Data Privacy

GDPR Consent Wording Examples: 8 Templates That Pass

GDPR consent wording examples: 8 copy-ready templates for cookies, newsletters, health data, children and sharing — plus the failures DPAs actually sanction.

The 5 GDPR requirements for valid consent wording (Article 4(11) + Recital 32): consent must be freely given (no detriment for refusing), specific (one purpose at a time), informed (controller identity, purposes, retention), unambiguous (clear affirmative action — no pre-ticked boxes), and withdrawable as easily as it is given. Wording that bundles multiple purposes, hides withdrawal mechanisms, or uses default-on toggles fails any DPA review.

The wording you put on a consent form determines whether the consent is valid under GDPR Article 4(11). Vague language (“we may use your data to improve our services”) fails. Multi-purpose toggles fail. Pre-ticked boxes fail. This guide provides copy-ready wording for the 8 most common consent scenarios, each tested against CNIL and EDPB enforcement priorities of 2024-2025.

For the broader consent framework, see our GDPR consent examples. For the opt-in vs opt-out distinction, GDPR opt-in opt-out guide. For the lawful basis alternative, legitimate interest guide.

Key takeaways

  • Consent wording must name the controller, the purpose, and the recipients explicitly.
  • Each purpose requires a separate granular checkbox — no bundling.
  • Withdrawal mechanism must be described and as easy as giving consent.
  • For special categories of data (health, religion, biometrics): explicit consent required with even more precise wording.
  • The CNIL has issued multiple sanctions in 2024-2025 (totalling €30M+) for consent wording failures.

How to read these examples

Each example below follows the same anatomy, and the anatomy is what makes it compliant rather than the phrasing. Four elements have to be present in the sentence the user reads before they act — not in a linked policy, not in a tooltip, not further down the page.

The controller, named. Not “we”, not “the site”, not a trading name that does not appear in any register. The legal entity, and for most consumer-facing scenarios its address. If a user cannot identify who will hold their data from the consent text alone, the consent is not informed within the meaning of Recital 42.

The purpose, in operational language. “To send you a weekly newsletter about GDPR compliance” is a purpose. “To improve your experience”, “for marketing purposes” and “to provide our services” are not — they describe a category of activity broad enough to cover anything, which defeats the specificity requirement. The test to apply: could two reasonable people read this purpose and disagree about whether a given processing operation is covered? If yes, rewrite it.

The recipients, named. Article 13(1)(e) requires recipients or categories of recipients; where the consent covers sharing, the EDPB and the CNIL both expect actual names. “Our trusted partners” has been sanctioned repeatedly. If the list is long or changes, link to a maintained list from within the consent text and version it.

The withdrawal route, concrete. Article 7(3) requires withdrawal to be as easy as giving consent. In wording terms this means naming the mechanism and, ideally, the time it takes effect: “unsubscribe link in every email”, “account settings → Privacy, effective within 24h”. “You may withdraw your consent at any time” states the right without providing the means, which is what regulators look for.

A fifth element applies to every example and is a matter of layout rather than wording: the affirmative action must be unticked by default, and where a refusal option exists it must be as prominent as the acceptance option. No amount of good drafting rescues a pre-ticked box.

Compliant wording

We use cookies for two purposes:

[ ] Strictly necessary cookies — required for the site to function.
    (Always active, no consent needed.)

[ ] Analytics cookies (Google Analytics 4) — to measure site usage.
    These cookies collect anonymized event data sent to Google in the EU.
    Retained: 14 months. You can withdraw at any time via the
    "Cookie preferences" link in our footer.

[ Refuse all ]  [ Customize ]  [ Accept selected ]

What makes this compliant

  • Explicit purpose (“measure site usage”)
  • Recipient named (“Google”)
  • Retention period stated
  • Withdrawal mechanism described
  • Refusal as visually prominent as acceptance
  • No pre-ticked boxes

What fails

  • ❌ “We use cookies to improve your experience. [Accept]” — no purpose, no recipient, no granular choice
  • ❌ Pre-ticked analytics box
  • ❌ “Accept all” button with no equivalent “Refuse all”
  • ❌ Refuse only available after 2-3 clicks

2. Newsletter sign-up

Compliant wording

Subscribe to our weekly newsletter

[ ] I consent to receive marketing emails from [Company SAS, 12 rue X,
    75001 Paris] about [GDPR compliance products and content].
    Frequency: 1 email per week. You can unsubscribe at any time
    using the link in every email or by writing to privacy@company.com.
    Your email is retained for 24 months after the last interaction.

