Clarifying consent: the case of Planet49

05 novembre 2019

 
 
Does a pre-ticked I agree box constitute valid consent for data processing? The answer from the EU Court of Justice, published on 1 October 2019, was a resounding no.

The company involved in the case, Planet49, had used a pre-ticked box in order to obtain consent to receive marketing messages from participants in a promotional lottery. In its ruling on case 673/17, the Court noted that even under the General Data Protection Regulation’s (GDPR) predecessor, Directive 95/46/EC, this did not constitute valid consent. 

The definition of consent in the GDPR and Regulation 2018/1725, which applies to the EU institutions, is even clearer. Under these new rules, consent must be provided in the form of a statement or by a clear affirmative action.

The Court also referred to the need for valid consent to be unambiguous. In the case of a pre-ticked box, this cannot be the case, as it would be easy for an individual to miss the box. Additionally, consent must be specific. Controllers must therefore seek consent for different purposes separately, and not bundle together consent sought for separate purposes.

As the Court confirmed, affirmative, unambiguous and specific consent is required independently of whether the cookie collected qualifies as personal data or not. This is because Article 5(3) of the EU’s ePrivacy Directive requires consent for the storing of information and the gaining of access to information already stored via cookies or similar tools for marketing purposes.

The Court’s ruling helps to clarify how, and in what cases, consent is required under the EU’s data protection rules. It should act as a reminder to all controllers to ensure that their consent procedures are fully compliant with these rules.

Source: EDPS

Archivio news

 

News dello studio

feb9

09/02/2026

Accessing a dismissed employee's company email account can violate privacy laws and data protection regulations

According to the Italian Data Protection Authority, the content of emails, contact data related to communications, and any attachments fall within the notion of correspondence. Therefore emails are  protected

feb6

06/02/2026

Proposal for a Directive as regards simplification measures and alignment with the Cybersecurity Act

The Commission has proposed a new cybersecurity package to further strengthen the EU's cybersecurity resilience and capabilities. The package introduces measures to simplify compliance with

feb6

06/02/2026

Proposal for a Regulation for the Digital Networks Act (DNA)

The Commission proposes the Digital Networks Act (DNA), which offers a modern, simplified, and harmonised legal framework to bolster Europe's competitiveness. By strengthening digital

News Giuridiche