A UX designer notices that a cookie consent banner uses a large, colorful 'Accept All' button but a tiny gray 'Manage Preferences' link. Which regulatory body would classify this as non-compliant and why?
-
A
NIST, because it violates cybersecurity framework principles
-
B
EU Data Protection Authorities, because asymmetric choice design compromises freely given GDPR consent
-
C
ISO, because it fails usability standards
-
D
FCC, because it misrepresents data practices