Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Deceptive Design Patterns

Dark Patterns

Also known as: Deceptive Patterns, Deceptive Design Patterns
Simply put

Dark patterns are user interface designs that are deliberately crafted to trick or manipulate people into taking actions they might not otherwise choose, typically to benefit the company behind the design. In a cookie consent context, this can mean making it much easier to accept tracking than to decline it. The term is increasingly referred to as 'deceptive patterns' by some practitioners.

Formal definition

Dark patterns (also termed deceptive patterns or deceptive design patterns) are user interface and interaction designs engineered to deceive or manipulate users into behavior that aligns with the operator's interests rather than the user's own, often contrary to the user's actual preferences. In cookie consent management, dark patterns may undermine the validity of consent, which in most EU jurisdictions must be freely given, specific, informed, and unambiguous under the GDPR; examples commonly discussed include visually deemphasized reject options, pre-selected non-essential cookie choices, and confusing or asymmetric consent flows. The evidence provided defines the concept generally and does not establish specific regulatory tests, enforcement thresholds, or an exhaustive taxonomy of which design practices are considered unlawful in a given jurisdiction, so the legality of any particular pattern depends on applicable law, competent authority guidance, and the specific facts, which fall outside the scope of this definition.

Why it matters

Dark patterns matter in the cookie consent context because they strike directly at the validity of consent. In most EU jurisdictions, consent to place or access non-essential cookies must be freely given, specific, informed, and unambiguous under the GDPR, and it must result from a clear affirmative action. Interface designs that manipulate users toward acceptance, for example by visually deemphasizing a reject option, pre-selecting non-essential choices, or building asymmetric consent flows, can undermine each of those requirements. Where a design steers users into a choice they would not otherwise have made, the resulting consent may not be genuine, which can expose an organization to the risk that its legal basis for processing collapses.

For privacy officers, legal counsel, and design teams, the practical significance is that a technically functional consent banner is not the same as a compliant one. The presence of an accept and a reject button does not, on its own, resolve whether the flow is fair; the manner in which options are presented can itself be scrutinized. Because dark patterns sit at the intersection of user experience design and legal compliance, they require collaboration between disciplines that do not always share the same vocabulary, hence the shift among some practitioners toward the term "deceptive patterns" to describe the same phenomenon.

It is important to be precise about the limits of what can be stated here. The evidence available defines the concept generally and does not establish specific regulatory tests, enforcement thresholds, or an exhaustive list of which patterns are unlawful in any particular jurisdiction. Whether a given design crosses the line depends on applicable law, competent authority guidance, and the specific facts, and enforcement positions continue to evolve. Organizations should treat the identification and remediation of dark patterns as a matter of ongoing legal judgment rather than a one-time checklist exercise.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for the lawfulness of processing need to assess whether consent collected through a banner or preference center is genuinely freely given and unambiguous. Dark patterns can undermine the validity of that consent, so identifying and remediating manipulative designs is part of maintaining a defensible legal basis. The specific standards and enforcement expectations vary by jurisdiction and depend on competent authority guidance.
Legal counsel and compliance teams
Counsel advising on cookie consent must evaluate whether interface designs align with the requirement that consent be freely given, specific, informed, and unambiguous in EU jurisdictions, while recognizing that other regimes may apply different tests. Because the legality of a particular pattern depends on applicable law and the specific facts, this is an area calling for case-by-case legal judgment rather than reliance on the mere presence of accept and reject controls.
UX designers and web developers
The people who build consent interfaces control the defaults, visual hierarchy, and flow structure that determine whether a design nudges or deceives users. Designers should be aware that choices such as deemphasizing a reject option, pre-selecting non-essential categories, or adding friction to declining can constitute deceptive patterns, and should coordinate with legal and privacy teams. Some practitioners now use the term 'deceptive patterns' to describe this design category.
Marketing and analytics stakeholders
Teams that rely on tracking technologies for analytics and advertising have an interest in maximizing opt-in rates, which can create pressure toward manipulative design. Understanding what constitutes a dark pattern helps these stakeholders distinguish legitimate optimization from designs that may compromise the validity of the consent their data collection depends on.

Inside Dark Patterns

Interface Interference
Design choices that visually or structurally privilege one option over another, such as making an 'Accept all' button prominent while the 'Reject all' or rejection option is hidden, greyed out, or requires additional clicks. This can undermine the requirement that consent be freely given and unambiguous under the GDPR in EU jurisdictions.
Pre-selection and Default Settings
Presenting non-essential cookies (such as analytics or advertising) as already enabled through pre-ticked boxes or defaulted-on toggles. Pre-ticked boxes are widely considered non-compliant in the EU because valid consent requires a clear affirmative action.
Nagging and Repeated Prompting
Repeatedly presenting consent requests to users who have declined, pressuring them to change their choice. This can undermine the 'freely given' standard for consent in EU jurisdictions.
Obstruction and Asymmetric Effort
Making it substantially harder to refuse or withdraw consent than to grant it, for example by burying rejection controls in multiple layers of menus. In most EU jurisdictions, withdrawing consent is generally expected to be as easy as giving it.
Misleading or Emotionally Loaded Language
Wording, colour, or framing that steers users toward acceptance (sometimes called 'confirmshaming'), or that misrepresents the consequences of choices. This can compromise the 'informed' component of valid consent.
False Hierarchy and Forced Action
Techniques including cookie walls that condition access to a service on acceptance, which are widely regarded as problematic in the EU where consent must be freely given. Note that requirements differ under frameworks such as US state privacy laws, which often rely on opt-out mechanisms rather than opt-in.

