OneTrust’s default cookie banner meets GDPR’s minimum legal bar for consent 41% of the time, more than ten times the 4% compliance rate recorded for Osano, according to a CHI 2025 study of 254,148 websites by Nouwens et al. (published 2025). Usercentrics, the single most-installed CMP on the web, clears that same bar just 17% of the time.
That gap sits behind every number below: which vendors’ default templates actually pass a GDPR compliance test, how much of that gap comes down to the vendor rather than the site running it, and how real-world opt-in behavior compares once you leave banner design and look at what visitors actually click.
Which CMP has the highest cookie-banner compliance rate?
Among the twenty most commonly deployed CMPs, compliance rates range from 65% down to 4%, a 61-point spread for banners doing the same legal job. Nouwens et al.’s CHI 2025 study defines “compliant” as meeting three minimum conditions: consent is explicit, rejecting is no harder than accepting, and no optional box arrives pre-ticked. Shopify’s built-in checkout consent banner tops the list at 65%, ahead of every dedicated third-party CMP. Among the general-purpose vendors a site owner actually chooses between, OneTrust leads at 41%, with tarteaucitron (54%) and iubenda (48%) close behind.
The vendors with the biggest installed base are not the most compliant ones. Usercentrics, the most-used CMP at 17.26% of all detected installations, sits at 17% compliance. CookieYes, the second most common at 12.45% share, comes in at just 8%. Osano, used on 7.10% of measured sites, has the lowest compliance rate of any CMP in the top twenty at 4%.
| CMP | Compliance rate | Installation share |
|---|---|---|
| OneTrust | 41% | 8.03% |
| Usercentrics | 17% | 17.26% |
| Didomi | 17% | 1.95% |
| CookieYes | 8% | 12.45% |
| Osano | 4% | 7.10% |
Source: Nouwens et al., CHI 2025, Table 7. Top twenty most commonly used CMPs, accounting for 78% of all identified CMPs.
Figure 1: Compliance rate for six widely recognized CMP vendors. Source: Nouwens et al., CHI 2025, Table 7.
Installing a market-leading CMP is not the same as installing a compliant one. A site owner picking a vendor by name recognition alone is, on this data, more likely to land near the bottom of the compliance ranking than the top.
How much of the compliance gap comes down to CMP choice itself?
A large share. The study’s ANOVA found that choice of CMP explains 17.8% of the statistical variance in compliance (F(115, 270053) = 509.9, p < 0.001), compared with just 0.8% for whether a country’s regulator has published guidance and a mere 0.1% for a website’s overall popularity ranking. In a follow-up regression using non-CMP banners as the baseline, individual vendor effects ranged from a 61.1 percentage-point compliance boost for Shopify down to a small, sometimes negligible improvement for others: CookieYes added only 4.8 points over having no CMP at all, and Osano added just 1.1 points. OneTrust added 36.9 points and Usercentrics added 13.6 points.
Figure 2: Where six CMPs sit on installation share versus compliance rate. X-axis position reflects each vendor’s installation share relative to Usercentrics (the largest), from Table 7. Source: Nouwens et al., CHI 2025.
Almost every widely used CMP sits in the “popular and non-compliant” quadrant. Only OneTrust breaks into the upper half of the compliance axis while still holding a meaningful installed base, which is the closest thing this dataset offers to a case for switching vendors on compliance grounds alone.
This compliance-rate gap is a separate layer from a CMP’s IAB Transparency and Consent Framework vendor-list registration status, which tracks whether a vendor is listed at all rather than whether its default banner design passes a legal minimum test.
What’s the single biggest reason banners fail, regardless of vendor?
A missing reject button, by a wide margin. Across all 169,901 consent interfaces the study evaluated, 56.2% lacked a reject-all option entirely, the single most common reason for non-compliance. A further 29.6% withheld granular purpose-level controls, and 23.9% displayed a reject option that was harder to find or click than accept. Only 2.6% failed on pre-ticked optional boxes, the smallest of the four failure categories, though it is the specific dark pattern most explicitly named in the GDPR’s own recitals.
Figure 3: Share of evaluated interfaces failing each compliance condition (a single interface can fail more than one). Source: Nouwens et al., CHI 2025, Figure 4.
These four failure modes are also the fastest fixes available to a site owner who does not want to switch CMPs at all. Adding a same-prominence reject button and turning off pre-ticked defaults closes most of the gap between a 4% compliance rate and something closer to OneTrust’s 41%, without touching the underlying vendor. Pairing that fix with a cookie policy generator that accurately describes what the (now-compliant) banner actually does keeps the published document in sync with the real configuration.
