First Layer
In cookie consent, the 'first layer' is the initial screen or banner a user sees when they arrive on a website, before any non-essential cookies are set. It typically presents a short summary of what cookies are used and the main choices, such as accepting or rejecting, with the option to view more detail on a further layer. It is part of a 'layered' approach to giving people information about cookies, and should not be confused with the unrelated 3D-printing term of the same name.
The first layer is the top-level component of a layered (multi-tiered) information and consent interface used to inform users about the placing of, and access to, cookies and similar technologies on their device and to obtain any consent required. In EU practice, the first layer generally carries the core notice and the primary consent controls, while additional detail (for example, purpose-by-purpose descriptions, vendor lists, and retention information) may be provided on subsequent layers. The device-access aspect is governed by the ePrivacy Directive as implemented in national law, while any processing of personal data that follows is governed by the GDPR; consent obtained at the first layer must, where the GDPR applies, meet the standard of being freely given, specific, informed, and unambiguous through a clear affirmative action. Data protection authorities and the EDPB have scrutinised first-layer design in particular, for example, whether a means to refuse non-essential cookies is presented at the same level as the means to accept them, though specific enforcement positions vary by jurisdiction and continue to evolve. This entry describes the concept of the first layer as a design and compliance construct; it does not prescribe a definitive layout that is lawful in all jurisdictions, and requirements differ between the EU, the UK, and US state regimes (which often rely on opt-out mechanisms rather than the EU's prior opt-in model). The precise adequacy of any given first layer depends on facts not covered by this definition and on current regulatory guidance.
Why it matters
The first layer is the moment where cookie compliance either succeeds or fails, because it is the interface most users actually see and interact with. Under EU practice, the design of this initial screen determines whether any consent obtained can meet the GDPR standard of being freely given, specific, informed, and unambiguous. Data protection authorities and the European Data Protection Board have paid particular attention to first-layer design, for example, examining whether a means to refuse non-essential cookies is presented at the same level as the means to accept them. A first layer that makes acceptance easy while burying or omitting the option to reject risks being treated as failing to obtain valid consent.
Who it's relevant to
Inside First Layer
Common questions
Answers to the questions practitioners most commonly ask about First Layer.