Common questions

Answers to the questions practitioners most commonly ask about Dark Patterns.

Does using a dark pattern automatically make my cookie consent unlawful?
Not automatically, but it puts consent at serious risk. The presence of a dark pattern is not a separate offence in itself under most EU frameworks; rather, it undermines whether the resulting consent meets the GDPR standard of being freely given, specific, informed, and unambiguous. If a design nudges, confuses, or pressures users into accepting cookies, data protection authorities in many EU jurisdictions may treat the consent as invalid. However, whether a particular design crosses the line depends on the specific facts, the wording, the visual presentation, and evolving regulatory guidance, so no blanket rule applies. Assessments also differ outside the EU, particularly in US states that rely on opt-out rather than opt-in models.
If my consent banner is technically compliant, does that mean it is free of dark patterns?
Not necessarily. A banner can satisfy formal requirements, such as offering an accept and a reject option, while still using design choices that steer users toward acceptance, for example through color contrast, button prominence, misleading labels, or added friction on the reject path. Technical presence of the right options and genuinely neutral, non-manipulative design are distinct questions. In many EU jurisdictions, regulators have signalled that manipulative design can invalidate otherwise formally correct consent, but interpretations vary and depend on the overall user experience rather than any single element.
How can I tell whether the reject and accept options on my banner are balanced enough?
A common practical approach is to assess whether accepting and rejecting cookies require comparable effort and receive comparable visual weight. This may include comparing the number of clicks, the prominence, size, and color of buttons, and the clarity of the labels. Designs that hide the reject option in a secondary menu, or make it visually less noticeable, are more likely to be viewed as steering users in several EU jurisdictions. That said, there is no single quantified standard, and what regulators consider acceptable can evolve, so treat balance as a matter of overall neutrality rather than a fixed formula. This is general guidance and does not replace legal review of your specific implementation.
What design elements should I review to reduce the risk of dark patterns in a consent interface?
Practical areas to review typically include button styling and contrast, the wording and framing of choices, the placement and accessibility of the reject or manage-preferences options, the use of pre-selected settings, and any friction added to less profitable choices such as declining. It is also worth reviewing emotionally loaded or guilt-inducing language and repeated re-prompting after a user has declined. Because these technologies and designs may also apply to pixels, local storage, SDKs, and similar tracking methods, review the surrounding interface for those as well. None of these checks guarantees compliance; they support a broader assessment that should involve legal judgment and, where relevant, local regulatory guidance.
Can a consent management platform prevent dark patterns for me?
A CMP can help by providing configurable templates, balanced default layouts, and options for reject and preference controls, but it does not by itself guarantee that your interface is free of dark patterns. Many CMPs allow extensive customization, so an organization can still configure a manipulative design within a compliant tool. Responsibility for the final user experience rests with the organization deploying it. Use a CMP as a support for neutral design, but validate the actual configuration against applicable requirements and, where appropriate, legal review, rather than assuming the tool ensures compliance.
How should we document that our consent interface avoids manipulative design?
Organizations commonly keep records of their consent interface design decisions, including screenshots or captures of banner versions, rationale for button placement and wording, and any internal or external review of neutrality. This supports broader consent record-keeping and accountability expectations that apply in many EU jurisdictions. Documenting design testing, changes over time, and how reject and accept paths were balanced can help demonstrate good-faith effort if questioned. There is no universal prescribed format for this documentation, and requirements differ across the EU, the UK, and individual US states, so tailor record-keeping to the regimes that apply to your users.

Common misconceptions

As long as a consent banner offers a reject option somewhere, the design cannot be a dark pattern.
The mere presence of a reject option is generally not sufficient in the EU. If accepting is visually prominent while rejecting is obscured, requires more effort, or is buried in additional layers, the design may still undermine the requirement that consent be freely given and unambiguous. The relative ease and clarity of each choice matters, not just its existence.
Dark pattern rules are uniform across all jurisdictions, so a single banner design works everywhere.
Obligations vary between the EU, the UK, and individual US states such as California under the CCPA and CPRA. EU regimes generally require opt-in consent through a clear affirmative action, while several US state frameworks rely on opt-out approaches. A design acceptable under one regime may not satisfy another, so scope should be assessed per jurisdiction.
Using a consent management platform (CMP) automatically means the interface is free of dark patterns.
A CMP supports consent collection and record-keeping but does not by itself guarantee compliance. The specific configuration, wording, colour, and layout chosen within the tool can still create interface interference or asymmetry. Legal judgment is required to assess whether a given implementation meets applicable standards.

Best practices

Present accept and reject options with equal prominence at the same layer, so refusing non-essential cookies is generally as easy as accepting them, consistent with EU expectations.
Avoid pre-ticked boxes and default-on toggles for non-essential cookies, since valid consent in the EU requires a clear affirmative action.
Use neutral, plain-language wording and visual design that does not steer users toward acceptance or shame them for declining, supporting the informed and freely given standards.
Make withdrawing consent as straightforward as giving it, and avoid repeatedly re-prompting users who have already declined.
Assess the interface separately for each applicable regime (for example the EU, the UK, and relevant US states such as California), because opt-in and opt-out expectations differ and a single design may not satisfy all of them.
Treat any CMP or consent tool as support rather than a guarantee of compliance, and have privacy and legal reviewers evaluate the actual configuration, wording, and layout against current data protection authority guidance.
Application Security Isn’t Optional Anymore.