The question at hand
You're redesigning your consent mechanism. Engineering wants a streamlined experience with minimal clicks. Legal wants clear, granular choices. Your product manager argues that friction kills conversion. Your privacy counsel points to the Norwegian Consumer Council's complaint against Grindr, which led to a proposed $12 million fine from Datatilsynet, and warns that "frictionless" can cross into "manipulative."
This tension is central to consent design. Should you add friction to ensure users make informed decisions? Or does friction become a dark pattern when it frustrates users into abandoning services?
The regulatory landscape offers conflicting signals. Article 4(11) GDPR requires consent to be "freely given, specific, informed and unambiguous." Article 7(2) demands that consent requests be "clearly distinguishable from other matters, in an intelligible and easily accessible form, using clear and plain language." But what counts as "easily accessible"? A single toggle that bundles purposes? Or a multi-step flow that separates each processing activity?
The case for friction
Privacy advocates argue that meaningful consent requires cognitive engagement. The Norwegian Consumer Council's report on dark patterns showed how companies nudge users toward business-friendly choices. When Datatilsynet proposed its enforcement action against Grindr, it signaled that regulators will penalize designs prioritizing speed over understanding.
Friction proponents highlight design elements that force deliberation. Separating marketing consent from essential processing requires users to evaluate each purpose. Requiring users to scroll through a full privacy notice before enabling a "Continue" button ensures they've seen the information. Disabling pre-ticked boxes means users must actively opt in.
The European Data Protection Board's Guidelines 05/2020 on consent under GDPR support this. The EDPB states that consent can't be bundled with terms of service, and that silence, pre-ticked boxes, or inactivity don't constitute valid consent. These requirements inherently create friction by preventing one-click acceptance flows.
From a liability perspective, friction creates documentation. When a user clicks through multiple consent screens, you've generated clear evidence of informed choice. If that user later files a complaint or exercises their Right to Withdraw Consent, your audit trail shows you met the "specific" and "informed" requirements. Frictionless flows leave you vulnerable to claims that users didn't understand what they were agreeing to.
The case for clarity over friction
Critics of deliberate friction argue you're confusing "informed" with "exhausted." Adding steps doesn't guarantee comprehension. It guarantees abandonment, which serves neither users nor controllers.
Consider the user who encounters your five-screen consent flow after creating an account. They've already invested time in registration. Your friction-heavy design presents them with a binary choice: click through everything to access the service they want, or abandon the account entirely. This isn't meaningful consent. It's compliance theater that forces users to pretend they've read and understood complex processing descriptions.
The UK Information Commissioner's Office guidance on consent emphasizes that controllers must make it "as easy to withdraw consent as to give it." If your consent mechanism requires multiple steps to grant permission, your withdrawal process must match that complexity. But the ICO also recognizes that unnecessary complexity can undermine consent validity. Users who don't understand your consent request because it's buried in procedural friction haven't given informed consent; they've given frustrated consent.
Product teams argue that genuine user protection comes from clear, concise communication, not from artificial barriers. A single screen that explains data processing in plain language, with separate toggles for distinct purposes and a prominent "Reject All" button, respects user autonomy more than a multi-page flow that exhausts users into clicking "Accept" just to make it stop.
There's also a competitive dimension. Your friction-heavy consent flow drives users to competitors who've found ways to communicate clearly without creating obstacles. You're not protecting users; you're selecting for users who'll click through anything, which is precisely the behavior you claim to prevent.
Where practitioners actually land
Most privacy officers implement a hybrid approach that varies by processing purpose and user context. They add friction where regulatory risk is highest: special category data, automated decision-making, third-party sharing for marketing. They reduce friction for processing that's genuinely necessary for service delivery and where users have clear expectations.
Your preference center becomes the key architectural element. At registration, you present a streamlined flow that covers only essential processing, with clear language and no pre-selections. You defer granular marketing choices to a separate preference center that users access after they've experienced your service and understand what they're consenting to. This approach satisfies the EDPB's requirement that consent be unbundled from terms of service while acknowledging that users at registration aren't equipped to make informed decisions about processing they haven't experienced yet.
You also differentiate between new users and returning users. A first-time visitor sees more explanation and requires more explicit action. A returning user who's already configured their preferences sees a confirmation rather than a full consent flow. This respects the principle that consent must be informed without treating every interaction as if the user has no prior knowledge.
Our take
Friction is a tool, not a principle. The question isn't whether to use it, but where and why.
Add friction when you're asking users to make decisions with significant privacy implications they might not immediately grasp. Separate consent for location tracking from consent for email newsletters. Require Informed Consent for sharing data with third parties. Make users acknowledge when processing involves automated decision-making that affects them materially.
Remove friction when it serves only to create documentation for your audit file. If users need to click through six screens to access basic functionality, you haven't protected them. You've created a process that trains them to ignore your consent requests entirely.
The Norwegian Consumer Council's work demonstrates that regulators and advocacy organizations are scrutinizing design choices, not just legal text. Datatilsynet's proposed $12 million fine against Grindr signals that "we disclosed it" won't protect you if your interface design undermines that disclosure.
Your consent mechanism should pass a simple test: if a user later claims they didn't understand what they agreed to, can you point to specific design elements that ensured comprehension? Not steps they had to click through, but information they had to engage with. That's the distinction between friction that protects users and friction that protects only you.



