Skip to main content
Category: Consent Principles

Consent or Pay

Also known as: Pay-or-Okay, Consent or Pay Cookies
Simply put

Consent or pay is a website approach that gives visitors a choice between agreeing to have their personal data used for tracking and personalised advertising, or instead paying a fee to access the same service without that tracking. It is used by some online platforms to increase the rate at which users agree to data processing. Whether this model offers a genuinely free choice, as consent law generally requires, is contested and has drawn scrutiny from data protection authorities in the EU and UK.

Formal definition

Consent or pay (also called pay-or-okay) is a consent-collection model in which a user is presented with a binary choice: consent to the processing of personal data for purposes such as personalised advertising, or pay a monetary fee to access the service without such processing. The model raises questions under the GDPR standard that consent be freely given, since a paid alternative may be argued to affect the voluntariness of the consent option; the EDPB has indicated that negative consequences are likely to arise when large online platforms use this model, and that such models should offer a real choice. The ICO has published guidance addressing how the consent option and the pay option should be designed and presented under UK data protection law. Because these are practitioner and regulatory positions that continue to evolve, and because outcomes depend heavily on specific facts such as fee level, platform size, and available alternatives, the lawfulness of a given consent or pay implementation is not settled and varies by jurisdiction; this definition does not resolve those open questions.

Why it matters

Consent or pay models sit at the centre of an unresolved debate about what it means for consent to be freely given under EU and UK data protection law. Because valid consent under the GDPR must be freely given, specific, informed, and unambiguous, the introduction of a paid alternative raises the question of whether a user who agrees to tracking to avoid a fee is really exercising a genuine choice. For privacy officers, legal counsel, and marketing compliance teams, this is not an abstract concern: how a consent or pay wall is designed can determine whether the consent it collects is defensible or vulnerable to regulatory challenge.

The model has attracted direct scrutiny from data protection authorities. In April 2024 the EDPB indicated that negative consequences are likely to arise when large online platforms use a consent or pay model to obtain consent, and stated that such models should offer people a real choice. The ICO has separately published guidance under UK data protection law addressing how the consent option and the pay option should be presented, including how to design each option and what to do when someone wishes to leave. The approach has been associated most prominently with Meta, which has been publicly identified as a company using this tactic to increase consent rates.

Because regulatory positions in this area continue to evolve and outcomes depend heavily on specific facts, no organisation should treat a consent or pay implementation as settled or presumptively lawful. The lawfulness of any given design turns on factors such as the platform's size, the level of the fee, and the alternatives available to users, and it varies by jurisdiction. Organisations deploying or evaluating these models should treat authority guidance as a starting point for legal analysis rather than a guarantee of compliance.

Who it's relevant to

Privacy and data protection officers
DPOs and privacy teams evaluating whether a consent or pay model can produce valid consent need to weigh EDPB and ICO positions against the specific facts of their deployment, including platform size, fee level, and available alternatives. Because the lawfulness of these models is not settled, they should document their reasoning and treat authority guidance as an input to legal analysis rather than a compliance guarantee.
Legal counsel and compliance advisers
Counsel advising on consent or pay implementations must account for the unresolved question of whether a paid alternative affects the voluntariness of consent under the GDPR, and for the fact that positions differ by jurisdiction between the EU and UK. They should track the EDPB's stance on large online platforms and the ICO's guidance on designing the consent and pay options.
Marketing and advertising compliance teams
Teams responsible for personalised advertising rely on consent as the basis for the associated data processing. Because consent or pay is used to increase consent rates, these teams should understand that the way the choice is presented can affect whether the consent collected is defensible, and should coordinate closely with legal and privacy functions before relying on it.
Web developers and CMP implementers
Developers and consent management platform teams translate the consent or pay model into the user interface, controlling how the consent option and pay option are designed and presented, a factor regulators have highlighted. They should implement the model in line with legal guidance on option design and on what happens when a user declines both, recognising that technical implementation supports but does not replace legal judgment.

Inside Consent or Pay

Consent-or-pay binary choice
A model in which a website or app presents users with an alternative: either consent to data processing (typically for advertising or analytics purposes involving cookies and similar technologies) or pay a fee to access the service without such tracking. It is sometimes called 'pay or okay' or a 'consent paywall'.
Interaction with the ePrivacy consent requirement
Because the model concerns the placing of and access to information on a user's device, the ePrivacy Directive (and its national implementations) is engaged for the tracking option. The paid alternative is offered as a means of providing an option other than consenting to that storage or access.
Interaction with the GDPR 'freely given' standard
Where the consent option leads to processing of personal data, that consent must still meet the GDPR standard of being freely given, specific, informed, and unambiguous. A central contested question is whether requiring payment as the alternative undermines the 'freely given' element.
Relationship to the cookie wall debate
Consent or pay is closely related to, but distinct from, a pure cookie wall (which blocks access entirely absent consent). The paid alternative is presented by proponents as offering a genuine choice, whereas critics question whether a fee constitutes a real alternative for all users.
Fee-level and equivalence considerations
The model raises questions about whether the price charged is appropriate or reasonable, and whether the paid tier offers an equivalent service, since these factors bear on whether users face genuine free choice rather than pressure to consent.

