GDPR Consent Requirements: What Counts as Valid Consent (2026)

Under GDPR Article 4(11), valid consent requires four cumulative conditions: the individual must give it freely, for a specific purpose, with full information, and through an unambiguous affirmative action. Article 7 then requires controllers to document that consent and to make withdrawal as easy as giving it. It also directs that, in judging whether consent was freely given, utmost account is taken of whether a service is made conditional on consent to processing that is not necessary for it.
Consent is one of the six lawful bases for processing personal data under the GDPR. When an organisation relies on it, the standards are strict. A privacy policy buried in terms and conditions does not qualify. A pre-ticked checkbox does not qualify. Inactivity does not qualify.
Getting consent wrong can trigger enforcement fines. Getting it wrong at scale -- as Google and SHEIN discovered in September 2025 -- can mean nine-figure penalties. This guide explains what valid consent requires, when consent is the right basis (and when it is not), and what the 2024-2026 regulatory developments mean in practice.
For a full overview of the regulation, see What Is GDPR. For cookie-specific rules, see the ePrivacy Directive guide. For a step-by-step compliance programme, see the GDPR compliance checklist.
This article is for informational purposes only and does not constitute legal advice. Consult a qualified data protection attorney or privacy professional for guidance specific to your situation.
Quick Answer: What Makes Consent Valid Under GDPR?
Article 4(11) of the GDPR defines consent as "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her."
Four elements must all be present at the same time. Missing even one invalidates the consent entirely.
- Freely given -- genuine choice, no coercion, no bundling with unrelated conditions
- Specific -- separate consent for each distinct purpose
- Informed -- clear, plain-language explanation of who, what, and why before the individual decides
- Unambiguous -- a positive opt-in act; silence or inactivity is never enough
Article 7 then adds conditions on how consent must be managed once obtained. The EDPB Guidelines 05/2020 on consent remain the authoritative interpretation of these requirements.
The Four Elements in Detail
1. Freely Given
Consent is only valid if the individual has a genuine, free choice and can refuse without suffering any disadvantage.
Power imbalance. When there is a significant imbalance between the controller and the data subject, consent is unlikely to be freely given. In Meta Platforms v Bundeskartellamt (Case C-252/21, Grand Chamber, 4 July 2023) the CJEU held that users of a dominant social network must be free to refuse individual processing operations that are not necessary for the contract without having to give up the service, which means they must be offered, if necessary for an appropriate fee, an equivalent alternative not accompanied by those operations. The clearest example is the employment relationship. Employees may feel they have no practical ability to refuse their employer's data processing requests. The EDPB guidelines warn that in most employment contexts, consent will not be a valid basis precisely because of this asymmetry.
Conditionality. Article 7(4) is a weighting rule rather than a flat prohibition: when assessing whether consent is freely given, utmost account is taken of whether performance of a contract is made conditional on consent to processing that is not necessary for that contract. Recital 43 goes further and says consent is presumed not to be freely given in that situation. So an e-commerce site that requires customers to consent to marketing emails as a condition of completing a purchase will struggle to show that the consent was free.
Granularity. A single "I agree to all data uses" checkbox covering multiple unrelated purposes does not satisfy the specificity requirement and undermines freedom of choice. Individuals must be able to accept some purposes and decline others independently.
No detriment. Refusing or withdrawing consent must carry no penalty, degraded service, or restricted access beyond what is strictly necessary. If a platform downgrades features for users who decline optional data processing, the consent obtained from those who agree is open to challenge.
2. Specific
Consent must be tied to each individual processing purpose. Blanket consent covering all current and future data uses is invalid.
The EDPB guidelines require a separate consent request for each distinct operation. If an organisation collects email addresses for a newsletter and also wants to share them with third-party advertisers, it needs two separate consent requests -- presented independently, not stacked under a single checkbox.
Purpose creep is a common problem. An organisation that later wants to use data for a purpose not covered by the original consent cannot simply rely on that original consent. It must seek a new, specific consent for the new purpose, or identify a different lawful basis.
