No “reject all” button? Different colours in a cookie banner? Belgian DPA orders a change, based on “dark pattern” allegations and lack of freely given consent. Readers know I have my doubts on this, due because “in the physical world” we are led to make choices all the time based on product colours (some of which is branding), placement (in a supermarket, the more expensive products are at eye level) and other factors.
A more in-depth piece on “dark patterns” will come soon, but here are some key takeaways of the Belgian DPA’s decision 113/2024:
1. On “reject all”:
– Not freely given: “The consent, on the one hand, is not �free� if the person who does not wish to give his consent […] is obliged to perform more acts in order to refuse the consent […] A choice implies at least an equally valid option to perform a different action (no consent) than the one for which the choice is offered (consent). […] [the user] cannot close the cookie banner without making a choice, which constitutes a problematic form of a so-called cookie wall.” [108]
“Reject all” is misleading too if the label is insufficiently precise, though, so I’m not sure this provides a full picture.
– Not unambiguous: “consent is not �unambiguous� where the data subject cannot similarly take the active action of not consenting because, for example, he or she is unaware of the option to refuse the cookies, since such option is only stated or can be chosen in a subsequent �layer� of the cookie banner” [110]. The Belgian DPA links this also to consent fatigue – yet if consent fatigue is a problem because people click the “accept” button, why shouldn’t systematic “reject” behaviour be questioned too? What should website operators do – prevent a choice until a timer has passed?
2. On button colours:
– One of the criticisms is that one website used a dark red button (for “Accept & close”) vs a grey button (for “More information”). While grey vs the rest is a very touchy discussion, the Belgian DPA talks stresses that “the choice of certain colours [can violate] the duty of fairness [= Art. 5(1)(a) GDPR] in light of personal data processing activities” [143]. Yet dark red is typically seen as a “STOP” colour in guidance from authorities – the kind that you might want to avoid for psychological reasons. Between red (“DON’T TOUCH THIS”) and grey, one could ask why the red is so bad.
– The Belgian DPA recognises that “supervisory authority and European Data Protection Board guidelines do not have the force of law. However, this does not mean that they do not (should not) have authoritative value” [145, also 127]. [I have often advocated questioning guidance from authorities and the EDPB and have sometimes done so in litigation cases.]
3. Analytics
The Belgian DPA requires consent for analytics (“not strictly necessary”).
More comments later.
Decision (in Dutch): https://lnkd.in/eVxc4mpM
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