[ Subscribe ]

What makes this compliant

  • Controller fully identified
  • Topic of marketing specified
  • Frequency disclosed
  • Two withdrawal channels
  • Retention period stated

3. Marketing personalization based on behavior

Compliant wording

[ ] I consent to [Company] using my browsing history on company.com to
    personalize the content and product recommendations I see during my
    next visits. Recipients: [Company] only — no third-party transfer.
    Retention: 12 months from last visit. Withdrawal: account settings →
    Privacy → "Disable personalization", takes effect within 24h.

[ Confirm ]  [ Skip ]

The CNIL and EDPB have repeatedly stated that consent is generally not valid for employer-employee processing because of the power imbalance. Use legitimate interest or legal obligation instead. If consent is unavoidable (e.g., for non-essential perks):

Compliant wording

This consent is voluntary. Refusal will not affect your employment
relationship, salary, evaluation, or career progression in any way.

[ ] I consent to my participation in the [internal mentorship program],
    which involves [Company] sharing my contact details and area of
    expertise with other employees. Withdrawal at any time via the
    HR portal, with no consequence.

[ Confirm ]

5. Special category data — health (Article 9)

For sensitive data (health, religion, sexual orientation, etc.), Article 9 requires explicit consent — typically a written or otherwise unambiguously documented confirmation.

Compliant wording

Your medical record contains data classified as "health data" under
Article 9 GDPR. To process this data for the purpose of [providing
remote consultation services], we need your explicit consent.

[ ] I expressly consent to [Clinic SAS] processing my health data —
    specifically my consultation notes, prescriptions, and test results
    — for the purpose of providing remote consultation services.
    Recipients: [Clinic SAS] only. Retained for the legal medical
    record period (20 years post-consultation under French law).
    Withdrawal: at any time, via [process], without affecting the
    quality of care for ongoing treatments.

[ I expressly consent ]

6. Children (under 16, or lower threshold per Member State)

Article 8 GDPR requires verification that the consent of the holder of parental responsibility was given. For children under 16 (or under 13-15 depending on Member State):

Compliant wording

You appear to be under 16 years old. Before we can create your account,
we need verification that your parent or guardian has authorized this.

Please ask your parent/guardian to enter their email below. We will send
them a verification message describing what we collect and how we use it.

[ Parent/guardian email ]  [ Send verification ]

Common scenarios: company photos, event recordings, marketing material.

Compliant wording

[ ] I consent to my photograph being captured during the [event name]
    on [date] and used by [Company] for [marketing purposes on the
    company website, LinkedIn, and brochures]. Retained for [3 years].
    Withdrawal: email privacy@company.com to request removal of any
    photo containing me. Note: photos in printed materials cannot be
    recalled, but no new prints will be made.

[ I consent ]

8. Data sharing with named third parties

Compliant wording

[ ] I consent to [Company] sharing my email address with the following
    partner companies for the purpose of receiving offers from them:
    [Partner A — type of offers], [Partner B — type of offers].
    Each partner becomes the data controller of your data once shared.
    Withdrawal of consent stops future sharing but does not undo past
    sharing — to remove your data from a partner's database, contact
    them directly.

[ I consent ]

9. Common wording failures (CNIL 2024-2025 enforcement)

The CNIL fined multiple companies in 2024-2025 for consent wording failures. Patterns:

Failure Example Fix
Bundled purposes “I accept the terms and consent to marketing.” Two separate checkboxes
Pre-ticked boxes Analytics box checked by default Default unchecked, user must tick
Vague purpose “to improve our services” Specific purpose: “to send weekly newsletter”
Missing recipient No mention of which third parties Name each recipient
Asymmetric refusal Big “Accept” button, hidden “Refuse” Equally visible refusal
No withdrawal info “You can change your mind” Specific channel + timing
Forced consent for service “You must accept cookies to use the site” Refusal must be possible without losing service

Most consent text does not need to be written from scratch; it needs to be taken apart. Consider a line that appears, in one form or another, on a large share of European sign-up forms:

☑ I agree to the Terms of Service and Privacy Policy and consent to receive communications from us and our partners.

This single sentence fails on five separate counts, and it is worth naming each because the same five recur.

It is pre-ticked, which is disposed of by Planet49 (C-673/17): consent requires an active choice, and a box the user has to untick records the absence of an objection, not the presence of an agreement.

It bundles a contract with a consent. Accepting terms of service is a contractual act; consenting to marketing is a data protection act with a different legal nature and a different withdrawal regime. Tying them means the user cannot accept the service without accepting the marketing, so the consent is not freely given (Article 7(4)).

It bundles two purposes — communications from the controller, and communications from partners. These are separate purposes with separate recipients and must each carry their own checkbox.