3. Informed
Individuals must receive enough information to make a meaningful decision before they consent. EDPB Guidelines 05/2020, paragraph 64 set the minimum that must be disclosed at the time of the consent request:
- The identity of the controller
- The purpose of each processing operation for which consent is sought
- What types of data will be collected and used
- The existence of the right to withdraw consent
- Where relevant, use of the data for automated decision-making under Article 22(2)(c)
- The possible risks of transfers to countries with no adequacy decision and no appropriate safeguards under Article 46
This information must be in clear, plain language. Hiding it behind a link to a lengthy privacy policy, or presenting it in legalese, does not satisfy the informed requirement. The EDPB has consistently held that layered notices -- short summaries with accessible links to full detail -- are acceptable, but the core information must be genuinely accessible and understandable before the consent action is taken.
4. Unambiguous (Clear Affirmative Action)
The GDPR and Recital 32 are explicit: silence, pre-ticked boxes, and inactivity do not constitute consent.
Valid affirmative actions include:
- Ticking an unticked opt-in box
- Clicking an "I consent" or "Accept" button where the processing information is clearly presented
- Choosing specific settings on a privacy dashboard
- Signing a written consent form
- Making an oral statement (though documenting this is difficult)
Scrolling through a page, remaining on a site after a notice appears, or failing to untick a pre-ticked box are not affirmative actions. The Planet49 case (CJEU, Case C-673/17, October 2019) settled this conclusively: the Court held that a pre-ticked box does not constitute valid consent under either the ePrivacy Directive or the GDPR, because it does not reflect active behaviour by the user.

The Article 7 Conditions for Managing Consent
Article 4(11) defines what consent is. Article 7 governs how it must be managed once obtained.
Demonstrability (Article 7(1))
The controller must be able to demonstrate that the data subject consented. This is an ongoing obligation, not a one-time event. The ICO guidance on recording consent recommends documenting:
- Who consented (enough detail to identify the individual)
- When they consented (date and time)
- What they were told at the time (the exact consent statement or form as presented)
- How they consented (online checkbox, verbal, signed form)
- Whether consent has since been withdrawn, and when
Storing a bare "consent = true" flag is insufficient. If the consent statement later changes, version histories must be kept so the organisation can prove exactly what each individual agreed to at the time.
Intelligibility and Accessibility (Article 7(2))
Where consent is given in the context of a written declaration covering other matters (such as terms of service), the consent request must be clearly distinguishable, in plain language, and must not use unnecessarily complex wording. Any part of that written declaration which infringes the GDPR is not binding, which voids the offending part rather than the whole document.
Right to Withdraw (Article 7(3))
Two rules are non-negotiable.
Withdrawal must be as easy as giving consent. If consent was given with one click, withdrawal must be achievable with no more than one click. Requiring a phone call, a letter, or navigation through several account settings menus to withdraw consent originally given by ticking a box is a violation. Enforcement actions have cited this breach directly.
The right to withdraw must be communicated before consent is obtained. Informing individuals of their withdrawal right only after they have already consented does not satisfy Article 7(3).
Withdrawal is not retroactive. Processing that occurred while consent was valid remains lawful. However, the organisation must cease all consent-based processing immediately going forward.
No Detriment (Article 7(4))
The conditionality rule is codified here: when assessing whether consent is freely given, utmost account is taken of whether the performance of a contract is conditional on consent to processing not necessary for that contract.
