Regulatory Watch  /  DE-NI  /  Enforcement
Low impactEnforcementDecided

German DPA declares heise.de "Pay or Okay" cookie banner illegal

The Lower Saxony Data Protection Authority (LfD) ruled that the "Pay or Okay" model used by heise.de in 2021 violates GDPR because it does not provide specific consent for each purpose. The authority issued a reprimand, noting that tracking cookies were set before consent and that consent was not informed, specific, or freely given. The decision follows similar findings by the Austrian DSB and highlights concerns about disproportionate costs for users.

Why it matters: The ruling sets a precedent that "Pay or Okay" consent models on news sites breach GDPR consent requirements.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
„Pay or Okay“ on tech news site heise.de illegal, decides German DPA
noyb · primary source · Jul 14, 2023
„Pay or Okay“ on tech news site heise.de illegal, decides German DPA
noyb · Jul 14, 2023
Details
JurisdictionDE-NI
RegulatorData Protection Authority of Lower Saxony (LfD)
LawGeneral Data Protection Regulation
StatusDecided
PublishedJuly 14, 2023
Effectivenot stated
Organisationsheise.de, noyb
Topicsconsent, transparency, cookies, data minimization, tracking, privacy
Datapersonal