Back to insights
Checking Compliance Practices

How does consent look like?

Learn what valid consent looks like with this GDPR checklist. Spot dark patterns, pre-ticked boxes, and audit any provider's consent practices in minutes.

How does consent look like?

How does consent look like?

Key Facts

  • 99% of Canadian websites contained at least one deceptive design indicator according to the 2024 OPC sweep across 25+ privacy authorities
  • 65% of sites preselected the least privacy-protective option by default, violating GDPR's affirmative-action standard per the OPC sweep
  • 96% of privacy policies were excessively long or confusing, and 0% rated 'very easy to read' in the OPC 2024 sweep
  • 83% of privacy policies required a university-level reading level to understand according to OPC findings
  • 43% of sites made account deletion impossible to find at all in the OPC examination
  • Pre-ticked boxes are explicitly invalid under GDPR Recital 32 and the CJEU Planet49 ruling per legal analysis
  • Regulators require privacy-protective choices to be 'at least, equally visible' — no squinting to find 'Reject' per OPC guidance

A consent banner can look official and still be worthless. In 2024, Canada's Office of the Privacy Commissioner coordinated a sweep with more than 25 privacy authorities worldwide and found that 99% of examined Canadian websites and apps contained at least one deceptive design indicator. Almost nobody passed the eye test.

The problem isn't missing legal text — it's design that quietly steers you toward "yes." The sweep examined five patterns: complex or confusing language, interface interference, nagging, obstruction, and forced action. And these patterns compound: when two or more are used together, they become even more effective at influencing privacy decisions.

Why does this matter for a business? Because consent obtained through manipulation isn't valid consent. As one legal analysis puts it, dark patterns "ostensibly obtain user consent, but they do not actually validate it." Under GDPR, the standard is settled law: consent must be a free, specific, informed, and unambiguous declaration of will — and pre-ticked boxes are explicitly invalid under Recital 32 and the CJEU's Planet49 ruling. A company can collect "permission" that protects it in exactly zero ways.

The sweep's numbers show how widespread the tricks are:

  • 65% of sites preselected the least privacy-protective option by default
  • 65% used false hierarchy, making the "Accept" choice visually dominant
  • 96% of privacy policies were excessively long or confusing, and 0% rated "very easy to read"
  • 43% made account deletion impossible to find at all

Regulators have drawn a clear line: privacy-protective choices must be "at least, equally visible — no one should have to squint to find out how to protect their personal information." That means a "Reject" button deserves the same size, contrast, and placement as "Accept." Burying the reject option in a second layer, one legal analysis notes, practically prevents users from withdrawing consent at all.

This is also why the consent screen itself is the best evidence when you're checking a provider's compliance practices. As the IAPP's Dale Smith observed, an inscrutable privacy policy and a pre-ticked "I Agree" box no longer count as adequate permission. The interface is visible proof — or visible failure.

It's a standard we hold ourselves to. Worqd's booking funnel asks for explicit, unchecked consent — "I agree to be contacted about my request" — rather than relying on silence or preselection. When you evaluate any marketing partner, look at their consent screen first. If it fails the eye test, the permission it collects won't protect them — and it won't protect you either.

If you can't tell whether a visitor actually agreed to your terms, they probably didn't. Valid consent isn't a legal footnote — it's a design standard you can see the moment a consent banner appears on screen.

The law is blunt about this. GDPR Recital 32 states that silence, pre-ticked boxes, or inactivity don't count as consent, and the EU's Planet49 ruling confirmed that pre-ticked checkboxes are invalid. Consent must be an affirmative, active action — an unchecked box that the user deliberately ticks, or an "Accept" button clicked before any data collection begins.

