# CJEU, Judgment of 1 October 2019, C-673/17, Planet49

Requirements for valid consent in the online context: active conduct, no pre-ticked boxes, clear information about cookies.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.10-eugh-planet49
> Sprache: en



## 1 Overview [#1-overview]

In the Planet49 case, the CJEU held that valid consent to the setting of cookies and comparable technologies presupposes active conduct. A pre-ticked box which the user would have to deselect in order to refuse consent is not sufficient.

Reference: [CJEU, judgment of 1 October 2019, C-673/17, Planet49](https://curia.europa.eu/juris/liste.jsf?num=C-673/17\&language=de)

## 2 Requirements for consent [#2-requirements-for-consent]

The Court interprets consent within the meaning of Article 2(f) and Article 5(3) of ePrivacy Directive 2002/58/EC read in conjunction with Article 2(h) of Data Protection Directive 95/46/EC. In substance, the requirements are largely identical to those laid down in Article 4(11) and Article 7 GDPR:

* active confirmation by the data subject,
* reference to the specific processing operation,
* information about the duration of the operation of the cookies and about any recipients.

## 3 Significance for practice [#3-significance-for-practice]

The decision has fundamentally changed the use of cookies in Germany and in Europe. The requirements initially implemented in Germany in the German Telecommunications Telemedia Data Protection Act (TTDSG), renamed the German Telecommunications Digital Services Data Protection Act (TDDDG), correspond to the Planet49 case law. § 25 TDDDG requires consent in principle for access to terminal equipment and for the setting of cookies that are not technically necessary.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.