Skip to main content
The state of ai impact assessment
Category: Consent Metrics

Rejection Rate

Simply put

In the cookie consent context, rejection rate generally refers to the share of users who decline cookies or tracking when presented with a consent banner or preference interface. It is commonly used alongside acceptance rate to understand how visitors respond to consent requests. Note: the evidence provided does not contain sources specific to cookie consent, so this definition reflects the general concept of a rejection rate applied to consent management rather than an authoritative cookie-specific source.

Formal definition

Rejection rate is typically calculated as the proportion of consent interactions in which a user declines some or all non-essential cookies or tracking technologies (for example, by clicking a 'Reject All' or equivalent control), out of the total set of eligible consent interactions over a defined period. In EU and UK contexts, where valid consent under the GDPR must be freely given, specific, informed, and unambiguous and reject options are generally expected to be as accessible as accept options, rejection rate can serve as an operational signal for how a consent management platform (CMP) is performing, though it is not itself a measure of legal compliance. The precise measurement depends heavily on definitional choices, such as whether partial rejections, banner dismissals, non-interactions, or expired consents are counted, and whether the metric is scoped per cookie category, per signal (such as Global Privacy Control), or across an entire session. Important limitation: the supplied evidence covers rejection-rate concepts from unrelated domains (recruitment, biometrics, and manufacturing) and does not include any source addressing cookie consent, so no cookie-specific formula, benchmark, or regulatory expectation can be cited here.

Why it matters

In EU and UK contexts, where valid consent under the GDPR must be freely given, specific, informed, and unambiguous, and where reject options are generally expected to be as accessible as accept options, rejection rate offers privacy and compliance teams an operational signal for how users are actually responding to a consent interface. A sudden shift in rejection rate after a banner redesign, for example, may prompt teams to review whether the change made the reject control easier or harder to find. Because banner design choices can influence outcomes, this metric is often examined alongside acceptance rate rather than in isolation.

It is important to treat rejection rate as an operational indicator, not a measure of legal compliance. A low rejection rate does not confirm that a banner is lawful, and a high rejection rate does not by itself indicate a problem; compliance depends on whether the consent mechanism meets applicable legal standards, which vary between the EU, the UK, and individual US states. Teams that read too much into the number risk optimizing for higher acceptance in ways that may undermine the requirement that consent be freely given.

The evidence available for this entry addresses rejection-rate concepts from unrelated domains such as recruitment, biometrics, and manufacturing, and does not include any source specific to cookie consent. As a result, no cookie-specific benchmark, target figure, or regulatory expectation for rejection rate can be stated here, and readers should be cautious about applying general 'rejection rate' definitions from other fields to consent management.

Who it's relevant to

Privacy and data protection officers
Rejection rate gives privacy officers an operational view of how visitors respond to consent requests, which can inform reviews of banner design and CMP configuration. It should be treated as a signal to investigate, not as evidence of compliance, since legal validity of consent turns on standards that this metric does not measure.
Web developers and CMP administrators
Developers who implement and configure consent interfaces rely on clear definitions of what counts as a rejection, including how partial rejections, dismissals, and non-interactions are handled, so that logged metrics are consistent and interpretable. They also need to ensure that reject controls remain accessible, which in EU and UK contexts is generally expected alongside accept options.
Marketing and analytics compliance teams
These teams often watch acceptance and rejection rates together to understand data availability for analytics and advertising. They should be careful that efforts to influence these numbers do not compromise the requirement, in the EU and UK, that consent be freely given and that reject options be as accessible as accept options.
Legal counsel
Counsel may use rejection-rate trends as context when assessing consent practices, while recognizing that the metric is not itself a measure of lawfulness. Compliance obligations differ between the EU, the UK, and individual US states such as under the CCPA and CPRA, so the significance attached to any figure depends on the applicable regime.

Inside Rejection Rate

Rejection Count
The number of users who decline consent to non-essential cookies, typically captured through a 'Reject All' action or granular refusals within a consent management platform (CMP).
Denominator (Consent Prompt Impressions)
The total population against which rejections are measured, usually the number of users presented with a consent banner or preference interface during a given period.
Granular vs. Blanket Rejection
A distinction between users who reject all non-essential cookies outright and those who decline only specific purposes or categories (for example, refusing advertising cookies while accepting analytics), which can materially affect how the rate is interpreted.
Interface and Design Context
The banner layout, prominence of accept versus reject options, and the presence or absence of a 'Reject All' button, all of which can influence the observed rate and are relevant to assessing whether consent is freely given under the GDPR.
Consent Logging Linkage
The connection between the rejection rate and the underlying consent records, since defensible reporting generally depends on the CMP maintaining logs of when and how each choice was made.
Scope and Jurisdiction
The geographic and legal context in which the rate is measured, given that EU/UK opt-in expectations and US state opt-out models produce structurally different figures that are not directly comparable.

Common questions

Answers to the questions practitioners most commonly ask about Rejection Rate.