Consent vs. the Other Five Lawful Bases
Consent is only one of six lawful bases under Article 6. Many organisations default to consent when a different basis would be simpler, more stable, and legally sounder.
| Lawful Basis | When It Applies |
|---|---|
| Contract (Art. 6(1)(b)) | Processing is necessary to perform a contract with the data subject, or to take pre-contractual steps at their request |
| Legal obligation (Art. 6(1)(c)) | Processing is required by EU or member state law (e.g., tax reporting, AML compliance) |
| Vital interests (Art. 6(1)(d)) | Protecting someone's life where they cannot consent |
| Public task (Art. 6(1)(e)) | Exercising official authority or carrying out a task in the public interest |
| Legitimate interests (Art. 6(1)(f)) | The controller's or a third party's interests override the data subject's rights after a documented balancing test |
| Consent (Art. 6(1)(a)) | The data subject freely agrees to the specific processing |
Why choosing consent carelessly creates problems. Consent generates ongoing management overhead: maintaining records, providing withdrawal mechanisms, re-obtaining consent when purposes change, and handling withdrawal requests. If a different basis legitimately applies, it is almost always more practical to use it. The ICO guidance on when consent is appropriate recommends consent only when you genuinely want to give individuals ongoing control over processing that is not otherwise required.
Organisations also cannot switch bases retrospectively. If consent is withdrawn, the organisation cannot simply declare it was relying on legitimate interests all along unless that basis genuinely applied from the start and was documented as such.
Explicit Consent for Special-Category Data
Article 9 prohibits processing special categories of data -- health, genetic data, biometric data processed for the purpose of uniquely identifying a person, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and data concerning sex life or sexual orientation -- unless a specific exception applies. One exception is "explicit consent."
Article 9(2)(a) carries a limit that is easy to miss. Explicit consent lifts the prohibition except where Union or member state law provides that the prohibition may not be lifted by the data subject. In those areas consent is not available as a route at all.
Explicit consent is a higher standard than ordinary consent. It requires:
- A clear, express statement specifically referencing the sensitive data category and the processing purpose
- Active, unambiguous confirmation -- implied or inferred consent is never enough for special-category data
- Separate consent from any general consent to other processing
A generic "I agree to my data being processed" does not satisfy explicit consent for health data. The consent must name the data type and purpose directly.

Children's Consent (Article 8)
Article 8 imposes additional requirements when offering information society services (ISS) directly to children. An ISS covers social media platforms, apps, online games, streaming services, and most commercial websites that collect personal data.
Age Thresholds Across Europe
The GDPR sets the default age threshold at 16. Below that age, parental consent is required. Member states may lower the threshold to a minimum of 13. The result is a patchwork:
| Age | Countries |
|---|---|
| 13 | Belgium, Estonia, Finland, Latvia, Malta, Portugal, Sweden |
| 14 | Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain |
| 15 | Czech Republic, Denmark, France, Greece, Slovenia |
| 16 | Croatia, Germany, Hungary, Ireland, Luxembourg, Netherlands, Poland, Romania, Slovakia |
A service operating across multiple EU member states must apply the age threshold of each country for users in that country, not a single EU-wide age.
Thresholds move, so check the current national act rather than an older table. Denmark raised its threshold from 13 to 15 with effect from 1 January 2024 (Lov nr. 1783 af 28. december 2023, now consolidated as LBK nr. 289 af 08/03/2024, section 6(2)). Czechia has been 15 since Act No. 110/2019 Sb., section 7. Croatia is 16 under Narodne novine 42/2018, article 19. Germany, Hungary, Luxembourg, the Netherlands, Poland and Romania apply the GDPR default of 16 because their implementing acts set no lower age.
Verification and Age Assurance
Article 8(2) requires "reasonable efforts" to verify that parental consent was given. What counts as reasonable is proportionate to the processing risks involved. The EDPB Statement 1/2025 on age assurance, adopted on 11 February 2025, addresses the growing use of technical age-verification tools and identifies three categories: age estimation, age verification, and self-declaration. It also warns that robustness has little meaning for self-declaration, because the reliability of that method depends mostly on the goodwill of the user, and it records the EDPB's serious doubts about self-declaration for high-risk processing.
Age assurance is also increasingly relevant under the Digital Services Act, which imposes separate obligations on very large online platforms concerning minors. The EDPB's draft Guidelines 3/2025 on the interplay between the DSA and the GDPR address the interaction between these regimes. They were released for public consultation, which closed on 31 October 2025, and no final version has been adopted.
