Pre-ticked Boxes
A pre-ticked box is a checkbox on a website form or cookie banner that is already marked as accepted before the user does anything, so consent is granted by default unless the user actively unchecks it. Under EU and UK data protection law, this approach is generally not accepted as valid consent, because consent is expected to come from a deliberate, positive action by the user rather than from inaction. In practice, organisations relying on pre-ticked boxes to obtain consent typically face a significant compliance risk.
A pre-ticked box is a user interface element presented in a pre-selected (checked) state that treats non-action as agreement to a given processing or tracking purpose. In most EU jurisdictions and in the UK, it does not meet the GDPR standard for valid consent, which must be freely given, specific, informed, and unambiguous and expressed through a clear affirmative action; GDPR Recital 32 indicates that silence, inactivity, or pre-ticked boxes do not constitute consent. UK ICO guidance similarly directs organisations not to use pre-ticked boxes or other default-consent methods and requires a positive opt-in. Where cookies or similar technologies (such as pixels, local storage, SDKs, or fingerprinting) require prior consent under the ePrivacy regime and its national implementations, a pre-ticked box does not provide the required consent for placing or accessing information on the user's device, and any consent-based GDPR processing that follows would likewise lack a valid basis. Scope note: requirements differ under other frameworks, including certain US state privacy laws that rely on opt-out rather than opt-in mechanisms, so the invalidity of a pre-ticked box is stated here with respect to EU/UK consent standards. Narrow exceptions such as the soft opt-in for email marketing are context-specific and outside the scope of this cookie-consent definition; their applicability depends on facts not addressed here.
Why it matters
Pre-ticked boxes sit at the heart of one of the most settled questions in EU and UK consent law: consent cannot be inferred from a user's inaction. Because the GDPR requires consent to be freely given, specific, informed, and unambiguous through a clear affirmative action, a checkbox that is already marked when the page loads shifts the burden onto the user to opt out rather than to opt in. Recital 32 of the GDPR expressly indicates that silence, inactivity, and pre-ticked boxes do not constitute valid consent, and UK ICO guidance directs organisations to use a positive opt-in and not to rely on pre-ticked boxes or other default-consent methods. For organisations that place analytics, advertising, or other non-essential cookies or similar technologies, relying on a pre-ticked box therefore generally leaves both the ePrivacy consent for accessing the device and any downstream GDPR processing without a valid basis.
Who it's relevant to
Inside Pre-ticked Boxes
Common questions
Answers to the questions practitioners most commonly ask about Pre-ticked Boxes.

