At a Glance
- Consent or Pay (CoP) is governed by fragmented national guidance, not one EU statute. Nine EU/EEA countries plus the UK have dedicated guidance, but most don’t.
- Regulators generally weigh four factors: a genuine alternative to consenting, a reasonable (not punitive) fee, true equivalence between paths, and fair presentation.
- The EDPB’s Opinion 08/2024 applies to large online platforms only and is not a general rule for mid-size or niche publishers, though some national DPAs test similarly.
- Austria’s derStandard ruling and Norway’s open Schibsted case remain unresolved and worth watching. This guidance isn’t legal advice and may date as they progress.
This guide explains how publishers can configure a Consent or Pay (CoP) model that meets current EU/EEA and UK regulatory expectations. It covers the four factors regulators check most: power imbalance, fee appropriateness, service equivalence, and fair presentation, plus a country matrix and a worked example. Intended for privacy, legal, and product teams evaluating a CoP setup.
This guidance helps publishers configure a Consent or Pay (CoP) model that holds up against current EU/EEA and UK regulatory expectations. It is based on published guidance from:
- ICO (UK)
- CNIL (France)
- DSK (Germany)
- Datatilsynet (Denmark)
- Datatilsynet (Norway)
- AEPD (Spain)
- APD/GBA (Belgium)
- DSB (Austria)
- Garante (Italy)
- IMY (Sweden)
Plus one live enforcement case (Austria’s derStandard ruling). However, this is not legal advice. Regulatory positions on CoP are still evolving, coverage varies sharply by country, and enforcement varies by market.
Scope: EU, EEA, and UK Are Not the Same Regime
Norway is not an EU Member State, but the GDPR applies there directly through the EEA Agreement, so Norwegian guidance carries the same legal weight as an EU Member State’s for these purposes.
The UK is different. Post-Brexit, it runs its own UK GDPR, a closely related but separate and independently evolving regime. Throughout this guide, Norway is treated alongside EU countries as the EU/EEA, while the UK is kept as its own reference point.
The EDPB and Large Online Platforms
You may see references to the EDPB’s April 2024 Opinion 08/2024, which found that a pure binary consent-or-pay choice is “in most cases” not valid consent.
That Opinion is explicitly scoped to large online platforms doing behavioral advertising, i.e., Meta-scale reach, market dominance, or DSA/DMA-style gatekeeper status. It is not a general rule for ordinary ad-funded publishers.
Spain’s regulator has folded it into national guidance, and Belgium’s has formally acknowledged it, but both apply it only as the stricter bar that kicks in once a publisher is found to be in that large-platform category.
Don’t apply “Meta can’t do it” reasoning to a mid-size or niche publisher’s setup. The four-factor test below is the actual baseline that applies broadly. Broader EDPB guidance extending beyond large platforms is in active development but not yet published, so this baseline may need updating once it lands.
Cookie Wall vs. Consent or Pay: These Are Different Questions
A cookie wall is a setup with only one exit: accept tracking or you cannot access the site at all. Regulators across the EU/EEA have consistently found this invalid, and it’s the oldest and most settled part of cookie-consent law, going back to the EDPB’s 2020 Consent Guidelines.
Consent or Pay is a different configuration. The site adds a genuine third option of payment alongside accept and refuse.
A country’s general “cookie walls are banned” rule doesn’t automatically bless or block CoP. It just means the old accept-or-nothing setup is off the table regardless. Whether adding a paid option is enough to make the “accept” side freely given is the separate question this guide is actually about, and most countries below have not said anything specific on it either way.
The Four Things That Matter
Every regulator we reviewed evaluates CoP models against the same four questions, even when they don’t name them the same way:
Do users have a genuine alternative or are they cornered into consenting?
Is the fee for avoiding tracking reasonable and not punitive?
Is the paid experience actually equivalent to the tracked one?
Is the choice presented fairly and without pressure or dark patterns?
Fail any one of these and the “consent” collected isn’t valid under the GDPR, regardless of how the rest of the setup looks.
Before You Launch
Before deploying your Consent or Pay model, ensure you have addressed the following core requirements to align with current regulatory expectations.
