Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Deceptive Design Patterns

Pre-ticked Boxes

Also known as: pre-checked boxes, default-ticked checkboxes, pre-selected consent boxes
Simply put

A pre-ticked box is a checkbox on a website form or cookie banner that is already marked as accepted before the user does anything, so consent is granted by default unless the user actively unchecks it. Under EU and UK data protection law, this approach is generally not accepted as valid consent, because consent is expected to come from a deliberate, positive action by the user rather than from inaction. In practice, organisations relying on pre-ticked boxes to obtain consent typically face a significant compliance risk.

Formal definition

A pre-ticked box is a user interface element presented in a pre-selected (checked) state that treats non-action as agreement to a given processing or tracking purpose. In most EU jurisdictions and in the UK, it does not meet the GDPR standard for valid consent, which must be freely given, specific, informed, and unambiguous and expressed through a clear affirmative action; GDPR Recital 32 indicates that silence, inactivity, or pre-ticked boxes do not constitute consent. UK ICO guidance similarly directs organisations not to use pre-ticked boxes or other default-consent methods and requires a positive opt-in. Where cookies or similar technologies (such as pixels, local storage, SDKs, or fingerprinting) require prior consent under the ePrivacy regime and its national implementations, a pre-ticked box does not provide the required consent for placing or accessing information on the user's device, and any consent-based GDPR processing that follows would likewise lack a valid basis. Scope note: requirements differ under other frameworks, including certain US state privacy laws that rely on opt-out rather than opt-in mechanisms, so the invalidity of a pre-ticked box is stated here with respect to EU/UK consent standards. Narrow exceptions such as the soft opt-in for email marketing are context-specific and outside the scope of this cookie-consent definition; their applicability depends on facts not addressed here.

Why it matters

Pre-ticked boxes sit at the heart of one of the most settled questions in EU and UK consent law: consent cannot be inferred from a user's inaction. Because the GDPR requires consent to be freely given, specific, informed, and unambiguous through a clear affirmative action, a checkbox that is already marked when the page loads shifts the burden onto the user to opt out rather than to opt in. Recital 32 of the GDPR expressly indicates that silence, inactivity, and pre-ticked boxes do not constitute valid consent, and UK ICO guidance directs organisations to use a positive opt-in and not to rely on pre-ticked boxes or other default-consent methods. For organisations that place analytics, advertising, or other non-essential cookies or similar technologies, relying on a pre-ticked box therefore generally leaves both the ePrivacy consent for accessing the device and any downstream GDPR processing without a valid basis.

Who it's relevant to

Privacy and data protection officers
DPOs and privacy teams responsible for demonstrating a valid lawful basis need to identify and remove pre-ticked boxes from consent flows, since under EU and UK standards they generally do not satisfy the requirement for a clear affirmative action. Because the organisation must be able to show that consent was validly obtained, any purpose relying on a default-ticked control typically represents a material compliance risk that should be flagged in privacy reviews and audits.
Web developers and CMP implementers
Those building or configuring cookie banners and consent management platforms should ensure that checkboxes for non-essential purposes render in an unchecked state by default and that non-action does not trigger consent. Consent management tooling can support compliant defaults, but configuration choices, such as pre-selecting categories, can undermine that support, so the technical setup should be reviewed against the applicable EU or UK consent standard rather than assumed compliant.
Marketing and growth teams
Marketing teams often favour pre-ticked boxes to maximise opt-in rates, but under EU and UK law this approach generally does not produce valid consent for cookie-based tracking or marketing. Teams should design forms and banners around genuine opt-in and be aware that narrow context-specific exceptions, such as the soft opt-in for email marketing, depend on facts outside the scope of cookie consent and should be assessed separately with legal input.
Legal counsel and compliance advisers
Counsel advising on consent architecture can rely on the settled position in EU and UK guidance, reflected in the GDPR's Recital 32 and ICO guidance, that pre-ticked boxes do not constitute valid consent. Because enforcement positions and guidance evolve, and because requirements differ across jurisdictions including certain US state regimes that use opt-out models, advisers should scope their assessments to the relevant jurisdictions rather than treating the opt-in requirement as universal.

Inside Pre-ticked Boxes

Definition
A pre-ticked box is a consent checkbox or toggle that is set to the affirmative (opted-in) state by default, requiring the user to actively deselect it to refuse rather than to actively select it to agree.
Relationship to the affirmative action standard
Valid consent under the GDPR must be given through a clear affirmative action. Pre-ticked boxes place the burden on the user to opt out, which is generally not regarded as an unambiguous, active indication of agreement in most EU jurisdictions.
Application to cookies and similar technologies
Where consent is the lawful basis relied upon for placing or accessing non-essential cookies, pixels, local storage, SDKs, or fingerprinting, a default opted-in checkbox typically does not satisfy the consent standard applicable in the EU and, in most cases, the UK.
Interaction between ePrivacy and GDPR
The ePrivacy Directive and its national implementations govern the placing of and access to information on a device and, for non-essential cookies, generally require prior consent. The GDPR governs any subsequent processing of personal data and defines the quality of that consent. A pre-ticked box may fall short of both, and satisfying one does not automatically satisfy the other.
Scope by jurisdiction
The concerns about pre-ticked boxes described here reflect the opt-in model applied in the EU and the UK. Some US state privacy frameworks, such as the CCPA and CPRA in California, often rely on an opt-out model, so the analysis of default settings can differ; the specific requirements depend on the applicable regime.

