The Nullware Standard0 trackers on this page
Articles / Position

Consent doesn’t cure it

Why a click on “Accept” doesn’t make handing a customer to an ad platform acceptable under the Nullware Standard.

Roland Erich·Draft, checked 20 Sep 2026·7 min read
In short
01
A cookie banner “Accept” can make an ad pixel lawful. It doesn’t make it acceptable to us. Clause NFS-1.3 says consent doesn’t cure a breach.
02
Regulators keep finding banners built to get a yes, and people can’t meaningfully agree to what a platform does with their data after the hand-off.
03
You’re free to rely on consent. You just can’t carry our badge while you do. Things a customer actively chose, like a newsletter, are still fine.
01

The most common question we get from applicants goes like this: “Our Meta pixel only fires after the visitor clicks Accept. That’s legal. Why isn’t it allowed?”

Yes, it’s often legal. It still isn’t allowed. The Standard doesn’t ask whether you had permission to hand a customer to an ad platform. It asks whether you handed them over. Clause NFS-1.3 is one line: consent doesn’t cure a breach. This piece explains why we drew the line there, and where consent still counts.

What the banner is measuring

A consent banner is supposed to record a free, informed choice. In practice it mostly measures how the banner was designed.

In 2020, researchers from Aarhus, UCL and MIT scraped consent pop-ups on the top 10,000 UK websites. Of the 680 banners from the five most popular consent platforms, only 11.8% met the minimal requirements the researchers based on European law. In a field experiment, taking the “reject” button off the first screen raised consent by 22 to 23 percentage points. The people hadn’t changed. The button had.

Regulators have found the same thing, repeatedly:

  • In January 2023 the European Data Protection Board published the report of its cookie banner taskforce. It listed the recurring problems: no reject option on the first layer, pre-ticked boxes, deceptive link design, colours and contrast that steer people to “Accept”, “legitimate interest” claims that don’t hold up, and consent that’s hard to withdraw.
  • In January 2022 France’s regulator, the CNIL, fined Google €150 million and Facebook €60 million because refusing cookies took more effort than accepting them.
  • In September 2025 the CNIL fined Google €325 million and SHEIN €150 million. On shein.com, cookies were placed before visitors had touched the banner, and cookies kept being placed and read after people clicked “Refuse all”.
  • In the UK, the ICO reviewed cookie compliance on the country’s top 1,000 websites during 2025. By December it reported that 564 sites had improved after it got involved and 17 had been sent preliminary enforcement notices.

We take the ICO’s result as progress. We also note what it tells you about the starting point: more than half of the country’s biggest websites fixed their banners only after a regulator got in touch.

Then there’s fatigue. A shopper who meets a banner on every site learns that “Accept” makes the box go away. Chairing the EDPB when it adopted its 2024 opinion on “consent or pay”, Anu Talus said most users consent without understanding the full implications. A click given to get to a pair of shoes is a weak foundation for handing someone’s browsing and purchases to an advertising company.

Pay or consent shows the ceiling

The “consent or pay” argument is the clearest test of how much a click can carry.

In November 2023 Meta gave people in the EU a binary choice: agree to their data being combined for personalised ads, or pay a monthly fee for no ads. In April 2024 the EDPB’s Opinion 08/2024 said that, for large online platforms, offering only that binary choice will not in most cases meet the requirements for valid consent. It also said that getting consent does not release a company from the basic principles of data protection law, including data minimisation and fairness.

In April 2025 the European Commission fined Meta €200 million under the Digital Markets Act. It found the model did not give users a specific choice of an otherwise equivalent service using less of their data, and that users couldn’t freely consent to their data being combined. The breach covered March to November 2024. Meta has said the decision is “incorrect and unlawful” and that it is appealing. In December 2025 the Commission announced that Meta had committed to offering EU users a less-personalised ads option from January 2026.

Note the scale. One of the best-resourced companies in the world spent years in front of regulators trying to design a consent choice that would hold up. A small shop’s banner, installed from a template, isn’t going to do better.

Nobody can consent to what happens downstream

Even a perfectly designed banner has a limit. It covers the hand-off. It can’t cover what happens next.

In its 2019 Fashion ID judgment, the Court of Justice of the EU looked at a retailer that had put Facebook’s “Like” button on its site. The court found the retailer shared responsibility for collecting the visitor’s data and sending it to Facebook. It wasn’t responsible for what Facebook did with the data afterwards, and so its consent request only needed to cover the part it was responsible for.

That’s sensible as law. As a customer protection, it leaves a gap. The business asks for consent to the transfer. The platform decides what happens next, under its own terms, for its own purposes, and those terms can change. A customer who clicked “Accept” on your banner agreed to something neither of you can fully describe.

