Interesting that this site itself may use one of the described dark patterns. The banner on the main page has options "Got it" and "Learn more". There is no indication as to whether the "Got it" button is taken as consent for tracking, nor is there a "Reject all non-essential tracking" option on the main banner. Whether or not this site is compliant depends on whether the "Got it" button is taken as affirmative conse…
"It shall be as easy to withdraw as to give consent."
All those dark patterns to hide the rejection, keep some things ticked etc. are a complete waste of time. They all violate GDPR and are just another case for: no one has read the GDPR and is just copying everyone else.
It is just a waste of developers time, hiding rejection of consent, making it less understandable, etc. is just violating the GDPR. Google is violating it, Facebook is violating it,... but they have money for lawsuits, if you have it too, no problem, just copy them, if not, reconsider your tactics.
Bottom line, you are wasting time and effort to implement it, you are trolling the users with popups and at the end even the consents that you got is invalid and void. So why doing it?
Imagine the scenario, your beautiful website, your beautiful android application is being checked for a GDPR compliance based on lawsuit.
And you bring in your dark-patterned consent dialog (whoever the provider is, it doesn't matter, YOU are the controller, YOU are the one who needs to care for your visitors/users privacy and you will be fined if google ads are violating privacy by their scripts run from your application/site).
What do you think will happen, you will get pat on your back and someone one will say "you poor thing, you didn't understand, let me pardon you" or you will get an "Tommy Lee Jones" implicit facepalm [1]?
Same goes for all the sites that stuff the user id into the "consent/no consent" cookie where just setting "consent=yes" or "consent=no" would be enough. Again, just same thing, for avoiding storing one PII you create another PII (by GDPR, anything that is unique to a person is PII) and violate it by doing that. Just why. Dont bother. Wait for a law suit and that is it. Dont just waste more money with same result as not wasting it, rather label a jar with "GDPR Lawsuit" label and stuff the money wasted for illegal consent methods into the jar.
[1] https://me.me/i/implied-facepalm-when-something-is-so-ridicu...