Common questions

Answers to the questions practitioners most commonly ask about Pre-ticked Boxes.

If a user leaves a pre-ticked consent box unchanged, does that count as valid consent?
No. Leaving a pre-ticked box unchanged is not a clear affirmative action, and it is therefore widely regarded as failing the GDPR standard for valid consent, which must be freely given, specific, informed, and unambiguous. Silence, inactivity, or pre-selected options do not demonstrate that the user actively agreed. In most EU jurisdictions, data protection authorities and guidance have treated pre-ticked boxes as non-compliant. The precise treatment can still depend on national implementations and the facts of a given case, so this should be read as the general position rather than a universal rule.
Isn't a pre-ticked box acceptable as long as the user is given the option to untick it?
Generally not for consent-based purposes under EU law. The concern is not merely whether the box can be unticked, but whether the arrangement reflects an unambiguous, affirmative choice. Requiring a user to take action to withdraw a pre-selected agreement typically shifts the burden in a way that does not meet the GDPR consent standard. This is distinct from opt-out mechanisms that apply under some other frameworks, such as certain US state privacy laws, where an opt-out model may be permitted for particular processing. Because scope differs by jurisdiction, the acceptability of a pre-selected option depends on which legal regime applies and the purpose involved.
How should a consent banner present cookie options instead of using pre-ticked boxes?
For consent-dependent categories such as analytics or advertising cookies, controls are generally presented in an unselected or off state, so that the user takes a clear affirmative action to enable them. Strictly necessary cookies are typically not presented as a consent choice at all, since they are generally exempt from consent under EU rules, though they may still be disclosed for transparency. Beyond the initial state of any toggles, the design as a whole should support a genuinely free and informed choice. The specific layout that a data protection authority considers acceptable can vary, so this describes common practice rather than a guaranteed-compliant template.
Do the same concerns about pre-ticked boxes apply to technologies other than cookies?
Yes, in general. The consent requirements that make pre-ticked boxes problematic apply to the placing of or access to information on a user's device and to the processing of any resulting personal data. That scope can extend to pixels, tags, software development kits, local storage, and similar tracking technologies, not only to cookies in the literal sense. Where such technologies rely on consent, presenting them as pre-selected raises the same issues as a pre-ticked cookie box. The exact analysis still depends on the technology's function and the applicable legal regime.
If our consent management platform includes a pre-ticked box configuration, does using the CMP make it compliant?
Not on its own. A consent management platform can support compliance by presenting options, recording choices, and managing signals, but a CMP does not replace legal judgment, and its default configuration is not automatically appropriate for every jurisdiction or purpose. If a CMP offers a pre-ticked or pre-selected option, that configuration may be inconsistent with the EU consent standard even though the tool technically permits it. Organizations generally need to review and configure the platform against the requirements that apply to them rather than relying on default settings.
What should we do if we discover consent was previously collected using pre-ticked boxes?
As a general matter, consent collected through pre-ticked boxes may not meet the EU standard, which can mean the affected consents are not a reliable basis for the relevant processing. Common practical steps include reviewing where such mechanisms were used, correcting the consent interface, and considering whether fresh, validly obtained consent is needed for the purposes concerned, alongside your consent record-keeping. Whether and how re-consent should be sought, and how to treat data already collected, depends on the facts, the applicable jurisdiction, and current regulatory guidance, so these are matters that typically warrant specific legal assessment rather than a one-size-fits-all response.

Common misconceptions

A pre-ticked box is acceptable because the user can always untick it.
Allowing a user to untick a default-on box shifts the burden to opting out rather than opting in. In most EU jurisdictions this is generally not considered a clear affirmative action and therefore typically does not meet the GDPR consent standard.
Pre-ticked boxes are prohibited everywhere in the same way.
Cookie consent obligations vary between the EU, the UK, and individual US states. The default opt-in concern is most directly relevant under EU and UK opt-in models; frameworks that rely on opt-out, such as some US state laws, may treat default settings differently. Always identify the applicable jurisdiction.
Avoiding pre-ticked boxes is enough to make cookie consent compliant.
Removing pre-ticked boxes addresses only the affirmative-action element. Consent must also be freely given, specific, and informed, and separate ePrivacy and GDPR obligations may apply. A single design fix does not by itself guarantee compliance, which depends on the full context and legal judgment.

Best practices

Present non-essential cookie options in an unticked or off state by default, so that consent results from the user's active selection rather than from deselecting a pre-set choice.
Do not treat continued browsing, implied consent, or a default-on setting as a valid affirmative action for non-essential cookies in EU and UK contexts.
Distinguish strictly necessary cookies, which are generally exempt from consent, from analytics, advertising, and functional cookies and similar technologies, which typically require prior opt-in consent in the EU before they are set.
Confirm the applicable legal regime before designing consent defaults, recognising that opt-in expectations in the EU and UK differ from the opt-out models common under some US state laws.
Record and retain evidence of how and when consent was obtained, so that the affirmative nature of each user's choice can be demonstrated if challenged.
Use a consent management platform to support these controls, but treat it as an aid rather than a guarantee of compliance, and seek legal judgment on contested or fact-specific points.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps