Most form tutorials show you what’s possible. This one shows you what actually works. The State of CSS 2024 survey puts Tailwind CSS at 62% developer usage. More teams are…
Table of contents
Most consent checkboxes on the web wouldn’t survive a regulator’s second look. A 2020 study out of MIT, UCL, and Aarhus University, presented at the ACM CHI Conference, scraped consent management platforms across the top 10,000 UK websites and found that only 11.8 percent met the minimum legal bar Article 7 sets for consent under GDPR.
That bar sits low on paper, just four words: freely given, specific, informed, unambiguous. Getting all four to hold up under review is where most controllers, whether they’re running a signup flow, a cookie banner, or an HR onboarding pack, get tripped up.
What Is a GDPR Consent Form?
What separates this document from every other bit of paperwork on a signup page is the burden it has to carry: proof, on request, that a specific person agreed to a specific thing. Article 4(11) puts that standard in writing.
It defines consent as any freely given, specific, informed and unambiguous indication of the data subject’s wishes, and that’s the line every version of the form has to clear, whether it’s sitting on a website, printed in an intake pack, or built into a mobile app’s onboarding screen.
It exists so a controller can prove consent was given, not assumed. That distinction matters more than it sounds like it should, because most disputes come down to exactly that question.
Among the many types of forms a website runs, this is the one built specifically to prove permission rather than collect it in passing.
- Web forms with a checkbox and submit action
- Printed intake forms with a signature line
- Verbal scripts recorded during a phone call
- In-app prompts before a feature turns on
A consent form isn’t a privacy notice. The notice explains what happens to the data. The form is where someone actually says yes.
What Makes GDPR Consent Legally Valid?
Four conditions decide whether a checkbox counts as lawful consent, and Article 7 doesn’t give partial credit for meeting three out of four. Miss one, and whatever got collected doesn’t count as a legal basis at all.
| Condition | Requirement | Common Failure |
|---|---|---|
| Freely given | No penalty for refusing, no bundling with unrelated terms | Consent tied to accessing the service |
| Specific | One consent per distinct purpose | Single checkbox covering several purposes |
| Informed | Plain language naming the controller and the purpose | Vague wording like “improve our services” |
| Unambiguous | A clear affirmative action, not silence | Pre-ticked boxes or implied consent from scrolling |
Recital 32 spells out what counts as that affirmative action: ticking a box, choosing settings, or another statement that clearly signals agreement. The same recital rules out silence, pre-ticked boxes, and plain inactivity as stand-ins for consent.
Recital 42 puts the burden of proof on the controller, not the data subject. If a regulator asks, the organization has to produce evidence that consent was given. Not the other way around.
Recital 43 goes further on conditionality. Consent isn’t free when it’s bundled into a contract or made a requirement for using the service at all.
Planet49 GmbH found this out directly. Its pre-ticked lottery checkbox became the test case the CJEU used to rule, in Case C-673/17 (2019), that only active behavior by the user can count as consent.
What Must a GDPR Consent Form Include?
See the Pen
Modern GDPR Cookie Consent Form by Bogdan Sandu (@bogdansandu)
on CodePen.
Picture a checkbox that just says “I agree,” with nothing else nearby. That’s usually where forms start falling apart, because a checkbox alone isn’t informed consent. It needs several things sitting around it to actually count.
It needs to say who’s asking, in real terms, the organization’s actual name and contact details, not a vague “we.” It needs a plain-language purpose statement, one sentence per purpose, each with its own separate tickbox rather than one box trying to cover everything at once. It has to show the actual mechanism used to grant consent, whether that’s a checkbox, a signature, or a click-to-accept button.
It also has to spell out how to withdraw, right there on the form itself rather than three clicks into a privacy policy nobody reads. And it needs a stated retention period, meaning how long both the data and the record of consent will actually be kept.
Bundled consent trips up more forms than anything else on this list. A single checkbox covering newsletter signup, data sharing, and profiling all at once fails the specificity test outright. Each purpose needs its own box, left unticked.
Getting all five right from a blank page takes more than good intentions, which is why a full walkthrough of how to create GDPR compliant forms is worth reading alongside this one.
Some site owners build this checkbox directly into their signup page rather than installing a dedicated plugin. The process for creating forms in WordPress without plugins covers the native fields and code needed to do that.
GDPR Consent Form Examples by Use Case
A marketing checkbox and an employee sign-off sheet rely on the exact same legal basis, and they read nothing alike. That pattern holds across every use case below. The requirement stays fixed, specific and informed permission, while the format bends to fit whatever’s actually being collected.
| Use Case | Trigger | Typical Consent Format |
|---|---|---|
| Marketing emails | Newsletter or promotional signup | Single unticked checkbox |
| Website cookies | Non-essential tracking or analytics | Layered banner with reject option |
| Employee data | Optional processing beyond the employment contract | Signed form, reviewed for imbalance |
| Photography and media | Publishing identifiable images | Written release naming the specific use |
Marketing and Newsletter Consent

Image source: cookielawinfo.com
Marketing without consent shows up again and again in enforcement data. France’s CNIL flagged it as one of the top issues in its review of 2024 corrective actions.
A compliant newsletter checkbox names the actual sender and states how often emails will land in the inbox. It also needs to sit unticked by default, always.
- “Send me [Company]’s weekly product newsletter” instead of “Keep me updated”
- A visible unsubscribe link in every email that follows
- No pre-selected box, ever
Real subscription form examples show how brands separate the newsletter checkbox from account creation entirely.
Cookie and Website Consent

Image source: wpamelia.com
A compliant cookie form treats strictly necessary cookies as needing no consent at all, then asks separately for analytics cookies, and separately again for marketing and advertising cookies.
A first-layer banner that gives “Accept” and “Reject” equal visual weight clears the unambiguous bar. Bury “Reject” inside a settings menu instead, and it doesn’t matter how compliant the rest of the banner looks. That clears nothing.
Employee and HR Consent

Consent rarely works as a lawful basis inside an employment relationship. The power imbalance between employer and employee makes freely given hard to prove, so most HR processing relies on contract necessity or legal obligation instead.
It still applies to a narrow set of optional activities though: appearing in a company newsletter photo, joining a wellness program that collects health data, or taking part in an internal survey that goes beyond required reporting.
Photography and Media Consent