Written assessment of market position and user reliance (power imbalance)
Documented rationale for the fee, tied to user valuation of privacy, not to lost ad revenue
Core service defined and confirmed identical across consent and pay paths
Consent request is specific, granular, and separate from other purposes
No non-essential tracking before consent is given
Visible, one-step withdrawal mechanism in place
DPIA completed and signed off
If market position is uncertain, contextual-ads fallback option scoped as a contingency
1. Power Imbalance: Can the User Actually Say No?
Regulators are checking whether your market position, your users’ reliance on your site, or a lack of real competitor alternatives leaves people with no genuine choice but to consent.
Setup Checklist
Identify whether your site holds a dominant or hard-to-substitute position in its category
For example, niche news, essential service, or high switching costs for existing subscribers.
If yes, plan for a third option
This needs to exist alongside consent and pay: free access with non-personalized (contextual) advertising. This is the fallback several regulators point to when a power imbalance can’t be ruled out.
Document your reasoning
Regulators expect a written assessment of market position and user reliance as part of your DPIA, not just an assumption that “our fee is low enough.”
When to Skip This
Skip this if you operate in a genuinely competitive market with low switching costs, though it’s still worth a one-line note in your DPIA explaining why.
Market-Specific Information
Austria’s DSB draws a hard line here: CoP cannot be used by a monopoly or near-monopoly player, or by public-sector bodies, regardless of fee or alternative design. See the country matrix at the end of this guide for which countries treat power imbalance as a named requirement and which haven’t addressed it yet.
2. Appropriate Fee: Priced to Allow a Real Choice, Not to Force Consent
While there is no universally accepted price point, regulators focus on the “fairness” of the cost relative to the service provided. To ensure your model withstands scrutiny, your fee structure must be transparent and evidence-based.
What Regulators Are Checking
Whether the fee is set so high that “pay” isn’t a real option, meaning everyone ends up consenting by default.
Setup Checklist
Base the fee on what users value
In exchange for not having their data used for personalized ads, rather than on lost ad revenue, production costs, or general subscription pricing benchmarks. Those are legitimate business inputs but don’t hold up as a compliance justification.
If you're layering Consent or Pay on top of an existing paywall
Only the incremental fee — the difference between “subscribe with ads” and “subscribe without ads” — is what gets scrutinized, not the full subscription price.
Avoid one combined price
Don’t bundles core access with ad-avoidance. Regulators specifically flag this structure as harder to defend.
Where possible, gather evidence
User research, survey data, or observed willingness-to-pay for ad-free tiers. This is your defense if a regulator asks you to justify the number.
No regulator sets a threshold
There is no “safe” euro amount. The test is always relative to your audience and market.
Market-Specific Information
France’s CNIL explicitly suggests micropayments or a virtual-wallet model as an alternative to a flat subscription fee, and limits what the wall can cover. It can only gate purposes tied to funding the service (e.g. targeted-ad consent), not unrelated purposes like editorial personalization. Austria requires the fee to reflect “reasonable, realistic costs.” See the country matrix for where a fee test is a named requirement.
3. Equivalence: Same Core Service Either Way
Achieving true equivalence is more than a technical requirement. It’s a transparency exercise that helps make sure your users feel they are making a comparable choice. Understanding the specific factors regulators use to assess this balance will help you avoid common pitfalls.
What Regulators Are Checking
Whether the paying user and the consenting user get the same underlying product, not a stripped-down version designed to make paying unattractive.
Setup Checklist
Define your core service in writing
I.e., what you tell users the product does, how you market it, before deciding what belongs in each tier.
Keep the core service identical across the consent and pay paths
Content, functionality, and access must match.
Extra features are fine in either direction
For example, a “premium” tier with bonus content, or small perks for consenting users, as long as they sit on top of the core service, not baked into it.
Do not use missing features as a lever to justify a higher fee
Also, do not degrade the free/consent option to make the paid one look better by comparison.
Review equivalence whenever you change functionality on either path
It’s not a one-time setup decision. Like reviewing your cookies/trackers in use, regulatory obligations, and consent workflows, equivalence needs periodic review.
Market-Specific Information
Spain’s AEPD adds a rule that applies to every company, not just large platforms: the alternative must be offered by the same provider. You cannot point users to a competitor’s or partner’s equivalent service and call that a valid alternative.
4. Fair Presentation: No Pressure, No Dark Patterns
Even with a fair fee and valid alternative, the mechanism you use to present these choices can determine whether the consent is truly free. Regulators apply strict design principles to ensure transparency and clarity throughout the user journey.
What Regulators Are Checking
Whether users can actually understand what they’re choosing and can refuse as easily as they can accept.
Setup Checklist
Label choices in plain language
Avoid framing like “continue for free” for the consent option, since it hides what’s actually being agreed to.
Present consent and pay options with equal visual weight
No pre-selected option, no greyed-out decline button, no extra clicks to find the paid or free-alternative path.
Make sure personalized-advertising consent can be given or refused separately
Keep distinct from other purposes (analytics, retargeting, embedded content) somewhere in the flow, typically the granular settings layer. A bundled “Accept All” shortcut is fine as a convenience. What’s invalid is having only a bundled accept/reject with no granular option at all.
Don't fire any non-essential cookies or tracking before the user has made a choice
Same logic as opt-in regulatory requirements for prior consent. Ensure cookies and trackers are correctly detected and categorized, the block them until consent is obtained.
Build in an always-visible way to withdraw consent
Make sure it’s as easy to use as the original consent mechanism. At minimum, stop processing the withdrawn data immediately. The ICO and EDPB go further and treat withdrawal as equivalent to an erasure request where there’s no other legal basis to retain the data, but that specific framing isn’t stated across the board. Check what applies in your market before assuming it’s universal.
Run a DPIA before launch and keep it under review
Business operations, technologies in use, and regulatory requirements change. Periodic DPIAs help maintain security and privacy standards.
Market-Specific Information
Germany’s TTDSG §25(1) additionally caps what can be stored/accessed on the devices of non-consenting, tracking-free subscribers to what’s strictly necessary for the service they asked for.
Anything beyond that needs its own Art. 6(1) GDPR legal basis. Spain’s AEPD and the UK’s ICO both have detailed banner-design and granularity rules. France and Denmark’s published guidance doesn’t go into this level of UX detail.
Real-World Precedent
The Austrian DPA (DSB, decision 2023-0.174.027) found derStandard’s Pay-or-Okay banner unlawful because “consent” was one bundled accept/reject covering analytics, personalized advertising, and third-party social plugins together, with no granular option to split them out. derStandard argued granular consent was operationally impossible given its ad-funded free tier.
The Federal Administrative Court rejected that argument on appeal (18 August 2025), and also flagged a ~99.9 percent consent rate on the banner as evidence the choice wasn’t genuinely free.
The case is still appealable (potentially to the CJEU), but it’s the clearest real-world illustration of the granularity requirement failing in practice. A working “pay” option does not excuse a banner with no way to consent selectively.
Where Guidance Exists
Quick lookup: for every EU Member State (plus Norway, which follows GDPR directly as an EEA state), does the national DPA have a dedicated document on Consent or Pay specifically, not just a general cookie-wall rule? Where the answer is yes, the link goes to the primary source.
| Country | Guidance Status | Primary Source |
|---|---|---|
| Austria | Guidance | DSB FAQ on cookies and data protection |
| Belgium | Guidance | APD/GBA Recommendation 01/2025 on direct marketing |
| Bulgaria | No guidance | |
| Croatia | No guidance | |
| Cyprus | No guidance | |
| Czech Republic | No guidance | |
| Denmark | Guidance | Datatilsynet: Cookies og lignende teknologier |
| Estonia | No guidance | |
| Finland | No guidance | |
| France | Guidance | CNIL: Cookie walls, premiers critères d’évaluation |
| Germany | Guidance | DSK Beschluss: Bewertung von Pur-Abo-Modellen auf Websites |
| Greece | No guidance | |
| Hungary | No guidance | |
| Ireland | No guidance | |
| Italy | Guidance (consultation, no ruling) | Garante: public consultation on Pay or Ok models |
| Latvia | No guidance | |
| Lithuania | No guidance | |
| Luxembourg | No guidance | |
| Malta | No guidance | |
| Netherlands | No guidance | |
| Norway (EEA, GDPR applies) | Guidance | Datatilsynet: EDPB on “pay or okay” |
| Poland | No guidance | |
| Portugal | No guidance | |
| Romania | No guidance | |
| Slovakia | No guidance | |
| Slovenia | No guidance | |
| Spain | Guidance | AEPD: Guía sobre el uso de las cookies |
| Sweden | Guidance | IMY: Samtycke eller betala – arbete med riktlinjer pågår |
Country-by-Country Requirement Matrix
This covers the nine EU/EEA countries above with dedicated guidance, plus the UK and the EU-level EDPB Opinion as separate reference points.