It names no recipient. “Our partners” tells the user nothing about who ends up holding their email address, and each of those partners becomes a controller in its own right the moment the data reaches them.

It describes no withdrawal route, and by referring to “communications” rather than a defined message type, it gives the user no way to know what they would be withdrawing from.

The repaired version is longer, which is the point — the compression was doing the damage:

[ ] I accept the Terms of Service.        (required to create an account)

[ ] I consent to receive the weekly product newsletter from
    [Company SAS, 12 rue X, 75001 Paris]. One email per week.
    Unsubscribe link in every email; effective immediately.

[ ] I consent to [Company SAS] sharing my email address with
    [Partner A] and [Partner B] so they can send me their own offers.
    Each becomes an independent controller. Withdrawing stops future
    sharing; to be removed from a partner's list, contact them directly.

Three boxes instead of one, none pre-ticked, and only the first is a condition of the service. The second and third can be refused with no consequence — which is what makes them valid.

11. Wording is not the whole obligation: keeping the record

Article 7(1) puts the burden of proof on the controller: “the controller shall be able to demonstrate that the data subject has consented”. Perfect wording that is not logged is unenforceable in front of a supervisory authority, because there is nothing to produce.

A defensible consent record contains five fields: who consented (a stable user identifier, not just an email that may have changed), what they consented to (a version identifier for the exact wording shown — not a description of it), when (a server-side timestamp), how (the form, banner or endpoint, and the interaction that constituted the affirmative act), and the subsequent state (any withdrawal, with its own timestamp).

The field organisations most often omit is the second. Consent is given to a specific text; if the text changes, the old consents cover the old text and nothing else. Storing “consented: true” against a user row, without a pointer to the wording version, means that any change to the form retroactively invalidates your evidence for every prior consent. Version the wording, store the version identifier, and keep the historical texts.

The second most common omission is the withdrawal timestamp. Withdrawal is not deletion of the consent record — you still need to be able to show what was lawful and for how long. Overwriting the record on withdrawal destroys the evidence for the period during which processing was lawful.

12. Wording validation checklist

Before publishing a consent form, verify:

  • ☐ Controller fully identified (legal name + address)
  • ☐ Purpose stated specifically (not “to improve”)
  • ☐ Recipients named (not “our partners”)
  • ☐ Retention period stated
  • ☐ Withdrawal channel stated and as easy as consent
  • ☐ Each purpose has its own checkbox
  • ☐ No pre-ticked boxes
  • ☐ Refusal as visually prominent as acceptance
  • ☐ For Article 9 data: explicit consent language

Legiscope audits consent wording on collection forms automatically: detects bundled purposes, missing recipients, pre-ticked boxes, asymmetric UI. For a SaaS with 5-15 collection points, the audit takes minutes vs. days of manual review.

For related implementation guides: GDPR consent examples, GDPR information notices, cookie consent compliance guide, GDPR legitimate interest.

Official sources: the CNIL guidance on consent and cookies, the EDPB Guidelines 05/2020 on consent, and Article 4(11) and 7 of Regulation (EU) 2016/679 on EUR-Lex.

Conclusion

Consent wording is the most-audited element of a privacy program. The CNIL alone issued 21 cookie/consent sanctions in 2025. The compliant patterns are well-established — the failures repeat the same mistakes (bundling, vague purpose, pre-ticked boxes, asymmetric refusal). Using the templates in this guide, calibrated to the CNIL and EDPB criteria, removes the most common failure modes.

FAQ

No specific format, but it must satisfy Article 4(11): freely given, specific, informed, unambiguous, withdrawable. The wording must include the controller’s identity, the purposes, the recipients, retention period, and how to withdraw. Use plain language, not legal jargon.

No. The CJEU confirmed in Planet49 (Case C-673/17) that pre-ticked boxes do not constitute valid consent. The user must take an active, affirmative action.

No. Each separate purpose requires its own granular consent. Bundling (e.g., “I accept the terms and consent to marketing”) is one of the most common failure modes the CNIL sanctions.

No. GDPR requires unambiguous consent through a clear affirmative action. Continued use of a site, scrolling, or non-objection do not constitute consent. The cookie banner that says “by continuing, you accept” is invalid.

Consent (Article 6(1)(a)) requires explicit user permission and can be withdrawn at any time. Legitimate interest (Article 6(1)(f)) does not require consent but requires a documented balancing test showing the controller’s interest outweighs the data subject’s rights. Many marketing activities can use legitimate interest instead of consent — see our legitimate interest guide.

See Legiscope in action

AI-powered GDPR compliance that saves 340+ hours/year. Trusted by compliance professionals across Europe.

Request a demo
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →