Skip to main content
Category: Consent Principles

Clear Affirmative Action

Also known as: Affirmative Action (data protection sense), Clear Affirmative Act
Simply put

Clear affirmative action means a person must take a deliberate, specific step to agree to the use of their data, such as ticking an unticked box or clicking an 'accept' button. Silence, inactivity, or continuing to browse a website does not count. It is one of the requirements for valid consent under EU and UK data protection law.

Formal definition

Clear affirmative action is a core element of the standard for valid consent under the GDPR and UK GDPR, requiring that a data subject signal agreement through a deliberate and specific act rather than through inaction. According to ICO guidance, the individual must take deliberate and specific action to opt in or agree to the processing, though it need not be expressed in any particular form. In the cookie context this typically means consent obtained before non-essential cookies or similar technologies (such as pixels, SDKs, or local storage) are placed cannot rely on pre-ticked boxes, implied consent from continued browsing, or default settings. Note that requirements described here reflect EU and UK opt-in frameworks; other regimes, such as US state privacy laws, often operate on an opt-out basis and do not impose the same affirmative-action standard. The term is unrelated to the US civil-rights concept of 'affirmative action,' which several general-reference sources in the evidence describe and which falls outside the scope of this entry.

Why it matters

Clear affirmative action is one of the load-bearing requirements that separates valid consent from the invalid consent that data protection authorities in the EU and UK regularly criticise. Because valid consent under the GDPR and UK GDPR must be freely given, specific, informed, and unambiguous, the affirmative-action element is what makes agreement 'unambiguous.' Without a deliberate, specific step by the individual, an organisation cannot demonstrate that a person actually agreed, which undermines the lawfulness of any subsequent processing that relied on consent.

In the cookie context this requirement has direct, practical consequences for how consent banners are designed. Pre-ticked boxes, default 'on' settings, and the assumption that continued browsing signals agreement do not meet the standard in EU and UK opt-in frameworks, because none of these involve a deliberate act by the user. Where non-essential cookies or similar technologies such as pixels, SDKs, or local storage are placed before the individual takes a clear affirmative step, the consent relied upon is generally vulnerable to challenge.

It is important to distinguish this data protection concept from the unrelated US civil-rights concept of 'affirmative action,' which appears in general-reference sources but is entirely outside the scope of cookie consent and data protection. Practitioners should also note that requirements differ by jurisdiction: US state privacy laws often operate on an opt-out basis and do not impose an equivalent affirmative-action standard, so a design that satisfies one regime may not satisfy another.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for consent frameworks must ensure that the mechanisms relied upon capture a genuine deliberate act by the user, and that this can be evidenced. This is central to demonstrating valid consent under the GDPR and UK GDPR, and to defending consent-based processing if it is questioned.
Web developers and CMP implementers
Developers building or configuring consent banners need to ensure that non-essential cookies and similar technologies do not fire before the user takes an affirmative step, and that default states are not pre-selected to 'accept.' Interface design choices directly determine whether the affirmative-action standard is met in EU and UK contexts.
Legal counsel and compliance teams
Counsel advising on consent should assess whether a given design meets the clear affirmative action requirement in the relevant jurisdiction, and flag that opt-out regimes such as certain US state privacy laws do not impose the same standard. They should also account for the fact that authority guidance and enforcement positions may evolve.
Marketing and analytics teams
Teams deploying advertising pixels, analytics tags, and tracking SDKs should understand that these technologies typically require prior consent obtained through a clear affirmative action in EU and UK jurisdictions, and cannot rely on implied consent from continued browsing or on defaults being switched on.

Inside Clear Affirmative Action

Unambiguous Indication of Wishes
Clear affirmative action requires the data subject to signal agreement through a positive, deliberate act. Under the GDPR, consent must be given by a statement or by a clear affirmative action that unambiguously indicates the individual's acceptance of the processing of their personal data.
Positive Opt-In Mechanism
The action must be an active choice, such as clicking an 'Accept' button, ticking an unticked box, or selecting settings. Silence, inactivity, or the mere continuation of browsing do not constitute a clear affirmative action in most EU jurisdictions.
Link to Informed and Specific Consent
A clear affirmative action does not stand alone; it operates alongside the other GDPR consent conditions, meaning consent must also be freely given, specific, and informed. The affirmative act typically follows the presentation of clear information about the cookies or technologies in question.
Applicability Beyond Cookies
The requirement extends to consent for placing or accessing information on a device under the ePrivacy rules and to processing of personal data under the GDPR. Where similar technologies such as pixels, local storage, SDKs, or fingerprinting rely on consent, the same standard of a clear affirmative action generally applies.
Jurisdictional Scope
The clear affirmative action standard is a feature of EU (and UK) consent law. Many US state privacy frameworks, such as those in California, rely on opt-out mechanisms rather than affirmative opt-in, so this concept is not universal across all regimes.

