Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Enforcement and Compliance

Planet49 Ruling

Also known as: Planet49, Case C-673/17, Planet49 GmbH v Bundesverband
Simply put

The Planet49 ruling was a decision by the Court of Justice of the European Union (CJEU) about how websites must obtain consent to store cookies on a user's device. The case arose from a German online lottery run by Planet49 GmbH, where users had to provide personal information and were presented with a consent option to allow cookies for advertising purposes. The ruling addressed whether consent given through a pre-ticked checkbox could be considered valid.

Formal definition

Planet49 (Case C-673/17) is a CJEU judgment, delivered on a request for a preliminary ruling from the German Bundesgerichtshof, interpreting the consent requirements applicable to the storage of and access to information (including cookies) on a user's terminal equipment. The case concerned Planet49 GmbH's promotional lottery, in which participation was linked to the use of the user's personal data for advertising purposes and consent to cookies was presented via a pre-ticked checkbox. The ruling addressed the interpretation of consent under the relevant EU instruments, including the ePrivacy Directive and the GDPR's standard of consent as a legal basis, with the CJEU generally being understood to have found that consent obtained through a pre-ticked box does not meet the requirement for a clear affirmative action. Practitioners should note that the precise scope, the interplay between the ePrivacy Directive and the GDPR, and the subsequent national-level application (including the German Federal Court of Justice's final ruling and its reading of Section 15(3) TMG) are matters that turn on the full text of the judgments; this entry summarizes the case rather than substituting for the operative reasoning, and application to specific facts and jurisdictions may vary.

Why it matters

The Planet49 ruling is a reference point for how consent to cookies must be obtained under EU law. It addressed a practice that had been common across many websites, presenting users with a consent option through a pre-ticked checkbox, and the CJEU is generally understood to have found that consent obtained in this way does not meet the standard of a clear affirmative action. For privacy officers, legal counsel, and web developers, this reinforces that valid consent under the GDPR must be freely given, specific, informed, and unambiguous, and that silence, inactivity, or a box the user must actively deselect does not qualify.

The case is significant because it touches on the interplay between the ePrivacy Directive, which governs the storage of and access to information on a user's terminal equipment, and the GDPR, which sets the standard for what counts as valid consent. Because the storage of non-essential cookies for advertising purposes typically requires prior consent in most EU jurisdictions, the ruling is frequently cited when assessing whether a cookie banner or consent mechanism is compliant. Practitioners should note, however, that the precise scope of the judgment and its interaction between the two instruments turn on the full text of the decision, and application to specific facts may vary.

The ruling also has a national dimension that is easy to overlook. Following the CJEU's preliminary ruling, the German Federal Court of Justice issued a final ruling in the Planet49 matter that is reported to have addressed how Section 15(3) of the German TMG should be read. This illustrates that a CJEU judgment on a preliminary reference does not resolve the underlying dispute on its own; national courts apply the interpretation to the facts, and outcomes can differ across jurisdictions and over time as guidance evolves.

Who it's relevant to

Privacy officers and data protection professionals
The ruling supports the position that consent for non-essential cookies must involve a clear affirmative action and cannot rely on pre-ticked boxes. It is a useful reference when reviewing consent banners and mechanisms for alignment with the GDPR consent standard, though the precise application depends on the facts and the jurisdiction involved.
Legal counsel and compliance teams
For those advising on cookie consent, Planet49 illustrates the interplay between the ePrivacy Directive and the GDPR and the role of national courts in applying a CJEU preliminary ruling. Counsel should read the full text of both the CJEU and the German Federal Court of Justice judgments, as the scope and national application turn on their operative reasoning.
Web developers and CMP implementers
Developers configuring consent management platforms and cookie banners should ensure that consent options are not pre-selected and that non-essential cookies are not set before the user takes an affirmative action. Implementing this correctly supports compliance but does not by itself guarantee it, as legal assessment of the overall design remains necessary.
Marketing and advertising compliance teams
Because the case involved cookies used for advertising purposes and a lottery conditioned on data use for advertising, teams running advertising-linked promotions should be cautious about bundling or conditioning participation on consent. Whether a given practice is lawful depends on the specific facts and applicable jurisdiction.

Inside Planet49 Ruling

Pre-ticked checkbox invalidity
The core holding addressed whether consent signalled by a pre-ticked checkbox that the user must deselect constitutes valid consent. The Court of Justice of the European Union concluded that such pre-selected boxes do not meet the standard, because valid consent requires an active, affirmative step from the user rather than a failure to opt out.
Active affirmative action requirement
The ruling reinforced that consent must be given through a clear affirmative act, aligning the interpretation with the GDPR's requirement that consent be unambiguous. Silence, inactivity, or continued use are generally insufficient to demonstrate a genuine indication of the user's wishes.
Application to ePrivacy and GDPR standards
The case concerned the storing of and access to information on a user's device, which falls under the ePrivacy Directive, while drawing on the consent definition used in EU data protection law. It is generally read as confirming that the consent standard is the same regardless of whether the information stored or accessed qualifies as personal data.
Information duties
The ruling also touched on the information that must be provided to users, generally understood to include details relevant to an informed consent decision such as the nature of the technologies used. The precise scope of required disclosures depends on national implementation and subsequent guidance.

