CookieDetox
Sanctions & Amendes 2026-08-09

Consent or Pay CNIL: Ultimate Decryption of GDPR Conditions

CD

Par Cellule Investigation CookieDetox

Expertise Juridique & Conformité

🔗
T

Key Takeaways

The Consent or Pay (CoP) model offers a choice between accepting advertising tracking for free access or paying a subscription without ads. In France, the CNIL strictly regulates it, requiring a genuine choice, an equivalent and non-discriminatory alternative, and a reasonable cost to be legal.

The Consent or Pay Model: Legal Context and Evolution

Genesis and Legal Framework (GDPR, ePrivacy)

The 'Consent or Pay' (CoP) model emerged from the confrontation between the economic imperatives of digital platforms and the growing demands for personal data protection. Its genesis is intrinsically linked to the advent of the General Data Protection Regulation (GDPR) in May 2018. The GDPR established free, specific, informed, and unambiguous consent as the cornerstone of data processing. Concurrently, the ePrivacy Directive ↗, often referred to as the 'cookie law,' already required consent for the placement and reading of non-essential trackers.

These legislative frameworks put traditional economic models, largely based on user data monetization via targeted advertising, under pressure. Content publishers faced a dilemma: how to finance their services while scrupulously respecting privacy rights? CoP emerged as a pragmatic response, offering a binary choice: accept advertising tracking (and thus data processing) in exchange for free access, or pay a subscription for an ad-free and tracking-free experience. This approach aimed to reconcile economic imperatives and legal requirements but quickly raised fundamental questions about the validity of the consent thus obtained.

The EDPB's Interpretation and Its Impact

The emergence of Consent or Pay quickly attracted the attention of the European Data Protection Board (EDPB), the body responsible for ensuring the consistent application of the GDPR. The EDPB published crucial guidelines on consent, directly impacting the legitimacy of CoP. Its position is clear: to be valid, consent must be 'free.' The central question is whether a choice between 'accepting tracking' and 'paying' can be considered truly free, especially if the paid alternative is the only option to refuse processing.

The EDPB emphasized that consent is not free if the user faces 'constraint' or 'diversion' in case of refusal (e.g., inability to access content). It insisted on the need to offer a 'genuine alternative' that does not penalize the user refusing data processing. Although the EDPB did not explicitly prohibit CoP, it set strict conditions, requiring the paid alternative to be 'reasonable' and that refusal of consent does not result in 'significant detriment.' This interpretation forced many stakeholders to review their practices, encouraging them to offer more balanced options and justify the proportionality of their subscription fees.

The CNIL's Granular Position

In France, the National Commission for Informatics and Liberties (CNIL) adopted a particularly detailed and often more restrictive approach than the general EDPB guidelines, refining the interpretation of Consent or Pay. The CNIL quickly emphasized the notion of 'real and equitable choice.' For the CNIL, a simple 'all or nothing' binary choice is insufficient if the paid alternative is disproportionate or if it does not allow for a genuine exercise of user rights.

The CNIL particularly insisted on the need for a 'non-paying' alternative or, failing that, a paid option whose cost is 'reasonable' and 'justified' in light of the service rendered and the data collected. It also reiterated the importance of the principle of granularity: the user must be able to consent specifically to each processing purpose, rather than giving global consent. Furthermore, the ease of withdrawing consent is a crucial point, requiring the withdrawal mechanism to be as simple as the initial consent mechanism. The CNIL's decisions have had a major impact on the practices of French publishers, pushing them to refine their consent banners and justify their prices, emphasizing that CoP, if poorly implemented, can be perceived as a circumvention of the GDPR.

Genuine Choice and Proportionality: Cornerstones of CoP

The implementation of 'Consent or Pay' (CoP) models has profoundly redefined the landscape of digital consent, placing two fundamental principles of the General Data Protection Regulation (GDPR) at the heart of discussions: genuine choice and proportionality. These concepts are not mere formalities; they constitute the pillars upon which the very legitimacy of these mechanisms rests. A thorough understanding of their application is essential for any entity wishing to operate in compliance, thereby avoiding legal pitfalls and potential sanctions.

Definition and Criteria of Genuine Choice (Art. 4(11) GDPR)

GDPR, in its Article 4(11), defines consent as 'any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.' In the context of a CoP model, the notion of 'free choice' is scrutinized with particular attention. A choice is genuine if it is free from any constraint, pressure, or undue influence. This means that the user must have a genuine alternative to consenting to the processing of their data, without suffering significant detriment in case of refusal. The central question is whether the paid option, offered in exchange for the absence of advertising tracking, constitutes a truly free and equitable alternative. If refusing to consent leads to a substantial degradation of access to the service or a prohibitive cost, then freedom of choice is compromised, potentially rendering the consent invalid. The European Data Protection Board (EDPB) has repeatedly emphasized that the balance of power between the user and the controller must be respected, and that an absence of genuine choice amounts to an absence of valid consent.

The Principle of Proportionality and the Paid Alternative

The principle of proportionality requires that data processing be adequate, relevant, and limited to what is necessary for the purposes for which they are processed. Applied to CoP models, this principle raises crucial questions about the nature and amount of the paid alternative. Should the cost of the ad-free subscription be proportional to the economic value of the data collected or to the actual cost of the service without the advertising model? Regulators, particularly the CNIL and the EDPB, have clearly indicated that the amount requested should not be excessive to the point of forcing the user to accept data processing by default. A disproportionate price could be interpreted as an attempt to circumvent the requirement of free consent. The proportionality analysis must consider several factors: the nature of the service, the volume and sensitivity of the data processed, the revenue generated by targeted advertising, and the average financial capacity of users. The objective is to ensure that the paid option does not become an artificial barrier to the exercise of fundamental rights of data subjects, but a fair and reasonable alternative.

Absence of Consent Diversion (Art. 7(4) GDPR ↗)

Article 7(4) of the GDPR stipulates that 'when assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.' This principle is fundamental to prevent 'bundling' or 'tying' of services, where consent is artificially linked to access to a service. In the CoP context, the question is whether the paid option, as an alternative to consent, does not create a form of subordination. If data processing for advertising purposes is not strictly necessary for the provision of the basic service (e.g., reading a news article), then requiring payment to refuse this processing could be perceived as a diversion of consent. The EDPB has emphasized that controllers cannot make access to a service conditional on consent for data processing that is not essential to that service. The challenge is to ensure that consent remains a voluntary act and not a forced exchange currency to access essential or widely used services. The legitimacy of a CoP model will therefore depend on its ability to offer genuine freedom of choice, without the paid alternative becoming a disguised constraint.

The CNIL's Granular Requirements for Consent or Pay

The 'Consent or Pay' model has established itself as a complex and controversial monetization strategy for many online content publishers. Faced with this proliferation, the National Commission for Informatics and Liberties (CNIL) has adopted a firm and detailed position, strictly regulating its application to ensure compliance with the fundamental principles of the General Data Protection Regulation (GDPR). Far from being a mere formality, the implementation of such a mechanism requires a thorough understanding and rigorous adherence to the directives of the French authority. Ignoring these requirements exposes organizations to significant legal and reputational risks. We will dissect the pillars of the CNIL's doctrine, revealing the expected granularity for any compliant deployment.

Summary of CNIL's Key Requirements for CoP

Scroll horizontally ↔
CNIL Requirement Detailed Description Relevant GDPR Article
Clear and Specific Information The user must be transparently informed about the purposes, collected data, partners, retention period, and rights, without "dark patterns." The cost of the paid option must be justified and proportionate. Art. 13 & 14
Equivalent and Non-Discriminatory Alternative A genuine choice must be offered. The paid option must not be the only alternative to consent. User experience must not be degraded for those who pay or refuse tracking. The price must be reasonable. Art. 7(4), Recital 42
No Deterioration of Experience The choice not to consent (and to pay) must not result in a significantly worse user experience (loading times, reduced functionalities, etc.). Principle of free consent
Proof of Consent and Revocability The data controller must be able to prove consent (date, time, policy version, choices). Withdrawal of consent must be as simple as granting it and effective immediately. Art. 7(1), 7(3)

Clear, Transparent, and Specific Information (Art. 13 & 14 GDPR)

The first cornerstone laid by the CNIL concerns the obligation of information. Before any decision is made by the user, they must be fully and precisely informed of the implications of their choice. This goes far beyond a simple mention. In accordance with Articles 13 and 14 of the GDPR, the information must be not only clear and transparent but also specific. This means the user must unambiguously understand:

  • The exact purposes of personal data processing (targeted advertising, audience measurement, etc.).
  • The categories of data collected and processed.
  • The identity of the data controllers and, where applicable, the data recipients.
  • The data retention period.
  • The existence and modalities for exercising their rights (access, rectification, erasure, objection, portability, restriction).
  • The consequences of each option (consenting to tracking or paying not to be tracked).

