Consent UX

Cookie banner dark patterns are an enforcement problem

Buried reject buttons and pre-ticked boxes are not a style debate. They are what regulators screenshot, and what coerced consent data hides.

Consent UX 5 min read The UserGuard team

Key takeaways
  • A reject control belongs on the first layer at accept’s visual weight and click count — an expectation set by regulator guidance, not GDPR’s own text.
  • CCPA and CPRA are opt-out regimes built on notice and honored GPC signals, not prior-consent banners; the failure there is an opt-out that quietly does nothing.
  • A coerced accept is a data-quality problem — an accept rate you can explain is worth more than a high one you engineered.

Banner design is now evidence

The cookie banner is one of the few interfaces on a site that a regulator will screenshot. Design choices that would be harmless on a pricing page — a low-contrast secondary button, a nudge in the microcopy, one extra click — become evidence when the thing being designed is consent. Dark patterns in banners are not a taste argument. They are a documented enforcement theme.

New York's attorney general settled with Todd Snyder for $345,178 in 2025 over a misconfigured banner that let tags fire regardless of what visitors chose. Sephora settled with California for $1.2 million in 2022 after ignoring Global Privacy Control signals, and California's privacy regulator ordered Honda to pay $632,500 in 2025 over opt-out flows that asked more of people leaving than of people staying.

None of those turned on whether the banner looked good. They turned on whether the interface did what it claimed, and whether the easy path and the honest path were the same path. This is general information rather than legal advice, but the pattern across the actions is consistent enough to design around.

The reject button regulators expect to see

Under GDPR and ePrivacy, non-essential cookies require prior opt-in: nothing fires before a clear affirmative act. The companion expectation — that rejecting is as easy as accepting — does not appear in the GDPR text itself. It comes from regulator guidance, including EDPB work on deceptive design, and from national authorities who have been ruling on banner layouts for years.

In practice that means the reject control sits on the first layer, at the same visual weight, reachable in the same number of clicks as accept. A banner offering "Accept All" as a filled button and "Manage preferences" as gray text two shades off the background is the exact configuration that keeps turning up in enforcement summaries.

Withdrawal gets the same treatment. If giving consent took one click, taking it back should not take a support ticket. Article 7(1) also requires you to be able to demonstrate that consent was given, which means the record you keep matters as much as the button you ship.

  • Reject on the first layer, never behind "Manage preferences"
  • Same color, same size, same contrast, same click count as accept
  • Withdrawal reachable from any page, not buried in a policy

Pre-ticked boxes are the oldest of the group and the least defensible. Consent has to be an affirmative act, and a checkbox someone failed to clear is not one. The same logic covers toggles that default to on, legitimate-interest switches pre-enabled for advertising vendors, and implied-consent language that treats continued scrolling as agreement.

Confirmshaming is the copy problem: "No thanks, I prefer irrelevant ads," or a decline option written to make the visitor feel cheap. It works, briefly, and it reads badly in a complaint file. Emotional pressure applied at the moment of choice undercuts any later argument that the choice was freely given.

Cookie walls are the genuinely unsettled one. Blocking all access unless a visitor accepts tracking has drawn sustained criticism in the EU, and consent-or-pay models remain contested rather than settled. The UK runs on UK GDPR plus PECR, and the calculus there shifted with the Data (Use and Access) Act 2025, which raised PECR penalties to UK GDPR levels — ICO cookie enforcement now carries much larger numbers.

Opt-out states fail in a different place

US comprehensive privacy laws work differently, and conflating them is its own risk. CCPA and CPRA are opt-out regimes: notice at collection, a working "Do Not Sell or Share My Personal Information" mechanism, and mandatory honoring of Global Privacy Control. California requires no prior-consent banner, apart from opt-in before selling or sharing data on consumers under sixteen, so calling it a banner law points the work in the wrong direction.

As of 2026, 19+ comprehensive state laws are in force, with Indiana, Kentucky and Rhode Island among the recent additions, and twelve states requiring universal opt-out signals like GPC to be honored. Maryland goes further and bans the sale of sensitive data outright. The dark pattern here is rarely a buried button; it is an opt-out that quietly does nothing.

That is what Healthline's $1.55 million settlement with California in 2025 turned on — sharing that continued after people had opted out. A signal your interface acknowledges but your tag stack never acts on is worse than no handling at all, because it creates a durable record of a promise you did not keep. Confirm your own obligations with counsel; the failure mode is the same everywhere.

A real reject button produces better data

Here is the unglamorous business case. A coerced accept is a data-quality problem. It pads your consented population with people who never wanted to be measured, and feeds analytics and ad platforms sessions that behave nothing like genuine interest. An accept rate you can explain is worth more than a high one you engineered, because you can act on the first.

Google Consent Mode v2 has been required since March 2024 for Google advertising and measurement features covering EEA and UK users, and it carries four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. Wiring those to honest choices gives modeling something real to work from. Wiring them to a banner nobody can decline gives you noise with a compliance story attached.

UserGuard is built around that record. Its evidence gate counts something as a cookie only when there is a Set-Cookie header, an HTTP-only record, or a document.cookie value; everything else is kept as labeled context, which is designed to keep your disclosures tied to what actually runs. Consent events are tied to site, banner version, region and timestamp, and export to CSV.

We are newly launched, so that describes how the product is designed rather than a long track record. UserGuard is not a Google-certified CMP and is not IAB TCF validated; TCF is roadmap only. Pricing is $10 per site per month with automatic volume discounts (current rates), an accessibility widget included per site, and GPC and geo-targeting never behind a tier.

Go deeper: the UserGuard cookie banner · symmetric consent UX, by design

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started → 30-day money-back guarantee · cancel anytime