Regulators now judge consent by what the interface looks like, not just what the legal text says. Canada's Office of the Privacy Commissioner puts it simply: privacy-protective choices should be "at least, equally visible" — no one should have to squint to find out how to protect their information. In practice, that means:

  • "Accept" and "Reject" buttons with equal size, contrast, and placement — no false hierarchy that nudges one choice over the other.
  • An unchecked box by default. Preselection is invalid under GDPR and, per the Planet49 ruling, generates no valid consent at all.
  • Plain, neutral language. No jargon, no guilt trips, no "No thanks, I hate saving money" confirm-shaming.
  • Withdrawal that's as easy as giving consent — not a "Reject" button buried in a second settings layer.

Most websites fail this test badly. The OPC's 2024 sweep of 145 Canadian sites found that 99% contained at least one deceptive design indicator, and 65% preselected the least privacy-protective option by default. On the language side, 96% of privacy policies were excessively long or confusing, 83% required a university-level reading level, and not a single one was rated "very easy to read." A university education should not be a prerequisite for understanding how your data gets used.

This matters when you're choosing a marketing provider, because the consent interface is visible evidence of a provider's compliance practices. As IAPP's Dale Smith put it, an inscrutable privacy policy and a pre-ticked "I Agree" box no longer serve as adequate permission. When we built Worqd's booking funnel, we kept this standard front and center: an explicit, unchecked consent statement ("I agree to be contacted about my request") with a clear note that details are only used to prepare for the call. It's the same bar we'd want any partner we work with to meet.

One more thing to ask any provider: how consent is enforced after collection. Consent that doesn't carry through to analytics, CRM, and ad platforms "becomes a record, not a control" — and a German court found that using tools like Google Tag Manager without proper consent enforcement creates legal risk even when a banner exists. Collection is the easy part. Provable application is the real test.

The most honest compliance audit you'll ever run takes ten minutes and a browser tab: open the provider's own forms and booking flows, and look at what they show the public. As the IAPP notes, regulators and users can evaluate GDPR compliance by simply viewing any public-facing data ingestion screen — the interface itself is the evidence.

Start with the visual test. Does "Reject" get the same button size, color, contrast, and placement as "Accept"? Canada's Office of the Privacy Commissioner found that 65% of examined sites showed false hierarchy in privacy settings, steering people toward the least protective option. The OPC's standard is blunt: privacy-protective choices must be "at least, equally visible."

Next, test the affirmative-action standard. Pre-ticked boxes are invalid under GDPR Recital 32 and the CJEU's Planet49 ruling, so consent must come from a clear, active choice — an unchecked box the user clicks, not a default they inherit. Worqd's own booking funnel follows this pattern: an explicit, unselected statement ("I agree to be contacted about my request") that states exactly what the details will be used for.

Then read the language. The same OPC sweep found 96% of privacy policies were excessively long or confusing, and 83% required a university reading level. If you need a law degree to understand what you're agreeing to, the consent isn't valid.

But collection is only half the audit. The harder question — and the one enforcement is moving toward — is whether consent actually propagates downstream. As compliance practitioners now frame it, regulatory pressure is shifting from "did you collect consent?" to "can you prove how it was applied?" A German court ruling found that running tools like Google Tag Manager without proper consent enforcement creates legal risk even when a consent banner exists.

So ask any growth or lead-gen partner three questions:

  • When someone opts out, does the signal actually reach your analytics, CRM, and ad platforms — or does it just sit in a log?
  • Do you keep versioned records of what was agreed, when, and under which legal basis?
  • Do you avoid sending sensitive form fields into public analytics systems?

A partner who can answer those questions concretely — and whose live forms pass the squint test — is one worth signing with.

The consent interface itself is the compliance evidence — regulators and users can evaluate it by simply viewing any public-facing data ingestion screen. That principle guided how we built the booking funnel at Worqd: an explicit, unchecked statement reading "I agree to be contacted about my request" sits beside a clear purpose note, with no sensitive form fields ever sent to public analytics and withdrawal available at any time.

