Cookie banner rejection and GDPR consent complaints
Under GDPR and the ePrivacy rules, non-essential cookies and SDK identifiers need consent before they are set, not after.
What the rejection means
Under GDPR and the ePrivacy rules, non-essential cookies and SDK identifiers need consent before they are set, not after.
The usual causes
- Analytics fires on page load, before any banner is answered.
- The banner has an accept button and no refuse button.
- Consent is assumed from continued scrolling.
What to change
Block non-essential scripts until consent, give refusing the same weight as accepting, and record what was consented to.
Before you resubmit
- Open every URL you entered in a private window.
- Read the reviewer's message again and answer the specific point, not the general topic.
- Reply in Resolution Center saying what you changed and where to see it.
Keeping it true after launch
A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. No store re-checks your pages against your build, so the drift is yours to notice.
- Re-read it whenever you add a dependency that sees user data.
- Re-check what loads on the page after any change: the cookie notice and the policy have to agree.
- Keep the URL stable. Changing where a policy lives breaks every listing that points at it.
Common questions
How long does a resubmission take?
Usually the same as a first review. Answering the exact point raised, with a link, is what shortens it.
Can I argue a rejection?
You can, and sometimes you should. It works when the reviewer has misread something and you can show it in one sentence with a link. It rarely works as a general objection.
