How to spot it
- The private option is available and it is four levels deep.
- Accepting everything is one button and refusing is a list.
- A setting you changed is back on after an update, described as a new feature.
- The consent dialogue explains the benefits of sharing and not the consequences.
- Necessary is doing a great deal of work in the phrase strictly necessary cookies.
Why it works on you
Almost nobody visits a settings page, so whatever is set when you arrive is what most people will live with. That makes the default the actual policy and the settings page the alibi. The wording does the rest: framing a refusal as a loss of functionality converts a privacy choice into a fear of a worse product, which is a different question with a different answer.
What to do
- Go through settings once, deliberately, when you are not in the middle of something else.
- Re-check after major updates. A setting that reverts is worth knowing about.
- Prefer reject all when it is offered. Under EU and UK rules it must be as easy to reach as accept all.
- Ask what the service does for money. It is usually the shortest route to understanding the defaults.
Where the law stands
The GDPR requires data protection by design and by default, meaning the default setting must be the privacy-protective one, and it requires a lawful basis for each purpose rather than one blanket acceptance. European regulators have repeatedly held that a cookie banner offering accept all with no equally easy refusal is non-compliant. Article 25 of the Digital Services Act prohibits interfaces that nudge users toward a particular choice. In the United States, the FTC's 2022 report names obscured privacy choices as one of its four categories of dark patterns.
This is a description of published regulation, not legal advice, and rules in this area have changed more than once. The sources below are the primary ones.