DigitalMANIPULATIVE

Consent Theater

What it is

Cookie banners and permission dialogs built to produce a recordable “yes” rather than an informed, free choice — accept-all in colour, reject buried or absent, “legitimate interest” pre-toggled, and the same prompt repeated until the user gives in.

How it works

The GDPR and the ePrivacy rules require consent that is freely given, specific, informed, and unambiguous, and the Court of Justice held in Planet49 (2019) that a pre-ticked box is none of those. Consent theater satisfies the letter — a dialog appeared, a click was logged — while defeating the point. The design draws on the whole dark-patterns kit: visual asymmetry, a reject option two layers down, hundreds of “partners” toggled on under a “legitimate interest” heading, and a banner that returns on every visit until the user stops fighting. Nouwens and colleagues scraped the consent-management platforms used by the top UK sites in 2020 and found that fewer than one in eight met even minimal legal requirements; in a field experiment, removing the reject button from the first layer raised consent by 22-23 percentage points. Utz and colleagues found that position and nudging drove acceptance, and Matte, Bielova and Santos found platforms that registered consent before the user chose, or after the user refused. The mechanism is fatigue plus asymmetry: every acceptance costs one click, every refusal costs several, and the prompt is repeated until the cheaper path wins. France's CNIL fined Google and Facebook in 2022 precisely for making refusal harder than acceptance.

Real-world examples

  • The CNIL's January 2022 fines of €150 million against Google and €60 million against Facebook for cookie banners on which accepting took one click and refusing took several.
  • Nouwens et al. (2020) found that only 11.8% of the consent-management platforms on the top 10,000 UK websites met minimal GDPR requirements (explicit consent, reject as easy as accept, no pre-ticked boxes).
  • Matte, Bielova and Santos (2020) found sites using the IAB consent framework that stored a positive consent signal before any choice was made, or that ignored a refusal.
  • Meta's 2023 “pay or consent” model for EU users — pay a subscription or accept behavioural advertising — drew an April 2024 EDPB opinion that a binary choice of that kind will in most cases fail the “freely given” test for large platforms.

Ethical guidelines

  • Reject must be as easy as accept, on the same layer, in the same visual weight; if a design would lose consent by meeting that standard, the consent it was getting was not consent.
  • No pre-toggled purposes, no “legitimate interest” switch-ons hidden under a heading, no re-prompting after a refusal for a reasonable period.
  • Log refusals as carefully as acceptances, and act on them — a banner that records “no” and drops the cookie anyway is fraud, not friction.
  • The EDPB's 2023 cookie-banner taskforce report and its deceptive-design guidelines set the baseline; DSA Article 25 extends the prohibition on impairing free choice to platform interfaces generally.

How to defend against it

  • Automate your refusal: install Consent-O-Matic (Aarhus University) or enable your browser's cookie-banner handling and the EasyList Cookie filter in uBlock Origin, so the banner's design never reaches your decision.
  • Turn on the Global Privacy Control signal in a browser that supports it; sites subject to California and Colorado law must honor it, and it removes the dialog from the loop.
  • When you must click, find “Reject all” or “Manage settings” first; if there is no reject on the first layer, close the tab or close the banner — closing is not consent, and the site cannot lawfully treat it as such.
  • Block third-party cookies at the browser level (Firefox and Safari do it by default) so that a consent you did not give cannot be acted on anyway.
  • Report banners with no first-layer reject or with pre-toggled purposes to your data-protection authority or to noyb.eu, which has filed hundreds of such complaints; in the EU keep a screenshot with the date.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Nouwens, M., Liccardi, I., Veale, M., Karger, D., & Kagal, L. (2020). Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence. Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems
    The 11.8% compliance figure and the field experiment on how removing the first-layer reject button and using nudges changes consent rates.
  2. Utz, C., Degeling, M., Fahl, S., Schaub, F., & Holz, T. (2019). (Un)informed Consent: Studying GDPR Consent Notices in the Field. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS)
    Field evidence that banner position, nudging, and pre-selection drive acceptance rates.
  3. Matte, C., Bielova, N., & Santos, C. (2020). Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from the IAB Europe Transparency and Consent Framework. Proceedings of the 2020 IEEE Symposium on Security and Privacy
    The finding that some consent platforms registered positive consent before the user chose or after a refusal.
  4. Court of Justice of the European Union (2019). Bundesverband der Verbraucherzentralen v. Planet49 GmbH, Case C-673/17. Judgment of 1 October 2019
    The ruling that a pre-ticked checkbox does not constitute valid consent to cookies.
Last reviewed
Suggest a correction

Detect Consent Theater in any text

Paste any message, email, or article into our free Manipulation Detector to see if Consent Theater or other techniques are being used on you.

Related Articles