Do real-world opt-in rates match banner compliance rates?
Not closely, and the two measure different things. Compliance, as defined above, asks whether a banner’s design meets GDPR’s minimum legal bar. Opt-in rate asks what visitors actually clicked. Commanders Act’s Privacy Barometer, published June 2026 from an analysis of 2,391 live CMP configurations across sectors and regions, found a 68.82% desktop opt-in rate and a 76.35% mobile opt-in rate, alongside a separate desktop “no-choice” rate (visitors who never made an active decision) of 47.01%, up 7.74 percentage points from the prior year’s edition of the same report.
Warning
Commanders Act sells its own consent management and tag management platform, so this benchmark is drawn from sites running its commercial product, not an independent measurement across competing CMP brands. The 2,391-configuration sample size is disclosed, which is more than many vendor benchmarks offer, but the report does not publish a breakdown by named competing CMP the way the CHI 2025 academic study does. Treat the opt-in figures as directional evidence that acceptance behavior runs well above design compliance, not as a cross-vendor ranking.
The pattern holds regardless: a banner can be non-compliant by design and still collect a high opt-in rate, because a missing reject button or an unequal-prominence layout is specifically engineered to push visitors toward “accept.” High opt-in numbers on a non-compliant banner are a liability indicator, not a sign the banner is working as intended.
Figure 4: How CMP compliance and opt-in measurement has developed. Sources: Nouwens et al., CHI 2020 and CHI 2025; Commanders Act Privacy Barometer, 2026.
The Bottom Line
The CMP a site installs measurably changes whether its banner meets GDPR’s minimum bar, more than the site’s popularity or its country’s regulatory climate combined. OneTrust’s default template clears that bar 41% of the time; Osano’s clears it just 4% of the time; the market-leading Usercentrics sits in between at 17%. None of that compliance gap shows up in opt-in rate, where Commanders Act’s 2026 data puts desktop acceptance above two-thirds regardless of the underlying banner’s legal standing. A site owner’s fastest lever is not necessarily switching vendors: adding a same-prominence reject button and disabling pre-ticked defaults, the two failures behind most of the non-compliant 85%, moves a banner most of the way toward OneTrust’s numbers on any CMP. Keeping the published cookie policy accurate to whatever configuration results is the other half of that fix. For the vendor landscape behind these numbers, see our look at CMP market share by installation and where CMPs fail their own 2025 compliance audits.
Frequently Asked Questions
What percentage of cookie banners meet GDPR’s minimum compliance bar? Only 15% overall, but the rate varies enormously by vendor: from 65% for Shopify’s built-in banner down to 4% for Osano among the twenty most common CMPs, per a CHI 2025 study of 254,148 websites by Nouwens et al.
Which consent management platform has the best compliance rate? Shopify’s built-in checkout banner tops the ranking at 65%, but among dedicated third-party CMPs, OneTrust leads at 41% compliance, according to the same CHI 2025 study.
Does the CMP you choose actually affect consent compliance? Yes. CMP choice alone explains 17.8% of the statistical variance in banner compliance, far more than website popularity (0.1%) or the existence of regulator guidance (0.8%), per the study’s own ANOVA.
How does real-world opt-in behavior compare to banner design compliance? Commanders Act’s June 2026 Privacy Barometer, analyzing 2,391 live CMP configurations, found a 68.82% desktop and 76.35% mobile opt-in rate, even though most underlying banners likely fail one or more of the GDPR minimum-compliance tests the CHI 2025 study defines.
Sources and References
- Nouwens, Kristensen, et al.. (2025). “A Cross-Country Analysis of GDPR Cookie Banners and Flexible Methods for Scraping Them.” CHI 2025, ACM. 254,148 websites across 31 countries; Table 7 ranks the twenty most common CMPs by compliance rate.
- Nouwens, Liccardi, Veale, Karger. (2020). “Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence.” CHI 2020, ACM. Original minimum-compliance methodology and per-CMP scraper study (n=680).
- Commanders Act. (2026). “Privacy Barometer 2026.” Analysis of 2,391 live CMP configurations, published June 15, 2026. Vendor-published benchmark from Commanders Act’s own consent platform.
Note: All figures verified as of September 2026. The CHI 2025 compliance-by-CMP figures reflect a single cross-country measurement (data collected 2024) and are refreshed at least twice a year as newer academic measurements become available. The Commanders Act opt-in figures are a single vendor’s benchmark and should be re-checked against its own report before each refresh.