Accessibility

An inaccessible consent banner undermines valid consent

If a visitor using a keyboard or screen reader cannot reach your reject button, the consent your banner records is hard to call freely given.

Accessibility 6 min read The UserGuard team

Key takeaways
  • If accept is reachable by keyboard and reject is not, reject is not as easy as accept — the accessibility defect has become a consent defect.
  • Banners break in three places: keyboard reach (Tab, Enter, Space), focus moved into the dialog and returned on close, and contrast — 4.5:1 on text, 3:1 on controls.
  • No widget makes a site ADA compliant; the FTC’s 2025 order against an overlay vendor is the cautionary tale, and the fixing still happens in your markup.

The banner is the first thing anyone meets

Most consent banners load before anything else on the page. They open as a modal, they take focus, and they sit between the visitor and the content. For a sighted mouse user that is a two-second annoyance. For someone navigating by keyboard or screen reader, it is the first interactive element on your site, and it is frequently the last one they can reach.

Picture the common failure. The dialog appears. Focus stays behind it on the page body. The screen reader announces nothing, because the container has no role and no accessible name. Tab cycles through links the visitor cannot see. Somewhere in there are two buttons, one labeled with an icon and no text.

The visitor now has three options: guess, leave, or accept whatever is easiest to dismiss. Two of those are bad for the visitor. All three are bad for you, because the row you just wrote to your consent log describes a decision nobody actually made.

Freely given assumes the visitor could refuse

Under GDPR and the ePrivacy rules, consent must be freely given, specific, informed, and unambiguous, and nothing non-essential may fire before it. Regulator guidance, including from the EDPB, supplies the rule most teams know in practice: rejecting must be as easy as accepting, and withdrawing must be as easy as giving. That equal-prominence rule comes from guidance rather than the GDPR text itself, and none of this is legal advice.

Now apply that standard to an interface a person cannot operate. If accept is reachable and reject is not, reject is not as easy as accept; it is impossible. If the dialog never announces itself, it is hard to argue the visitor was informed. If the only exit is a click, the choice is not free. The accessibility defect has become a consent defect.

Article 7(1) requires you to be able to demonstrate that a visitor consented. That is a records question, and a records question has an uncomfortable follow-up: can you also demonstrate the person could have said no? A log full of accepts collected through an unusable dialog is evidence, just not the kind you want.

The UK runs a parallel track: UK GDPR plus PECR, enforced by the ICO, now diverging under the Data (Use and Access) Act 2025. That act raises PECR fines to UK GDPR levels, which turns a cookie-banner problem from a modest line item into a serious one. If the banner is unusable for part of your audience, your exposure scales with that ceiling.

At the keyboard first, and keyboard operability is the floor. Every control in the banner — accept, reject, preferences, each category toggle, close — has to be reachable with Tab and operable with Enter or Space, in an order that matches what is on screen. Custom divs styled to look like buttons are the usual culprit. They look right, they respond to clicks, and they are invisible to everything else.

Focus management is the part teams skip. When the dialog opens, focus should move into it; while it is open, focus should stay inside it; when it closes, focus should return where the visitor was. The dialog needs a role and an accessible name. Category toggles need real labels, real states, and text saying what switching them off does.

Contrast is where design and compliance argue. The reject path is often the low-contrast one: gray on gray, a hairline outline, a link dressed as a footnote. WCAG 2.1 AA asks for 4.5:1 on body text and 3:1 on interface components. Equal-prominence guidance asks for something similar in spirit. When both point at the same button, notice.

  • Keyboard: every control reachable by Tab, operable by Enter or Space
  • Focus: moved into the dialog on open, returned to the trigger on close
  • Contrast: 4.5:1 on text, 3:1 on controls, including reject

Is the consent banner inside your accessibility scope?

Yes. A consent banner is part of your website, inside the same accessibility scope as everything else. In the US, WCAG 2.1 AA is the working benchmark for web accessibility claims. In Europe, the European Accessibility Act has applied since June 2025, benchmarked by EN 301 549, covering a broad slice of consumer-facing digital services. The banner gets no exemption for being small.

Be blunt about overlays: no widget makes a site ADA compliant. The FTC's 2025 order against an accessibility overlay vendor is the cautionary tale, and the lesson generalizes. Claims of automatic compliance do not survive contact with a regulator. Tools help you find and prioritize problems. The fixing still happens in your markup.

The opt-out world is quieter about banners and louder about signals. CCPA/CPRA is an opt-out regime: notice at collection, a "Do Not Sell or Share My Personal Information" mechanism, and mandatory honoring of Global Privacy Control. The enforcement action most relevant to interface design is Honda's $632,500 settlement in 2025, which turned in part on an opt-out flow that asked more of the person leaving than of the person staying — a burden that lands hardest on the users who already find your interface hardest to operate.

As of 2026, nineteen or more comprehensive state privacy laws are in force, with Indiana, Kentucky, and Rhode Island among the recent additions, and twelve states require honoring universal opt-out signals. Maryland bans the sale of sensitive data outright. Which of these reach you depends on your footprint and your data; treat this as orientation, not legal advice. The signal requirement carries an accessibility dividend: GPC asks nobody to see, tab to, or click anything.

What we are building into the banner

UserGuard is newly launched, so read this as design intent rather than a track record. The banner is built to be operable by keyboard alone, to trap focus while the centered modal is open, to announce itself to assistive technology, to pre-select neither choice, and to draw reject as the same button as accept, in the same color, size, and weight. Accessibility is not a separate line item here; an accessibility widget is included with every site.

On the record-keeping side, the evidence gate is the piece we care most about. It is designed so a record only becomes a cookie when there is a Set-Cookie header, an HTTP-only record, or a document.cookie value behind it. Everything else stays labeled context. Consent events are tied to site, banner version, region, and timestamp, and export to CSV. A banner that records a choice while sharing continues is its own failure mode, roughly what Healthline's $1.55 million settlement in 2025 turned on.

For Google advertising and measurement features covering EEA and UK users, Consent Mode v2 has been required since March 2024, and UserGuard is designed to pass all four signals: ad_storage, analytics_storage, ad_user_data, and ad_personalization. We are not a Google-certified CMP and we are not IAB TCF validated. TCF is on the roadmap, not in the product.

Pricing is $10 per site per month, with automatic volume discounts as you add sites — current rates are on the pricing page. Every feature sits on every tier. GPC honoring and geo-targeting are never paywalled, because charging extra for the one opt-out path that works without a mouse would be a strange thing to do.

Go deeper: privacy + accessibility on one script · the accessibility widget

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started → 30-day money-back guarantee · cancel anytime