← Back to list

Consent or Coercion?

How digital platforms shape our privacy choices

Bristi Seal in Bootcamp · 2026-04-03 17:34 · 112 claps · 5.3 min read
#website-cookies #dark-ux #dark-ux-designs #thesis #ux-research
Open on Medium ↗
Wiki topics: UX · UI/UX Design 🔒 · Cybersecurity

Consent or Coercion?

How digital platforms shape our privacy choices

Abstract

This thesis investigates whether consent flows in modern apps and websites truly enable informed, free privacy choices or subtly coerce users into sharing more data than they intend.

It combines analysis of legal standards under GDPR, CCPA/CPRA and related regulations with UX and interface research on dark patterns in cookie banners, app permissions, and advertising settings.

Studies of cookie consent notices show that a majority use manipulative patterns, such as pre-selected options and missing “reject all” choices, which undermine the idea of freely given consent.

Focusing on platforms such as Instagram, the thesis argues that tracking and personalisation systems rely heavily on interface tricks, complex settings, and user fatigue rather than clear, meaningful permission.

It concludes with design guidelines and policy recommendations for consent experiences that respect user autonomy, transparency, and control.

01. Introduction

People share huge amounts of personal data through phones, browsers, and social media, which feeds large-scale tracking and targeted advertising systems. In response to public concern, regulations like the EU’s GDPR and California’s CCPA/CPRA set strict conditions for valid consent, emphasizing that it must be specific, informed, and freely given, with easy withdrawal at any time. Yet real-world consent interfaces often tell a different story, using interface nudges, confusing language, and repetitive pop-ups that pressure users to accept tracking just to access services.​

This thesis asks: do current consent and privacy flows in digital platforms genuinely support informed, free consent, or do they operate closer to coercion in practice? To answer this, the work combines legal analysis, a review of UX research on dark patterns, interface audits of real consent banners and app permission dialogs, and a small user study on how people understand and experience these flows.

02. Background: Digital Consent, Dark Patterns, and Law

Definition of dark patterns - Dark patterns are interface designs that intentionally confuse, pressure, or mislead people into actions they might not otherwise take, such as sharing more data or accepting extra tracking.

How dark patterns work - Research shows that these designs exploit cognitive biases and fast, automatic thinking, for example by making the “accept” button bright and large while hiding the “reject” path behind extra clicks and low‑contrast links.

Impact on consent - GDPR defines consent as a freely given, specific, informed and unambiguous indication of the data subject’s wishes, and its guidance rejects pre‑ticked boxes, silence, or inactivity as valid consent. CPRA, building on CCPA, goes further by saying that any agreement obtained through dark patterns does not count as consent, describing dark patterns as interfaces that subvert or weaken user autonomy and decision‑making.

Legal standards (GDPR and CPRA/CCPA) - Despite these legal rules, empirical studies of cookie banners and opt‑out mechanisms find low compliance, with many sites still nudging users toward acceptance or failing to provide a simple, straightforward way to refuse.

Despite these legal rules, empirical studies of cookie banners and opt‑out mechanisms find low compliance, with many sites still nudging users toward acceptance or failing to provide a simple, straightforward way to refuse.

03. Methods

The thesis uses a mixed-method approach with three main components.

First, a doctrinal legal analysis compares how GDPR, CCPA/CPRA and emerging Indian guidance conceptualise consent, fairness, and manipulative design.

This involves reading statutory definitions, regulatory guidance, and enforcement cases, including actions against companies that tried to bypass consent requirements for targeted ads or used technical identifiers without proper permission.

Second, an interface audit examines consent banners and privacy controls across a sample of popular websites and mobile apps, including news outlets, e‑commerce platforms, and social media.

Each interface is coded along dimensions such as symmetry of choices (accept vs reject), number of steps to refuse processing, clarity of language, default states (pre-selected toggles), and visibility of further information.

An example of a dark pattern Cookie Banner, where the Reject button is missing. SOURCE: https://cookie-script.com/blog/what-are-dark-patterns-in-google-consent

An example of a dark pattern Cookie Banner, where the Reject button is missing. SOURCE: https://cookie-script.com/blog/what-are-dark-patterns-in-google-consent

Third, a small user study explores how people experience consent flows and privacy decisions. Participants are shown anonymised screenshots of real consent interfaces, such as cookie banners with and without dark patterns, and app permission screens modeled on Instagram’s tracking settings and asked what they think will happen if they click each option, how pressured they feel, and which designs they consider fair.

