Enforcement

Dark Patterns in Cookie Banners: A Growing GDPR Risk

European regulators have made it unmistakably clear: manipulative cookie banner design is not a grey area. It is a violation that carries nine-figure fines. In 2025 alone, the CNIL levied €475 million in penalties against Google and SHEIN for deceptive consent practices. Here is everything you need to know about dark patterns, the enforcement cases that define the rules, and how to ensure your own banner is compliant.

Definition

What Are Dark Patterns?

Deceptive design techniques that manipulate users into making choices they would not otherwise make.

The term “dark pattern” was coined by UX researcher Harry Brignull in 2010 to describe user interface designs that deliberately trick or manipulate people into taking actions that benefit the business at the user’s expense. In the context of cookie consent, dark patterns are design techniques used to steer visitors toward accepting all cookies — including advertising and tracking cookies — rather than making a genuine, informed choice. They exploit cognitive biases, visual hierarchies, and the natural tendency of users to follow the path of least resistance.

Dark patterns are not merely bad UX. They are a deliberate subversion of the consent mechanism that the GDPR and ePrivacy Directive require. Under GDPR Article 4(11), consent must be “freely given, specific, informed and unambiguous.” The European Data Protection Board (EDPB) has issued comprehensive guidelines — most notably Guidelines 3/2022 on Dark Patterns in Social Media Platform Interfaces — that define manipulative design as a direct obstacle to valid consent. When a cookie banner uses dark patterns, the consent collected through that banner is legally void. Every cookie set on the basis of that invalid consent constitutes an independent violation.

The practical implication is severe. If your consent banner uses dark patterns and your website receives 500,000 visitors per month, you are potentially committing 500,000 consent violations per month. This is precisely the kind of calculation that led the CNIL to issue its record-breaking fines. Regulators are no longer interested in whether you intended to manipulate users. They are interested in whether your banner design effectively steers users toward acceptance. If the design makes it easier, faster, or more intuitive to accept cookies than to reject them, you have a dark pattern problem.

Taxonomy

Eight Types of Dark Patterns in Cookie Banners

Regulators have identified and penalized each of these patterns. Many cookie banners use several simultaneously.

01

Asymmetric Choices

The “Accept All” button is large, brightly colored, and prominently positioned. The “Reject” option is a small, grey, or unstyled text link that blends into the background. Austria’s Supreme Administrative Court ruled in January 2025 that this visual disparity alone invalidates consent, establishing that button parity — identical sizing, color contrast, font weight, and placement — is a legal requirement.

02

Hidden Reject Option

No “Reject All” button appears on the first layer of the cookie banner. Users must click through to a “Manage Settings” or “Cookie Preferences” panel, navigate category toggles, and then save their choices to decline. This creates an asymmetry of effort: one click to accept, three or more clicks to reject. The CNIL’s landmark fines against Google and Facebook in January 2022 targeted this exact pattern.

03

Confusing Categories

Cookie categories are labeled in unnecessarily technical or vague terms such as “functional performance enhancement,” “experience optimization,” or “partner integration cookies.” When users cannot understand what a category means, they cannot give informed consent. Some banners deliberately use euphemistic language to disguise advertising cookies — labeling them “Improve your experience” instead of “Advertising and tracking.”

04

Pre-Selected Toggles

When users open the cookie preferences panel, all non-essential categories (analytics, advertising, social media) are toggled on by default. Users must actively switch each one off to decline. The GDPR explicitly requires that consent be given through an affirmative act. Pre-ticked boxes were ruled non-compliant by the Court of Justice of the EU in the Planet49 case (C-673/17) as far back as October 2019.

05

Confirm-Shaming

The reject option is worded to make users feel guilty or stupid for declining. Instead of a neutral “Reject All,” the button reads “I don’t care about my experience,” “No thanks, I prefer irrelevant content,” or “Continue with limited functionality.” This manipulative language is designed to create social pressure and emotional discomfort that nudges users toward acceptance.

