From cookie banners to consent signals: What financial websites need to get right
Most consent failures on financial websites happen behind the cookie banner.
A visitor clicks "Reject all," but a marketing pixel hard-coded into the page still sends the visit to an ad platform.
Regulators in the EU, UK, and US now check whether a site's tracking follows the visitor's choice, and financial sites carry more risk than most because their visitors share account and financial data.
This article covers the rules that apply, what a compliant banner looks like, and how to make consent signals reach every system that collects data.
Cookie banners ask, consent signals enforce
A cookie banner is the visible part: the notice that tells visitors which tracking technologies a site uses and, in many regions, asks permission for the optional ones.
Early banners only announced that cookies existed. Under GDPR and the ePrivacy rules, they became choice screens where visitors accept or decline non-essential tracking.

A consent signal is what happens to that choice next. It turns the visitor's decision into a machine-readable instruction that tags, SDKs, server-side integrations, and ad platforms can act on. The main standards are:
- IAB Europe Transparency and Consent Framework (TCF): passes consent choices to advertising vendors in Europe through a standard consent string.
- Google Consent Mode: changes how Google tags behave depending on what the visitor allowed.
- Global Privacy Control (GPC): a browser setting that tells every site the visitor opts out of the sale or sharing of their data.
- IAB Tech Lab Global Privacy Platform (GPP): carries privacy signals for multiple regions, including US states, in one string.
A site can have a well-designed banner and still fail if none of these signals reach the systems that collect data.
The rules financial websites answer to
Financial websites usually serve visitors from more than one region, and each region treats tracking differently. Europe and the UK require consent before optional tracking starts, while most US states let it run until a visitor opts out.
Europe and the UK
In the EU, the ePrivacy rules require consent before a site stores or reads non-essential cookies, and GDPR sets the standard for that consent. The European Data Protection Board's guidelines on consent say it must be freely given, specific, informed, and unambiguous, which rules out pre-ticked boxes and continued scrolling as a form of agreement.

