Skip to main content
The state of ai impact assessment
Category: Consent Interfaces

Layered Notice

Also known as: Layered Privacy Notice, Layered Approach to Privacy Information, Multi-tiered Notice
Simply put

A layered notice is a way of presenting privacy information in stages rather than in one long document. It starts with a short summary of the most important points, such as who is collecting the data and how it will be used, and then lets people click through to more detailed explanations if they want them. The aim is to make privacy information easier to read and understand while still providing the full detail somewhere.

Formal definition

A layered notice is a multi-tiered method of delivering privacy information in which disclosures are structured across two or more levels, with a concise top layer presenting key information (for example, controller identity and core purposes of processing) and subsequent layers providing progressively fuller detail. UK ICO guidance describes this as a way to satisfy transparency obligations under the UK GDPR right to be informed, and equivalent approaches are commonly used to support the transparency and information requirements under the EU GDPR. Practitioner guidance (for example, from the IAPP) emphasizes that an effective layered notice is not merely a set of nested webpages; the design and layout of the first layer must genuinely convey the essential information rather than simply linking onward. In the cookie consent context, layered notices may be used to present cookie-related information at the point of consent, but this definition addresses the notice structure itself and does not, on its own, establish whether valid consent has been obtained under the ePrivacy rules governing access to and storage of information on a device, nor does it determine compliance with any specific jurisdiction's requirements. The precise content and adequacy of each layer depend on the applicable legal regime and the facts of the processing, and remain matters of legal judgment.

Why it matters

Privacy notices have long faced a practical dilemma: comprehensive disclosures tend to be long and dense, which can undermine the very transparency they are meant to deliver. A layered notice responds to this by presenting the most important information first, in a concise top layer, while making fuller detail available for those who want it. This structure supports the transparency and information obligations that apply under the EU GDPR and the equivalent right to be informed under the UK GDPR, where individuals are expected to understand who is processing their data and for what purposes.

For cookie consent specifically, layered notices are commonly used to surface cookie-related information at the point where consent is sought, allowing a short first-level explanation to be paired with access to more granular detail. It is important to be clear about the limits of this design, however. A well-structured layered notice addresses how information is presented; it does not, by itself, establish that valid consent has been obtained under the ePrivacy rules that govern the storage of and access to information on a user's device, nor does it resolve whether any particular jurisdiction's requirements have been met.

As UK ICO guidance and practitioner commentary from the IAPP emphasize, the effectiveness of a layered notice depends on execution rather than structure alone. An effective layered notice is not simply a set of nested webpages; the design and layout of the first layer must genuinely convey the essential information rather than merely linking onward. Where the top layer fails to communicate key points, the layered approach may not adequately support transparency obligations, and the adequacy of each layer remains a matter of legal judgment tied to the facts of the processing and the applicable legal regime.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for transparency compliance use layered notices to satisfy the information obligations under the EU GDPR and the right to be informed under the UK GDPR. They need to ensure the top layer genuinely conveys key information rather than simply linking onward, and should treat the adequacy of each layer as a matter of legal judgment tied to the applicable regime and the facts of the processing.
Legal counsel
Counsel advising on privacy notice structure should recognize that a layered approach addresses how information is presented, not whether valid consent has been obtained under the ePrivacy rules governing access to and storage of information on a device. They also need to account for how requirements differ across jurisdictions such as the EU, the UK, and individual US states.
Web developers and UX designers
Those implementing notices must design the first layer so its layout genuinely communicates the essential points, since, as IAPP guidance notes, an effective layered notice is not merely a set of nested webpages. In the cookie context, developers may present cookie-related information at the point of consent through a layered structure.
Marketing compliance teams
Teams managing cookie and tracking disclosures may rely on layered notices to surface cookie-related information concisely at the point of consent. They should understand that the notice structure alone does not establish that valid consent has been obtained or that a specific jurisdiction's requirements are met.

Inside Layered Notice

First layer (short notice)
A concise, prominent summary presented at the point of first interaction, typically within a cookie banner. It generally identifies that cookies or similar technologies are used, the broad purposes involved, and provides immediate access to controls such as accept, reject, and manage-preferences options.
Second layer (detailed notice)
A fuller explanation, often reached via a link or preference center, that describes the categories of cookies and similar technologies in more detail, their purposes, typical durations, and third parties involved. This layer supports the informed element of consent by making granular information available without overwhelming the initial interaction.
Granular controls
Mechanisms allowing users to accept or reject specific categories or purposes rather than an all-or-nothing choice. In most EU jurisdictions, non-essential categories such as analytics and advertising generally require prior consent, while strictly necessary cookies are typically exempt and may be presented as always active.
Links to further information
References to a full cookie policy or privacy policy, which may sit as a further layer, providing comprehensive detail relevant to obligations under the ePrivacy rules governing device storage and access and, where personal data is processed, under the GDPR.
Scope indicators
Contextual signals about which legal regime and controls apply, since layered notices are frequently adapted to the user's location. Requirements and default states may differ between the EU, the UK, and individual US states such as under the CCPA and CPRA.

Common questions

Answers to the questions practitioners most commonly ask about Layered Notice.

Does a layered notice let me hide the details users need in order to give informed consent?
No. A layered notice is a presentation technique, not a way to withhold required information. The purpose is to surface key points in a concise first layer while making the fuller detail readily accessible in subsequent layers. For consent to be valid under the GDPR it must be informed, which generally means users can access clear information about the categories of cookies, their purposes, and relevant parties before or at the point they decide. Layering the presentation does not reduce what must ultimately be disclosed; it organizes it. If essential information is buried so deeply that a reasonable user would not find it, the informed element of consent may be undermined.
Is having a layered notice enough to make my cookie banner compliant?
Not on its own. A layered notice addresses how information is structured and presented, but compliance depends on more than presentation. In most EU jurisdictions, valid consent must still be freely given, specific, informed, and unambiguous through a clear affirmative action, non-essential cookies must not be set before consent, and there must typically be a way to refuse as easily as to accept. Requirements also differ across the EU, the UK, and individual US state regimes, some of which rely on opt-out rather than opt-in. A layered notice can support these obligations but does not by itself satisfy them, and it is not a substitute for legal judgment about the specific processing involved.
What information typically belongs in the first layer versus the deeper layers?
There is no single mandated split, and practice varies, but a common approach places concise, high-level information in the first layer and the fuller detail in subsequent layers. The first layer often summarizes that cookies or similar technologies are used, the broad purposes involved, and the choices available, together with a clear route to accept, refuse, or manage preferences. Deeper layers may set out the specific categories of cookies, their purposes, retention periods, and the parties involved. Because the informed element of consent depends on users being able to access what they need before deciding, teams should confirm that key information is genuinely reachable rather than only technically present. The precise allocation should be assessed against applicable guidance in the relevant jurisdiction.
How should a layered notice handle technologies that are not literally cookies, such as pixels, local storage, SDKs, or fingerprinting?
These technologies generally fall within the same rules that govern cookies where they involve storing or accessing information on a user's device, so a layered notice should not silently omit them. The first layer can describe the use of cookies and similar technologies in broad terms, while deeper layers identify the specific mechanisms where that helps users understand what is happening. Framing the disclosure around cookies alone risks misrepresenting the actual tracking in place. The appropriate level of detail depends on the technologies used and the applicable legal regime, and teams should map their actual technologies before deciding how to present them.
How does a layered notice interact with a consent management platform (CMP)?
A CMP is often the tool that renders the layered notice, records the user's choices, and controls whether non-essential technologies fire based on those choices. The layered structure typically corresponds to the CMP's interface layers, such as an initial banner, a preferences or settings view, and links to a fuller policy. However, a CMP supports compliance rather than guaranteeing it: the accuracy of the categories, purposes, and parties shown depends on how the CMP is configured and on the underlying technical mapping of what actually runs on the site. Teams should verify that what the layered notice presents matches the CMP's actual behavior, including that consent is logged and honored.
Should the same layered notice be used across the EU, the UK, and US states?
Not necessarily. While the layering technique can be reused, the substance and mechanics often need to differ by jurisdiction. In most EU jurisdictions and in the UK, non-essential cookies generally require prior consent through an affirmative action before they are set, whereas several US state regimes commonly rely on an opt-out model and may recognize signals such as Global Privacy Control. This can affect what the first layer says, what choices it offers, and whether technologies fire before a choice is made. Because obligations and enforcement positions vary and continue to evolve, the appropriate configuration should be determined per applicable regime rather than assuming one notice fits all.

Common misconceptions

A layered notice by itself satisfies all consent requirements.
A layered notice is a presentation technique that supports the informed element of consent. It does not, on its own, guarantee compliance. In most EU jurisdictions valid consent must also be freely given, specific, and unambiguous through a clear affirmative action, and the ePrivacy rules on device access and the GDPR rules on any resulting personal data processing must each be addressed. Practices such as pre-ticked boxes, implied consent, or cookie walls are widely regarded as non-compliant in the EU regardless of how the notice is layered.
The short first layer can stand alone without deeper information.
The first layer is intended to be a summary that links to more detailed layers. Providing only a brief banner without accessible granular detail may undermine the informed standard expected in most EU jurisdictions, where users are generally expected to be able to understand the categories, purposes, and third parties involved before consenting.
A single layered notice works identically everywhere.
Cookie consent obligations vary by jurisdiction. The EU and UK generally rely on prior opt-in consent for non-essential technologies, while several US state frameworks often operate on an opt-out basis. A layered notice frequently needs to be adapted, including its default states and available controls, to reflect the applicable regime and the user's location.

Best practices

Ensure the first layer clearly states that cookies and similar technologies (including pixels, local storage, SDKs, and fingerprinting where relevant) are used and provides equally accessible accept, reject, and manage-preferences options.
Use the second layer to describe categories, purposes, typical durations, and third parties in enough detail to meet the informed standard generally expected in EU and UK contexts, and link to the full cookie or privacy policy.
Provide granular controls so users can consent to specific purposes; treat only strictly necessary cookies as exempt and avoid pre-ticked boxes, implied consent, or cookie walls in EU-facing implementations.
Adapt the notice and its default settings to the user's jurisdiction, recognizing that opt-in generally applies in the EU and UK while several US states such as under the CCPA and CPRA often rely on opt-out, and honor signals such as Global Privacy Control where applicable.
Keep the technical and organizational elements aligned by configuring your consent management platform to reflect the choices offered in the notice and to maintain consent logs, while remembering that tools support but do not replace legal judgment.
Review the layered notice periodically against evolving data protection authority guidance and enforcement positions, and involve legal counsel to confirm that presentation, defaults, and record-keeping remain appropriate for each relevant regime.
Application Security Isn’t Optional Anymore.