Preventive and Counseling Services
Recital 38 states that the consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child. That is guidance on how Article 8 should be read rather than an exception written into the Article, whose three paragraphs cover only the age rule, the reasonable-efforts verification duty, and the saving for national contract law.
Cookie Consent and the ePrivacy Directive
Cookie consent currently operates under the ePrivacy Directive (Directive 2002/58/EC), not the GDPR directly. When cookies involve personal data, the GDPR applies to the subsequent processing of that data, but the permission to set the cookie in the first place is governed by ePrivacy. For the full framework, see the ePrivacy Directive guide.
The Key Rule: Consent Is Mandatory for Non-Essential Cookies
Legitimate interest cannot be used as the basis for setting non-essential cookies. The ePrivacy Directive requires consent for storing information on a user's device, and that consent must meet all GDPR standards. The bar on legitimate interest comes from Article 5(3) of the ePrivacy Directive itself and from paragraph 24 of the EDPB Cookie Banner Taskforce report, which records that the legal basis for placing or reading cookies under Article 5(3) cannot be the controller's legitimate interests. Planet49 (Case C-673/17) is authority for a different point: a pre-checked box is not consent, and users must be told how long the cookies operate and whether third parties may access them.
Cookies That Require Consent
- Analytics and measurement cookies (Google Analytics and similar tools)
- Advertising and behavioural tracking cookies
- Social media plugins and share buttons
- Personalisation cookies not strictly necessary for the service
Cookies That Do Not Require Consent
Strictly necessary cookies are exempt. These include:
- Session management (shopping carts, login state)
- Security and fraud prevention cookies
- Load-balancing tokens
- User preference cookies for accessibility or language settings
Cookie Banner Requirements
The EDPB Cookie Banner Taskforce report identified the most common violations:
- No reject option on any layer alongside an accept button, which a vast majority of the participating authorities treated as an infringement (a few declined, because Article 5(3) ePrivacy does not expressly mention a reject option)
- Pre-ticked checkboxes for optional cookies
- Deceptive design patterns steering users toward accepting
- Invoking legitimate interest as a basis for advertising cookies
- Making withdrawal of cookie consent more difficult than giving it
The EDPB Guidelines 03/2022 on deceptive design patterns address banner manipulation in detail and apply to social media platforms and other online services alike.
The "Consent or Pay" Model and EDPB Opinion 08/2024
Large online platforms have increasingly offered users a binary choice: consent to behavioural advertising or pay a subscription fee. In April 2024, the EDPB issued Opinion 08/2024, requested by the Dutch, Norwegian, and Hamburg data protection authorities.
Core conclusion. In most cases, a large online platform cannot satisfy the requirements for valid consent when it presents users only with a binary choice between consenting to behavioural advertising data processing or paying a fee. The opinion does not declare these models always unlawful, but it sets strict conditions.
What the opinion requires:
- The "consent" option must genuinely satisfy all four GDPR consent conditions, including being freely given.
- The paid alternative must be a genuine equivalent service, not a degraded version.
- Where the platform charges for the alternative, it should consider offering a further alternative free of charge and without behavioural advertising, for example a version using a form of advertising that involves processing less (or no) personal data. Whether that free alternative exists will in most cases have a substantial impact on the validity of the consent, because of the detriment element.
- The fee charged must not be set so high as to effectively coerce consent from users who cannot afford to pay.
The EDPB committed to developing fuller guidelines on "consent or pay" models with broader scope. A stakeholder consultation event was held on 18 November 2024.
Meta tried to have the opinion annulled and failed. The General Court dismissed the action by order of 29 April 2025 in Case T-319/24, in part as inadmissible and in part as manifestly lacking any foundation in law, holding that an Article 64(2) opinion is not a challengeable act. Meta's appeal, Case C-454/25 P, was brought on 10 July 2025 and no judgment has been published.
This opinion is directly relevant to social media platforms, news publishers, and any service that has implemented or is considering a subscription-based alternative to ad-funded free access.
