This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Open AccessArticle
GDPR Dark Patterns in Cookie Consent: An Automated Study of High-Traffic Websites Accessed from Denmark
by
Christos Ntemkas
Christos Ntemkas ,
Laura Vieira Teixeira
Laura Vieira Teixeira ,
Lejla Islami
Lejla Islami ,
Gaurav Choudhary
Gaurav Choudhary *
and
Nicola Dragoni
Nicola Dragoni
Department of Applied Mathematics and Computer Science (DTU Compute), Technical University of Denmark, 2800 Kongens Lyngby, Denmark
*
Author to whom correspondence should be addressed.
Future Internet 2026, 18(9), 487; https://doi.org/10.3390/fi18090487 (registering DOI)
Submission received: 26 June 2026
/
Revised: 5 September 2026
/
Accepted: 15 September 2026
/
Published: 17 September 2026
Abstract
This paper examines how often GDPR-relevant dark patterns appear in cookie-consent banners and how often users receive a choice that is free and informed. We use an adapted version of CCrawler to crawl 99 high-traffic websites accessed from Denmark, detect consent interfaces, and extract first-layer choice pathways and settings-layer elements for compliance-risk coding. We then assess detected banners against four GDPR-informed interface-level criteria: first-layer refusal availability, absence of pre-ticked or default-enabled options, relative accept/reject prominence, and non-obstructive presentation. These operational criteria are observable interface proxies rather than final legal determinations of GDPR compliance. Cookie banners were detected on 90 of 99 sites; the nine non-detections are reported separately and are not treated as evidence of non-compliance. The results indicate a structural imbalance: acceptance is usually available on the first layer, while refusal is often placed behind additional steps or settings dialogues. A subset of reachable settings interfaces also contained pre-ticked options. To place these observations in the European context, we compare the two directly comparable first-layer choice indicators with a recent 31-country study. Acceptance availability is close to that study’s Denmark-specific estimate, whereas first-layer rejection in our high-traffic Denmark-accessed sample lies between its Denmark-specific estimate and its 31-country aggregate. These cross-study comparisons are descriptive and are not treated as matched statistical estimates because the sampling frames and measurement procedures differ. The findings provide Denmark-specific, time-bounded evidence that known consent-interface asymmetries remain visible on high-traffic websites, together with a reproducible workflow for future audits.
Share and Cite
MDPI and ACS Style
Ntemkas, C.; Teixeira, L.V.; Islami, L.; Choudhary, G.; Dragoni, N.
GDPR Dark Patterns in Cookie Consent: An Automated Study of High-Traffic Websites Accessed from Denmark. Future Internet 2026, 18, 487.
https://doi.org/10.3390/fi18090487
AMA Style
Ntemkas C, Teixeira LV, Islami L, Choudhary G, Dragoni N.
GDPR Dark Patterns in Cookie Consent: An Automated Study of High-Traffic Websites Accessed from Denmark. Future Internet. 2026; 18(9):487.
https://doi.org/10.3390/fi18090487
Chicago/Turabian Style
Ntemkas, Christos, Laura Vieira Teixeira, Lejla Islami, Gaurav Choudhary, and Nicola Dragoni.
2026. "GDPR Dark Patterns in Cookie Consent: An Automated Study of High-Traffic Websites Accessed from Denmark" Future Internet 18, no. 9: 487.
https://doi.org/10.3390/fi18090487
APA Style
Ntemkas, C., Teixeira, L. V., Islami, L., Choudhary, G., & Dragoni, N.
(2026). GDPR Dark Patterns in Cookie Consent: An Automated Study of High-Traffic Websites Accessed from Denmark. Future Internet, 18(9), 487.
https://doi.org/10.3390/fi18090487
Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details
here.
Article Metrics
Article Access Statistics
For more information on the journal statistics, click
here.
Multiple requests from the same IP address are counted as one view.