PrivacyCache← All articles
GDPR

Consent or Pay: Are 'Pay-or-Okay' Cookie Walls Legal in 2026?

6 min read
Professional choosing between a payment card and a two-option consent screen on a laptop in a café

You have seen the banner. "Accept all cookies to continue — or subscribe for €X/month to browse without tracking." It looks like a neat solution to the consent problem: give visitors a genuine choice, and monetise the ones who refuse tracking. Publishers across Europe have adopted it, and plenty of smaller sites are tempted to copy it.

The question is whether it is actually legal. Under GDPR, consent has to be freely given — and the moment the alternative to "yes" is opening your wallet, that freedom is exactly what regulators start to question. Here is where consent or pay (also called "pay-or-okay") stands in 2026.

What a Consent-or-Pay Model Is

A consent-or-pay wall presents visitors with two options and no third door:

  1. Consent to tracking (analytics, advertising, profiling) and use the site for free, or
  2. Pay a subscription fee to use the site without that tracking.

The logic is that the user has a real choice, so any consent given in option 1 must be valid. The counter-argument is that a choice between "give up your data" and "pay money" is not really free at all — it is a paywall wearing a consent banner.

The Legal Heart of the Problem: "Freely Given"

Article 4(11) of the GDPR defines consent as "freely given, specific, informed and unambiguous." Recital 42 adds that consent is not free if the person has "no genuine or free choice" or cannot refuse without detriment.

That word — detriment — is the whole debate. If refusing tracking costs you money, is that a detriment? If it is, the consent of everyone who clicked "accept" to avoid paying may be invalid, which would make the tracking unlawful. Consent-or-pay lives or dies on how that question is answered.

What the EDPB Actually Said

In 2024 the European Data Protection Board issued Opinion 08/2024 on consent-or-pay models deployed by large online platforms. It stopped short of banning them, but it set a demanding bar. The key points:

The direction of travel is clear: a binary "pay or be tracked" wall, with no gentler middle option, is on very thin ice.

Does This Apply to Your Site?

The EDPB opinion is explicitly about large online platforms, so a small business is not its direct target. But do not read that as a green light. The opinion interprets the underlying "freely given" requirement, and that requirement applies to everyone. National data protection authorities and courts are applying the same reasoning well beyond the largest players.

For most ordinary websites, the practical takeaway is simpler still: you probably do not need a consent-or-pay wall at all. These models exist to monetise refusal at large ad-funded publishers. If you are a SaaS company, a services business, or an e-commerce store, a clean consent banner that genuinely lets people reject non-essential cookies is both cheaper to run and far easier to defend.

The Traps Even a Well-Meaning Wall Falls Into

Organisations that do adopt consent-or-pay routinely undermine themselves in ways that have nothing to do with the fee:

That last two points share a root cause: what your banner promises and what your site actually does on load are two different things, and only one of them is visible to you.

Check what your site really does before and after the choice. Our free Website Privacy Scanner loads your pages like a real browser and flags every tracker that fires — including those running before consent, the exact failure that makes any consent model (paid or free) unlawful. It is the fastest way to confirm your banner and your reality match. A detailed report with a step-by-step fix guide is available for a small one-off fee.

The Safer Path for Most Businesses

If you are not a large ad-funded platform, the defensible approach in 2026 is straightforward:

  1. Offer a real reject. Accept and reject should be equally prominent and equally easy — same number of clicks, same visual weight.
  2. Block non-essential trackers until consent. Nothing but strictly necessary cookies should fire before the visitor chooses. Verify it, do not assume it.
  3. Honour rejection completely. A "no" must actually stop the trackers, for everyone, every time.
  4. Disclose what you use. Your cookie and privacy policies must name the trackers and their purposes. Our Cookie Policy Generator can help you produce one that matches what actually runs.
  5. Re-scan regularly. Trackers and tags drift back in over time; a periodic check keeps your banner honest.

The Bottom Line

Are consent-or-pay cookie walls legal in 2026? For large platforms, only under tight conditions — and generally only when a genuine, non-paid alternative exists alongside them. For everyone else, they are usually a solution to a problem you do not have, and they add legal risk rather than removing it.

Whatever model you choose, its legality depends on one unglamorous fact: whether tracking actually waits for consent. Scan your site to see what fires and when, then work through our cookie banner self-audit to close the gaps. To see how regulators are treating consent failures in practice, browse our enforcement monitor.

Stay ahead of privacy regulations

Get compliance insights delivered to your inbox — new regulations, enforcement actions, and practical tips.

We respect your privacy. Privacy Policy

Related articles

Contract files, encrypted drive, and cable crossing a relief map between Europe and North America
GDPR7 min read

International Data Transfers Under GDPR: The 2026 Guide to DPF, SCCs, and TIAs

How EU data transfers really work in 2026: the Data Privacy Framework, SCCs, transfer impact assessments, and where the real GDPR risk sits.

Analytics dashboard, EU data map, and consent gate for GDPR-compliant tracking
GDPR6 min read

Google Analytics and GDPR in 2026: Is GA4 Legal in the EU?

Is Google Analytics 4 legal under GDPR in 2026? Where GA4 stands after the EU-US Data Privacy Framework, what still creates risk, and how to check.

Tracker data streams leaving a website before cookie consent is given
GDPR6 min read

Pre-Consent Tracking: The Hidden Cookie Violation on Most Websites

Pre-consent tracking — trackers that fire before visitors accept cookies — is a common, serious GDPR violation. What it is and how to detect it.

Track real GDPR enforcement actions

Monitor fines from 30+ European data protection authorities. Understand what violations get penalized and benchmark your risk.

Browse Enforcement Actions