It is illegal, at least from the point of view of the GDPR which is what these pop ups are supposed to comply with.
You could argue that the artificial delay is implemented as a way to dissuade people from declining which would fail the idea that data processing consent should be freely given (you can’t force people to opt-in).
You could also argue that even if there was a legitimate technical reason for the delay then it wouldn't be compliant because it would prove that data processing is enabled by default before the user opts-in (otherwise the delay should be on opt-in and opt-out should be instant as it's essentially a no-op).
TrustArc essentially provides "breaching the GDPR as a service" and their continued existence proves the incompetence of the data/privacy regulators in all EU countries.
It may also be a sign of how much national governments care about privacy, compared to the EU parliament which voted for the e-Privacy Directive.
I suppose the counter-argument would be that passing legislation is cheap, but enforcing it costs money, and governments have other priorities, but, for example, in the UK there can be fines of up to £500,000 for breaches of the e-Privacy Directive[0], which should be more than enough to cover the cost of the investigation.
You could argue that the artificial delay is implemented as a way to dissuade people from declining which would fail the idea that data processing consent should be freely given (you can’t force people to opt-in).
You could also argue that even if there was a legitimate technical reason for the delay then it wouldn't be compliant because it would prove that data processing is enabled by default before the user opts-in (otherwise the delay should be on opt-in and opt-out should be instant as it's essentially a no-op).
Here are the ICO’s guidelines on the subject - you’ll see that this TrustArc trash fails on multiple points: https://ico.org.uk/for-organisations/guide-to-data-protectio...
TrustArc essentially provides "breaching the GDPR as a service" and their continued existence proves the incompetence of the data/privacy regulators in all EU countries.