means to accept them. A first layer that makes acceptance easy while burying or omitting the option to reject risks being treated as failing to obtain valid consent.

Who it's relevant to

Privacy and Data Protection Officers
First-layer design sits at the centre of demonstrating that consent meets the GDPR standard where it applies, and that device-access rules under the ePrivacy Directive as implemented nationally are respected. DPOs generally need to review whether the initial screen presents refusal options fairly alongside acceptance, mindful that specific enforcement positions vary by jurisdiction and continue to evolve.
Web Developers and UX Designers
Those building consent interfaces implement the first layer as the top tier of a layered approach, deciding what summary information and controls appear before non-essential cookies are set and what detail is deferred to later layers. The precise adequacy of any given layout depends on facts not covered by a general definition and on current regulatory guidance.
Legal Counsel and Compliance Teams
Legal teams assess whether a first layer supports a defensible compliance position, recognising that requirements differ between the EU, the UK, and US state regimes, the latter often relying on opt-out mechanisms rather than the EU's prior opt-in model. First-layer design is a construct that supports compliance but does not, on its own, guarantee it.

Inside First Layer

First layer of a cookie banner
The initial notice or interface a user encounters when arriving on a website, before any non-essential cookies or similar technologies are placed. In the layered-information approach commonly discussed in EU practice, the first layer presents the most essential information and controls, while further detail is provided in subsequent layers reachable through links or expandable sections.
Layered-information approach
A method of presenting transparency information in stages rather than all at once. The first layer surfaces key points concisely, and deeper layers provide the fuller detail required to meet the informed element of consent under the GDPR and transparency expectations under the ePrivacy regime. This approach is a design pattern, not a legal safe harbour.
Core consent controls
The action buttons or mechanisms typically expected on the first layer. Guidance from certain EU data protection authorities and coordinated bodies has scrutinised whether an option to reject or decline non-essential cookies should appear on the same first layer as the option to accept. This remains an area shaped by evolving supervisory positions and may differ between jurisdictions.
Essential transparency information
The minimum information many EU authorities expect on the first layer, which may include the identity of the party placing cookies, the purposes, and how to accept or refuse. The exact expected content is not uniform across jurisdictions and depends on national implementations of the ePrivacy Directive and applicable guidance.
Relationship to the underlying legal regimes
The first layer is an interface element, not a legal category in itself. The placing of and access to information on the user's device is governed by the ePrivacy Directive and its national implementations, while any subsequent processing of personal data is governed by the GDPR. First-layer design supports compliance with both but does not by itself satisfy either.

Common questions

Answers to the questions practitioners most commonly ask about First Layer.

