>Not to mention that if there were any hypothetical API calls those could be made asynchronously after closing the modal.
If you did that, users wouldn't be able to see whether their opt out was successful.
If you did that, users wouldn't be able to see whether their opt out was successful.
Like the sibling poster said, the default should be opt-out.
It's not as if this TrustArc modal is some old product that was repurposed for GDPR. This is all planned and done in bad faith, period. It's a dark pattern.