Common questions

Answers to the questions practitioners most commonly ask about Clear Affirmative Action.

Does continuing to browse a website count as clear affirmative action?
No. In most EU jurisdictions, continued browsing is not treated as a clear affirmative action because it is passive rather than an unambiguous, deliberate signal of consent. Guidance from EU data protection authorities has generally taken the position that implied consent from continued use does not meet the GDPR standard of a clear affirmative act. Requirements differ under some non-EU frameworks, such as certain US state privacy laws that rely on an opt-out model, so the geographic scope of the site's audience matters.
Do pre-ticked boxes satisfy the clear affirmative action requirement?
Generally not, in the EU and UK context. A pre-ticked box requires the user to take action to withdraw rather than to give consent, so it does not reflect a clear affirmative act by the user. This position is widely reflected in EU data protection guidance. Because standards vary across jurisdictions, teams operating under opt-out based frameworks should assess the applicable rules separately rather than assuming a single approach applies everywhere.
What kinds of user actions can qualify as clear affirmative action for cookies?
Actions that involve a deliberate, unambiguous step by the user are typically considered clear affirmative action, such as clicking an accept or agree button, toggling a consent control to the on position, or selecting specific preferences and confirming them. The action should relate to the specific processing purposes presented. Because interpretations can vary and enforcement guidance evolves, the exact design should be assessed against current guidance in the relevant jurisdiction, and legal judgment remains necessary.
How does clear affirmative action apply to non-cookie technologies like pixels, local storage, or SDKs?
The same consent standards generally apply to these technologies where they involve placing or accessing information on a user's device or processing personal data, even though they are not literally cookies. Under the ePrivacy rules governing storage and access, and the GDPR governing any subsequent processing of personal data, a clear affirmative action may be required before such technologies are activated in EU contexts. Whether consent is required for a specific technology depends on its function and purpose, which is out of scope for a general definition.
Should the same clear affirmative action be relied on for multiple processing purposes?
Consent under the GDPR must be specific, so a single affirmative action intended to cover unrelated purposes may not meet the standard where users cannot meaningfully consent to each purpose. In practice this often means presenting distinct choices or controls so the affirmative act maps to the purposes being consented to. The appropriate level of granularity can be a contested and fact-dependent question, and current regulatory guidance in the applicable jurisdiction should inform the design.
How should a clear affirmative action be recorded to support accountability?
Because organizations subject to the GDPR are generally expected to be able to demonstrate that valid consent was obtained, it is common to log details such as what the user was shown, which action they took, the purposes involved, and when it occurred. Consent management platforms can support this record-keeping, but a tool does not by itself guarantee compliance and does not replace legal judgment. The specific records required, and their retention, depend on the applicable framework and should be assessed accordingly.

Common misconceptions

Continuing to browse a website counts as a clear affirmative action giving consent.
In most EU jurisdictions, implied consent from continued browsing is widely considered non-compliant. A clear affirmative action requires a deliberate positive act, and inactivity or scrolling generally does not meet the standard.
A pre-ticked box satisfies the clear affirmative action requirement because the user can untick it.
Pre-ticked boxes are widely regarded as invalid under the GDPR because they do not involve an active choice by the user. The affirmative action must come from the individual, not be assumed by default.
A clear affirmative action on its own guarantees valid consent.
An affirmative act is necessary but not sufficient. Consent must also be freely given, specific, and informed, which is why cookie walls and bundled consent may still be problematic even where a click is involved. The affirmative action does not cure defects in the other consent conditions.

Best practices

Design consent interfaces so that agreement requires an active step, such as clicking an 'Accept' button or ticking an unticked box, and avoid pre-ticked boxes or default-on settings for non-essential cookies.
Do not treat continued browsing, scrolling, or inactivity as consent in EU or UK contexts, and ensure non-essential cookies and similar technologies are not set before an affirmative action is taken.
Present clear and specific information about the cookies and technologies in use before the user acts, so the affirmative action reflects informed and specific consent rather than a click in isolation.
Offer users a genuine and equally accessible choice to reject non-essential cookies, so that the affirmative action can be considered freely given and not the product of a cookie wall or forced acceptance.
Log and retain records of the affirmative action, including what the user agreed to and when, to support consent record-keeping obligations, while recognizing that logging supports but does not by itself establish valid consent.
Tailor consent flows to the applicable jurisdiction, applying opt-in affirmative action where EU or UK rules govern and adapting to opt-out models where US state privacy laws apply, and seek legal advice where the correct approach is unclear.