Forced action · European Union

Forced or bundled consent

The label “Forced or bundled consent” describes this recurring design mechanism: access is conditioned on accepting optional or separable data uses, communications or permissions as one bundled choice. It is a design and research taxonomy, not a standalone legal conclusion. Depending on the complete journey and likely effect, current EU consumer or sector rules may require separate assessment. No published Digital Fairness Act proposal currently creates a pattern-specific prohibition or duty under this label.

Editorial analysis
Also known as
  • take-it-or-leave-it consent
  • consent wall
  • bundled permission
Journey stages

Definition

What is this pattern?

Access is conditioned on accepting optional or separable data uses, communications or permissions as one bundled choice. The label describes a recurring design mechanism; whether a particular implementation is harmful or unlawful depends on the complete journey, audience, evidence and rules within scope.

How it works

Access is conditioned on accepting optional or separable data uses, communications or permissions as one bundled choice. Several distinct processing purposes are collapsed into one take-it-or-leave-it permission, so a person cannot accept necessary operation without optional uses.

Warning signs

  • Multiple consequences or purposes are attached to one acceptance control.
  • At least one consequence appears separable from the core function.
  • Refusal blocks or materially burdens access.

Potential harms

  • A visitor cannot distinguish necessary operation from optional data uses or express separate choices.
  • Refusing unrelated marketing appears to prevent completion of the requested transaction.

Learn by comparison

What does this look like?

These fictional examples make the design mechanism easier to recognise. They do not depict a real company and do not establish that an individual interface is unlawful.

Illustrative example 1 · News site entry

A fictional news service presents one accept control for essential storage, audience analytics, advertising profiles and partner sharing, while access is blocked.

Potential consumer harm: A visitor cannot distinguish necessary operation from optional data uses or express separate choices.

Illustrative example 2 · Ticket checkout

A fictional ticket seller requires one checkbox that accepts the purchase terms, promotional messages and sharing with event partners.

Potential consumer harm: Refusing unrelated marketing appears to prevent completion of the requested transaction.

What is a fairer alternative?

Separate distinct purposes, make optional uses genuinely optional, and provide an equally accessible refusal path.

Context matters

Context and boundary cases

  • Multiple consequences or purposes are attached to one acceptance control.
  • At least one consequence appears separable from the core function.
  • Refusal blocks or materially burdens access.
  • Exclude or qualify the label where single necessary processing operation clearly explained.
  • Exclude or qualify the label where bundle with granular equivalent controls and no penalty for refusal.

When a similar design can serve a legitimate purpose

  • A similar design should not be classified this way where single necessary processing operation clearly explained.
  • A similar design should not be classified this way where bundle with granular equivalent controls and no penalty for refusal.

Operational review

What teams should review

Teams
  • Product
  • UX
  • Legal
  • Engineering
  • Content design
  1. What functional need makes “Accept everything” necessary for the news site entry goal, and can that need be met with less disclosure or commitment?
  2. Capture every peer option, its default state and visual prominence; do those states support “Multiple consequences or purposes are attached to one acceptance control”?
  3. Could the stated purpose make this dependency genuinely necessary under the boundary “Single necessary processing operation clearly explained”, and what product evidence would demonstrate that necessity?
  4. What functional need makes “Accept all terms and offers” necessary for the ticket checkout goal, and can that need be met with less disclosure or commitment?
  5. Which fields or permissions are required, what happens on refusal, and does the resulting state support this criterion: “At least one consequence appears separable from the core function”?
  6. Could the stated purpose make this dependency genuinely necessary under the boundary “bundle with granular equivalent controls and no penalty for refusal”, and what product evidence would demonstrate that necessity?
  7. Which complete journey evidence supports or contradicts the forced or bundled consent classification?

Evidence to retain

  • Versioned captures of the Signup and Checkout states before, during and after the relevant decision
  • Configuration, content and event records supporting the observed forced or bundled consent mechanism
  • Responsive, keyboard and assistive-technology review of every material option and consequence
  • Control defaults, validation rules and consent or selection state changes

Legal map and implementation tools

Evidence base

Sources

  1. An Ontology of Dark Patterns KnowledgeGray et al.; ACM CHI 2024 · Secondary · checked 2026-09-14 · DOI 10.1145/3613904.3642436; arXiv:2309.09640
  2. Behavioural study on unfair commercial practices in the digital environmentEuropean Commission, Directorate-General for Justice and Consumers · Secondary · checked 2026-09-14 · DOI 10.2838/859030; ISBN 978-92-76-52316-1
  3. Unfair Commercial Practices DirectiveEuropean Parliament and Council of the European Union · Primary · checked 2026-08-09 · Directive 2005/29/EC; CELEX 02005L0029-20220528
  4. Digital Fairness Act: call for evidence for an impact assessmentEuropean Commission · Primary · checked 2026-08-09 · Initiative 14622; Ares(2025)6275573
  5. Commission work programme 2026: Europe's Independence MomentEuropean Commission · Primary · checked 2026-09-14 · COM(2025) 870 final; CELEX 52025DC0870; Annex I item 30