Skip to main content
Category: Consent Principles

Active Consent

Also known as: affirmative consent, express consent
Simply put

Active consent means a person clearly agrees to something by taking a deliberate action, such as ticking an unchecked box or clicking an accept button. In the cookie context, it means a website visitor must actively choose to allow cookies rather than being assumed to agree by staying on the page. This stands in contrast to passive or implied consent, which is generally not accepted as valid in the EU.

Formal definition

Active consent refers to consent given through a clear affirmative action by the individual, such as clicking a button or checking an unticked box, rather than through inaction, pre-ticked boxes, or continued browsing. It aligns with the GDPR requirement that valid consent be unambiguous and given by a clear affirmative act, which in most EU jurisdictions rules out implied consent and cookie mechanisms that assume agreement. The concept applies to the placing of and access to cookies and similar technologies (including pixels, local storage, and SDKs) under the ePrivacy regime, where prior consent is typically required for non-essential cookies. Note that requirements differ under other frameworks, such as certain US state privacy laws that rely on opt-out rather than opt-in mechanisms; whether a specific active-consent implementation satisfies applicable law depends on the relevant jurisdiction and facts not addressed by this definition.

Why it matters

Active consent sits at the heart of what makes cookie consent valid under EU law. The GDPR requires that consent be unambiguous and given through a clear affirmative act, which means that a website cannot rely on a visitor's silence, inaction, or continued browsing to infer agreement. For privacy officers and legal counsel, the distinction between active and passive consent is often the dividing line between a compliant consent mechanism and one that a data protection authority in the EU would likely treat as invalid.

The practical stakes are significant because many legacy consent designs depend on assumptions that active consent rejects. Pre-ticked boxes, banners that treat scrolling or clicking anywhere on the page as acceptance, and implied consent from continued use are generally not accepted as valid in the EU. Organizations that place non-essential cookies before a visitor has taken a deliberate affirmative action risk deploying tracking technologies without a lawful basis under the ePrivacy regime and the GDPR.

It is important to note that the active-consent standard is tied to EU and comparable opt-in frameworks. Certain US state privacy laws rely instead on opt-out mechanisms, so a design that assumes agreement until the user objects may be acceptable in some jurisdictions but not in the EU. Whether any particular implementation is compliant depends on the applicable law and facts that this concept alone does not resolve.

Who it's relevant to

Privacy and data protection officers
Those responsible for demonstrating a lawful basis for cookies need to ensure that consent mechanisms rely on a clear affirmative action rather than inferred agreement. Active consent is central to showing that consent obtained under the GDPR is unambiguous, particularly in EU jurisdictions where implied consent is generally not accepted.
Legal and compliance counsel
Counsel assessing consent designs must distinguish between the opt-in expectations of EU and comparable frameworks and the opt-out models used under certain US state privacy laws. Whether an active-consent implementation satisfies applicable law depends on the relevant jurisdiction and facts not resolved by the concept alone.
Web developers and CMP implementers
Developers building or configuring consent banners and consent management platforms translate the active-consent standard into interface behavior, such as unticked boxes and explicit accept buttons, and ensure non-essential cookies and similar technologies are not fired before a deliberate affirmative action. These tools support compliance but do not replace legal judgment.
Marketing and analytics teams
Teams deploying analytics, advertising, and functional technologies including pixels, local storage, and SDKs need to understand that these generally require active consent in the EU before activation, since assuming agreement from continued browsing is widely considered non-compliant there.

Inside Active Consent

Clear Affirmative Action
Active consent requires a positive, unambiguous act by the user, such as clicking an 'Accept' button or ticking an unchecked box. Under the GDPR standard, silence, inactivity, or continued browsing does not constitute valid consent.
Freely Given
The user must have a genuine choice, without detriment for refusing. In most EU jurisdictions, mechanisms such as cookie walls that condition access on acceptance are widely considered problematic, though enforcement positions vary.
Specific and Granular
Consent should be sought separately for distinct purposes or cookie categories (for example analytics versus advertising) rather than bundled into a single all-or-nothing choice, so users can consent to some processing while refusing others.
Informed
Before acting, the user should receive clear information about what cookies or similar technologies are used, their purposes, and typically the identity of parties involved, enabling a meaningful decision.
Prior to Processing
Under the ePrivacy rules governing the placing of and access to information on a device, non-essential cookies and similar technologies (such as pixels, local storage, SDKs, and fingerprinting) should generally not be set until active consent is obtained.
Revocability and Record-Keeping
Consent must be as easy to withdraw as to give, and controllers are generally expected to log and retain records demonstrating that valid consent was obtained, often supported by a consent management platform (CMP).

Common questions

Answers to the questions practitioners most commonly ask about Active Consent.

