Opt-out is a model where consent is presumed and the user must take active steps if they do not wish to be tracked. For cookies in the EU, this model is unlawful – the GDPR requires opt-in.
What is opt-out?
In the opt-out model, the default state is "I consent". Cookies are stored automatically and the user must take an active action (find settings, opt out) if they wish to reject tracking.
Why is opt-out unlawful for cookies in the EU?
- ePrivacy Directive – Requires prior consent before storing cookies
- GDPR – Consent must be active, not presumed
- CJEU ruling – Planet49 confirmed the requirement for active consent
Examples of unlawful opt-out
- "By continuing to use the website you agree to cookies"
- Pre-ticked checkboxes in the cookie banner
- Storing cookies before the cookie banner is displayed
- A cookie banner with no option to reject
- Rejection requiring more steps than acceptance
Where is opt-out used lawfully?
The opt-out model may be used for:
- Email marketing – For existing customers (soft opt-in)
- Certain US jurisdictions – For example, CCPA allows opt-out
- B2B communications – In certain cases
CCPA vs. GDPR
The California CCPA uses an opt-out model ("Do Not Sell My Personal Information"), whilst the GDPR requires opt-in. For websites targeting both the EU and the US, implementing the stricter opt-in standard is necessary.