DMA and GDPR: Gatekeeper Obligations
For platforms designated as "gatekeepers" under the Digital Markets Act, additional constraints apply. Article 5(2) DMA requires a specific choice and valid consent before a gatekeeper combines personal data across its core platform services. In October 2025 the EDPB and the European Commission published draft Joint Guidelines on the interplay between the DMA and the GDPR for public consultation, which closed on 4 December 2025. A final version has not been adopted. For platforms that are both DMA gatekeepers and subject to the GDPR, both sets of requirements apply simultaneously.
Enforcement has already followed. On 23 April 2025 the Commission adopted its first DMA non-compliance decision against Meta and fined it 200 million euros. The Commission found that Meta's November 2023 binary consent-or-pay model on Facebook and Instagram did not give users the required specific choice to opt for a service that uses less of their personal data but is otherwise equivalent to the personalised-ads service, and did not allow users to exercise their right to freely consent to the combination of their personal data. The decision covers March 2024, when the DMA obligations became legally binding, to November 2024, when Meta introduced a revised less-personalised ads model that the Commission is separately assessing.

Common Consent Mistakes
DPA enforcement decisions and EDPB audit findings consistently identify the same failures. These are the most common:
1. Treating consent as the default basis without reviewing alternatives. Many organisations consent-wash operations that could legitimately rely on contractual necessity or legitimate interests. This creates unnecessary withdrawal obligations and complicates operations when users later exercise the right to withdraw.
2. Pre-ticked boxes or no reject option. Still the single most cited cookie consent violation. A vast majority of the supervisory authorities in the EDPB taskforce treat a banner that carries an accept button but no reject option on any layer as invalid consent, and several DPAs, notably the CNIL, go further and require refusal to be as easy as acceptance on the first layer.
3. Making withdrawal harder than giving consent. Requiring phone calls, letters, or navigating buried account settings to undo consent given by clicking a button is a direct Article 7(3) breach.
4. Bundled consent. A single checkbox covering newsletter subscription, profiling for advertising, and third-party data sharing is invalid. Each purpose needs a separate, independently presented checkbox.
5. No version control on consent statements. Changing a consent form without keeping the prior version means the organisation cannot prove what any individual who consented before the change actually agreed to.
6. Misclassifying analytics cookies as strictly necessary. Measuring how users navigate a site is useful but not strictly necessary to deliver the service. Analytics cookies require consent.
7. Continuing to process after withdrawal. Systems must have a mechanism to immediately cease consent-based processing when a withdrawal is recorded. Delays in downstream systems fed by a CRM are a recurring source of complaints.
8. Using legitimate interest for cookie-based tracking. This remains explicitly prohibited under the current ePrivacy framework. Citing it in a cookie consent notice does not make it lawful.
Enforcement Examples
CNIL v. Google (September 2025, 325 Million Euros)
The French CNIL imposed a combined fine of 325 million euros on Google LLC (200 million euros) and Google Ireland Limited (125 million euros) in September 2025. The investigation, which followed a complaint from NOYB, found two distinct violations. First, Gmail displayed promotional messages inserted between private emails in users' inboxes without consent. Second, during account creation, the consent design made it materially harder to refuse advertising cookies than to accept them, and failed to inform users that Google group service access depended on the placement of advertising cookies. The CNIL ordered Google to stop inserting advertisements into Gmail without prior consent within six months.
CNIL v. SHEIN (September 2025, 150 Million Euros)
In the same enforcement cycle, the CNIL fined SHEIN's Irish subsidiary Infinite Styles Services Co. Limited 150 million euros for placing advertising cookies on users' devices before any interaction with the consent banner -- that is, before the user had the opportunity to accept or refuse. The investigation also found that even when users clicked "refuse all," cookies continued to be placed and previously-set cookies continued to be read. With approximately 12 million French residents visiting the site monthly, the scale of the violation drove the penalty size.