That is why our rule is about the route, not the paperwork. Pixels (ruling R-003), conversions sent back (R-004), uploaded or hashed audiences (R-002, R-005): once the data reaches a recipient that uses it for its own ends, the customer has been handed over, whatever the banner said.

“People should be free to choose”

This is the strongest objection, and we take it seriously. Adults can decide what to share. Refusing to let a banner count could look paternalistic.

Our answer has three parts.

First, we don’t restrict anyone’s choice. The Nullware Standard is voluntary. Any business can run consent-gated pixels, stay within the law and trade happily. It just can’t carry our badge while it does. The badge means one thing, and a mark that meant “doesn’t hand customers over, unless they clicked Accept” would mean very little.

Second, the choice the objection defends isn’t the one on offer. The customer didn’t come to decide whether to be handed to an ad platform. They came to buy shoes. The banner turns a purchase into a data negotiation the customer never asked for, on terms set by the other side.

Third, our badge is itself a choice, and it’s aimed at the customer. It lets people who don’t want to be handed over find businesses that don’t do it, without reading forty banners. That adds to their options.

Legal is the floor. Our Standard is meant to sit above it.

Where consent still does its job

Consent isn’t worthless. It works when the person asks for the thing, can see what they get, and the data stays with you.

Fine
A newsletter someone signed up to, sent through your own email tool acting as your processor, with audience syncs to ad platforms switched off (NFS-1.4, R-008).
Aggregate email counts: how many opened, how many clicked (NFS-2.2).
Order history, basket reminders and recommendations on your own site, if you’re open about them, never use them for pricing and never build them on sensitive inferences (NFS-3.1).
Cookieless, aggregate visitor counting that needs no banner at all (NFS-2.1, R-007).
Never, even with consent
Ad pixels, including ones that wait for “Accept” (R-003).
Conversion APIs, enhanced conversions or click-ID imports (R-004).
Customer list uploads and lookalikes (R-002, R-005).
Per-person open logs used to build segments (R-008).
Selling, renting or pooling customer data (NFS-1.1, NFS-1.2).

You can still advertise. Members can buy ads on any platform, including ads using the platform’s own targeting, as long as no customer data goes back.

What the Standard says
  • NFS-1.3 Consent doesn’t cure a breach. A consent record is not evidence of compliance with the core rule.
  • NFS-1.1 / NFS-1.2 No selling or pooling of customer data, whatever the customer agreed to.
  • R-003, R-004, R-002, R-005 Pixels, conversions sent back, click IDs and uploaded audiences are breaches whether or not they’re consent-gated.
  • NFS-2.1, NFS-2.2, R-007, R-008 Count, don’t follow. Newsletters are fine when they’re chosen, kept with your processor and not synced to ad platforms.

If you’re unsure where your own setup stands, start with the self-check or “Where data goes”.

Read the StandardRulings registerTake the self-check
Sources (13), checked 20 September 2026
  1. Nouwens, Liccardi, Veale, Karger and Kagal, “Dark Patterns after the GDPR” (CHI 2020), arXiv
  2. EDPB: Report of the work undertaken by the Cookie Banner Taskforce, 18 January 2023
  3. CNIL fines Google €150 million and Facebook €60 million, PL&B, January 2022
  4. CNIL: Cookies placed without consent, SHEIN fined 150 million euros, September 2025
  5. Lewis Silkin: When the cookie crumbles, lessons from the CNIL (Google €325m and SHEIN), September 2025
  6. ICO: action to tackle cookie compliance across the UK’s top 1,000 websites, 23 January 2025
  7. ICO: action secures increased cookie compliance, 4 December 2025
  8. EDPB: “Consent or Pay” models should offer real choice, 17 April 2024
  9. EDPB Opinion 08/2024 on valid consent in consent or pay models (PDF)
  10. European Commission: Commission finds Apple and Meta in breach of the Digital Markets Act, 23 April 2025 (IP/25/1085)
  11. The Register: Meta calls €200M EU fine “unlawful”, July 2025
  12. European Commission: Meta commits to give EU users choice on personalised ads under the DMA, 8 December 2025
  13. Covington Inside Privacy: CJEU Fashion ID judgment (C-40/17), 29 July 2019
This article is general information, not legal advice.
02

Keep reading

All articles
Position6 min · Draft
The pixel you can’t see: server-side tracking
Moving tracking to a server hides it from scanners. It doesn’t change where the data ends up.
Law and practice7 min · Draft
The badge replaces the banner
Since February 2026, a UK site that counts visitors without tracking them usually needs no cookie banner.
Explainer6 min · 14 Sep 2026
Hashed isn’t anonymous
Why sending “encrypted” customer emails to ad platforms still counts as handing people over.