120Feet

15 Consent Mistakes We Still See in 2025 (and How to Fix Them)

Geoff

23-09-2025

Read Time: 5 minutes

Consent – An Introduction

Cookie banners and Consent Management Platforms (CMPs) have been around for years, yet many organisations are still getting the basics wrong. Under the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR), compliance isn’t optional.

When consent is mismanaged the impact is felt in three ways: (1) regulatory exposure, (2) brand reputation and (3) the quality of your analytics data.

At 120Feet we’ve audited many consent implementations across financial services, retail, travel, education and beyond. We see the same issues time and again.

So, here are 15 of the most common mistakes we’re still seeing in 2025 – and, crucially, suggestions on how to fix them.

Consent Banner Design & UX

Mistake 1: Reject All Button Missing

❌ ICO guidance has been clear since 2019: users must be able to refuse non-essential cookies or similar tracking as easily as they accept them (ICO cookie guidance). Hiding “Reject All” in a second or third layer fails that test and undermines trust.
Fix: Display “Accept All” and “Reject All” side by side, style them equally and test across all devices.

Mistake 2: Vague Consent Declarations

❌ Using categories like Performance or Analytics is fine – most CMPs rely on them. The issue is stopping there without providing meaningful detail.

The UK GDPR requires that consent is specific and informed. Users must be able to see:
  • What the data is used for (purpose)
  • Who sets it (vendor)
  • How long it lasts (retention)

Example:

  • Category: Analytics
    • _ga – Google Analytics, used to measure site traffic, expires after 13 months
    • AMCV_####@AdobeOrg – Adobe Analytics, used for visitor ID, expires after 2 years
Fix: Keep categories in the banner but provide detailed vendor-level declarations in your cookie or consent policy. You can also consider CMPs that help manage and update vendor details automatically, making it easier to keep policies accurate.

Mistake 3: No Manage Consent Option

❌ Consent must be as easy to withdraw as to give. Without a clear and persistent “Manage Consent” option, users cannot revisit or update their preferences after their initial choice.
Fix: Provide a visible and consistent link (for example in the footer or privacy section) that reopens the Consent Management Platform (CMP) preference centre at any time.

Mistake 4: Dark Pattern Styling

❌ Highlighting “Accept All” in bright colours while greying out “Reject All” is manipulative. Regulators view this as nudging users unfairly and users notice.
Fix: Style all consent choices equally to demonstrate respect for user choice and reduce regulatory risk.

Mistake 5: Poor Mobile Experience

❌ On mobile, banners often collapse badly: buttons off-screen, text overlapping or overlays blocking navigation. If users can’t realistically choose, consent is invalid.
Fix: Test CMPs across devices, breakpoints and orientations. Responsive design is not optional.

Technical Implementation

Mistake 6: Consent Not Enforced in Tag Manager

❌ Marketing tags and analytics often fire before consent due to poor CMP–tag manager integration. Under PECR, non-essential services require prior consent – even one rogue hit is non-compliant.
Fix: Integrate CMP signals directly into Google Tag Manager (GTM), Tealium or Adobe Launch. Test acceptance and rejection states in browser consoles and network logs.

Mistake 7: Data Sent Before Consent

❌ Analytics events sometimes fire immediately on page load before the banner appears. This fails the requirement for prior consent.
Fix: Wrap analytics in CMP logic so no hits fire until consent is given. If early initialisation is required, buffer events until the CMP provides a signal.

Mistake 8: Over-Reliance on Auto-Blocking

❌ Auto-blocking can work on simple sites but often fails for complex implementations – breaking functionality or missing edge cases.
Fix: Configure blocking rules manually for enterprise sites. Document them and retest after every release.

Mistake 9: Misconfigured Consent Frameworks and APIs

Google Consent Mode v2, the Meta Conversions API (CAPI) and the Adobe Web Software Development Kit (SDK) are increasingly central to accurate measurement and compliance. Misconfigurations can either result in unlawful data collection or cause you to discard valuable aggregated data.
Fix: Validate that consent signals flow correctly through frameworks and APIs. Use test environments where possible, and confirm not only that restricted data is blocked but also that lawful, aggregated data is still recovered.

Mistake 10: No Consent Testing in QA

❌ New scripts or site changes often bypass CMP controls because release Quality Assurance (QA) excludes consent testing.
Fix: Add consent checks to QA. Validate every new vendor, script or code change against the CMP before release.

Governance & Compliance

Mistake 11: “Set and Forget” Mentality

❌ Consent is treated as a one-time project. Regulations evolve, browsers change and vendors update scripts – meaning yesterday’s compliance may fail tomorrow.
Fix: Schedule quarterly reviews, retest banners across devices and update policies annually.

Mistake 12: Assuming CMP Alone Solves It

❌ A CMP overlay doesn’t equal compliance. The UK GDPR requires consent to be informed, specific and enforceable – this only works if the CMP is correctly configured.
Fix: Integrate your CMP with your tag manager and data layer. Do not assume it works out of the box.

Mistake 13: No Consent Audit Trail

GDPR Article 7(1) requires organisations to demonstrate consent. Many implementations lack logs, leaving no evidence in case of audit.
Fix: Log consent with timestamp, banner version, user choice and user ID or anonymous token. Store securely and consistently.

Mistake 14: Ignoring Regional Differences

❌ A single global banner rarely works. The UK GDPR, EU GDPR and ePrivacy differ from US frameworks like the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
Fix: Adapt CMP configuration by region. A “Do Not Sell” notice may work in California but not under UK/EU consent standards.

Mistake 15: Vendor Transparency Missing

❌ Many privacy or consent policies still state “we use third parties” without naming them. GDPR Article 13 requires disclosure of actual recipients or categories of recipients.
Fix: Update your cookie or consent policy to list key vendors (Google, Meta, TikTok, etc) and describe their role. Keep this list updated.

Conclusion

Getting consent right is about more than ticking a box. It builds trust with users, protects you from regulatory risk and ensures the data you rely on is lawful and accurate.

The organisations that succeed treat consent as an ongoing programme – tested regularly, updated as technology changes and integrated into their wider data strategy.

If you’re unsure where you stand, now is the time to audit and improve.

If you’d like help auditing your consent setup or advice on how to improve it, get in touch with us. We can work with any consent tool such as Usercentrics, OneTrust, CookieYes and others.

Unsure if your consent setup is working as it should?

Our team can review your implementation and highlight where improvements are possible.

Some of the Most Used CMPs We Have Worked With

OneTrust

Enterprise-grade consent & preference management. Widely adopted across large organisations with robust integrations and compliance features.

Visit OneTrust
Usercentrics

Strong EU focus: multi-language support, modern UX, clear dashboards, and granular control.

Visit Usercentrics
CookieBot

Automated cookie scans, global repository and customisable banners. Supports multiple languages and straightforward deployments.

Explore CookieBot
Tealium

Built-in consent features for clients already using Tealium’s tag manager or Customer Data Platform (CDP). Lets you enforce consent logic across client and server flows.

Learn about Tealium