Study Finds Most EU Cookie Banners Use Dark Patterns to Force Consent
A new academic study reveals that the vast majority of EU cookie consent notices rely on manipulative design tricks rather than offering genuine choices. Researchers conclude that if websites asked for consent legally, almost no one would agree to be tracked.
A new study from researchers at Ruhr-University Bochum and the University of Michigan reveals that most European cookie consent notices rely on manipulative design tactics instead of offering genuine choices. Following the implementation of the GDPR in 2018, websites across Europe deployed these pop-ups to comply with strict privacy rules, but the research shows they often exploit user confusion and mistrust surrounding how cookies actually function.
The academics analyze approximately 5,000 cookie banners and find that 86 percent offer no real choice at all, presenting only a confirmation button to proceed. Additionally, 93 percent of these notices do not block interaction with the underlying website, and 57 percent actively use dark patterns—such as highlighted accept buttons or misleading wording—to nudge users toward granting permission for extensive data tracking.
Through a live field test involving over 82,000 visitors to a German e-commerce site, the researchers demonstrate that these design choices drastically inflate consent rates. They conclude that if websites collected cookie consent in a fully legal, unbiased manner, only a tiny fraction of consumers would actually agree to be tracked by advertisers and data brokers.