Meta Behavioural Advertising (EDPB Binding Decision, 2023)
On 27 October 2023 the EDPB adopted Urgent Binding Decision 01/2023 under Article 66(2) GDPR, at the Norwegian supervisory authority's request, instructing the Irish Data Protection Commission to impose an EEA-wide ban on Meta's processing of personal data for behavioural advertising on the bases of contract and legitimate interest. Article 66(2) is the urgency procedure, which a concerned authority invokes precisely because ordinary one-stop-shop cooperation has not produced final measures. The decision resulted in Meta shifting away from its previous "legitimate interests" and "contract performance" justifications toward a consent-based model in the EU/EEA. Individuals in Ireland who believe a company relied on invalid consent can complain to the Data Protection Commission.
Recent and Upcoming Developments (2025-2026)
November 2025: The Digital Omnibus Package
On 19 November 2025, the European Commission published its Digital Omnibus Package, a broad simplification initiative proposing amendments to the GDPR, the ePrivacy Directive, NIS2, and the Data Act.
The most significant proposed changes for consent and cookie law are:
Moving the device-access rule into the GDPR. The proposal would disapply the ePrivacy Directive's Article 5(3) device-access rule where the user is a natural person and personal data is involved, moving that case into a new GDPR Article 88a. For that case the current two-step framework -- ePrivacy Directive for the device access permission, GDPR for subsequent processing -- would become a single rule. The rest of the ePrivacy Directive would continue to apply, including confidentiality of communications, traffic and location data, the Article 13 direct-marketing consent rule, and Article 5(3) itself where the subscriber is a legal person.
Consent fatigue measures. The proposals include a single-click refusal option wherever consent is relied upon, a restriction on repeat consent requests for the same purpose within six months of a refusal, and a move toward browser-based machine-readable preference signals.
Statutory exemptions for security and first-party audience measurement. Proposed Article 88a(3) would make storing or reading data on a device, and the processing that follows, lawful without consent where necessary to transmit a communication, to provide a service the user explicitly requested, to create aggregated audience-measurement statistics, or to maintain or restore the security of the service. That is an exemption from the consent requirement, not a legitimate-interest basis. The audience-measurement limb applies only where the controller of the online service does it solely for its own use, which leaves third-party analytics outside it.
Browser-based consent signals. Proposed Article 88b would require controllers to let people give consent, refuse it, or object through automated machine-readable means, and would require browser providers that are not SMEs to supply the technical means to do so. The harmonised standards do not yet exist. The proposal fixes no calendar date: Article 88a would apply 6 months after entry into force, the duty on controllers to accept machine-readable signals 24 months after, and the browser-provider duty 48 months after. Entry into force has not happened, and procedure 2025/0360(COD) is still at the opinion stage, with no European Parliament first-reading position and no Council general approach.
Status. The Digital Omnibus remains a legislative proposal. It must pass through trilogue negotiations between the Commission, the European Parliament, and the Council before becoming law. Nothing in it changes current compliance obligations today.
EDPB Summary on Consent (April 2026)
In April 2026, the EDPB published a concise summary on consent to help organisations understand when consent is required, what it must look like, and what obligations it creates. The document complements the full Guidelines 05/2020 with a more accessible overview aimed particularly at small and medium-sized businesses.
More GDPR Guides
- What Is GDPR for a comprehensive overview of the regulation
- GDPR Compliance Checklist for a step-by-step compliance guide
- GDPR Fines and Penalties for enforcement data and the consequences of non-compliance
- GDPR Data Subject Rights for all eight individual rights
- GDPR Breach Notification 72-Hour Rule for breach reporting obligations
- GDPR for Small Businesses for SME-specific guidance
- EU Cookie Law (ePrivacy Directive) for the full cookie consent framework
- EU Data Privacy Laws for the complete EU data protection overview
Frequently Asked Questions
What counts as valid consent under the GDPR?
