KHO 2026:65: Refusing cookies must be as easy as accepting them

September 10, 2026 | Niko Hannolainen

Refusing cookies must be as easy as accepting them. This is what the Supreme Administrative Court (KHO) held in its precedent decision KHO 2026:65, issued on 27 August 2026. The ruling concerns Otavamedia Oy’s website suomenkuvalehti.fi, but its requirement applies to every Finnish website.

The question was whether the structure of the consent management mechanism steered the user into giving consent in the service provider's favour. Where acceptance sits behind a single highlighted button and refusal behind a menu and a block of text, consent is not based on a free choice.

The ruling confirms the interpretation of the Finnish Transport and Communications Agency (Traficom) and upholds the outcome of the Helsinki Administrative Court's (HAO) decision 638/2026 of 5 February 2026.

Background to the case

Traficom found, in its supervisory decision of 26 April 2024, that the cookie practices of the suomenkuvalehti.fi website breached section 205(1) of the Act on Electronic Communications Services (917/2014, the "Communications Services Act"). Among other things, Traficom ordered the company to amend its consent management mechanism. At the first layer of the mechanism, users needed to be given not only the option to accept all cookies, but also the option to refuse cookies other than those that are strictly necessary.

Otavamedia appealed Traficom's decision to the administrative court, which dismissed the appeal on 5 February 2026. The company sought leave to appeal to the KHO and asked that a preliminary ruling be sought from the Court of Justice of the European Union. The KHO granted leave to appeal but dismissed both the request for a preliminary ruling and the appeal itself.

No option to refuse at the first layer

According to the KHO's reasoning, the first layer of the mechanism contained brief general information along with the buttons “Accept all” and “Settings” (para. 14). The former button was highlighted with a green background. Pressing it took the user straight to the site's content, with all cookies accepted.

First-layer consent management mechanism on the suomenkuvalehti.fi website, 18.10.2023
First-layer consent management mechanism on the suomenkuvalehti.fi website, 18.10.2023

Withholding consent was not possible at the first layer. Nor did that layer indicate how cookies other than those strictly necessary could be refused. The refusal option ("Block all") appeared only at the second layer, buried within an extensive body of information, and the accept button was highlighted there too.

Section 205 of the Communications Services Act links to the General Data Protection Regulation's concept of consent

Under section 205(1) of the Communications Services Act, storing cookies on a user's terminal equipment requires the user's consent, together with clear and comprehensive information about the purpose of that use. The provision implements Article 5(3) of the ePrivacy Directive (2002/58/EY, as amended by directive 2009/136/EY).

That article concerns the confidentiality of communications. Under recital 24 of the Directive, users' terminal equipment and the information stored on it form part of the users' private sphere, which is protected under the European Convention on Human Rights. Consent is therefore required for storing information on terminal equipment and for accessing information already stored there, regardless of whether the operation generates personal data.

The Directive's concept of consent (point (f) of the second paragraph of Article 2) originally referred to the now-repealed Directive 95/46/EC. Under Article 94(2) of the General Data Protection Regulation, that reference must now be read as a reference to the General Data Protection Regulation. The national cookie provision must accordingly be interpreted in light of the General Data Protection Regulation's consent requirements.

Under Article 4(11) of the General Data Protection Regulation, valid consent must be freely given, specific, informed and unambiguous. Under the European Data Protection Board's Guidelines 05/2020 on consent, being freely given requires that the data subject has a genuine choice to accept or decline the terms offered, and that declining causes no detriment (paras. 3 and 13). In the end, the only question before the KHO was whether consent had been freely given.

The issue was asymmetry

Otavamedia argued that Traficom and the HAO had categorically prohibited two-layer consent management mechanisms. The KHO's decision, however, concerned the asymmetry between acceptance and refusal. A two-layer structure as such was permissible.

Acceptance and refusal were out of balance from the user's perspective. Giving consent had been made markedly simple and fast, whereas refusing required locating the settings button, browsing a menu, and finding a less prominent button within an extensive body of information. The KHO stated that “the differences between giving and withholding consent cannot be explained by the company's cited need to provide the user with sufficient and appropriately specific information” (para. 40).

