GDPR Consent Requirements: What Counts as Valid Consent (2026)

By Recording Law Editorial TeamReviewed September 11, 202624 min read
GDPR Consent Requirements: What Counts as Valid Consent (2026)

Frequently Asked Questions

What counts as valid consent under the GDPR?

Valid GDPR consent must be freely given, specific, informed, and unambiguous. The individual must take a clear affirmative action -- ticking an unticked box, clicking a consent button, or choosing specific settings. Pre-ticked boxes, silence, inactivity, and scrolling are explicitly excluded. Each processing purpose needs its own consent, and the individual must receive clear information about who is processing their data and why before consenting.

Can I use pre-ticked checkboxes for GDPR consent?

No. The GDPR and Recital 32 explicitly prohibit pre-ticked boxes as a form of consent. Consent requires a clear affirmative action by the individual. The checkbox must start unticked, and the individual must actively tick it. The CJEU confirmed this in Planet49 (Case C-673/17, 2019), which held that pre-ticked boxes do not constitute valid consent under EU law.

Do I need consent for every type of data processing?

No. Consent is only one of six lawful bases under Article 6. You may not need consent if processing is necessary to perform a contract, comply with a legal obligation, protect vital interests, carry out a public interest task, or pursue legitimate interests that do not override the individual's rights. Relying on consent when another basis applies creates unnecessary management overhead and withdrawal risks.

At what age can children consent under the GDPR?

The GDPR sets a default threshold of 16 for information society services (apps, social media, online platforms). EU member states can lower this to a minimum of 13. In practice, the age varies: 13 in Belgium, Estonia, Finland, Latvia, Malta, Portugal and Sweden; 14 in Austria, Bulgaria, Cyprus, Italy, Lithuania and Spain; 15 in Czechia, Denmark, France, Greece and Slovenia; 16 in Croatia, Germany, Hungary, Ireland, Luxembourg, the Netherlands, Poland, Romania and Slovakia. Denmark moved from 13 to 15 on 1 January 2024. A service operating across Europe must apply the applicable age for each country.

How do I withdraw consent under the GDPR?

Consent can be withdrawn at any time. The withdrawal process must be as easy as giving consent. If consent was given with one click, withdrawal must require no more than one click. The right to withdraw must be communicated before consent is obtained. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal, but the organisation must stop consent-based processing going forward.

Do I need consent for cookies on my website?

Non-essential cookies -- analytics, advertising, tracking, social media -- require consent under the ePrivacy Directive. That consent must meet GDPR standards. Legitimate interest cannot be used to justify setting non-essential cookies. Strictly necessary cookies (session management, security, load balancing) are exempt. The November 2025 Digital Omnibus proposes simplifying these rules, but it is not yet law.

What is the difference between consent and explicit consent?

Regular consent requires a clear affirmative action for standard personal data processing. Explicit consent is a higher standard required for special-category data -- health, genetic data, biometric data used to identify a person uniquely, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, or sexual orientation. It requires an express statement of consent that names the sensitive data category and the specific purpose. It does not have to be on paper: EDPB Guidelines 05/2020 accept an electronic form, an email, an uploaded scanned signed document, an electronic signature, a two-stage email or SMS confirmation, or a recorded telephone confirmation, provided the controller can demonstrate it. Implied or general consent is never enough.

Is a consent-or-pay model lawful under the GDPR?

Not automatically. EDPB Opinion 08/2024 concluded that in most cases a large online platform cannot obtain valid consent under a pure binary model -- consent to behavioural advertising, or pay a fee. The EDPB says a paid alternative should not be the default, and that where a platform does charge for the equivalent alternative it should consider offering a further alternative free of charge without behavioural advertising, for example one using a form of advertising that processes less (or no) personal data. Whether that free option is offered has a substantial impact on the validity of the consent. Fees must not be set so high that they effectively coerce consent. The consent option must still meet all four GDPR consent conditions.

What does the November 2025 Digital Omnibus change about cookie consent?