Valid GDPR consent must be freely given, specific, informed, and unambiguous. The individual must take a clear affirmative action -- ticking an unticked box, clicking a consent button, or choosing specific settings. Pre-ticked boxes, silence, inactivity, and scrolling are explicitly excluded. Each processing purpose needs its own consent, and the individual must receive clear information about who is processing their data and why before consenting.
Can I use pre-ticked checkboxes for GDPR consent?
No. The GDPR and Recital 32 explicitly prohibit pre-ticked boxes as a form of consent. Consent requires a clear affirmative action by the individual. The checkbox must start unticked, and the individual must actively tick it. The CJEU confirmed this in Planet49 (Case C-673/17, 2019), which held that pre-ticked boxes do not constitute valid consent under EU law.
Do I need consent for every type of data processing?
No. Consent is only one of six lawful bases under Article 6. You may not need consent if processing is necessary to perform a contract, comply with a legal obligation, protect vital interests, carry out a public interest task, or pursue legitimate interests that do not override the individual's rights. Relying on consent when another basis applies creates unnecessary management overhead and withdrawal risks.
At what age can children consent under the GDPR?
The GDPR sets a default threshold of 16 for information society services (apps, social media, online platforms). EU member states can lower this to a minimum of 13. In practice, the age varies: 13 in Belgium, Estonia, Finland, Latvia, Malta, Portugal and Sweden; 14 in Austria, Bulgaria, Cyprus, Italy, Lithuania and Spain; 15 in Czechia, Denmark, France, Greece and Slovenia; 16 in Croatia, Germany, Hungary, Ireland, Luxembourg, the Netherlands, Poland, Romania and Slovakia. Denmark moved from 13 to 15 on 1 January 2024. A service operating across Europe must apply the applicable age for each country.
How do I withdraw consent under the GDPR?
Consent can be withdrawn at any time. The withdrawal process must be as easy as giving consent. If consent was given with one click, withdrawal must require no more than one click. The right to withdraw must be communicated before consent is obtained. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal, but the organisation must stop consent-based processing going forward.
Do I need consent for cookies on my website?
Non-essential cookies -- analytics, advertising, tracking, social media -- require consent under the ePrivacy Directive. That consent must meet GDPR standards. Legitimate interest cannot be used to justify setting non-essential cookies. Strictly necessary cookies (session management, security, load balancing) are exempt. The November 2025 Digital Omnibus proposes simplifying these rules, but it is not yet law.
What is the difference between consent and explicit consent?
Regular consent requires a clear affirmative action for standard personal data processing. Explicit consent is a higher standard required for special-category data -- health, genetic data, biometric data used to identify a person uniquely, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, or sexual orientation. It requires an express statement of consent that names the sensitive data category and the specific purpose. It does not have to be on paper: EDPB Guidelines 05/2020 accept an electronic form, an email, an uploaded scanned signed document, an electronic signature, a two-stage email or SMS confirmation, or a recorded telephone confirmation, provided the controller can demonstrate it. Implied or general consent is never enough.
Is a consent-or-pay model lawful under the GDPR?
Not automatically. EDPB Opinion 08/2024 concluded that in most cases a large online platform cannot obtain valid consent under a pure binary model -- consent to behavioural advertising, or pay a fee. The EDPB says a paid alternative should not be the default, and that where a platform does charge for the equivalent alternative it should consider offering a further alternative free of charge without behavioural advertising, for example one using a form of advertising that processes less (or no) personal data. Whether that free option is offered has a substantial impact on the validity of the consent. Fees must not be set so high that they effectively coerce consent. The consent option must still meet all four GDPR consent conditions.
What does the November 2025 Digital Omnibus change about cookie consent?
Nothing yet -- it remains a legislative proposal. The Commission proposed moving the device-access consent rule for individuals into a new GDPR Article 88a, exempting security and first-party audience measurement from consent, requiring single-click refusal, barring a repeat request for the same purpose for at least six months after a refusal, and requiring machine-readable consent signals. The proposal names no calendar date: its 6, 24 and 48 month deadlines all run from an entry into force that has not happened, and the file (procedure 2025/0360(COD)) is still at the opinion stage. Until it passes and takes effect, current cookie consent rules under the ePrivacy Directive apply unchanged.