The burden of refusing is assessed against the user's overall situation. Cookie choices have to be made on the great majority of websites, so even a relatively minor extra burden in refusing can steer the user toward giving consent. That effect is stronger the faster acceptance has been made (para. 37).

The relevant test, then, is whether the mechanism steers the user toward consenting given that the same choice is made on the great majority of websites. The triviality of a single extra click on one particular website then loses its significance.

The service provider determines the question, the options, their order and their appearance, while the user can only respond. That is precisely why the design itself is subject to regulation. It follows from the KHO's decision that access to the device must be capable of being denied just as easily as it is granted.

The overall burden of refusal decides the matter

Case C-673/17 (Planet49) concerned a pre-ticked checkbox (para. 56). Case C-61/19 (Orange România) concerned a requirement to fill in a separate form in order to refuse (paras. 50 and 52). Neither case turned on a difference in the number of clicks within one and the same interface, which is what Otavamedia relied on.

From those judgments, the KHO drew a more general criterion: what matters is whether the practical measures affect a person's actual ability to exercise their freedom of choice (para. 36). Because the criterion focuses on the outcome, a pre-ticked box, a separate form and a hidden button are all assessed in the same way.

The same reasoning extends to devices that were not assessed in this decision, such as re-prompting the user repeatedly after refusal, or giving a refusal choice only a short period of validity. The KHO did not require that acceptance and refusal take exactly the same number of clicks. The assessment considered the interface as a whole, asking whether it steered the user toward giving consent by making refusal substantially slower or more cumbersome.

The same devices are identified in the European Data Protection Board's Guidelines 03/2022 on deceptive design patterns. Those guidelines concern social media platforms but note that such patterns also occur in cookie banners.

Freedom to conduct a business and freedom of expression did not defeat Traficom's interpretation

Throughout the proceedings, Otavamedia emphasised that exploiting cookies is essential to the advertising-based funding of domestic journalism. In the company's view, a strict interpretation could divert advertising sales to foreign operators. This, it argued, would infringe the freedom to conduct a business and freedom of expression protected under Article 16 of the EU Charter of Fundamental Rights.

The KHO held that Traficom's decision did not unjustifiably restrict the freedom to conduct a business, nor did it interfere with the dissemination of information protected by freedom of expression, because the decision was based on rules ensuring the protection of users' private life (para. 43). This balancing exercise was not reasoned in any further detail.

The consent requirement is counterbalanced by Articles 7 and 8 of the Charter. The reasoning does not indicate in what circumstances a business's revenue model would be relevant to assessing the validity of consent. The revenue model does not change who holds the power of decision over access to the device.

Checklist for service providers

  1. Can all cookies other than those that are strictly necessary be refused at the first layer?
  2. Does the first layer make clear that refusal is possible?
  3. Are the accept and refuse buttons alike in colour, size, placement and contrast?
  4. How many clicks, and how much reading, does accepting require compared with refusing?
  5. Do the cookies classified as strictly necessary include analytics or advertising measurement?
  6. How soon is a user who has refused asked for consent again?
  7. Who, under the contract, is responsible for the default settings of the consent management software?

What to do now

This decision, together with KHO 2026:64, issued the same day, confirms Traficom's supervisory approach at the highest level. Traficom's future decisions will now rely on this precedent, raising the threshold for challenging them.

If refusal is not possible at the first layer, if the buttons look different from one another, or if the path to accepting is shorter, the mechanism is probably unlawful. All three of these can be checked simply by opening the banner.

Where valid consent has not been obtained, personal data collected through cookies and similar tracking technologies also lacks the processing basis required under the General Data Protection Regulation. In that case, both placing the cookies and processing the data collected through them, for example, for targeted advertising, are unlawful.

We help companies audit their digital services, including by technically reviewing cookie practices and tracking technologies on both websites and mobile applications. Get in touch and we will go through what is worth reviewing in your situation.

Our associate trainee Emma Hermanson took part in writing this article.

Nordic LawPioneer in Web3 and Fintech law