Note · 2 September 2026

The next check of your cookie banner probably won't come from a visitor

Bart Knijnenberg · 3 min read

For years, cookie enforcement worked like a complaints desk. Someone got annoyed, filed a report, and a regulator eventually looked into it. That model has changed. Since April 2025 the Dutch data protection authority has been checking banners in bulk, using software that inspects tens of thousands of cookie banners at once rather than one site after a complaint. In November 2025 the authority reported that it had sent warnings to more than 200 websites and that roughly three-quarters adjusted their banner, with formal investigations starting against the rest.

That matters for one practical reason: an automated check does not read your privacy statement or your intentions. It looks at what your page actually does.

What a crawler can see, and what it can't

A scan can register whether a refuse option exists at the first layer, whether it looks like the accept button or like a small grey link, whether toggles are pre-checked, and whether tracking requests fire before any choice is made. All of that is visible from the outside, at scale, without a human being involved.

What a scan cannot see is your record of consent. That part only surfaces when someone asks you to demonstrate it, and under Article 7(1) GDPR the burden of proof sits with you, not with your visitor. A banner that looks correct in a crawl and has no log behind it is still a problem waiting for a slower, more expensive conversation.

The numbers say the visible part is still often wrong

Consumer organisation Consumentenbond checked 100 popular websites against the Dutch authority's rules in 2025 and found that 32 of the 84 sites with a banner, 38 percent, did not ask for consent properly. News and media sites did worse: of 20 media sites with a banner, 16 were not in order. The 2023 figure was higher at 61 percent, although the samples were only partly the same, so read the trend as direction, not as precision.

```cijfers
titel: Dutch banners that do not ask for consent correctly
eenheid: %
bron: https://www.consumentenbond.nl/acties-claims/nieuws/2025/onderzoek-cookies-nog-steeds-teveel-opgedrongen (Consumentenbond, cookie research 2025)
Sample 2023, all sites: 61
Sample 2025, all sites: 38
Sample 2025, news and media sites: 80
```

The chart shows something useful about risk: the average is improving, but if you run an ad-funded or media-heavy site, you are statistically in the worst-performing group and therefore the most likely to be flagged by an automated sweep.

Fines are no longer theoretical

Dutch enforcement has been slow in absolute terms. The same Consumentenbond piece notes only two cookie fines from the Dutch authority in 2024, following investigations that started in 2019 and 2020. France shows the other end of the scale. The CNIL reported that in 2025 it sanctioned 21 entities for tracker breaches and issued €486,839,500 in cumulative fines, including €325 million and €150 million against two large players, partly for not acting on refusal or withdrawal of consent.

What to do this week

Load your own homepage in a clean browser profile, open the network tab, and refuse everything. If requests to analytics or ad domains still go out, your banner is decoration. Then check whether refusing takes the same number of clicks as accepting. Then ask a simple question of your setup: if a letter arrives asking you to show consent for a specific date, can you produce it?

That last question is why PlainConsent logs consent with a real audit trail, in five languages, at one flat price per site with every feature included. Not because a log makes you compliant on its own, but because it is the only part of this an outside scan cannot check for you.

Sort your cookie banner in ten minutes.

Then we look at your site and tell you in plain words whether it is right. One flat price per site, every feature included.

See pricing
← All notes