Consent Theater
What it is
Cookie banners and permission dialogs built to produce a recordable “yes” rather than an informed, free choice — accept-all in colour, reject buried or absent, “legitimate interest” pre-toggled, and the same prompt repeated until the user gives in.
How it works
Real-world examples
- •The CNIL's January 2022 fines of €150 million against Google and €60 million against Facebook for cookie banners on which accepting took one click and refusing took several.
- •Nouwens et al. (2020) found that only 11.8% of the consent-management platforms on the top 10,000 UK websites met minimal GDPR requirements (explicit consent, reject as easy as accept, no pre-ticked boxes).
- •Matte, Bielova and Santos (2020) found sites using the IAB consent framework that stored a positive consent signal before any choice was made, or that ignored a refusal.
- •Meta's 2023 “pay or consent” model for EU users — pay a subscription or accept behavioural advertising — drew an April 2024 EDPB opinion that a binary choice of that kind will in most cases fail the “freely given” test for large platforms.
Ethical guidelines
- ●Reject must be as easy as accept, on the same layer, in the same visual weight; if a design would lose consent by meeting that standard, the consent it was getting was not consent.
- ●No pre-toggled purposes, no “legitimate interest” switch-ons hidden under a heading, no re-prompting after a refusal for a reasonable period.
- ●Log refusals as carefully as acceptances, and act on them — a banner that records “no” and drops the cookie anyway is fraud, not friction.
- ●The EDPB's 2023 cookie-banner taskforce report and its deceptive-design guidelines set the baseline; DSA Article 25 extends the prohibition on impairing free choice to platform interfaces generally.
How to defend against it
- ►Automate your refusal: install Consent-O-Matic (Aarhus University) or enable your browser's cookie-banner handling and the EasyList Cookie filter in uBlock Origin, so the banner's design never reaches your decision.
- ►Turn on the Global Privacy Control signal in a browser that supports it; sites subject to California and Colorado law must honor it, and it removes the dialog from the loop.
- ►When you must click, find “Reject all” or “Manage settings” first; if there is no reject on the first layer, close the tab or close the banner — closing is not consent, and the site cannot lawfully treat it as such.
- ►Block third-party cookies at the browser level (Firefox and Safari do it by default) so that a consent you did not give cannot be acted on anyway.
- ►Report banners with no first-layer reject or with pre-toggled purposes to your data-protection authority or to noyb.eu, which has filed hundreds of such complaints; in the EU keep a screenshot with the date.
From the Defense Playbook
On any checkout, sign-up, or consent screen, read each checkbox and toggle before you continue, noting whether it is already ticked and whether ticking means yes or no, because defaults and confusing wording are how extras, marketing consent, and data sharing are obtained from people who never chose them.
When an interface tricks you (a hidden charge, a fake countdown, a cancellation maze, consent you never gave), document it and report it to the regulator and the platform, because enforcement against deceptive design is driven by complaint data and one documented report protects people who would never have spotted the trick.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Nouwens, M., Liccardi, I., Veale, M., Karger, D., & Kagal, L. (2020). Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence. Proceedings of the 2020 CHI Conference on Human Factors in Computing SystemsThe 11.8% compliance figure and the field experiment on how removing the first-layer reject button and using nudges changes consent rates.
- Utz, C., Degeling, M., Fahl, S., Schaub, F., & Holz, T. (2019). (Un)informed Consent: Studying GDPR Consent Notices in the Field. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS)Field evidence that banner position, nudging, and pre-selection drive acceptance rates.
- Matte, C., Bielova, N., & Santos, C. (2020). Do Cookie Banners Respect my Choice? Measuring Legal Compliance of Banners from the IAB Europe Transparency and Consent Framework. Proceedings of the 2020 IEEE Symposium on Security and PrivacyThe finding that some consent platforms registered positive consent before the user chose or after a refusal.
- Court of Justice of the European Union (2019). Bundesverband der Verbraucherzentralen v. Planet49 GmbH, Case C-673/17. Judgment of 1 October 2019The ruling that a pre-ticked checkbox does not constitute valid consent to cookies.
Related Articles
Dark Patterns in UX: How Apps Manipulate Your Behavior
Subscription traps, misleading interfaces, and engineered addiction. Understanding the persuasion techniques built into the apps you use every day.
OSINT for Beginners: Open Source Intelligence Explained
Open Source Intelligence (OSINT) uses publicly available data to gather actionable insights. Here is a beginner-friendly guide to what OSINT is and how it is used.