A Regulator Just Ruled on the Design of a Consent Box. Read Your Cookie Banner Again.

Posted on
Hand holding a smartphone showing app icons, representing app consent prompts

A competition regulator spent four years arguing about a pop-up. Not whether consent was collected. Whether the box was designed to make you say yes.

On 17 August the Bundeskartellamt, Germany’s competition authority, closed its case against Apple’s App Tracking Transparency Framework after accepting binding commitments. The finding underneath it is the part marketers should copy out and keep, because it has almost nothing to do with Apple.

What the regulator actually objected to

Apple’s framework requires third-party apps to get an extra layer of consent, on top of data protection consent, before using cross-company data for personalised ads. Apple’s own apps sit outside that framework and use their own prompt.

The authority’s assessment was that the two prompts were not equivalent, and that the gap was bigger than the underlying data processing could justify. In its words, the wording, design and selection options in Apple’s own request had the potential to encourage consent, while the request Apple wrote for everyone else had the potential to discourage it. Third-party apps also had to ask more than once in some cases, even where valid data protection consent already existed.

So Apple will now remove what the regulator called possibly discouraging symbols and wording, and the prompts will be, in the Bundeskartellamt’s phrasing, neutral in terms of content, wording and layout. Apple has four months to implement. The commitments run for seven years with an independent monitoring trustee, and although this was a German case, the changes are expected to reach most of the EU.

Worth noting the price of getting there ahead of Germany: French and Italian authorities fined Apple 150 million and 98.6 million euros respectively over the same framework.

What most marketers will take from this, and why it is the wrong lesson

The obvious read is “iOS opt-in rates might improve, so app install campaigns get cheaper.” Maybe. Nobody should build a Q4 plan on it. Apple has four months, testing happens with app publishers first, and consent behaviour is stubborn in ways that survive prompt redesigns.

The lesson worth having is the standard itself. A regulator has now written down, in a binding decision, that asymmetric consent design is the problem. Not missing consent. Not unlawful processing. The symbols. The wording. The layout. The number of times you ask.

Now go and look at your own cookie banner.

Most small business sites are running a banner where Accept All is a filled button in the brand colour and Reject is grey text, or a link, or one layer down behind Manage Preferences. That is the exact shape of the thing Apple just spent four years defending and lost. The German case was argued under competition law rather than data protection law, so it does not directly create a new obligation for your site. But regulators read each other, and Andreas Mundt was explicit about the goal: users who do not want their data used must be able to make an equally free and informed decision as users who do.

Consent design is now a documented enforcement target, not a dark pattern that everyone quietly tolerates.

The bit that is actually good news

Buried in the commitments is something publishers have wanted for years. App publishers and content providers will get more scope inside the prompt to explain what personalised advertising means for their offering and their business model. Apple will also let publishers combine its required consent request with the ones required under data protection law, instead of stacking them.

That turns a compliance screen into a piece of copy. Someone has to write it.

This is a genuinely unusual opportunity, and I expect most teams to waste it. The instinct will be to write something manipulative, because the metric on the dashboard is consent rate. The regulator has pre-emptively closed that door: Mundt said plainly that the aim is not to achieve the highest possible levels of consent. Push too hard on the wording and you rebuild the problem from the other side.

The version that works is boring and specific. Not “we value your privacy” but “ads pay for this app, personalised ads pay roughly twice as much, and that is the difference between free and a subscription.” People respond to a real trade-off explained honestly far better than they respond to reassurance.

A simple action plan

Three things, in order, none of which require a lawyer to start.

  1. Screenshot your consent banner and look at it as a stranger. Are the two options equally easy to see, equally easy to click, equally weighted in colour and size? If a reasonable person would say the design is steering, it is steering.
  2. Count the asks. If a user has already consented once, does something ask them again on the next page or the next session? Repeat prompting was one of the specific complaints in this case.
  3. Write the honest explanation now. One or two sentences on why you want the permission and what the user gets. You will need it for app prompts within four months, and it improves your web banner today.

If everything is optimised for the yes, nothing is really consented. That is the direction the enforcement is moving, and the teams that get there voluntarily will spend a lot less on the retrofit than the ones who wait.

For advertisers, this sits alongside a broader pattern of platforms controlling the interface between you and your customer, which is the same tension behind Google labelling AI ads without an opt-out. You do not own the box your message appears in. You only own what it says.

Editor’s note: This area changes quickly, so check the latest platform policy before making compliance decisions.