Dark Patterns GDPR What Counts as Manipulative Design

Dark Patterns GDPR: What Counts as Manipulative Design 

A cookie banner with a bright green “Accept All” button and a barely visible grey “Reject” link buried three menus deep is not a design accident. Regulators across the EU treat that kind of layout as a GDPR violation in its own right, separate from whatever happens to the data once someone clicks through it.

Punti di forza

GDPR does not use the term “dark pattern,” but Articles 5, 7, and 12 prohibit the manipulative design techniques the term describes, because they undermine freely given, informed consent.

The EDPB has formally defined six categories of dark patterns: overloading, skipping, stirring, hindering, fickle, and left in the dark.

The CJEU ruled in 2019 that pre-ticked consent checkboxes are invalid, and French regulator CNIL has since escalated enforcement against manipulative cookie banner design specifically.

Rejecting cookies or withdrawing consent must be exactly as easy as giving it. Any design that makes refusal harder than acceptance is a compliance risk regardless of what the underlying privacy policy says.

What Are Dark Patterns Under GDPR?

Dark patterns, sometimes called deceptive design patterns, are interface choices that lead users toward decisions about their personal data that they would not have made with a clearer design. GDPR does not use the phrase directly, but Recital 32 requires consent to be freely given, specific, informed, and unambiguous, and a design that manipulates a user into clicking “accept” fails that test regardless of what the underlying text says.

The European Data Protection Board’s Guidelines 3/2022, finalised in February 2023, define dark patterns as interfaces and user experiences that lead users into making unintended, unwilling, and potentially harmful decisions about the processing of their personal data.

What Are the Six Categories of Dark Patterns the EDPB Identified?

The EDPB’s guidelines set out a taxonomy of six dark pattern categories, developed with social media interfaces in mind but applicable to any GDPR-covered service.

Overloading: overwhelming users with a large volume of requests, information, or options so they share more data than they otherwise would, simply to get through the interface.

Skipping: designing an interface so users forget or fail to consider the data protection aspects of a decision, often by pushing privacy choices out of the natural flow.

Stirring: appealing to users’ emotions or using visual nudges, such as colour and placement, to steer a choice.

Hindering: obstructing or blocking users from getting informed about their data or exercising control over it, by making certain actions hard or effectively impossible.

Fickle: designing an interface inconsistently and unclearly, so users struggle to understand what a given choice actually does.

Left in the dark: hiding information or controls, or designing an interface so users are unsure how their data is being used or what options are available to them.

Are Pre-Ticked Consent Boxes Illegal Under GDPR?

Yes. The Court of Justice of the EU ruled in Case C-673/17 (Planet49) on 1 October 2019 that pre-ticked checkboxes do not constitute valid consent, because only active behaviour from the user, not a default state they have to notice and undo, can signify consent. This ruling predates the EDPB’s dark patterns guidelines but remains the foundational case law behind the “no pre-ticked boxes” rule that now appears in essentially every GDPR cookie compliance checklist.

What Cookie Banner Designs Has CNIL Ruled Against?

France’s data protection authority, CNIL, issued formal notices to multiple website publishers in December 2024 after receiving complaints about misleading cookie banners. The specific practices CNIL flagged as non-compliant included:

the reject option presented as a plain text link with colour, size, and font disproportionately downplaying it compared to the accept button;

the reject option buried inside dense blocks of information without visual separation;

the accept option repeated multiple times across the banner, while the reject option appeared only once, in unclear wording such as “I decline non-essential purposes.”

CNIL gave the affected publishers one month to fix these designs or face further enforcement. The regulator’s underlying position, consistent with the EDPB’s cookie banner task force findings from January 2023, is that the law does not dictate a specific banner layout, but any layout that misleads the user about their choice invalidates the consent collected through it.

Has GDPR’s Dark Patterns Rule Actually Led to Fines?

Yes, at significant scale. On the same day, CNIL fined Google €325 million and fined fashion retailer Shein €150 million, together the largest cookie-related sanctions CNIL has issued. Google’s case followed a complaint from the privacy advocacy group noyb and centred partly on how its account creation flow nudged users toward personalised-advertising cookies over generic ones without making clear that accepting them was effectively a condition of using the service. Shein’s fine followed CNIL’s own inspection of shein.com and covered a different set of failures: cookies placed before users interacted with the consent banner at all, and a “Reject All” button that did not actually stop new cookies from being set. 

Our breakdown of GDPR fines and penalty structures explains how enforcement of this scale is calculated and what factors influence the final figure.

How Do You Avoid Dark Patterns in Your Own Interface?

The design test that consistently comes up across EDPB guidance and CNIL enforcement is symmetry: whatever it takes to accept must take exactly as much effort to decline. That means an equally sized and equally visible reject button, no pre-ticked options, no repeated accept prompts paired with a single buried refusal link, and language that is as plain in the negative option as it is in the positive one.

Beyond cookie banners, the same principle applies to account deletion flows, unsubscribe links, marketing consent checkboxes, and any interface where a user makes a choice about their data. If declining or withdrawing takes more clicks, more scrolling, or more cognitive effort than agreeing, that asymmetry is itself the compliance problem, independent of what happens to the data afterwards. Our guide to GDPR cookie compliance covers the banner-specific requirements in more detail, and the ongoing cookie banner reform debate at EU level may change parts of this landscape again.

Conclusione

Dark patterns turn a design decision into a legal one. The EDPB’s six-category taxonomy gives regulators a working vocabulary for what used to be assessed case by case, and CNIL’s escalating fines against Google and Shein show that enforcement is not limited to obscure or borderline cases. Any interface asking for consent, whether for cookies, marketing, or account settings, needs the “reject as easy as accept” test built in from the first design draft, not patched in after a complaint.

Frequently Asked Questions

Does GDPR specifically mention dark patterns?

No, the regulation itself does not use the term. Dark patterns are prohibited through GDPR’s existing requirements for freely given, informed, and unambiguous consent under Recital 32 and Articles 5, 7, and 12, and through EDPB guidance that interprets those requirements for interface design specifically.

Is a pre-selected “Accept All” cookie button always non-compliant?

Yes, if it is pre-ticked or pre-activated in a way that requires the user to actively opt out rather than opt in. The CJEU’s 2019 Planet49 ruling established that only an active, deliberate action from the user constitutes valid consent, so any default-on state fails that standard.

Can a company be fined just for cookie banner design, separate from any data breach?

Yes. CNIL’s enforcement against Google and Shein in 2025 targeted how consent was collected through interface design, not a data breach or unlawful data use after the fact. A misleading consent interface is treated as a standalone GDPR violation because the consent it produces is not legally valid.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

Ana Mishova

About the Author

Ana Mishova

Sales and Business Development Consultant — GDPRLocal

Ana focuses on helping organisations understand their compliance obligations and find the right data protection solutions. At GDPRLocal she works closely with businesses of all sizes, making GDPR and privacy compliance clear, practical, and accessible.

About the Author

Ana Mishova

Sales & Business Development Consultant

Ana Mishova is a Sales & Business Development Consultant at GDPRLocal, the UK’s fastest-growing B2B compliance partner. With four years at the company, she has experience across operations, from creating processes and shaping compliance services to driving growth through sales, marketing, and strategic partnerships.

Her prior experience includes working closely with current and prospective clients and coordinating with stakeholders to design and plan compliance products. She has led internal change initiatives, driven sales, and guided organisations in selecting the most appropriate compliance strategies.

She holds a degree in psychology, which enhances her ability to connect with people and understand their needs. At GDPRLocal, she works with colleagues to strengthen the sales function and plays an active role in developing the sales strategy.