The CNIL insists on the absence of 'dark patterns' or ambiguous formulations that could mislead the user or push them towards a default choice. The cost of the paid option must be clearly displayed, justified, and proportionate, and the benefits of the free option (with consent) must not be exaggerated to the detriment of clarity regarding data processing.

The Equivalent and Non-Discriminatory Alternative

The core of the CNIL's position lies in the requirement for an 'equivalent and non-discriminatory' alternative to the consent-to-tracking option. It is imperative that the user has a genuine choice, not a false dichotomy. The paid option cannot be the only way to access content without being tracked. The free alternative, based on consent, must offer comparable access to the service or content. The notion of 'non-discriminatory' is crucial: a user who refuses tracking and opts for payment must not experience a degraded experience compared to one who consents. Similarly, the free option must not be deliberately made less attractive to force the user's hand. The CNIL carefully examines the proportionality of the price requested for the paid option. An excessive price could be interpreted as an attempt to coerce consent, rendering it not 'freely given' and thus invalid under the GDPR. The objective is to prevent payment from becoming a sine qua non condition for fully enjoying the service, thereby transforming consent into a forced transaction.

No Deterioration of User Experience

As an extension of the non-discriminatory alternative, the CNIL ensures that the user's choice not to consent to the processing of their data (and thus to pay) does not lead to a significant deterioration of their experience. This concretely means that access to the service or content must remain fluid and functional, without obvious technical or ergonomic impediments. For example, the paid option must not be associated with excessively long loading times, complex navigation, or reduced functionalities compared to the option with consent. The supervisory authority scrutinizes practices that could indirectly push the user towards the consent option by deliberately making the paid alternative less pleasant or less performant. User experience must be preserved in both scenarios, ensuring that the choice is made on the basis of clear information and not under the constraint of a degraded experience. This requirement reinforces the principle of free and informed consent, by ensuring that the user's decision is not influenced by artificially created technical or comfort considerations.

Proof of Consent and Its Revocability (Art. 7(3) GDPR)

Finally, the CNIL reminds data controllers of their obligation to be able to prove at any time that valid consent has been obtained. This proof must be robust and documented. It involves the precise recording of the user's action (click, selection), the date and time of consent, the version of the privacy policy or information notice presented at that moment, and the specific choices made. Article 7(3) of the GDPR is categorical: 'The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.' It is therefore imperative that the mechanism for withdrawing consent is as simple and accessible as that for granting it. This means that a user must be able to withdraw their consent without difficulty, without having to navigate complex menus or send tedious requests. A clear and visible link (for example, in the website footer or user account settings) must allow for this revocation. Withdrawal must be effective immediately and must not result in any penalty or deterioration of access to the service. The CNIL expects platforms to implement sophisticated Consent Management Systems (CMP) capable of tracking these actions and ensuring compliance with these fundamental requirements.

Technical Implementation and Demonstration of Compliance

The current digital era demands much more than mere superficial adherence to data protection regulations. Robust and demonstrable compliance relies on rigorous technical implementation and an unwavering ability to prove that compliance. This section explores the essential technical pillars for building and maintaining a strong compliance posture, focusing on the architecture of Consent Management Platforms (CMPs), the infallible management of consent proofs, and the crucial importance of regular audits and policy updates.

