Why do websites ask you to accept cookies in every country comes down to where you happen to be standing, not what the website decides on its own. The same site can show a mandatory banner in France and nothing at all in Japan, because it is reading your location and applying whichever law covers that spot on the map.
The Short Answer: It’s the Law, But Which Law Depends on Where You Are
Cookie consent is the process of a website asking permission before it stores tracking cookies on your device. There is no single global cookie law. Instead, over 120 countries now have some form of data protection law, and each one sets different rules for when a site must ask, what counts as valid consent, and what happens if it does not ask. A website with visitors worldwide has to detect where each visitor is and switch its banner behavior accordingly, using geo-targeting, the practice of showing different content based on a visitor’s detected location.
Cookie Consent Laws by Country: The Global Map
Cookie consent laws by country split into three basic models:
- Opt-in countries: the site must get your permission before setting tracking cookies. This includes the EU under GDPR and the ePrivacy Directive, the UK, Brazil under LGPD, South Africa under the POPI Act, and Québec under Law 25.
- Opt-out countries: the site can track by default but must give you a way to stop it, typically a “Do Not Sell or Share My Personal Information” link. California’s CCPA and CPRA work this way, and several other US states have adopted similar models.
- No dedicated law: some countries have no comprehensive cookie or privacy law at all, so sites track freely with no banner requirement.
GDPR, the EU’s General Data Protection Regulation, is the reason cookie banners became common worldwide, because many global sites built one banner system and applied it everywhere rather than maintaining separate code for each region. The ePrivacy Directive is the older, narrower EU rule that specifically covers cookies and requires prior consent, while GDPR covers personal data more broadly. China’s PIPL adds another layer for sites with Chinese visitors, with its own consent and data localization requirements.
For a broader look at what personal data actually means in these laws, see GDPR explained for website visitors.
Why the Same Website Asks in France but Not in Japan
This is the question top guides skip. A site detects your IP address, matches it to a country, and only shows a full consent banner where the law requires opt-in tracking. France has strong GDPR enforcement and a high rate of visible cookie banners, since French regulators actively pursue non-compliant sites. Japan’s privacy law does not require the same opt-in banner model, so banner prevalence there is far lower. The site itself has not changed. Only the legal trigger has.
What Happens When You Click Reject
What happens if you reject cookies is the part most pages never test. Rejecting is supposed to stop the site from setting tracking cookies, but research into real-world compliance has found many sites keep sending tracking cookies after a rejection, and the rate is often worse for visitors outside the EU, where enforcement is weaker. Some sites treat “reject” as a formality rather than an instruction, particularly when a consent management platform, the software behind most cookie banners, is misconfigured or deliberately set loose.
Third-party cookies, the tracking cookies set by advertisers rather than the site you’re visiting, are the main target of these laws, since they are what allow behavioral advertising, ads built from your browsing activity across many sites. A rejected banner is supposed to block third-party cookies specifically, first-party site functionality cookies are typically unaffected either way.
The Dark Pattern Problem: Why Rejecting Feels Harder Than Accepting
Dark patterns are interface designs built to push you toward a choice the site prefers, and cookie banners are one of the most studied examples. A common pattern makes “Accept All” a single bright button while “Reject” is a small link buried in settings, sometimes requiring several extra clicks. French regulator CNIL fined Google and Meta a combined penalty over €150 million for exactly this, ruling that rejecting cookies must be as easy as accepting them. Spain’s SEAT was fined €20,000 in a smaller but similar enforcement case. Acceptance rates vary sharply by how a banner is built rather than by how people actually feel about tracking, with poorly designed banners in some markets pushing accept rates well above what a neutral design produces.
The New Pay or Consent Model
A newer trend, sometimes called “pay or consent,” gives users a choice between accepting tracking cookies or paying a subscription fee to use the site without them. This model grew after the UK’s Information Commissioner’s Office signaled it would tolerate the approach under certain conditions, and several major European publishers and platforms have since adopted versions of it. It reframes consent as a transaction: your data has a price, and now some sites are naming it directly instead of hiding it inside a free service.
You can compare how these tracking mechanics interact with browser level protections in how to browse the internet privately, and see what Incognito mode does and does not stop in what does incognito mode do and what it doesn’t.
FAQs
Why does the same website ask me for cookies every time I visit?
If you clear your cookies or use a browser that automatically deletes them, the site loses the record that you already responded, so it asks again on your next visit.
Can I just ignore the cookie popup?
Ignoring or scrolling past it usually leaves the site’s default setting in place, which on many non-EU sites means tracking cookies are already active before you interact with the banner at all.
Why are cookie banners different in the US versus Europe?
Europe runs on an opt-in model, where consent is required before tracking starts. Most of the US runs on an opt-out model, where tracking is allowed by default and you have to actively decline it.
Do websites actually get fined for skipping consent?
Yes. Regulators have issued real penalties, including CNIL’s fines against Google and Meta exceeding €150 million and a €20,000 fine against SEAT in Spain, both for consent violations tied to how their banners were designed.