06

Forced Action (Cookie Walls)

The website blocks all content behind a cookie consent overlay, refusing to let users access the page unless they accept cookies. The Dutch Data Protection Authority explicitly stated that cookie walls violate the GDPR because they make consent conditional on access to a service, violating the “freely given” requirement. Cookie walls have been found non-compliant by supervisory authorities across Europe.

07

Misleading Hierarchy

“Accept All” is styled as the primary call-to-action button, while “Manage Preferences” is styled as a secondary text link or is placed in a footer area beneath a wall of text. The visual hierarchy of the interface communicates that acceptance is the expected and recommended action. The EDPB’s Guidelines 3/2022 specifically identify interface hierarchy manipulation as a dark pattern.

08

Nagging

After a user rejects cookies, the banner reappears on every subsequent page load, on the next visit, or after a short interval. This repeated prompting is designed to wear users down until they eventually click “Accept” to make the interruption stop. It transforms rejection from a one-time action into an ongoing burden, effectively penalizing users who exercise their right to decline.

Compounding patterns

Most non-compliant cookie banners do not use just one dark pattern — they stack several together. A banner with an asymmetric accept button, hidden reject option, and pre-selected toggles is exponentially more manipulative than any single pattern alone. Regulators consider the cumulative effect of combined dark patterns when determining the severity of a violation and the size of the resulting fine.

Case law

Enforcement Actions: Real Fines for Dark Patterns

From six-figure penalties to nine-figure fines, regulators across Europe are systematically penalizing manipulative cookie consent design. These cases define the boundaries of what is and is not permissible.

The enforcement landscape has shifted dramatically between 2022 and 2026. What began as guidance and formal notices has escalated into immediate, substantial fines. The CNIL in France has been the most aggressive enforcer, but data protection authorities in the Netherlands, Italy, Austria, and Germany have all taken action. The trajectory is clear: penalties are escalating, and repeat offenders face progressively larger fines. Here are the landmark cases that every website operator should understand.

Case Authority Fine Date Violation
Google (Gmail & Account Signup) CNIL (France) €325M Sep 2025 Promotional ads shown in Gmail without consent; account signup flow used asymmetric design to steer users toward personalized advertising cookies. Escalated penalty due to repeat violations (prior fines of €100M in 2020 and €150M in 2022).
SHEIN CNIL (France) €150M Sep 2025 Advertising cookies placed on user devices before consent was given. Cookie banner lacked information about advertising purposes. The “Reject All” button was present but non-functional — clicking it did not actually block cookies. Affected approximately 12 million monthly visitors in France alone.
Google (google.fr, youtube.com) CNIL (France) €150M Jan 2022 No equally easy option to reject cookies. Accepting required one click; rejecting required navigating multiple screens. Failed the “equivalency” requirement under French data protection law. Given three months to comply, with €100,000 per day penalties for non-compliance.
Facebook (facebook.com) CNIL (France) €60M Jan 2022 Same asymmetric consent design as Google. One click to accept, multiple clicks to reject. The CNIL used the ePrivacy Directive rather than the GDPR, giving it direct territorial jurisdiction rather than requiring the cross-border “one-stop shop” mechanism.
Kruidvat (Dutch drugstore) Dutch DPA €600K 2024 Tracking cookies placed on kruidvat.nl without visitor consent. Cookie banner did not effectively block non-essential cookies before user interaction.
Coolblue (Dutch electronics) Dutch DPA €40K 2024 Used pre-ticked checkboxes in cookie consent mechanism. Failed to properly obtain affirmative consent before setting non-essential cookies.
Digital marketing company (Italy) Italian Garante €300K Feb 2023 First Italian GDPR fine specifically for dark patterns. The “continue without accepting” option was placed at the bottom of the page in small italic text, outside the pop-up banner, while the consent button was prominently displayed. Confirm-shaming language used throughout.
Austrian cookie banner case Austrian VwGH Ruling Jan 2025 Supreme Administrative Court ruled that a colored “Accept” button with a less visible reject option on a second layer violates GDPR. Established that visual button parity is a legal requirement, not an optional best practice. Industry-standard design does not justify non-compliance.