Common questions

Answers to the questions practitioners most commonly ask about Consent or Pay.

Does offering a paid alternative automatically make a consent-or-pay model compliant?
No. The availability of a paid option does not by itself render consent freely given or the overall model lawful. Regulators and data protection authorities in the EU have scrutinised these models closely, and their acceptability depends on factors such as whether the fee is appropriate rather than prohibitive, whether a genuine equivalent service is offered, and whether the choice is presented fairly. Because guidance in this area continues to evolve and interpretations differ, a paid tier should be treated as one factor among several rather than a guarantee of compliance.
Is consent-or-pay the same as a cookie wall?
They are related but not identical. A cookie wall generally conditions access to a service on the user accepting cookies with no genuine alternative, which is widely regarded as problematic under EU law. A consent-or-pay model instead offers a paid route as an alternative to consenting. Whether that alternative is sufficient to distinguish the model from an impermissible cookie wall is contested and fact-dependent, and views among regulators and across jurisdictions differ.
How should the price of the paid alternative be determined?
There is no single prescribed formula, and this is one of the more contested aspects of the model. Guidance generally suggests the fee should be reasonable and not so high that it effectively forces users toward consenting, which could undermine the argument that consent is freely given. Because what counts as an appropriate fee depends on the specific service and market, and because regulatory positions may vary and evolve, organisations should document their reasoning and monitor developments rather than rely on a fixed benchmark.
Does a consent-or-pay model need to work the same way across the EU, UK, and US?
Not necessarily. Consent obligations differ by jurisdiction, and a model designed around EU opt-in consent standards may not map onto UK expectations or the opt-out-based approach common in US state privacy laws such as those in California. Organisations operating across regions should assess the model separately against each applicable regime and its geographic scope, rather than assuming one implementation satisfies all of them.
What should be logged when a user chooses to pay instead of consenting?
As with any consent management approach, maintaining records that demonstrate how the choice was presented and what the user selected supports accountability. This may include capturing which option was offered, the choice made, and the configuration shown at the time, consistent with general consent logging and record-keeping practices. The specific records needed depend on applicable requirements, and a consent management platform can support this but does not replace legal judgment about what must be retained.
How does a consent-or-pay model interact with a consent management platform (CMP)?
A CMP can present the choice between consenting and paying, record the outcome, and manage the resulting cookie and tracking behaviour. However, the CMP implements the design decisions rather than validating their lawfulness, so the underlying questions, whether the fee is appropriate, whether the alternative is genuine, and whether consent remains freely given, must be resolved separately. Tools support this model but do not by themselves establish that it complies with applicable law.

Common misconceptions

Offering a paid alternative automatically makes the resulting consent valid under the GDPR.
The presence of a paid option does not by itself guarantee that consent is freely given. Whether such consent meets the GDPR standard is contested and depends on factors such as the fee level, the availability of an equivalent service, and the position of the relevant data protection authority. Guidance and enforcement positions on this model continue to evolve, and outcomes may differ between EU jurisdictions.
Consent or pay is lawful everywhere because it is used by many services.
Cookie consent obligations vary between the EU, the UK, and individual US states, and the lawfulness of a consent-or-pay model is assessed under the applicable regime rather than universally. Widespread use does not establish that the practice satisfies the freely given consent standard in any given jurisdiction, and its acceptability remains subject to unresolved regulatory questions in the EU.
Consent or pay is the same as a cookie wall.
A pure cookie wall conditions access solely on consent, whereas consent or pay adds a paid alternative to the consent option. Proponents present the fee as a genuine second choice, but critics argue it may still exert pressure to consent. The distinction matters legally, though both models attract scrutiny under EU rules on freely given consent.

Best practices

Assess whether the consent option in your model meets the GDPR requirements that consent be freely given, specific, informed, and unambiguous, and document the reasoning, rather than assuming a paid alternative resolves the freely-given question.
Consult current guidance from the relevant data protection authority for each jurisdiction in which you operate, since positions on consent or pay differ and continue to evolve across EU Member States and other regimes.
Consider whether the fee is set at a reasonable level and whether the paid tier offers an equivalent service, because these factors bear on whether users face a genuine choice.
Treat the placing of or access to information on the user's device as engaging the ePrivacy consent requirement, and ensure the model addresses both that requirement and any subsequent GDPR processing separately.
Maintain clear records of the choices presented, the information given, and the consent obtained, to support demonstrable accountability if the model is challenged.
Obtain legal advice before deploying a consent-or-pay model, recognizing that consent management tools and templates support compliance but do not replace legal judgment on this contested question.