Every time a website asks visitors to accept or reject cookies, it’s making a bet about how people respond to friction and design. In the latest Insights@Questrom blog post, Tesary Lin, Assistant Professor of Marketing at Boston University Questrom School of Business, examines why the real question isn’t how the cookie banner is designed – it’s whether banners should exist at all.
A field experiment on consent design, and what it means for regulators and for companies that collect data
In June, the Council of the European Union removed the provision that would have ended the cookie banner from its digital reform package, known as the Digital Omnibus.1This provision required websites to honor a privacy preference set once at the browser level and applied to all websites a user visits. The advertising industry had lobbied hard for the removal. The European Parliament has not yet taken a position, so the fight is not over.
California went the other way. Under the existing California Consumer Privacy Act, businesses serving California consumers must already honor a browser-level opt-out signal.2 The new California Opt Me Out Act requires that from January 2027 onward, every browser available to California users must offer a browser-level opt-out mechanism.3
Everyone in this debate has a theory about how consumers behave. Publishers and consent management platforms argue that without a banner on every site, consent disappears and with it their revenue. Privacy advocates say the banners are “privacy theater”, creating the illusion of agency and choice while offering little actual data protection. Regulators are somewhere in between. However, there has been little evidence from studies based on natural browsing data to support either position.
With my colleagues Chiara Farronato and Andrey Fradkin, I ran a field experiment to find out how consumers interact with cookie consent in a natural browsing environment. The results favor the browser-level choice by a wide margin, and they also say something useful to any company that hopes to keep collecting data.
The Experiment
We recruited U.S. adults who use Chrome and asked them to install a customized browser extension. When a participant visited a new website, the extension replaced the site’s cookie banner with one of our six designs, chosen at random. Each design offered the same three options (accept all, reject all, cookie settings) but presented them differently, in what economists call choice architecture: design elements that change the ease and salience of different actions. One design was the “no nudge” benchmark, where we present three options (accept all, reject all, cookie settings) with equal salience. The others either hid “reject all” or “accept all” behind a “settings” menu, reordered the position of different options, or grayed out options other than “accept”. Whatever the participant chose, the extension passed the choice back to the website. Participants browsed as they normally would for a week, visiting about 54 unique domains each. In total, we recorded 23.6k consent decisions across 5.4k unique domains.
Three features make the results credible: Random banner assignment allows us to cleanly identify how banner design affects cookie consent decisions and compare them against the benchmark. Participants react to banners in real browsing environments: quickly, distracted, while trying to read something else. Finally, a wide website coverage means our results describe the broader internet, rather than a selective few companies. Not All Choice Architectures Are Equal
Under the benchmark design, consumers choose “accept all” cookies 61 percent of the time and select “reject all” another 14 percent of the time during their own browsing. Hiding an option behind the “settings” menu decreases the probability of choosing this option by 70%: rejection rate decreases by 11 percentage points when hidden, while “accept all” decreases by 44 percentage points. When prompted to make one extra click to reach their preferred choices, consumers mostly decide to close the window directly, rather than attempting to go to the “settings” menu.
In contrast, pure visual changes did little to change consent decisions. Putting “accept” on top raises acceptance by a mere 3 percentage points. Graying out alternative options alone has a similar negligible effect. The common phrase “choice architecture” (also known as “dark patterns”) blurs a distinction between designs that create choice friction and those that do not, and we find that these two categories differ vastly in their effectiveness in changing consent decisions.
The Cost of Repeated Consent
In our experiment, we reduced the frequency of consent banner appearances to at most one every 10 minutes to address the concern that participants would exit the study due to fatigue. Still, people closed the banner without choosing 22 percent of the time during their ordinary browsing. Worse still, these decisions to abandon active choice often operate under a false assumption: 61% of our participants believed closing the window means rejecting cookies, while in the United States, websites usually continue collecting cookies upon consumer inaction, because no law requires a website to do otherwise.
Then there is time. A benchmark banner without deliberate obstruction took 7 seconds on average, 2.5 at the median. Clicking into settings added 4 more seconds per banner. Seven seconds times 54 sites a week, at the average U.S. wage of $36 an hour, is about $4 per week per person ($1.30 at the median). Multiplying this number by 270 million adults in the U.S. implies a $1.08 billion total weekly loss.
The Benefit of Simplified Choices Is Large for Every Type of Consumer
To compare policies, we built a model that turns choices and time into dollars of consumer welfare per person per week. We start with the best possible per-site banner: no hidden buttons, and a default set to what most people prefer. This banner is worth $2.96 per user per week. The typical U.S. banner, with the “reject” option hidden, is worth 20 percent less. The typical EU banner, removing all deliberate nudges but defaulting to reject, is worth 6 percent less. Telling people what the default does adds 15 percent.