Does continuing to browse a website count as active consent?
No. Continued browsing is a form of implied consent, which is the opposite of active consent. Active consent requires a clear affirmative action by the user, such as clicking an accept button. In most EU jurisdictions, implied consent from continued browsing is widely considered non-compliant under the GDPR, because valid consent must be unambiguous and given through a clear affirmative action. Requirements may differ under frameworks such as certain US state privacy laws, which often rely on an opt-out model rather than requiring active opt-in.
Is a pre-ticked box an acceptable way to obtain active consent?
No. A pre-ticked box does not satisfy the standard for active consent, because it does not involve a clear affirmative action by the user. Under the GDPR, consent must be freely given, specific, informed, and unambiguous, and pre-ticked boxes are widely considered non-compliant in the EU. The user must take a deliberate step to signal agreement rather than being deemed to consent by inaction. This entry does not address every design pattern that may or may not qualify; specific implementations should be assessed against current guidance from the relevant data protection authority.
Where in the consent flow should active consent be captured, relative to non-essential cookies being set?
In most EU jurisdictions, active consent should generally be captured before non-essential cookies or similar technologies (such as pixels, local storage, or SDKs) are placed on or read from the user's device. This reflects the prior consent requirement under the ePrivacy rules for the placing of and access to information on a device, which operates alongside the GDPR obligations that govern any subsequent processing of personal data. Strictly necessary cookies are generally exempt and may be set without active consent. The precise timing expectations can depend on national implementations and evolving regulatory guidance.
How can active consent be recorded to support record-keeping obligations?
Consent logging typically captures information that helps demonstrate a valid affirmative action occurred, and consent management platforms (CMPs) are commonly used to support this. What specific details should be retained depends on the applicable legal regime and organizational needs, and this entry does not prescribe a fixed data set. A CMP can support compliance by capturing and storing consent records, but a tool does not replace legal judgment or guarantee compliance. Organizations should assess their logging practices against the requirements and guidance relevant to their jurisdictions.
Does obtaining active consent for cookies also satisfy the GDPR requirements for the processing that follows?
Not automatically. The placing of and access to information on a device is governed by the ePrivacy rules, while any processing of personal data that follows is governed by the GDPR. Active consent captured at the cookie banner addresses the affirmative-action element, but organizations should not assume that consent obtained under one regime automatically satisfies the other. The two frameworks should be considered separately, and legal analysis may be needed to confirm an appropriate basis for the subsequent processing.
How should active consent be handled for different categories of cookies?
Active consent is generally required for non-essential categories such as analytics, advertising, and functional cookies before they are set, whereas strictly necessary or essential cookies are generally exempt from consent. Because valid consent must be specific, the affirmative action should typically allow users to make distinct choices by category rather than lumping all cookies together. Similar technologies such as pixels, local storage, SDKs, and fingerprinting generally fall within the same rules even though they are not literally cookies. The exact categorization and design should be reviewed against current guidance in the relevant jurisdictions.

Common misconceptions

Pre-ticked boxes or a banner that says 'by continuing to browse you accept cookies' count as active consent.
Pre-ticked boxes and implied consent from continued browsing are widely considered non-compliant in the EU, because they lack the clear affirmative action the GDPR standard requires. These approaches may, however, align with the opt-out model used under some US state privacy laws such as the CCPA and CPRA in California.
Active consent is required everywhere before any cookie is set.
Obligations vary by jurisdiction. The EU and UK generally follow an opt-in, prior-consent approach for non-essential cookies, whereas several US state regimes rely on opt-out signals. In addition, strictly necessary or essential cookies are generally exempt from consent even in the EU.
Obtaining active consent under the ePrivacy rules automatically satisfies all GDPR obligations for the data involved.
The ePrivacy rules govern the placing of and access to information on a device, while the GDPR governs any subsequent processing of personal data. Valid consent to set a cookie does not necessarily discharge separate GDPR requirements, and the two regimes should be assessed independently.

Best practices

Deploy consent mechanisms that require an unambiguous affirmative action and avoid pre-ticked boxes or reliance on continued browsing, particularly for users in the EU and UK.
Offer granular choices per purpose or cookie category, and make refusing or withdrawing consent at least as easy as granting it.
Block non-essential cookies and similar technologies (pixels, local storage, SDKs, fingerprinting) from firing until active consent is captured, while allowing strictly necessary cookies that are generally exempt.
Provide clear, accessible information about cookie purposes and the parties involved before the user makes a choice, so that consent is genuinely informed.
Use a consent management platform to capture and retain records of consent, but treat it as support for compliance rather than a guarantee, and pair it with legal review.
Map your consent approach to each jurisdiction you serve, recognizing that opt-in expectations in the EU and UK differ from opt-out frameworks such as the CCPA and CPRA, and monitor evolving regulatory guidance.