Common questions

Answers to the questions practitioners most commonly ask about Planet49 Ruling.

Does the Planet49 ruling mean that pre-ticked consent boxes are the only issue it addressed?
No. While the ruling is best known for holding that a pre-ticked checkbox does not constitute valid consent, it addressed broader points. It clarified that consent must involve a clear affirmative action by the user, and it confirmed that the consent requirements apply regardless of whether the information stored or accessed on a user's device constitutes personal data. In other words, the reasoning extends beyond the narrow question of pre-ticked boxes to the general standard for how consent must be obtained.
Did the Planet49 ruling only concern cookies in the literal technical sense?
Not exactly. Although the case arose in the context of cookies, the Court's reasoning focused on the storing of or gaining access to information on a user's terminal equipment. On this basis, the consent requirement is generally understood to apply to similar technologies that store or access information on a device, such as certain pixels, local storage, SDKs, and comparable tracking methods, rather than being limited to cookies as a specific technical format.
How does the Planet49 ruling affect the way we should design our consent banners?
The ruling supports designing consent mechanisms that require an active, affirmative choice rather than relying on defaults. In practice, this generally means avoiding pre-ticked boxes and any presentation that treats inaction as consent. Beyond that, the specific design of a banner depends on further guidance from relevant data protection authorities and applicable national law, which fall outside the scope of the ruling itself. Legal review of any specific implementation is advisable.
Does complying with the Planet49 ruling mean our consent process is fully compliant?
No. The ruling addresses the standard for obtaining consent to store or access information on a device, primarily under the ePrivacy framework, and reinforces that consent must be a clear affirmative act. It does not, by itself, resolve every obligation. Separate GDPR requirements, such as providing information, establishing a lawful basis for any subsequent processing of personal data, and maintaining records, may still apply. Meeting the ruling's standard is one component, not a guarantee of overall compliance.
What information should we present to users to align with the ruling?
The ruling indicates that consent must be informed, which generally implies giving users clear information relevant to their decision, such as details about the technologies used and, where relevant, matters like the duration of operation and access by third parties. The precise information to provide depends on the specific processing and on applicable national implementations and authority guidance, which are outside the scope of the ruling. Tailor disclosures to the facts of your deployment and seek legal input where uncertain.
Does the Planet49 standard apply outside the EU jurisdiction where the case arose?
The ruling was decided within the EU legal framework and interprets EU law, so its authority is tied to the EU context and national implementations of the relevant directives. It does not automatically govern non-EU regimes, such as UK rules following its own trajectory or US state privacy laws, which often rely on opt-out rather than opt-in models. Organizations operating across multiple jurisdictions should assess each applicable framework separately rather than treating this standard as universal.

Common misconceptions

The ruling only applies to cookies in the literal, technical sense.
The reasoning concerns the storing of and access to information on a user's terminal equipment, which in most EU interpretations extends to similar technologies such as pixels, local storage, SDKs, and comparable techniques, not only files labelled as cookies.
Because consent was found invalid, all non-essential cookies are simply prohibited.
The ruling addresses the conditions for valid consent, not an outright ban. Non-essential cookies may generally still be used where valid, freely given, specific, informed, and unambiguous consent is obtained through a clear affirmative action; strictly necessary cookies are typically exempt from consent altogether.
The ruling sets a global standard that applies the same way in every jurisdiction.
The decision reflects EU law and binds interpretation within the EU. Requirements differ in other regimes, and several US state privacy frameworks, for example, often rely on an opt-out rather than opt-in model, so the pre-ticked box analysis does not transpose directly everywhere.

Best practices

Replace any pre-ticked or pre-selected consent boxes with mechanisms that require a clear affirmative action before non-essential cookies or similar technologies are placed or accessed.
Ensure non-essential technologies, including pixels, local storage, and SDKs, are not activated until valid consent is obtained, rather than treating them differently from cookies.
Provide users with the information needed for an informed decision, and confirm the specific disclosure requirements under the applicable national implementation of the ePrivacy rules.
Distinguish strictly necessary cookies, which are generally exempt from consent, from analytics, advertising, and functional technologies that typically require prior consent in EU jurisdictions.
Retain records demonstrating that consent was given through an affirmative action, using a consent management platform to support but not substitute for legal judgment.
Assess obligations separately for each jurisdiction where you operate, since the EU standard reflected in this ruling may differ from UK guidance and from opt-out-based US state frameworks.
Promotional banner for the Pentest Readiness checklist download