Architecture of a CoP-Compliant CMP

A Consent Management Platform (CMP) is not just a simple cookie banner; it is a robust technical architecture, a cornerstone of compliance. To be truly compliant with the principles of Consent or Pay (CoP) as defined by the GDPR and EDPB/CNIL guidelines ↗, and in accordance with frameworks like IAB's TCF, a CMP must integrate several functional layers. At its core, a front-end module (UI) offers a clear and intuitive user interface, allowing for granular expression of consent for different purposes and vendors. In the background, a business logic engine manages preferences, stores them securely, and orchestrates the activation or deactivation of tracking tags. Integration with existing systems (CRM, DMP, analytical tools) is crucial, often via APIs or tag managers. This architecture must be designed for resilience, scalability, and, above all, to ensure that user choices are respected at every interaction, across all digital touchpoints. The ability to adapt to jurisdictional specificities (e.g., CCPA, LGPD) is also a technical imperative.

Management of Consent Proofs (Logging and Traceability)

Compliance is not limited to collecting consent; it requires the ability to prove that collection. The management of consent proofs relies on a meticulous logging system and infallible traceability. Every user interaction with the CMP, every consent choice (acceptance, refusal, detailed preferences), must be recorded securely and unalterably. These records must include essential metadata: a pseudonymized user ID, the precise timestamp, the version of the privacy policy and CMP in effect at the time of consent, and the source of consent (e.g., page URL). These logs constitute the legal 'proof.' They must be stored in secure databases, with audit trail mechanisms to detect any modification attempts. Traceability implies the ability to quickly retrieve and present these proofs in case of an audit or a user request, thereby demonstrating due diligence and proactive compliance.

Example Data Structure for Consent Proof (JSON)

{
  "consentId": "uuid-v4-example-12345",
  "userIdPseudonymized": "user_hash_abc123def456",
  "timestamp": "2023-10-27T10:30:00Z",
  "consentStatus": "accepted",
  "consentType": "consent_or_pay",
  "versionCmp": "v2.1.0",
  "versionPrivacyPolicy": "v1.5",
  "sourceUrl": "https://www.example.com/article-premium",
  "geoIp": "FR",
  "purposes": {
    "analytics": true,
    "advertising_personalization": true,
    "functional": true
  },
  "vendors": [
    {"id": "vendorA", "name": "AnalyticsCorp", "consented": true},
    {"id": "vendorB", "name": "AdTechSolutions", "consented": true}
  ],
  "paymentOptionSelected": false,
  "paymentAmount": null
}

Regular Audits and Policy Updates

Compliance is a dynamic process, not a static state. Regular audits are essential to ensure that the technical implementation of the CMP remains aligned with legal requirements and best practices. These audits must cover the entire consent lifecycle: from banner display to choice persistence, including integration with third-party tools. This involves verifying the CMP configuration, the accuracy of consent records, the list of vendors and their purposes, as well as the consistency between the published privacy policy and the actual behavior of the platform. Updates to privacy and cookie policies are inevitable in the face of evolving regulations or business practices. The CMP must be designed to manage these versions transparently, informing users of significant changes and requesting new consent if necessary. A robust change management process, including rigorous testing and clear documentation, is essential to maintain an unwavering compliance posture.

Risks, Sanctions, and Mitigation Strategies for CoP

Managing the 'Consent or Pay' (CoP) model is not a mere technical formality; it constitutes a fundamental pillar of compliance with the General Data Protection Regulation (GDPR). Ignoring its requirements or misinterpreting its principles exposes organizations to considerable legal and financial risks. As experts, we will dissect potential threats, deconstruct persistent myths, and propose robust mitigation strategies to secure your practices.

Potential CNIL Sanctions (Art. 83 GDPR ↗)

The National Commission for Informatics and Liberties (CNIL), as a supervisory authority, possesses a formidable arsenal of sanctions, framed by Article 83 of the GDPR. A proven failure in the collection, management, or proof of consent can lead to colossal administrative fines, potentially reaching 20 million euros or 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher. Beyond the monetary aspect, the CNIL can issue compliance orders, temporary or definitive processing limitations, or even prohibitions. The reputational impact is also significant, as decisions are often made public. These are not abstract threats but concrete realities, as evidenced by the numerous sanctions already imposed for consent-related breaches.

