There are two clearly labeled buttons with good contrast, one for "accept all" and one for "accept selected" (with the latter even being a bit bigger and more visible), plus a third (less visible) "decline" button for those who don't want to check whether the default is checking only essential cookies.
Moreover, if you actually take a closer look, none of the cookies the banner asks for are actually the usual user-hostile ad/tracking cookies. The only thing you can even turn on/accept is third party embeds.
Clicking "accept all" on this dialog puts you into a more privacy-friendly position than clicking "deny all" on many websites (because they then still use 20+ trackers claiming legitimate interest), and IMO this site is one of the few that isn't trying t to trick you into agreeing, and it has two single-click opt-out buttons.
It is easy to think of better UX patterns:
- Check both by default and have only one submit button. This is intuitive but IIUC disallowed by GDPR because it makes opt-out harder than opt-in.
- Skip the checkboxes and simply provide "Required cookies only" or "All cookies". This way there is only one place to make the choice and they aren't ignoring the checkboxes.
- Just remove the "Accept all" button and make the primary form button "Accept accepted".
- There are 2 "required" features. You don't need to get permission to place cookies that are needed to make your site function. Placing a cookie to track your consent is perfectly fine, no need to make that optional, or even mention it in the cookie banner. Same goes for the session cookie: if you need it just set it. You could question if you actually need it in this case, but as long as it's a true session cookie and not persisted I would consider it not personally identifiable.
- There are 2 optional features: Youtube Videos and Google Maps. Why do I have to fold open "Features" to find out what the features are? Just show me the list already. Hiding the list is a dark pattern employed by advertisers to get you to agree. In this case the features are actually valuable: embedded videos and embedded maps.
- Those 2 optional features are not even used on the linked page! Then why does it show me a consent banner?
For some reason people hear gdpr compliance and just slap on an annoying consent modal popup.
A much better solution is to just put an embed placeholder with the title of the linked content, and warn the user that 3rd party wants your personal data. Put a link to a detailed privacy policy, and a link to enable the embed. At that point record the consent and enable the embed.
Maybe you're less used to seeing them because you're not from the EU, but most cookie banners / popups have at least one or more actual obnoxious user-hostile patterns going on:
- Actual really hard to find decline / accept selected button, sometimes obfuscated behind a small, badly colored "More information" link. - A list of 60-120 "partners" (no joke) with no way to see what functionality they actually provide - No decline button at all - Pressing decline (or "agree to selected") makes the modal popup spin a spinner for 60 seconds while supposedly processing your request. Pressing accept makes it go away instantly - 4-5 categories. Required (/Essential), Functional, Marketing, Statistics with no clear explanation of what will be impacted when you disable a category. - No way to accept cookies from Vimeo embeds, but not accept cookies from Google (YouTube) embeds
I could go on and on.
This site on the other hand doesn't even have analytics or any of the scummy stuff the cookie consent law was designed to thwart, they clearly provide an explanation of each category and your options, all the buttons are the same size but clearly differentiated and was actually the first site I've ever(!) accepted all cookies from.
I love anti-patterns. My favorite is Android, in response to a government somewhere, every half year or so being required to ask my permission to destroy what shred of privacy I am still afforded. "What's the most honest way to meet the legal requirement and ask the user in good faith?" I hear you ask. Good question, and the solution is simple: randomly interrupt the user's existing workflow with a popup. Comprehending this non sequitur is near impossible. Rejecting the proposal is met with a caution that certain features may not function as expected and guarantees future interruption by the exact same question. And all this if you didn't accidentally click OK straight away because the popup jumped in front of whatever you were already trying to click in your intended app. 0.2 seconds of transient grey screen beyond which you regret that you have just given them permission to something you would never normally accept if it were explained in a single simple sentence, and undoing it is impossible. Sleazy.