EU Privacy Law EU/EEA

GDPR Consent Management: Building Lawful Consent Flows That Satisfy Regulators

What valid GDPR consent looks like under Articles 4(11) and 7, how regulators test consent banners, and how to build flows that hold up to scrutiny.

Regulation

GDPR, Articles 4(11) and 7; ePrivacy Directive, Article 5(3)

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Valid GDPR consent must be freely given, specific, informed, and unambiguous (Article 4(11)), and withdrawing it must be as easy as giving it (Article 7(3)).
  • Pre-ticked boxes are invalid consent, confirmed by the CJEU in the Planet49 judgment (C-673/17, October 2019).
  • France's CNIL fined Google EUR 150 million and Facebook EUR 60 million in 2021 because refusing cookies took more clicks than accepting them.
  • The burden of proof is on the organization: Article 7(1) requires you to be able to demonstrate who consented, when, and to what.
  • Consent collected by a misconfigured banner is invalid, which strips the lawful basis from every tracker that relied on it.

Consent is the most demanding lawful basis in the GDPR, and the one most often implemented wrongly. Article 4(11) defines it, Article 7 sets the conditions, and Article 5(3) of the ePrivacy Directive makes it mandatory before non-essential cookies or trackers are set. A banner that collects invalid consent gives you nothing: the processing behind it simply has no legal basis.

RegulationGDPR Arts. 4(11), 7; ePrivacy Directive Art. 5(3)
Max penaltyEUR 20M or 4% of global annual turnover
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The four validity tests

Freely given. The individual must have a real choice. Consent bundled with terms of service, extracted through a cookie wall, or obtained in a relationship with a power imbalance fails this test.

Specific. One consent per purpose. A single checkbox covering analytics, advertising, and email marketing is three invalid consents, not one valid one.

Informed. The person must know who is processing, for what purposes, and which third parties are involved, before deciding. A banner that names no vendors while 40 ad-tech companies receive data does not produce informed consent.

Unambiguous. A clear affirmative act. The CJEU held in Planet49 (C-673/17) that pre-ticked boxes are invalid, and recital 32 rules out silence and inactivity.

On top of these, Article 7(3) requires withdrawal to be as easy as giving consent. If accepting takes one click and withdrawing requires finding a settings page, the consent was never valid.

How regulators test banners

Enforcement follows a consistent script. Investigators load the site, count the clicks to refuse versus accept, check whether trackers fire before any choice is made, and compare the vendors disclosed against the vendors actually receiving data. The CNIL used exactly this method for its December 2021 decisions against Google (EUR 150 million) and Facebook (EUR 60 million), and noyb has filed hundreds of complaints across the EU generated by automated banner analysis.

That script is easy to run against your own site. A free privacy scan performs the same checks: which trackers fire pre-consent, what the banner offers, and whether disclosures match observed behavior.

Building a compliant flow

  1. Block all non-essential tags until a choice is made. Tag managers fire by default; configure explicit blocking.
  2. Present Accept and Reject with equal prominence on the first layer, purposes on the second.
  3. Name your vendors and link each to its role. Keep the list synchronized with what actually runs on the site.
  4. Record every consent event with timestamp, interface version, and choices.
  5. Offer a persistent way to change or withdraw choices, typically a footer link that reopens the preference center.
  6. Re-test after every marketing tag change. New pixels added outside the consent platform are the most common way compliant sites drift into violation.

For choosing and configuring a consent platform, see our CMP selection guide.

Frequently Asked Questions

What makes consent valid under GDPR?

Article 4(11) requires a freely given, specific, informed, and unambiguous indication by statement or clear affirmative action. Silence, inactivity, scrolling, and pre-ticked boxes do not qualify.

Does a 'Reject all' button have to be on the first layer of a cookie banner?

The CNIL, the Belgian DPA, and several other authorities have penalized banners where rejection required more effort than acceptance. The safe pattern is Accept and Reject with equal prominence on the first layer.

How do I prove consent was given?

Store a consent record: a timestamp, the text and interface version shown, the choices made, and an identifier. Article 7(1) puts the demonstration burden on you, and regulators ask for these records during investigations.

Does consent expire?

GDPR sets no fixed lifetime, but guidance differs by country: the CNIL recommends re-prompting cookie consent every 6 to 13 months. Consent also dies whenever your purposes or vendors change materially.

Is consent required for analytics cookies?

In most EU countries yes, because analytics cookies are not strictly necessary to deliver the service. A few authorities tolerate consent-free audience measurement under strict conditions, such as the CNIL's exemption criteria, but cross-site analytics never qualifies.

Regulatory Crosswalk

ePrivacy DirectiveUK PECRQuebec Law 25

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.