Nothing yet -- it remains a legislative proposal. The Commission proposed moving the device-access consent rule for individuals into a new GDPR Article 88a, exempting security and first-party audience measurement from consent, requiring single-click refusal, barring a repeat request for the same purpose for at least six months after a refusal, and requiring machine-readable consent signals. The proposal names no calendar date: its 6, 24 and 48 month deadlines all run from an entry into force that has not happened, and the file (procedure 2025/0360(COD)) is still at the opinion stage. Until it passes and takes effect, current cookie consent rules under the ePrivacy Directive apply unchanged.

Updates

Major expansion: Digital Omnibus November 2025 cookie reform, CNIL enforcement against Google (325M euros) and SHEIN (150M euros), draft EDPB-Commission joint DMA/GDPR guidelines, common consent mistakes section, UpdatesLog component.

Initial publication.

Sources and References

  1. GDPR Full Text -- Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  2. EDPB Guidelines 05/2020 on Consent under Regulation 2016/679(edpb.europa.eu).gov
  3. EDPB Summary on Consent (April 2026)(edpb.europa.eu).gov
  4. European Commission -- How Should My Consent Be Requested?(commission.europa.eu).gov
  5. ICO -- What Is Valid Consent?(ico.org.uk).gov
  6. ICO -- How Should We Obtain, Record and Manage Consent?(ico.org.uk).gov
  7. ICO -- When Is Consent Appropriate?(ico.org.uk).gov
  8. European Commission -- Specific Safeguards for Children Data(commission.europa.eu).gov
  9. EDPB Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models(edpb.europa.eu).gov
  10. EDPB Cookie Banner Taskforce Report (2023)(edpb.europa.eu).gov
  11. EDPB Guidelines 03/2022 on Deceptive Design Patterns(edpb.europa.eu).gov
  12. ICO -- Cookies and Similar Technologies(ico.org.uk).gov
  13. EDPB Guidelines 1/2024 on Legitimate Interest(edpb.europa.eu).gov
  14. EDPB Draft Guidelines 3/2025 on the Interplay between the DSA and the GDPR (public consultation closed 31 October 2025; not yet adopted)(edpb.europa.eu).gov
  15. EDPB and European Commission Draft Joint Guidelines on DMA and GDPR Interplay (public consultation closed 4 December 2025; not yet adopted)(edpb.europa.eu).gov
  16. CNIL -- Google Fined 325 Million Euros for Cookie and Advertising Consent Violations (September 2025)(cnil.fr).gov
  17. CNIL -- SHEIN Fined 150 Million Euros for Placing Cookies Without Consent (September 2025)(cnil.fr).gov
  18. European Commission -- Digital Omnibus Package (November 2025)(digital-strategy.ec.europa.eu).gov
  19. Your Europe -- Online Privacy for Businesses(europa.eu).gov
  20. Denmark -- Databeskyttelsesloven, LBK nr. 289 af 08/03/2024, section 6(2) (age 15 since 1 January 2024, per lov nr. 1783 af 28/12/2023)(retsinformation.dk).gov
  21. Czechia -- Act No. 110/2019 Sb. on Personal Data Processing, section 7 (child acquires capacity to consent on completing the fifteenth year of age)(eur-lex.europa.eu).gov
  22. Croatia -- Zakon o provedbi Opce uredbe o zastiti podataka, Narodne novine 42/2018, article 19 (age 16)(narodne-novine.nn.hr).gov
  23. European Commission -- First DMA Non-Compliance Decisions: Meta Fined 200 Million Euros over its Consent or Pay Model (23 April 2025)(digital-markets-act.ec.europa.eu).gov
  24. COM(2025) 837 final -- Digital Omnibus proposal, new GDPR Articles 88a, 88b and 88c and amendments to Directive 2002/58/EC (procedure 2025/0360(COD))(eur-lex.europa.eu).gov
  25. EDPB Statement 1/2025 on Age Assurance (adopted 11 February 2025)(edpb.europa.eu).gov
  26. CJEU -- Meta Platforms and Others v Bundeskartellamt, Case C-252/21 (Grand Chamber, 4 July 2023)(eur-lex.europa.eu).gov
  27. General Court -- Meta Platforms Ireland v EDPB, Case T-319/24, order of 29 April 2025 (challenge to EDPB Opinion 08/2024 dismissed; appeal C-454/25 P brought 10 July 2025)(eur-lex.europa.eu).gov
Share: