Skip to main content
Category: Consent Principles

Prior Consent

Also known as: consent obtained in advance
Simply put

Prior consent means getting someone's agreement before an activity starts, rather than after it has already begun. In the cookie context, this generally means a website must obtain a user's permission before placing non-essential cookies or similar tracking technologies on their device, not while or after they are already being set.

Formal definition

Prior consent refers to consent that is sought and obtained sufficiently in advance of the relevant activity commencing. As a general principle, the term signifies that agreement must be secured before authorisation or commencement of the activity to which it relates, rather than being inferred or collected retrospectively. In practice this timing requirement means an activity should not begin until valid consent has been given; the specific standard for what makes such consent valid (for example, that it be freely given, specific, informed, and unambiguous under EU frameworks, or the applicable requirements of other regimes) is governed by the relevant law and is out of scope for this timing-focused definition. The evidence provided addresses the general meaning of 'prior' as a timing concept and does not establish jurisdiction-specific cookie consent obligations; those vary between the EU, the UK, individual US states, and other regimes and should be confirmed against applicable guidance.

Why it matters

The timing of consent is a foundational concept in cookie compliance because it determines whether an activity is authorised at the moment it occurs. Prior consent means agreement is sought sufficiently in advance of any authorisation or commencement of the activity, at the early stages before it begins. Applied to cookies, this generally points toward obtaining permission before non-essential cookies or similar tracking technologies are placed on or read from a user's device, rather than setting them first and asking afterward. Where consent is only inferred or collected retrospectively, the very requirement that it come first is not met.

This distinction matters in practice because many technical implementations load analytics, advertising, or other non-essential technologies as a page renders, which can mean tracking has already begun by the time a user encounters a consent banner. If consent is required and must be prior, that sequencing is directly relevant to whether the activity was properly authorised. The precise obligations, and what makes consent valid, depend on the applicable legal regime and are not settled by the timing concept alone.

Because the standard for valid consent, and whether consent is required at all, varies between the EU, the UK, individual US states, and other regimes, professionals should treat prior consent as one component of a broader compliance analysis. The timing requirement described here is a general principle; jurisdiction-specific cookie consent obligations should be confirmed against the guidance applicable to the relevant territory.

Who it's relevant to

Privacy and data protection officers
Those responsible for cookie compliance need to assess whether consent is being obtained before non-essential technologies are placed, not after, and to confirm the applicable timing and validity standards against the guidance for each jurisdiction in which the organisation operates.
Web developers and engineers
Developers implement the sequencing that determines whether tracking technologies fire before or after a user interacts with a consent mechanism. The prior consent principle is directly relevant to how and when scripts, pixels, SDKs, and similar technologies are loaded on a page.
Legal counsel and compliance teams
Counsel advising on cookie practices must distinguish the timing requirement of prior consent from the separate question of what constitutes valid consent, and must map both to the regime that applies, since obligations differ across the EU, the UK, individual US states, and other jurisdictions.
Marketing and analytics teams
Teams deploying analytics and advertising technologies should understand that where prior consent is required, the relevant activity should generally not begin until consent has been given, which affects when tags and tracking can lawfully collect data.

Inside Prior Consent

Consent before placement or access
Prior consent means that consent must be obtained before non-exempt cookies or similar technologies are placed on, or accessed from, a user's device. Under the ePrivacy Directive as implemented in most EU jurisdictions, the storing of or gaining access to information on terminal equipment requires the user's consent beforehand, except where strictly necessary.
Scope limited to non-exempt technologies
The prior consent requirement generally applies to analytics, advertising, and functional cookies, as well as comparable technologies such as pixels, local storage, SDKs, and device fingerprinting. Strictly necessary or essential cookies are generally exempt and typically do not require prior consent.
Quality of the consent
Where consent is required, it must generally meet the GDPR standard of being freely given, specific, informed, and unambiguous, expressed through a clear affirmative action taken before the relevant technology is deployed.
Two overlapping legal bases
Prior consent chiefly derives from the ePrivacy Directive, which governs the act of placing or accessing information on a device. Any subsequent processing of personal data that follows is separately governed by the GDPR, and consent under one regime does not automatically satisfy the other.
Timing and default state
Because consent must be prior, non-exempt technologies should not fire in a default-on state before the user acts. In most EU jurisdictions, loading such tags before an affirmative choice is made would undermine the prior nature of the consent.
Jurisdictional variation
The prior (opt-in) consent model reflects EU and UK practice. Frameworks such as the CCPA and CPRA in California and other US state laws often rely on an opt-out approach rather than requiring consent before tracking begins, so the prior consent standard is not universal.

Common questions

Answers to the questions practitioners most commonly ask about Prior Consent.

Does clicking 'Accept' after a website has already loaded count as prior consent?
Generally, no. Prior consent means the consent must be obtained before non-exempt cookies or similar technologies are placed on or read from the user's device. If tracking cookies are set as the page loads and consent is only collected afterward, the 'prior' requirement is typically not met in most EU jurisdictions. The consent action must precede the setting of and access to the relevant technologies, not merely follow the user's arrival on the site.
If a user keeps browsing without interacting with the banner, can that be treated as prior consent?
No. Continued browsing is a form of implied consent, and implied consent is widely considered non-compliant under EU law because valid consent must be unambiguous and given through a clear affirmative action. Prior consent requires an affirmative signal before non-exempt technologies are deployed; the absence of an objection, or mere continued use of the site, does not satisfy this standard in most EU jurisdictions. Note that requirements differ under frameworks such as US state privacy laws, which often rely on an opt-out model rather than prior opt-in consent.
How can a site prevent non-exempt cookies from firing before consent is collected?
In practice, this typically involves configuring the site and any consent management platform (CMP) so that scripts and tags for analytics, advertising, and other non-exempt technologies are blocked or deferred until an affirmative consent signal is received. This may include gating tag manager triggers on consent state and controlling third-party SDKs and pixels, since similar technologies fall within the same rules even though they are not literally cookies. Strictly necessary or essential cookies are generally exempt and may load beforehand. A CMP supports this outcome but does not by itself guarantee compliance; legal judgment about which technologies are exempt remains necessary.
Which cookies are allowed to load before the user gives consent?
Cookies and similar technologies that are strictly necessary or essential to provide a service the user has requested are generally exempt from the prior consent requirement and may load before any consent action. Analytics, advertising, and many functional cookies typically require prior consent under EU law. Classifying a cookie as strictly necessary is a fact-specific judgment, and there can be contested interpretations at the margins; this entry does not resolve borderline classification questions.
How should prior consent be recorded to demonstrate it was obtained beforehand?
Organizations subject to EU rules generally maintain consent logs or records that can evidence that a valid, affirmative consent was given and, where relevant, the state of consent at the time non-exempt technologies were deployed. This can include what the user was shown, the choices made, and the timing. Consent record-keeping supports accountability, but the specific content and retention of such records depend on the applicable regime and the facts, which are out of scope for this definition.
Does obtaining prior consent for cookies also cover the later processing of personal data?
Not necessarily. Prior consent under the ePrivacy Directive and its national implementations concerns the placing of and access to information on the user's device. Any processing of personal data that follows is separately governed by the GDPR and requires its own lawful basis, which may or may not be consent. Consent obtained for one purpose under one regime does not automatically satisfy the requirements of the other; each layer should be assessed on its own terms.

Common misconceptions

Continued browsing or a pre-ticked box can supply prior consent.
In most EU jurisdictions, implied consent from continued browsing and pre-ticked boxes are widely considered non-compliant, because valid consent requires a clear affirmative action taken before non-exempt technologies are deployed.
Prior consent under the ePrivacy rules covers all downstream data processing.
The ePrivacy Directive governs the placing of and access to information on a device, while the GDPR separately governs any resulting processing of personal data. Satisfying one does not automatically satisfy the other, and each may require its own analysis.
Every jurisdiction requires prior opt-in consent before tracking.
The prior consent model is characteristic of EU and UK practice. Several US state laws, such as California's CCPA and CPRA, generally rely on opt-out mechanisms rather than requiring consent before tracking, so obligations differ by geography.

Best practices

Configure your CMP so that non-exempt cookies, pixels, SDKs, local storage, and fingerprinting are blocked until the user takes a clear affirmative action, keeping tags default-off before consent.
Classify each technology as strictly necessary or non-exempt and document the basis for treating any cookie as exempt from the prior consent requirement.
Analyze the ePrivacy placement/access requirement and the GDPR processing requirement separately, and record the legal basis relied upon for each, rather than assuming one consent covers both.
Avoid consent-defeating patterns such as pre-ticked boxes and reliance on continued browsing, which are widely considered non-compliant in most EU jurisdictions.
Adapt your approach by geography, applying an opt-in model for EU and UK users while accounting for opt-out mechanisms relevant to US state laws such as the CCPA and CPRA, and consult local guidance where practice differs.
Maintain consent logs and records that evidence what the user was shown and when consent was given, and treat CMPs as tools that support compliance rather than as a substitute for legal judgment.