Their responses are analysed thematically to understand misconceptions, frustration, and patterns of “consent fatigue.”

SOURCE: https://www.reddit.com/search/?q=WEBSITE+COOKIES+FRUSTRATIONS&cId=9649600f-10a9-4b56-b398-85a0a8bcf2b1

SOURCE: https://www.reddit.com/search/?q=WEBSITE+COOKIES+FRUSTRATIONS&cId=9649600f-10a9-4b56-b398-85a0a8bcf2b1

04. Findings

The legal analysis shows a clear shift towards recognising manipulative interfaces as incompatible with valid consent. GDPR guidance and CPRA’s dark-pattern clauses reject pre-checked choices, hidden opt-outs, and excessive friction for refusal, framing them as obstacles to autonomy and fairness. Enforcement cases against large platforms, including actions around personalized ads on Facebook and Instagram, highlight how attempts to treat advertising as a contractual necessity instead of a consent-based activity have been rejected by regulators.​

The interface audit reveals that many consent banners still rely on design patterns that favour acceptance over refusal. A large proportion of sites use bright, prominent “Accept all” buttons combined with greyed-out or nested “Manage options” links, and some provide no visible “Reject all” choice on the first layer. Only a minority present balanced options with equal visual weight and one-click refusal, these more balanced designs better reflect regulatory expectations but are less common.​

User study responses indicate that most participants feel rushed or confused when confronted with repeated consent prompts, leading to quick “accept” clicks just to access content. Many participants misinterpret what cookies and tracking actually do, and some assume that platforms like Instagram are “listening” to conversations, revealing a gap between technical reality and user perception shaped by opaque data practices and targeted content. Participants generally describe symmetric, plain-language designs with clear “accept” and “reject” buttons as more trustworthy and less coercive, while banners burying refusal options behind multiple steps are seen as manipulative.

05. Consent Metrics Tilted to “Accept All”

Consent Interfaces Still Favour Companies Over Users’ Privacy

72% users, click “Accept all” quickly due to confusing or pressuring designs.

16% users, try to manage settings but still share more data than they intended.

12% users, successfully refuse or minimise tracking.

06. Discussion

Taken together, the findings reveal a wide gap between what privacy laws expect from consent and what users actually encounter in everyday interfaces. While regulations increasingly ban dark patterns and require clear, balanced choices, many consent banners and settings screens still use visual hierarchy, default options, and extra clicks to subtly guide people toward “accept all” rather than an informed refusal.

This behaviour aligns with strong business incentives to maximise data collection and ad revenue, and it is reinforced by the practical difficulty of monitoring thousands of evolving interfaces across the web and app stores. Limited user awareness of data rights and the technical nature of tracking make it even easier for platforms to meet the surface appearance of compliance while still shaping outcomes in their favour.​

Platforms like Instagram show how these consent challenges extend far beyond the initial cookie or tracking pop-up. After the first prompt, data collection continues through a web of signals - likes, follows, interactions, device identifiers, and off‑platform events - feeding personalisation systems that are not always clearly explained to users.

Controls for ad preferences, third‑party tracking, and off‑platform data use are dispersed across multiple menus and sometimes linked to shared settings with Facebook or other Meta services, raising the cognitive and time cost for users who want to limit tracking. In practice, this fragmentation means that only highly motivated and knowledgeable users manage to find and configure all the relevant switches, while most people default to the path of least resistance and remain heavily tracked, even if this does not fully reflect their true privacy preferences.


메타데이터
post_id
6f620bff7ebd
slug
consent-or-coercion-6f620bff7ebd
url
https://medium.com/design-bootcamp/consent-or-coercion-6f620bff7ebd
canonical_url
https://medium.com/design-bootcamp/consent-or-coercion-6f620bff7ebd
author_url
https://medium.com/@bristiseal08
status
ok
fetched_at
2026-07-15 11:17:57