Does the first layer of a cookie banner need to show only an 'Accept' button, or must it also offer a way to refuse?
The first layer should not present acceptance as the only immediately available choice. Guidance from several EU data protection authorities and coordinated work at the EDPB level has criticised banners that offer an 'accept' option on the first layer while requiring users to move to a further layer to refuse. In most EU jurisdictions the expectation is that refusing should be as accessible as accepting, which many authorities interpret as requiring a reject or equivalent control on the same layer. This remains an area where supervisory authority positions and enforcement continue to develop, and the precise design that satisfies regulators may vary by country and over time.
Is the first layer the only notice a user needs to see to give valid consent?
No. The first layer is one part of a layered-information approach, not the complete disclosure. It typically presents concise, high-level information and the primary choices, while more detailed information, such as the specific categories of cookies and similar technologies, their purposes, retention, and any third parties, is generally provided on subsequent layers or a linked policy. For consent to be valid under the GDPR it must be informed, so the information across all layers taken together must be sufficient. A first layer alone, without accessible further detail, is unlikely to meet the informed standard in most EU jurisdictions.
What information is generally expected on the first layer of a cookie banner?
Practice in most EU jurisdictions is for the first layer to convey the essential points a user needs to make an initial decision, typically including the identity of the controller, a plain description that cookies or similar technologies are used, the broad purposes involved, and the primary choices available. Because valid consent under the GDPR must be specific and informed, the first layer usually links to further layers or a policy for granular detail. The exact contents that satisfy regulators can differ between the EU, the UK, and other regimes, and authority guidance evolves, so this should be treated as general practice rather than a fixed checklist.
Should the accept and reject controls on the first layer look the same?
Many EU data protection authorities have raised concerns about designs that make accepting visually prominent while making refusal harder to notice or use, treating this as a potential deceptive-design or 'dark pattern' issue that can undermine whether consent is freely given. As a general matter, presenting choices with comparable prominence and effort tends to align better with the expectation that consent be freely given and unambiguous. This is a design-and-facts question rather than a rule with a single lawful answer, and specific expectations differ by jurisdiction and remain subject to evolving guidance.
Can non-essential cookies be set while the first layer is still displayed and before the user has chosen?
Under the ePrivacy rules as implemented in most EU jurisdictions, non-essential cookies and similar technologies (including pixels, local storage, SDKs, and comparable identifiers) generally require prior consent, meaning they should not be placed or read while the first layer is shown and the user has not yet made an affirmative choice. Strictly necessary or essential cookies are generally exempt from this consent requirement. Requirements differ under some US state privacy laws, which often rely on an opt-out model rather than prior opt-in, so the timing of when tracking may operate depends on the applicable regime.
How does the first layer relate to a consent management platform (CMP) and consent record-keeping?
A CMP is commonly used to display the first layer and subsequent layers, to capture the user's choice, and to record it. The first layer is the user-facing interface, while the CMP handles the technical and organisational functions behind it, including logging what the user was shown and consented to, which supports the ability to demonstrate consent that controllers are generally expected to maintain. It is important to note that using a CMP or a particular consent framework supports compliance but does not by itself guarantee it; legal judgment about configuration, disclosures, and the applicable jurisdiction's requirements remains necessary.

Common misconceptions

If the first layer displays a cookie notice, consent has been validly obtained.
Merely displaying a first-layer notice does not constitute valid consent. Under the GDPR, consent must be freely given, specific, informed, and unambiguous through a clear affirmative action. Continued browsing, pre-ticked boxes, or a notice with no genuine choice are widely considered non-compliant in most EU jurisdictions. Requirements differ under frameworks such as certain US state privacy laws, which often rely on opt-out mechanisms.
The first layer only needs an 'Accept' button; rejection can be hidden in deeper layers.
Several EU supervisory authorities and coordinated bodies have scrutinised banners that offer acceptance on the first layer while making rejection harder to reach. The prevailing expectation in much of the EU is that refusing non-essential cookies should be as accessible as accepting, though specific positions vary by jurisdiction and continue to evolve.
First-layer rules are the same everywhere.
Expectations for first-layer content and controls vary between the EU, the UK, and individual US states, and depend on national implementations and authority guidance. What is expected under the ePrivacy regime in the EU should not be assumed to apply under, for example, the CCPA or CPRA in California.

Best practices

Present the essential information and the core choices on the first layer, and use deeper layers only for supplementary detail, so users are not required to navigate away to make a basic decision.
Where EU law applies, consider offering an option to refuse non-essential cookies with the same prominence and ease as the option to accept, reflecting the direction of supervisory guidance in most EU jurisdictions.
Do not place non-essential cookies or similar technologies (including pixels, local storage, SDKs, or fingerprinting) before the user gives valid consent through a clear affirmative action.
Adapt the first layer to the applicable jurisdiction, recognising that opt-in expectations in the EU differ from the opt-out approaches common under certain US state privacy laws.
Maintain records of the consent choices captured through the first layer to support consent logging and record-keeping obligations, keeping in mind that a consent management platform supports but does not guarantee compliance.
Review first-layer design periodically against current guidance from relevant data protection authorities, since enforcement positions and expectations continue to evolve and may not be uniform across regimes.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.