A photo release needs to name the specific use, a website gallery, a printed brochure, a social media post, rather than asking for blanket permission. “Marketing purposes” fails the specificity test the same way a bundled checkbox does.
A solid release spells out the description of each intended use, how long the image will actually be used, and who to contact if someone wants to withdraw consent later. Nothing gets processed beyond what the release names.
GDPR Consent Forms for Special Category Data and Minors
Health data and children’s data don’t get to ride on the standard four conditions alone. Article 9(2)(a) raises the bar to explicit consent for health, biometric, and similarly sensitive categories, and Article 8 layers age thresholds on top of that whenever a child’s data is involved.
Explicit Consent for Special Category Data
Explicit consent goes further than the standard version. It requires a written statement, or a clear digital action tied specifically to the sensitive category, not a general acceptance buried somewhere in a longer form.
Consent has to be explicit when it covers health data, including diagnoses and treatment history, biometric identifiers used for identification such as facial recognition, genetic data, or anything revealing racial or ethnic origin, religious belief, or sexual orientation.
Facial recognition is a good example of what happens when this gets ignored. The Dutch DPA fined Clearview AI 30.5 million euros in 2024 for processing facial recognition data, a special category under Article 9, without a valid lawful basis.
Parental Consent and Age Verification
| Age Threshold | Countries | Basis |
|---|---|---|
| 16 (default) | Germany, Netherlands, Hungary, Lithuania, Luxembourg, Slovakia | Article 8, no national reduction |
| 14 | Austria | Article 8, national law lowers the threshold |
| 13 (minimum allowed) | Czech Republic, Denmark, Ireland, Latvia, Poland, Spain, Sweden, UK | Article 8, lowest threshold permitted |
Below the applicable threshold, the child cannot give their own consent. A parent or legal guardian has to give or authorize it instead, and the controller has to make reasonable efforts to verify the adult actually holds parental responsibility, usually through an email sent to a parent’s address, a small payment check tied to an adult’s card, or by gating the age question before any data gets collected rather than after.
How to Write GDPR Consent Form Wording
Legal accuracy and plain language don’t always want to sit in the same sentence, but GDPR wording has to pull off both at once, naming the controller, the specific purpose, and the data involved, in language a non-lawyer actually understands.
Here’s roughly how that plays out step by step:
- Identify the single purpose the checkbox covers
- Draft a plain-language statement naming the controller and that purpose
- Separate every additional purpose into its own unticked checkbox
- Add a one-line withdrawal instruction directly beneath the checkbox
- Have legal review the wording before it goes live
| Weak Wording | Stronger Wording |
|---|---|
| “We may use your data to improve our services” | “We will send you our weekly newsletter by email” |
| “By continuing, you agree to our terms” | “Check this box to receive marketing emails from [Company]” |
| “Accept all cookies and policies” | Separate “Allow analytics cookies” and “Allow marketing cookies” boxes |
Sound form design keeps every purpose checkbox visually separate instead of stacked into one dense paragraph of legal text.
Wording and layout work together here. Neither one fixes the other’s mistakes on its own.
Common Mistakes That Invalidate a GDPR Consent Form
Regulators haven’t been shy about fining organizations for the same handful of mistakes, over and over.
Pre-ticked boxes are the classic one. The CJEU ruled them out entirely in the Planet49 case, since only active behavior by the user counts as consent, and a box that’s ticked by default just doesn’t clear that bar no matter what else is on the page. Bundled purposes cause almost as much trouble: a single checkbox trying to cover marketing, data sharing, and profiling at once fails the specificity test on its own, regardless of how clear the surrounding wording is.
Vague purpose statements are sneakier about it. Phrases like “enhance user experience” sound fine until someone asks what they actually tell the person agreeing to them, which is nothing. Consent tied to access breaks the freely given requirement outright, making a service conditional on agreeing to processing that has nothing to do with delivering that service. And a missing withdrawal path, forcing someone to hunt for how to opt out later, tends to show up right alongside the rest in enforcement actions.
A few numbers put the scale of this in perspective:
- Cumulative GDPR fines since 2018 have passed 7.1 billion euros, with 1.2 billion euros issued in 2025 alone (DLA Piper GDPR Fines and Data Breach Survey, 2026)
- France’s CNIL issued 83 sanctions worth roughly 486.8 million euros in 2025, including 325 million against Google and 150 million against SHEIN over cookie consent practices (CNIL, 2025)
- A 2024 study from Karlsruhe Institute of Technology and IT University of Copenhagen found 72% of websites use at least one dark pattern in their cookie banners
- The same study found 45% of banners preselect consent to all cookies by default, the exact practice the CJEU rejected in Planet49
None of these mistakes require bad intentions. Most come from reusing an old template, or copying a competitor’s banner without ever checking whether it actually passed muster.
When a GDPR Consent Form Does Not Apply
