The Lower Saxony Data Protection Authority (LfD) ruled that the "Pay or Okay" model used by heise.de in 2021 violates GDPR because it does not provide specific consent for each purpose. The authority issued a reprimand, noting that tracking cookies were set before consent and that consent was not informed, specific, or freely given. The decision follows similar findings by the Austrian DSB and highlights concerns about disproportionate costs for users.
Why it matters: The ruling sets a precedent that "Pay or Okay" consent models on news sites breach GDPR consent requirements.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.