Requirement = the regulator explicitly requires this to be satisfied for CoP consent to be valid. No guidance = this specific factor isn’t addressed even though the country has a dedicated CoP document overall.
✅ = Requirement
⚪ = No specific guidance
| Country | Requirements | Scope | Notes/Conditions |
|---|---|---|---|
| Austria | Power Imbalance: ✅ Appropriate Fee: ✅ Equivalence: ⚪ Fair Presentation/Granularity: ✅ | General | – Banned for public sector/monopolies.- Zero ad-tracking for payers.- Bundled consent is unlawful. |
| Belgium | Power Imbalance: ⚪ Appropriate Fee: ⚪ Equivalence: ⚪ Fair Presentation/Granularity: ⚪ | Large-only | Defers entirely to CJEU and EDPB Opinion 08/2024. |
| Denmark | Power Imbalance: ⚪ Appropriate Fee: ✅ Equivalence: ✅ Fair Presentation/Granularity: ⚪ | General | 4-criteria test, processing limited to necessary purposes for payers. |
| France | Power Imbalance: ✅ Appropriate Fee: ✅ Equivalence: ✅ Fair Presentation/Granularity: ⚪ | General | – Suggests micropayments.- Wall only gates funding-related purposes (no editorial personalization). |
| Germany | Power Imbalance: ⚪ Appropriate Fee: ✅ Equivalence: ✅ Fair Presentation/Granularity: ✅ | General | TTDSG §25(1) limits storage to strictly necessary for tracking-free subscribers. |
| Italy | Power Imbalance: ⚪ Appropriate Fee: ⚪ Equivalence: ⚪ Fair Presentation/Granularity: ⚪ | Pending | – Pending consultation outcome (July 2025).- High-risk status. |
| Norway | Power Imbalance: ✅ Appropriate Fee: ✅ Equivalence: ✅ Fair Presentation/Granularity: ⚪ | Partial | – Follows EDPB 08/2024.- Active supervisory case against Schibsted. |
| Spain | Power Imbalance: ✅ Appropriate Fee: ✅ Equivalence: ✅ Fair Presentation/Granularity: ✅ | Mixed | – Alternative must be the same provider.- Power imbalance/Appropriate Fee requirements apply strictly to large platforms. |
| Sweden | Power Imbalance: ⚪ Appropriate Fee: ⚪ Equivalence: ✅ Fair Presentation/Granularity: ⚪ | Partial | Awaiting general (non-large-platform) EDPB guidelines. |
Reference Points Outside the EU/EEA GDPR Regime
While these regimes operate independently of the EU/EEA GDPR, they provide critical operational benchmarks that often align with or inform wider compliance strategies.
| Jurisdiction | Requirements | Large Platform-only Scope? | Notes |
|---|---|---|---|
| UK (ICO) | Power Imbalance: ✅ Appropriate Fee: ✅ Equivalence: ✅ Fair Presentation/Granularity: ✅ | No | – Runs its own UK GDPR, not EU GDPR.- Most detailed operational framework of any regulator reviewed. – DPIA mandatory. – Applies broadly, not scoped to large platforms. |
| EU-level (EDPB Opinion 08/2024) | Power Imbalance: ✅ Appropriate Fee: ✅ Equivalence: ✅ Fair Presentation/Granularity: ✅ | Yes | – Not a country. – Applies only to “large online platforms” doing behavioral advertising, not a general rule for ordinary publishers. – Most detailed test overall, but narrowest scope. |
Illustrative Example: A Digital News Publisher
As an illustrative only, not a template to copy verbatim, we’ll use fictional publisher “Nordbrief”: a mid-size Dutch-market digital news site with roughly two million monthly readers, 40,000 subscribers, and three to four comparable competitors in its category. Nordbrief is considering CoP for the first time.