The Dutch DPA’s Systematic Campaign

Beyond individual fines, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has launched the most systematic cookie enforcement campaign in Europe. In April 2025, the Dutch DPA issued formal warnings to 50 organizations — including major online retailers, media companies, and insurers — for deploying misleading cookie banners. These organizations were given three months to comply or face investigations and administrative fines.

The Dutch DPA now monitors approximately 10,000 Dutch websites annually and intends to warn 500 organizations per year for non-compliance. The Dutch government allocated €500,000 per year for three years to the DPA specifically for enhanced supervision of tracking technologies and misleading cookie banners, followed by a permanent annual increase of €350,000 for investigations from 2027 onward. The message is clear: automated, large-scale enforcement is the new norm.

Of the over 200 websites that received warnings from the Dutch DPA, approximately three-quarters adjusted their banners to meet legal requirements. The remaining non-compliant organizations face investigations and fines. Recurring violations identified by the Dutch DPA include missing “Reject All” options on the first banner layer, pre-selected checkboxes, cookies placed before consent, cookie walls without valid justification, and absent or incomplete consent logs.

The Italian Garante’s Approach

Italy’s Garante per la Protezione dei Dati Personali has adopted a dual approach: comprehensive cookie guidelines paired with targeted enforcement. The Garante’s updated cookie guidelines, effective since January 2022, require that cookie banners contain a visible close button (“X”) that dismisses the banner without placing any non-essential cookies, clear information about cookie purposes, a consent button, and a link to detailed cookie preferences. Scrolling is explicitly rejected as a form of consent.

The landmark €300,000 fine in February 2023 against a digital marketing company was the first Italian enforcement action specifically targeting dark patterns under the GDPR. The Garante found that the website placed the “continue without accepting” option outside the consent pop-up, in smaller font and at the bottom of the page, while the consent button was prominently displayed inside the banner. The Garante explicitly referenced the EDPB’s dark pattern guidelines in its ruling, signaling that it views dark pattern enforcement as a permanent priority.

Where Enforcement Is Heading

The European Commission’s proposed Digital Fairness Act and Digital Package introduce standardized requirements for cookie banners, including mandatory one-click reject mechanisms with equal prominence to accept buttons. AI-powered enforcement tools are being developed that can scan millions of websites for dark patterns, moving enforcement from complaint-driven to proactive and automated. With €1.2 billion in GDPR fines issued in 2025 alone and cumulative fines exceeding €5.88 billion since May 2018, the financial risk of non-compliance has never been higher.

Self-assessment

How to Audit Your Own Banner

A five-point checklist to determine whether your cookie banner uses dark patterns. If you cannot answer “yes” to every question, your banner may be non-compliant.

  1. 1

    Is “Reject All” as prominent as “Accept All”?

    Both buttons must be the same size, the same font weight, and carry the same visual prominence. A bright red “Accept All” button paired with a grey “Reject” text link fails this test. Austria’s Supreme Administrative Court has ruled that button parity — identical sizing, color contrast, and placement — is a legal requirement. If your accept button is visually more attractive than your reject button, you have an asymmetric choice dark pattern.

  2. 2

    Can users decline in the same number of clicks as accepting?

    If accepting cookies requires one click and rejecting requires two, three, or more clicks through a preferences panel, your banner has a hidden reject dark pattern. The CNIL’s €150 million fines against Google and Facebook were based precisely on this asymmetry. The principle is straightforward: rejection must require the same effort as acceptance. One click to accept means one click to reject.

  3. 3

    Are non-essential cookie categories off by default?

    When users open your cookie preferences panel, all non-essential categories — analytics, advertising, social media, personalization — must be toggled off. Only strictly necessary cookies should be active by default. Pre-selected checkboxes were definitively ruled non-compliant by the Court of Justice of the EU in the Planet49 decision. If any non-essential toggle is on by default, your banner is non-compliant.

