Privacy gate as a workflow: what to check on a cookie wall after the DPG case
The Belgian regulator is handling the complaint against DPG's cookie wall. What this means for designing and checking your privacy gate as a workflow.
You must treat your privacy gate as an auditable workflow, not a banner. Every choice to accept or refuse consent, every subsequent change, and the data flows that follow must be traceable to the individual user. This is now an enforcement matter.
The prompt is an analysis of 6 September 2026 of privacy gate design under regulator scrutiny, which argues that consent screens are judged on their concrete operation, not their stated intent. The Belgian Data Protection Authority has decided to investigate a complaint against a media company's cookie wall, examining whether its design choices—button placement, colour nudging, withdrawal friction—actually permit free and informed consent. In our assessment, this signals that regulators will now examine the entire chain behind a consent screen: how consent is recorded, how preferences are changed, which data flows follow, and whether you can reconstruct each user's journey through that chain.
What makes a consent screen an enforcement target?
Consent has long been required to be free, specific, informed and unambiguous. The tension in the DPG case is that the company presents its privacy gate as proof of responsible data handling, whilst regulators are examining whether the gate's design actually delivers valid consent. The difference matters: a privacy architecture is not judged on intention, but on what happens at each moment of choice. When a refuse button is absent, when colours nudge users toward acceptance, or when withdrawing consent requires disproportionate effort, the screen fails the test—regardless of what the company intended.
Which design failures create regulatory risk?
- Asymmetric friction — accepting consent is easier than refusing it, or withdrawing is harder than granting.
- Absent or obscured refusal — no clear button or path to decline tracking alongside the accept option.
- Nudging through design — colour, layout or visual hierarchy that steers users toward consent rather than presenting choices neutrally.
- Opaque consent recording — no clear record of what the user chose, when, and under what terms.
- Trapped preference changes — users cannot easily change their mind after initial consent, or the mechanism to do so is hidden or burdensome.
What must you be able to demonstrate per user journey?
- Document the consent moment — record what choice the user made, when, which data categories they consented to, and on what lawful basis.
- Show the refusal path — prove that declining consent is as straightforward as accepting it, with equivalent visibility and effort.
- Trace data flows downstream — map which systems receive data after consent, which models or services process it, and whether that processing matches what the user was told.
- Record preference changes — maintain an audit trail of every time a user modifies their consent, including timestamp and the new state.
- Link consent to output — if AI generates content or personalisation based on consented data, show which consent decision enabled which output.
How does the privacy gate connect to the rest of your data chain?
The consent screen is not separate from the systems behind it. Account linking between brands, the data vault, the personalisation layer, and any AI models that draw on the data all depend on the consent decision. If you manage these as isolated silos, you cannot reconstruct what happened during an investigation. The regulator's question shifts from
Sources: This article draws on reporting and guidance from Tweakers, DPG Media, Article 29 Working Party and Consumer Finance Monitor.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.