Consentimento
LGPD
UX
Privacidade
Design

Real consent or regulatory theater: how to differentiate

Cookie banners are the most visible example of technical compliance that violates the spirit of the law — and there are objective criteria to distinguish real consent from staged consent.

Real consent or regulatory theater: how to differentiate

There is an implicit belief in the market that consent is a legal problem solved with the right text, in the right place, with the right checkbox. This belief is incorrect, and the error is not just ethical — it is strategic. Consent that does not withstand an honest examination of its conditions is not consent: it is a signature obtained under design pressure, and the difference between the two will become progressively more visible as regulation and jurisprudence mature.

Why the cookie banner became a symbol of the problem

The cookie banner is the most widespread artifact of regulatory theater and therefore the best starting point for understanding the pattern. GDPR, and later LGPD, required companies to obtain explicit consent before installing tracking cookies. The market responded with a minimal-effort solution: displaying a banner with two buttons, the first — "Accept all" — large, colorful and prominently positioned, and the second — "Manage preferences" or "Reject" — smaller, gray, and buried in secondary text.

The result is predictable. Eye-tracking studies and click-rate analysis show that block acceptance reaches 90% in designs that follow this standard. Not because users want to be tracked. Because the design was built so that the acceptance option is the one with the least resistance, and the rejection option is the one with the highest cognitive and interaction cost. This is a dark consent pattern: technically compliant with the requirement to display options, practically designed to eliminate them as real choices.

What characterizes genuine consent

The LGPD is clear enough in its requirements that it is possible to use the law itself as an audit criterion. Valid consent must be free, informed, unambiguous and for a specific purpose. Each of these terms has design implications.

Free means that the absence of consent cannot generate punitive consequences for the user. A website that completely blocks access to content if the user rejects cookies is placing access to the service as a bargaining chip for consent — which, depending on the nature of the service, constitutes coercion, not freedom. The user who accepts because the alternative is not being able to read the article they need is not freely consenting.

Informed means the user understands what they are accepting before accepting. A generic description of “advertising partners” that hides a list of 400 tracking technology companies isn’t information — it’s opacity with transparency formatting. The information needs to be specific enough for consent to be meaningful.

Unambiguous means that the user's action must clearly indicate the intent to consent. Pre-checked box does not qualify. Continuing to browse the site does not qualify. Action needs to be affirmative and deliberate. This is not an expansive interpretation — it is explicit in the text of the law.

For a specific purpose means that consent to "improve user experience" does not cover behavioral tracking to build advertising profiles. Purposes need to be specific and separate, with independent consent for each category.

How dark consent patterns work in practice

Manipulative design patterns in consent flows are well-documented and recognizable once you know what to look for. The interface that visually highlights "Accept all" with action color and demotes "Reject" to gray text is the most common, but not the only one.

Privacy confirmshaming appears when the reject button uses self-sabotaging language: "I don't want a personalized experience" or "I prefer irrelevant advertising" frame rejection as an irrational choice. The navigation architecture that requires multiple clicks to reach the reject option — while acceptance is a single prominent click — raises the cost of the choice the company would prefer you not to make. The "just-in-time consent" pattern that presents permission requests at the time of greatest engagement — when the user is in the middle of a task and wants to finish it quickly — uses the interruption context to bias the response.

These patterns are effective in the short term. They are also, increasingly, the type of evidence that regulatory authorities collect when investigating consent practices. The Irish DPC and the French CNIL have already fined companies specifically for the asymmetry in the design of consent controls, not just their absence.

How to audit your own consent flow

There's a simple test: Complete your product's opt-out flow and measure the number of clicks, screens, and time required. Then complete the acceptance flow and compare. If rejecting requires twice as many interactions as accepting, the design is asymmetrical in a way that will be difficult to defend as "free" to a regulatory authority.

The second test is comprehension: ask ten people who don't work in technology to read your privacy notice and then answer what the company does with their data. If the majority cannot answer accurately, the "informed" requirement is not being met in practice, regardless of what the legal text says.

The third test is reversibility: can the user revoke consent as easily as they granted it? The LGPD explicitly guarantees this right. If revocation requires opening a support ticket or sending an email to an address that takes days to respond, while consent was given with a click, reversibility is formal, not real.

What to implement to leave the theater

The transition from cosmetic consent to functional consent requires product decisions, not just compliance ones. The privacy center needs to be treated as a feature, not as a minimally fulfilled legal obligation. This means an interface comparable in quality to the rest of the product, easy and persistent access, and granular controls that actually work.

Separating the purposes of processing and asking for independent consent for each category — analytics, personalization, advertising, sharing with third parties — is more work to implement but produces genuinely useful preference data. The company now knows with much more precision what its users accept and what they reject, which has strategic value beyond compliance.

Documenting how consent was obtained — timestamp, version of notice displayed, affirmative action taken — is what allows you to demonstrate compliance in the event of an investigation. Without this record, any claim that consent was validly collected is an assertion without evidence.

Consent that works is not a cost of compliance. It's the foundation of a relationship with the user that can be maintained as they inevitably discover more about how their data is used — and not have to feel like they were tricked into getting to where they are.

Also read