Now replace all of them with a browser-level choice: choose whether to accept cookies once, and let the choice apply to all websites. This is what Global Privacy Control does, and similar to what the California Opt Me Out Act requires. It raises welfare by $3.67 a week over the best banner, more than doubling it. Under conservative assumptions about the value of time, browser-level choice still increases consumer value by 36%.
The publishers’ objection is that a browser setting loses granularity: you cannot say yes to your favorite newspaper and no to everyone else. In our data, 30% of consumers vary their consent choices across websites in the benchmark condition. Even for these consumers, the browser-level signal comes out ahead, because the benefit of time saving outweighs the loss of choice granularity. In our end-of-experiment survey, most participants said they prefer the browser setting to banners.
For Policymakers: The “How” of Choice
Consent regulation now has two different approaches. The first regulates consent banner design. Both the General Data Protection Regulation and the California Consumer Privacy Act have gone after “dark patterns,” interface designs that steer people toward giving up data. The second approach rethinks the necessity of consent banners. Rather than fixing every banner, it asks whether a single browser setting could replace it.
The two approaches sometimes contradict each other. More choice, in the form of a banner on every website, offers more consumer control at first glance. However, choice has a cost in time and attention, and a choice made ten thousand times has the potential to degrade decision quality when attention is scarce. Which matters more, the quality of choice or the granularity? Our experimental evidence points to the former.
The idea that complex choices cost consumers is not new. In other domains, such as health insurance and retirement savings, studies found that complex choices lead consumers to choose options that are clearly worse for them.4 However, repeated choices online take a toll of their own: repeated across thousands of websites, even small frictions such as a single click can materially compromise decision quality and decrease user welfare.
For Managers: Building a Sustainable Data Strategy
The Council of the EU’s vote does not settle the matter for companies, while California’s requirement is already finalized. In a previous version of the Digital Omnibus, the Commission proposed the browser-level signal but whitelisted digital publishers, who critically rely on cookie-based personalized advertising as a funding source. The likely future is both regimes at once: browser signals in some regions and banners in others. What should a company do?
First, stop investing in design-based steering. Where browser signals apply, consent engineering matters little. Where they do not apply, obstruction increases consent, but it is the one design feature regulators have both the evidence and the appetite to punish.5 A lever that enforcement agencies are scrutinizing is not a sustainable foundation for a data strategy.
Second, notice what raised consent without any design trick. In our study, people accepted cookies more often on sites they knew and visited regularly. The most common reason they gave for accepting was that they trusted the site. A recent study finds that after California and Virginia strengthened privacy rights in 2023, users of a receipt-rewards app in those states shared more data, with the largest change among the most reluctant users, potentially due to increases in trust.6 Trust is slow to build and hard to fake, making it an enduring advantage.
Watch the EU Parliament’s decision this fall. But whatever it decides, the lesson for anyone who builds a consent screen is the same. Remove the need for an extra click. Communicate your value and the options your customers have regarding data flow and retention. And, wherever you can, ask once.
Tesary Lin is an assistant professor of marketing at Boston University’s Questrom School of Business. The research described here, “Designing Consent: Choice Architecture and Consumer Welfare in Data Sharing,” was presented at several policy outlets including the FTC Microeconomics Conference and the Brussels Expert Workshop: Web Standards for Data Protection in the EU. It is forthcoming in Management Science.
- https://iapp.org/news/a/rewriting-the-rules-of-ai-targeted-eu-ai-act-amendments-in-the-digital-omnibus-on-ai ↩︎
- https://govt.westlaw.com/calregs/Document/I9786D7609E0F11F09EBEE9819175B1F8 ↩︎
- https://cppa.ca.gov/announcements/2025/20251008_2.html ↩︎
- https://economics.yale.edu/research/when-less-more-improving-choices-health-insurance-markets-0, https://academic.oup.com/rfs/article-abstract/23/4/1405/1591053 ↩︎
- https://cybernews.com/privacy/reject-all-cookies-button-must-be-present-in-europe
https://www.dwt.com/blogs/privacy–security-law-blog/2024/09/california-guidance-on-dark-patterns-and-privacy ↩︎ - https://www.hbs.edu/ris/Publication%20Files/26-001_1e7c05a4-cf66-4c28-a23d-04eb5097b1a4.pdf ↩︎




