  4. 4

    Is the language clear and non-manipulative?

    Your cookie categories should be described in plain, honest language. “Advertising cookies” should be called advertising cookies, not “experience enhancement cookies.” The reject option should use neutral wording like “Reject All” or “Decline,” not guilt-laden phrases like “I don’t care about my experience.” Read every piece of text on your banner and ask whether it could reasonably confuse or pressure a user.

  5. 5

    Can users easily change their preferences later?

    GDPR Article 7(3) requires that withdrawing consent must be as easy as giving it. Your website must provide a persistent, easily accessible way for users to revisit and change their cookie preferences at any time after their initial choice. A small icon, footer link, or settings button must be available on every page. If users can only manage their preferences by clearing their browser cookies and triggering the banner again, you are non-compliant.

Beyond the banner

Design compliance is necessary but not sufficient. Even a perfectly designed banner is non-compliant if cookies are set before consent is obtained, if the “Reject All” button does not actually block cookies (as the CNIL found with SHEIN), or if consent records are not properly maintained. Technical implementation must match the design intent.

Our approach

FixGDPR’s Approach to Compliant Design

Every enforcement case described above involves the same fundamental failure: the banner was designed to maximize consent rates rather than to respect user choice. FixGDPR takes the opposite approach.

FixGDPR’s consent banner is built from the ground up to be compliant by default. We do not offer toggle switches for dark patterns. We do not provide options to hide the reject button or make it less prominent. We do not allow pre-selected cookie categories. Compliance is not a configuration option; it is the architecture of the product. Every banner we deploy passes the five-point audit above, the EDPB’s Guidelines 3/2022 on dark patterns, and the specific requirements established by the CNIL, the Dutch DPA, the Italian Garante, and Austrian court rulings.

Equal-Prominence Buttons

Accept and Reject are always the same size, the same weight, and carry the same visual prominence. No asymmetric styling, no hidden options, no misleading hierarchy. Both choices are presented as equal first-class options on the first banner layer.

No Pre-Selected Categories

All non-essential cookie categories are toggled off by default in the preferences panel. Only strictly necessary cookies are active. Users must affirmatively opt in to each category, exactly as the CJEU mandated in Planet49 and as every DPA enforces.

Plain Language Throughout

Cookie categories are labeled honestly and clearly: Analytics, Advertising, Social Media, Functional. No euphemisms, no jargon, no confirm-shaming. The language is designed for informed choice, not psychological manipulation.

True Prior Blocking

Non-essential cookies and scripts are technically blocked before consent is given. Unlike SHEIN’s banner, where the “Reject All” button failed to actually block cookies, FixGDPR enforces consent at the script level. Rejection means rejection.

EDPB compliance

FixGDPR banners are designed to meet the requirements outlined in the European Data Protection Board’s Guidelines 3/2022 on dark patterns, the CNIL’s cookie regulation action plan, the Italian Garante’s cookie guidelines, and the Dutch DPA’s enforcement criteria. We track regulatory developments across all EU member states and update our banner templates when new requirements emerge — so you do not have to.

Take action

Check Your Banner for Dark Patterns

FixGDPR’s scanner analyzes your cookie banner for dark patterns, asymmetric button design, hidden reject options, pre-selected toggles, and cookies set before consent. Get a free compliance report in 30 seconds — before a regulator does it for you.

Keep reading

Related Resources

GDPR Fines Tracker

A comprehensive tracker of GDPR enforcement actions, penalties, and regulatory decisions across all EU member states.

View the tracker →

GDPR Cookie Consent

Everything you need to know about cookie consent requirements, prior blocking, and the ePrivacy Directive.

Read the guide →

GDPR Consent Banner

How to build a consent banner that meets GDPR requirements. Design, implementation, and technical best practices.

Read the guide →

Cookie Checker

Scan any website to see what cookies and tracking technologies are active. Free, instant, and no signup required.

Check cookies →