Power Imbalance Assessment
To determine if a power imbalance exists, we evaluated several key factors regarding our current market position.
Market Position
Nordbrief holds an estimated 12 percent share of national digital news readership. At least three competitors — comparable general-news outlets — offer similar content with low switching costs for readers. No exclusive-content lock-in, no network effects as readers don’t interact with each other on the platform, and no evidence of a professional or civic reliance comparable to a job-search or government-services site.
Existing Users
~40,000 paying subscribers already use a “subscribe for ad-free” tier unrelated to tracking consent. Free/ad-supported readers, whom a CoP rollout would newly affect, have no existing lock-in specific to Nordbrief.
Conclusion
No clear power imbalance identified. Nordbrief is not a monopoly or near-monopoly provider in its category, has no public-sector role, and users can switch to comparable alternatives at low cost. CoP can proceed without a mandatory third option that’s free, with contextual ads.
However, we’re adding one anyway as a goodwill/low-risk measure. Reassess if market share materially changes or a competitor exits.
Fee Rationale
To ensure our fee structure withstands regulatory scrutiny, we calculated the cost based on user-centric valuation rather than internal business metrics.
What We Didn’t Use
Lost ad revenue per user (EUR X/month), production cost per article, or the existing EUR 9.99/month ad-free subscription price, as these reflect Nordbrief’s business needs, not what a reader values in not being tracked.
What We Used
A reader survey (n=1,200) asking what respondents would pay monthly specifically to avoid personalized-ad tracking while keeping the same free content.
Median stated willingness to pay: EUR 2.50/month. Cross-checked against observed behavior in a soft-launch A/B test where three percent of free-tier users who saw a EUR 2.99/month “tracking-free” option converted, versus under 0.5 percent at a EUR 7.99 test price point, suggesting the higher price meaningfully suppressed genuine choice.
Fee Set
EUR 2.99/month for the tracking-free option, layered on top of free (ad + consent) access, not combined with Nordbrief’s existing EUR 9.99 premium ad-free subscription. The EUR 9.99 tier remains a separate, non-compliance-relevant product decision.
Core Service Definition
To ensure transparency and compliance, we must clearly articulate the core product offering that remains consistent across all user paths.
Written Definition (Used in ToS and Marketing)
“Nordbrief provides daily national and regional news articles, breaking news alerts, and reader comments, updated continuously throughout the day.”
Equivalence Check Across Paths
| Feature | Consent Path (Free) | Pay Path (€2.99/mo) |
|---|---|---|
| Article Access | Full | Full |
| Breaking News Alerts | Full | Full |
| Reader Comments | Full | Full |
| Advertising | Personalized | Contextual only |
| Personal Data Used for Ads | Yes | No |
| Site Speed / Ad Load | Standard | Slightly faster (fewer ad calls), disclosed as a direct consequence of no ad personalization, not a withheld feature. |
No features are withheld from the consent path to make the pay path more attractive. The only differences are a direct consequence of not processing data for personalized ads.
DPIA Excerpt
Processing Activity: Personal data processing for personalized advertising under a Consent or Pay model.
High-Risk Trigger: Behavioral profiling of website visitors for ad targeting, Art.35(3)(a) GDPR-adjacent, per WP248 criteria: evaluation/scoring, large-scale processing.
Necessity and Proportionality: Personalized advertising is not necessary for delivering the core news service, as defined above, and an equivalent tracking-free alternative exists at a fee assessed as non-prohibitive (see fee rationale). Consent is therefore an available lawful basis, provided it meets Art. 4(11) GDPR and Art. 7 GDPR conditions.
Risks Identified: (1) Risk that fee level indirectly coerces consent, mitigated via user-research-based pricing and A/B conversion monitoring, reviewed quarterly. (2) Risk that bundled consent (analytics + ads + embeds) invalidates granularity, mitigated via a granular settings panel allowing separate opt-in per purpose, tested against the Austrian derStandard precedent. (3) Risk of stale assessment, mitigated via a 12-month review cycle or immediate re-review on material market-share or pricing changes.
Sign-off: DPO reviewed and approved [date]. Next review: [date + 12 months].