Pre-ticked boxes are invalid under GDPR Recital 32 and the CJEU Planet49 ruling; consent must be an affirmative action before any data collection begins. The OPC's 2024 sweep found that 65% of examined sites preselected the least privacy-protective option by default, while 99% of Canadian sites contained at least one deceptive design indicator. Visual symmetry is the core test — privacy-protective choices must be "at least, equally visible" in size, contrast, and placement.

  • Unchecked, explicit consent statement with a named purpose
  • Equal visual weight for "Accept" and "Reject" actions
  • Plain, neutral language — no confirm-shaming or jargon
  • No sensitive fields transmitted to public analytics
  • Withdrawal as easy as giving consent, available at any time

Applying the strictest standard — GDPR-style opt-in — across jurisdictions avoids compliance gaps and builds trust. Even if only a small percentage of users are in the EU, GDPR is still applicable, and the safest approach is to apply its requirements globally. When evaluating a provider's compliance practices, inspect the consent interface first — then ask how that consent propagates downstream to analytics, CRM, and ad systems with versioned records of what was agreed, when, and under which legal basis.

Frequently Asked Questions

Are pre-ticked checkboxes on a consent form actually valid?
No. Under GDPR Recital 32 and the CJEU's Planet49 ruling, silence, inactivity, and pre-ticked boxes are explicitly invalid — consent must be an affirmative action, like ticking an unchecked box or clicking Accept before any data collection begins.
What does a legally compliant consent banner look like?
Regulators say privacy-protective choices must be "at least, equally visible" — so "Reject" needs the same size, contrast, and placement as "Accept," with no pre-ticked boxes and plain, neutral language. Burying the reject option in a second layer can practically prevent users from withdrawing consent at all.
How common are dark patterns on websites today?
Extremely common. Canada's OPC coordinated a 2024 sweep with 25+ privacy authorities and found that 99% of examined Canadian websites and apps contained at least one deceptive design indicator, and 65% preselected the least privacy-protective option by default.
Do I need to make my privacy policy easier to read?
Yes — long, confusing policies can undermine the validity of your consent. In the OPC's sweep, 96% of privacy policies were excessively long or confusing, 83% required a university-level reading level, and 0% were rated "very easy to read."
Isn't a consent banner enough to keep me compliant?
Not necessarily. A German court found that running tools like Google Tag Manager without proper consent enforcement creates legal risk even when a banner exists — consent that doesn't reach your analytics, CRM, and ad platforms "becomes a record, not a control."
How can I check whether a marketing provider follows good consent practices?
Open their own forms and booking flows — the consent interface is visible proof of their compliance, since regulators and users can evaluate it by simply viewing any public-facing data ingestion screen. Then ask how consent propagates downstream and whether they keep versioned records of what was agreed, when, and under which legal basis. At Worqd, our booking funnel uses an explicit, unchecked consent statement for exactly this reason.

The Interface Is the Evidence

Consent isn't a legal footnote — it's a design standard you can see the moment a banner loads. The OPC's 2024 sweep found that 99% of Canadian sites contained at least one deceptive design indicator, and regulators now judge compliance by what the interface looks like, not just what the legal text says. Valid consent means unchecked boxes by default, equal visual weight for "Accept" and "Reject," plain language, and withdrawal as easy as giving permission — all enforced downstream to analytics, CRM, and ad platforms with versioned records. When you evaluate a marketing partner, start with their own forms: if the consent screen fails the eye test, the permission it collects won't protect them, and it won't protect you either. Worqd builds to this standard across every funnel we run — explicit, unchecked consent, no sensitive fields in public analytics, and a clear path from first click to booked call. Ready to see what compliant growth looks like? Book a Growth Call and we'll find the bottleneck together.

Want help putting this into action?

Book a Growth Call
Topicsvalid consent requirementsGDPR consent checklistdark patterns consentconsent banner compliancepre-ticked boxes GDPRaudit provider complianceaffirmative consent design

Stay in the Loop