Common Pitfalls and Misconceptions about CoP

The CoP landscape is littered with misunderstandings that can prove costly. Let's demystify some of the most common pitfalls:

  • "A simple banner is enough": False. A banner without granular options, without clear information on purposes and partners, or with "Accept All" buttons more prominent than "Refuse," is insufficient. Consent must be free, specific, informed, and unambiguous.
  • "Implicit consent is valid": Incorrect. For most processing (non-essential cookies, direct marketing), the GDPR requires explicit consent, meaning a positive action by the user. Continued browsing does not constitute valid consent.
  • "Consent can be stored indefinitely": No. Consent must be reversible, and its validity period must be proportionate to the purpose. A clear retention policy is imperative.
  • "CoP is a technical formality": This is a fundamental misjudgment. CoP is first and foremost a legal and ethical obligation, requiring an integrated legal, technical, and organizational approach.

Best Practices and Recommendations for Risk Mitigation

To successfully navigate this complex regulatory framework, a proactive and rigorous approach is essential:

  • Implement a robust CMP (Consent Management Platform): Opt for a certified solution that allows for granular management and timestamped proof of consent.
  • Clear and accessible information: Ensure users understand precisely what they are consenting to. Information must be concise, transparent, and presented in plain language.
  • Proof of consent: Keep an undeniable record of each consent collected: date, time, banner version, user's choice. This proof is your line of defense in case of an audit.
  • Regular audits: The digital landscape evolves. Periodically audit your CoP mechanisms to ensure they remain compliant with the latest CNIL guidelines and industry best practices.
  • DPO involvement: The Data Protection Officer (DPO) must be at the heart of this process, ensuring regulatory watch and internal expertise.
  • Exhaustive documentation: Every step, every decision, every configuration must be documented. Documentation is the cornerstone of your compliance.
§

Official Legal Sources & Authoritative Decisions

Primary statutory texts, official DPA rulings, and European court judgments referenced in this analysis.

  • EUR-Lex Article 83 GDPR — General conditions for imposing administrative fines (statutory ceiling up to €20M or 4% turnover)
    View primary text
Updated 2026-08-09
Share this article:

FAQ : Consent or Pay CNIL: Ultimate Decryption of G

What is a Consent or Pay (CoP) model and is it legal in France according to the CNIL?

The Consent or Pay (CoP) model offers a choice between accepting data processing for free access or paying a subscription without tracking. In France, the CNIL deems it legal under strict conditions, requiring a genuine choice, an equivalent and non-discriminatory alternative, as well as a reasonable and justified cost.

What is the difference between EDPB and CNIL requirements for CoP?

The EDPB requires a reasonable paid alternative without detriment in case of refusal. The CNIL is more restrictive, requiring a non-paying alternative or a paid option with a reasonable and justified cost, and insists on the granularity of consent.

How to ensure that the proposed free alternative is truly 'equivalent' and non-discriminatory?

To be equivalent and non-discriminatory, the free alternative must offer comparable access to the service, without degrading the user experience for those who pay or refuse tracking. The price of the paid option must be reasonable and not excessive.

Can a paywall be considered 'undue pressure' on user consent?

Yes, a paywall can be undue pressure if its cost is prohibitive or disproportionate, or if refusing consent degrades access to the service. The GDPR prohibits making access to a service conditional on consent for non-essential data processing.

What are the penalties for non-compliance of a Consent or Pay model with the GDPR?

In case of non-compliance of a CoP model with the GDPR, the CNIL can impose administrative fines of up to 20 million euros or 4% of the total worldwide annual turnover. Compliance orders, processing limitations, or even prohibitions may also be issued.

How to prove user consent in a Consent or Pay model to the CNIL?

The data controller must securely and unalterably record each user interaction with the CMP. These proofs include the pseudonymized ID, timestamp, privacy policy version, and consent source. Withdrawal must be as simple and traceable as granting consent.

Is Consent or Pay compatible with the ePrivacy Directive and Articles 6 and 7 of the GDPR?

CoP is compatible with the ePrivacy Directive and Articles 6 and 7 of the GDPR if consent is free, specific, informed, and unambiguous. A genuine and unconstrained choice must be offered, without making access to the service conditional on non-essential consent.

Do I need to conduct a DPIA (Data Protection Impact Assessment) for my CoP model?

The provided article does not explicitly mention the obligation to conduct a Data Protection Impact Assessment (DPIA) for a Consent or Pay model. However, it emphasizes the importance of regular audits and exhaustive documentation to demonstrate compliance.