Sometimes the honest answer is that consent was never the right tool for the job, and using it anyway just adds paperwork without adding any real protection. Article 6 gives controllers other options, contract necessity, legal obligation, vital interests, public task, legitimate interest, and plenty of processing fits one of those better than it fits consent.
| Alternative Basis | Article | Fits Best When |
|---|---|---|
| Contract necessity | Article 6(1)(b) | Processing is required to deliver the service itself |
| Legal obligation | Article 6(1)(c) | A law requires the record, such as tax or payroll data |
| Legitimate interest | Article 6(1)(f) | Internal business processing with a documented balancing test |
Legitimate interest often fits internal business processing better than consent does, since it doesn’t depend on the person’s mood on signup day. It still needs its own paperwork though. A Legitimate Interest Assessment has to weigh the business purpose against the person’s rights before the processing even starts, and the European Data Protection Board tightened that standard in Guidelines 01/2024, published October 8, 2024, raising the bar for what counts as a genuine legitimate interest.
Employer-employee consent is treated as weak by default. The imbalance in that relationship makes it hard to argue an employee could refuse without consequence, so consent rarely survives the freely given test. The Hellenic Data Protection Authority fined PricewaterhouseCoopers Business Solutions 150,000 euros in 2019 for asking employees to consent to processing that should have run on contract necessity and legitimate interest instead (Hellenic DPA, 2019).
Public authorities face their own exclusion. A public body carrying out its official task can’t rely on consent for that task, since refusing a public service is rarely a real option for the person facing it.
Consent isn’t the default. It’s the basis you reach for only once the other five don’t fit.
How Consent Proof Is Recorded and Withdrawn
A database flag that just says “consent = true” proves nothing on its own, and regulators know it. What actually holds up is a log of the exact circumstances around the moment someone said yes, not just that they agreed, but when, how, and to what.
That means capturing the exact date and time consent was given, the IP address tied to that specific session (kept alongside the record, not stored as a standalone identifier), which version of the checkbox and its wording was live at that moment, and the specific sentence the person actually agreed to, rather than whatever the privacy policy happens to say today. This is what Recital 42’s burden of proof looks like in practice.
Article 7(3) requires withdrawal to be exactly as easy as giving consent was. The European Data Protection Board’s Guidelines 05/2020 on consent makes this concrete: consent collected through one click has to be withdrawable through one click, not a phone call or a buried account setting.
In practice that’s an unsubscribe link sitting in every marketing email, a toggle inside account settings, or a direct request routed to a named contact, whichever matches how the original consent was collected.
The consent record itself needs a retention period too. Most organizations keep it for as long as the underlying processing runs, plus whatever window their national law allows for a legal claim to be raised.
Consent Management Platforms Compared to Templates
A spreadsheet and a checkbox can only get an organization so far. At some point the number of forms, purposes, and jurisdictions outgrows what one person can track by hand, and that’s usually when a platform enters the conversation instead of a template.
The global consent management market was valued at 1.0 billion US dollars in 2025 and is projected to reach 2.8 billion by 2033 (Grand View Research, 2026). That growth isn’t random. More jurisdictions now require documented, withdrawable consent, not just a checkbox somewhere on a page.
| Platform | Primary Fit | Starting Point |
|---|---|---|
| OneTrust | Large enterprise privacy programs | 10,000 dollar annual minimum (Enzuzo, 2026) |
| Cookiebot | Small to mid-sized sites, automated scanning | Free tier, paid plans from roughly 30 euros a month |
| Usercentrics | Mid-market to enterprise, multiple jurisdictions | Custom pricing, scales with domain count |
| Termly | Small business, single-site compliance | Free tier, paid plans for added features |
| iubenda | Small business, simple EU legal documents | Affordable flat pricing, fewer integrations |
Usercentrics, which owns Cookiebot, now serves over 2.3 million websites combined, making it the most widely deployed option in the small to mid-market segment (consent management platform market analysis, 2026).
Template vs Platform: Which Fits Your Case
A free template is enough for one site with a handful of consent purposes, assuming someone’s willing to update it by hand when rules shift. A platform starts earning its cost once forms multiply across domains, purposes, or jurisdictions faster than one person can realistically track.
Where the template holds up
- No monthly cost
- Full control over the exact wording
- Fast to get a single form live
Where it runs out of road
- Every rule change means a manual update
- No automatic consent logging once there’s more than one form to track
- Gets unmanageable past a handful of purposes or domains
What a platform adds
- Automatic consent logging with timestamps built in
- One place to update wording across every site or purpose
- Withdrawal handling that’s already built, not bolted on afterward
What it costs
- A recurring bill, sometimes with a steep enterprise minimum
- Setup and configuration work upfront
- One more vendor sitting inside the compliance stack
GDPR Consent Form Examples

