What's more, if the 'cookie' is entirely local (i.e. it's never sent back to your own server, e.g. you're using the local storage API and the javascript on your page never puts that information into a request), like how this would normally be implemented nowadays, then these requirements don't apply at all (because a cookie according to the law is just something your server gives to the user's device and then the device gives back later).
If you want to remember dark mode with a cookie, then you can just gate that setting behind a “allow functional cookies” toggle.
Getting consent for functional cookies doesn’t have to be done with an intrusive cookie bar on landing. You can request consent as it becomes needed. There’s other ways of complying that aren’t dark patterns.
In any case here is a plain text interpretation from the EU (https://gdpr.eu/cookies/):
"Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user.
Preferences cookies — Also known as “functionality cookies,” these cookies allow a website to remember choices you have made in the past, like what language you prefer, what region you would like weather reports for, or what your user name and password are so you can automatically log in."
Farther down:
"To comply with the regulations governing cookies under the GDPR and the ePrivacy Directive you must:
Receive users’ consent before you use any cookies except strictly necessary cookies. ..."
So a preference cookie is categorized differently than "strictly necessary" by the ePrivacy rules predating, but now part of, GDPR. But elsewhere in this thread someone asserted that a cookie that is placed and the data never sent back to the server is exempt, so if you handle dark mode entirely client side you might be ok?
I'm beginning to understand why the lawyers in the EU just say "fuck it, put a banner up"
Google “lex especialis eprivacy GDPR”.
You are correct that people keep stating such things. But it is incorrect.
That example would be an essential cookie, also known as a strictly necessary cookie.
A shame this FUD is still being spread.
I suggest actually reading the GDPR if you think it applies to you. The EU put it up on a website for everyone to see. Here's the most relevant section: https://gdpr-info.eu/art-6-gdpr/
Notice how cookies are not mentioned, popups are not mentioned, and strictly necessary is not mentioned. Those are requirements the data harvesting industry invented out of whole cloth. They are not the actual requirements.
I'll just repeat that one more time: the GDPR does not mention cookies or popups. Let that sink in. It's all cargo-cult.
The GDPR also doesn't give a shit about dark mode preference. Literally nothing in it has any relevance to a dark mode preference, even (and especially) if you store it in a cookie.
In short: the GDPR doesn't mention it but it is covered by the ePrivacy directive/regulations which does cover cookies very specifically, and which is enforced through GDPR.
Have a good day.
b) Please don't re-implement OS/browser functionality in your website.