

How was there double consent required?
Without ATT companies use dark patterns, opt-out, and over burdensome Privacy Policies or Terms of Service to get what they claim is consent.
When users get a straightforward choice to allow tracking or not, like with ATT, most don’t allow it.

I don’t think two separate forms are needed for GDPR consent and ATT. Apps I worked on took the result from ATT and used that as the user consenting to be tracked in the app for GDPR.
I guess companies want to make it cumbersome as possible so user gets fatigued and just clicked through it mindlessly like with cookies banners on every website.