Image source: mashable.com

Image source: spotify.com

Image source: monzo.com

Image source: goflink.com

Image source: dice.fm

Image source: ovomcare.com

Image source: volkswagen-group.com

Image source: stellantis.com

Image source: mercedes-benz.com

Image source: allianz.com

Image source: bmwgroup.com

Image source: telekom.com

Image source: eon.com
FAQ on GDPR Consent Forms
Is a GDPR consent form the same as a privacy notice?
No. A privacy notice discloses how data will be used; a consent form requires a specific, affirmative action from the data subject.
Publishing a policy satisfies transparency. Only a checkbox, signature, or click satisfies Article 7’s proof requirement for consent.
What counts as an affirmative action for consent purposes?
Ticking an unticked box, clicking “I agree,” or choosing a specific setting all count. Recital 32 rules out silence, scrolling, or pre-ticked boxes as consent.
The action has to be deliberate, and separate from any other step on the page.
What free tools can generate a GDPR consent form?
Termly and CookieYes both offer free tiers that generate a compliant cookie consent banner for a single site. Free plans cover basic wording and category toggles.
Multi-domain or multi-jurisdiction operations usually outgrow them and need a paid consent management platform.
How long should GDPR consent records be kept?
GDPR sets no fixed number, tying retention to how long the processing itself continues.
In practice, most organizations align consent-log retention with national civil limitation periods, commonly three to six years across EU member states.
{
"@context": "https://schema.org",
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Is a GDPR consent form the same as a privacy notice?",
"acceptedAnswer": {
"@type": "Answer",
"text": "No. A privacy notice discloses how data will be used; a consent form requires a specific, affirmative action from the data subject. Publishing a policy satisfies transparency. Only a checkbox, signature, or click satisfies Article 7's proof requirement for consent."
}
},
{
"@type": "Question",
"name": "What counts as an affirmative action for consent purposes?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Ticking an unticked box, clicking \"I agree,\" or choosing a specific setting all count. Recital 32 rules out silence, scrolling, or pre-ticked boxes as consent. The action must be deliberate and separate from any other step on the page."
}
},
{
"@type": "Question",
"name": "What free tools can generate a GDPR consent form?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Termly and CookieYes both offer free tiers that generate a compliant cookie consent banner for a single site. Free plans cover basic wording and category toggles. Multi-domain or multi-jurisdiction operations usually outgrow them and need a paid consent management platform."
}
},
{
"@type": "Question",
"name": "How long should GDPR consent records be kept?",
"acceptedAnswer": {
"@type": "Answer",
"text": "GDPR sets no fixed number, tying retention to how long the processing itself continues. In practice, most organizations align consent-log retention with national civil limitation periods, commonly three to six years across EU member states."
}
}
]
}
What Should You Fix First in GDPR Consent Form Examples?
If a defective checkbox sits at the center of a form, nothing built around it matters much: not the wording, not the retention period, not which platform runs the backend. Fix that piece first, single-purpose and unticked by default. After that, a one-click withdrawal path and timestamped proof of exactly what was shown to the person carry most of the remaining weight.
Eighty-three sanctions from France’s CNIL in 2025 look substantial on their own, until they’re set against dark patterns present on 72 percent of sites (Karlsruhe Institute of Technology and IT University of Copenhagen, 2024). Enforcement volume and how widespread the problem actually is are not close to the same scale.
Once the consent mechanism holds up, the next audit point is how secure that WordPress form actually is, since that determines whether the data behind the checkbox stays put.


