Opt-in is a consent model where the user must actively and knowingly agree to the processing of their data. The GDPR requires the opt-in model for cookies that are not strictly necessary.
What is opt-in?
In the opt-in model, the default state is "I do not consent". The user must take an active action (click a button, tick a checkbox) to express consent. Without this action, cookies must not be stored.
GDPR requirements for opt-in
- Active action – Clicking a button, ticking a checkbox
- No pre-selection – Checkboxes must be empty
- Informed – The user knows what they are consenting to
- Granularity – The ability to consent to individual purposes
- Easy rejection – As simple as acceptance
Opt-in vs. Opt-out
- Opt-in – Default state is "no"; the user must actively consent
- Opt-out – Default state is "yes"; the user must actively reject
Examples of correct opt-in
- A cookie banner with "Accept all" and "Reject all" buttons at the same level
- Empty checkboxes for individual cookie categories
- A clear explanation before the buttons are displayed
What is not valid opt-in
- Pre-ticked checkboxes
- "By continuing to use the website you agree..."
- Hidden or hard-to-reach rejection
- Forced consent for access to content