The UK changed its rules in 2026. The ICO published final guidance on storage and access technologies on April 29, 2026, reflecting new consent exceptions in the Data (Use and Access) Act 2025. One allows some analytics without consent, but only under strict conditions: the data serves statistical purposes alone, and any analytics provider acts purely on the site's behalf. Advertising tracking still requires consent.
Enforcement is serious. In September 2025, France's CNIL fined Google €325 million and Shein €150 million for cookie violations. In Shein's case, those included placing advertising cookies without consent and refusal options that didn't stop cookies from being set.
United States
US state laws mostly work on notice and opt-out rather than opt-in consent. The opt-out still has to work, including when it arrives as a browser signal. California's first CCPA enforcement action was a $1.2 million settlement with Sephora in 2022, partly for failing to honor GPC. According to the California Privacy Protection Agency, California is now one of about a dozen states that require businesses to honor opt-out preference signals.
Financial institutions often assume the Gramm-Leach-Bliley Act exempts them from all of this. Under California's law, it doesn't. The CCPA exemption covers data regulated by GLBA, which leaves website cookies, analytics, and ad tracking in scope. As Orrick's analysis explains, the CCPA has never exempted financial institutions as entities, and several other states have since narrowed or removed their entity-level exemptions too. A bank's privacy team needs to check each state where it has customers.
What a good banner looks like
Alistair Hinchliffe, Product Manager at GetTerms, oversees a platform that generates privacy policies, terms and conditions, and cookie policies for websites and apps.
He says, "A cookie banner, a cookie policy, and a privacy policy describe the same facts, and regulators read them side by side. If the banner lists four categories, the policy describes three, and the site loads tags from a vendor that neither one mentions, that inconsistency becomes evidence. Whenever a new vendor is added or a tag changes, the policies should be updated in the same release as the code."
- A banner that holds up to scrutiny has:
- A "Reject all" button on the first screen, the same size and prominence as "Accept all"
- No pre-ticked categories
- A short first layer, with a link to full details for anyone who wants them
- A "Cookie settings" or "Privacy choices" link in the footer of every page, so visitors can change their decision later
The best banners on financial sites read like an explanation from someone who works there. They name each category of tracking, say what it does, and give an example the visitor will recognize.
The distinction that matters most is between essential and optional technologies. Session security, fraud detection, and login cookies keep accounts safe and don't need consent. Analytics, chat widgets, and advertising pixels are optional, and the banner should say so in those terms.
Wiring consent into the stack
Financial websites tend to have deep tag stacks: analytics, performance monitoring, attribution, fraud tools, support chat, mobile SDKs, and a few legacy scripts nobody remembers adding. A consent management platform (CMP) collects the visitor's choice. Getting that choice to every one of those systems is the harder job.
The usual failures:
- Tags hard-coded into page templates or iframes that fire before the CMP loads
- Server-to-server integrations that send data no matter what the visitor chose on the page
- Third-party scripts that set their own cookies after the site has blocked them
- Category names that differ between the banner, the CMP, and vendor contracts
The fix starts with an inventory. List every vendor, map each one to a purpose, and put each behind a consent check. Route data collection through a tag manager or a server-side gateway that reads the consent state before anything leaves the site's domain. Google tags should respect Consent Mode, and ad vendors in Europe should receive a TCF string. Use GPP where US state signals need to travel with the request.
Then test it the way a visitor would. Turn on GPC in Firefox or Brave, reject everything on the banner, and walk through the account-opening flow with the browser's network panel open. Any request to an ad or analytics domain that appears after a rejection is a defect, and it's far cheaper to find it yourself than to have a regulator's sweep find it.
Keeping measurement without dark patterns
Marketing teams want complete data, and every rejected banner leaves a gap. The temptation is to close it with design: a bright "Accept" button, a grey "Manage options" link, and no reject button until the second screen. Regulators look for exactly that. Making refusal harder than acceptance was part of the CNIL's case against Shein, and the EDPB considers cookie walls that block access until a visitor accepts tracking incompatible with freely given consent.
There are better ways to protect measurement:
Use Consent Mode's modeling. When a visitor declines, Google tags can send cookieless pings that feed modeled conversions. That keeps reporting directionally useful, though it doesn't replace a valid consent choice.

- Delay optional scripts on sensitive flows. Load chat and marketing tags after an application or trade is submitted, which keeps them off the pages handling account data.
- Rely on aggregate data where you can. Server logs and first-party aggregate reporting often answer questions that individual-level tracking was being used for.
A site that people trust with their savings has more to lose from a manipulative banner than a retailer does. The extra percentage points of consent are rarely worth it.
Preparing for 2027
Opt-out signals are about to become much more common. California's Opt Me Out Act (AB 566) takes effect on January 1, 2027, and requires every browser serving California users to offer a built-in opt-out preference signal. Today, GPC is mostly limited to privacy-focused browsers and extensions. Once it is a standard setting in mainstream browsers, a site that ignores it will be ignoring a large share of its visitors.
A practical schedule for the months ahead:
- Now: confirm the site detects GPC and that an opt-out signal actually stops sales and sharing on the server side as well as in the browser.
- Every quarter: scan for new cookies and tags, compare them against the vendor inventory, and retest the reject-all path.
- With every release that adds a vendor or changes data collection: update the banner categories and policies, and decide whether visitors need to be asked again.
- Whenever a regulator publishes new guidance: review it against the current setup. The ICO's 2026 guidance and new US state laws taking effect over the next year are both worth reading closely.
Keep records of consent choices and of each audit. If a regulator asks how the site handled a visitor's opt-out, a dated log of tests and fixes is the strongest answer available.
Compliance work happens alongside the day-to-day job of tracking what moves financial markets. FXStreet covers currency markets, central bank decisions, and economic data releases every day, which helps financial teams stay current on the developments that affect their customers.
Author


