Updates
Major expansion: Digital Omnibus November 2025 cookie reform, CNIL enforcement against Google (325M euros) and SHEIN (150M euros), draft EDPB-Commission joint DMA/GDPR guidelines, common consent mistakes section, UpdatesLog component.
Initial publication.
Sources and References
- GDPR Full Text -- Regulation (EU) 2016/679(eur-lex.europa.eu).gov
- EDPB Guidelines 05/2020 on Consent under Regulation 2016/679(edpb.europa.eu).gov
- EDPB Summary on Consent (April 2026)(edpb.europa.eu).gov
- European Commission -- How Should My Consent Be Requested?(commission.europa.eu).gov
- ICO -- What Is Valid Consent?(ico.org.uk).gov
- ICO -- How Should We Obtain, Record and Manage Consent?(ico.org.uk).gov
- ICO -- When Is Consent Appropriate?(ico.org.uk).gov
- European Commission -- Specific Safeguards for Children Data(commission.europa.eu).gov
- EDPB Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models(edpb.europa.eu).gov
- EDPB Cookie Banner Taskforce Report (2023)(edpb.europa.eu).gov
- EDPB Guidelines 03/2022 on Deceptive Design Patterns(edpb.europa.eu).gov
- ICO -- Cookies and Similar Technologies(ico.org.uk).gov
- EDPB Guidelines 1/2024 on Legitimate Interest(edpb.europa.eu).gov
- EDPB Draft Guidelines 3/2025 on the Interplay between the DSA and the GDPR (public consultation closed 31 October 2025; not yet adopted)(edpb.europa.eu).gov
- EDPB and European Commission Draft Joint Guidelines on DMA and GDPR Interplay (public consultation closed 4 December 2025; not yet adopted)(edpb.europa.eu).gov
- CNIL -- Google Fined 325 Million Euros for Cookie and Advertising Consent Violations (September 2025)(cnil.fr).gov
- CNIL -- SHEIN Fined 150 Million Euros for Placing Cookies Without Consent (September 2025)(cnil.fr).gov
- European Commission -- Digital Omnibus Package (November 2025)(digital-strategy.ec.europa.eu).gov
- Your Europe -- Online Privacy for Businesses(europa.eu).gov
- Denmark -- Databeskyttelsesloven, LBK nr. 289 af 08/03/2024, section 6(2) (age 15 since 1 January 2024, per lov nr. 1783 af 28/12/2023)(retsinformation.dk).gov
- Czechia -- Act No. 110/2019 Sb. on Personal Data Processing, section 7 (child acquires capacity to consent on completing the fifteenth year of age)(eur-lex.europa.eu).gov
- Croatia -- Zakon o provedbi Opce uredbe o zastiti podataka, Narodne novine 42/2018, article 19 (age 16)(narodne-novine.nn.hr).gov
- European Commission -- First DMA Non-Compliance Decisions: Meta Fined 200 Million Euros over its Consent or Pay Model (23 April 2025)(digital-markets-act.ec.europa.eu).gov
- COM(2025) 837 final -- Digital Omnibus proposal, new GDPR Articles 88a, 88b and 88c and amendments to Directive 2002/58/EC (procedure 2025/0360(COD))(eur-lex.europa.eu).gov
- EDPB Statement 1/2025 on Age Assurance (adopted 11 February 2025)(edpb.europa.eu).gov
- CJEU -- Meta Platforms and Others v Bundeskartellamt, Case C-252/21 (Grand Chamber, 4 July 2023)(eur-lex.europa.eu).gov
- General Court -- Meta Platforms Ireland v EDPB, Case T-319/24, order of 29 April 2025 (challenge to EDPB Opinion 08/2024 dismissed; appeal C-454/25 P brought 10 July 2025)(eur-lex.europa.eu).gov