Does a high rejection rate mean my cookie banner is broken or non-compliant?
Not necessarily. A high rejection rate reflects the proportion of users who decline non-essential cookies, and a genuinely compliant banner that offers a clear, equally prominent reject option will typically produce higher rejection rates than a banner designed to nudge acceptance. In many EU jurisdictions, regulators have criticised interfaces that make refusing harder than accepting, so a low rejection rate can itself be a warning sign of design practices that data protection authorities may view as undermining valid consent. Rejection rate is a metric to interpret in context, not a direct indicator of technical failure or legal soundness on its own.
Should I try to lower my rejection rate to improve compliance or performance?
Deliberately engineering a lower rejection rate carries risk. Consent under the GDPR must be freely given, specific, informed, and unambiguous, and techniques that discourage refusal, such as pre-ticked boxes, hidden reject options, or disproportionately prominent accept buttons, are widely considered non-compliant in the EU and can invalidate the consent you collect. A lower rejection rate achieved through such means may increase, rather than reduce, regulatory exposure. Where you operate under US state frameworks that generally rely on opt-out rather than opt-in, the dynamics differ, so the appropriate approach depends on the applicable legal regime and should be assessed with legal input rather than treated as a purely optimisation exercise.
How do I calculate rejection rate for my consent banner?
Rejection rate is generally expressed as the number of users who declined non-essential cookies as a proportion of users presented with the consent choice over a given period. Before calculating, decide how you treat users who neither accept nor reject, those who close the banner, and those who engage granular category-level controls, because these choices materially affect the figure. Your consent management platform (CMP) is typically the source of this data through its consent logging. Document your methodology so the metric is comparable over time, and note that there is no single universally mandated formula.
Where can I get the data to measure rejection rate?
Rejection rate data usually comes from your CMP's consent records or logs, which capture the choices users make when presented with the banner. Because record-keeping of consent is itself an accountability expectation in many EU jurisdictions, these logs often serve a dual purpose: demonstrating that valid consent was obtained and providing the underlying figures for metrics like rejection rate. Confirm what your CMP records, at what granularity (all-accept, all-reject, or per-category), and how long it retains the data, since these determine what analysis is possible.
Should I segment rejection rate by cookie category or region?
Segmentation is often useful because consent obligations and user behaviour vary. Splitting rejection rate by cookie category (for example analytics versus advertising) can show which processing users are most reluctant to accept, and segmenting by region is important because requirements differ between the EU, the UK, and individual US states such as under the CCPA and CPRA. A single blended rejection rate can obscure these differences, particularly where opt-in and opt-out models apply to different audiences. Choose segments that reflect the legal regimes and cookie categories relevant to your operations.
How does rejection rate relate to consent record-keeping obligations?
Rejection rate is a derived metric, while consent record-keeping is a compliance function; the two draw on overlapping data but serve different purposes. Your logs need to record individual consent and refusal decisions in enough detail to demonstrate that consent met the applicable standard, and rejection rate is one aggregate view of that same information. Tracking rejection rate does not by itself satisfy record-keeping expectations, and maintaining logs does not require you to monitor rejection rate. Treat the metric as an operational and design-review tool that supports, but does not replace, your underlying consent records and legal judgment.

Common misconceptions

A low rejection rate proves that a consent banner is compliant.
A low rejection rate can reflect a compliant, neutral interface, but it may equally result from design choices that discourage refusal, such as a missing 'Reject All' option or visually de-emphasized reject controls. In most EU jurisdictions, consent must be freely given, specific, informed, and unambiguous, so the rate alone says nothing definitive about lawfulness. Metrics support compliance assessment but do not replace legal judgment.
Rejection rates can be compared directly across regions and organizations.
Rejection rate is highly sensitive to jurisdiction and measurement method. EU and UK regimes generally rely on prior opt-in consent under the ePrivacy rules and GDPR, whereas several US state laws (such as the CCPA/CPRA in California) often operate on an opt-out basis. These are structurally different, so figures are typically not comparable without accounting for legal scope, interface design, and how the denominator is defined.
Rejection rate measures only cookies.
Where a consent prompt governs similar tracking technologies such as pixels, local storage, SDKs, or fingerprinting, refusals of those technologies may fall within the same rejection metric because they are subject to comparable rules under EU law. Treating the figure as cookie-only can misstate what users are actually declining.

Best practices

Document how you calculate the rejection rate, including exactly what counts as a rejection (blanket versus granular) and how the denominator of consent prompt impressions is defined, so the figure is interpretable and reproducible.
Track the rejection rate alongside the banner design and configuration in force at the time, since interface changes can shift the figure and are relevant to whether consent remains freely given in EU/UK contexts.
Segment the metric by jurisdiction rather than reporting a single global number, reflecting that EU/UK opt-in and US state opt-out frameworks produce non-comparable results.
Rely on your CMP's consent logs as the source of truth for rejections, and retain those records to support any record-keeping obligations that may apply.
Treat a low rejection rate as a prompt to review whether reject and accept options are presented with genuine parity, rather than as evidence of compliance in itself.
Use rejection-rate trends to inform, not replace, a legal review of the consent mechanism, and consult qualified counsel where design choices or interpretations are contested.
Application Security Isn’t Optional Anymore.