# CJEU, judgment of 11 November 2020, C-61/19, Orange România

Requirements for a pre-formulated declaration of consent in the online and contractual context; distinction from other matters of the contract, burden of proof on the controller.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/rechtsprechung/1.4.25-eugh-orange-romania
> Sprache: en



## 1 Overview [#1-overview]

Orange România, a Romanian mobile telephony provider, required its customers, when concluding a contract, to agree to the collection and storage of copies of their identity documents. The declaration of agreement was placed in a pre-formulated contract form alongside other clauses; in some instances the staff themselves ticked the corresponding boxes. The Romanian data protection supervisory authority imposed a fine; the dispute reached the Court of Justice by way of a reference for a preliminary ruling.

## 2 Headnotes [#2-headnotes]

Consent to the processing of personal data is not valid unless it is based on an active, informed and freely given indication of the data subject's wishes. Pre-ticked boxes, silence or inactivity do not suffice (paras. 36 et seq.).

A declaration of consent that forms part of a pre-formulated contract and is combined with further contractual terms must be clear, precise and distinguishable from the other matters of the contract. The data subject must be able to discern that they are expressly agreeing to the processing and what the scope of that agreement is (paras. 38 et seq.).

The controller bears the burden of proving that the data subject has consented. Contractual clauses which presuppose such consent are not sufficient on their own where it is not apparent that the data subject made an active choice (para. 52).

## 3 Significance [#3-significance]

The decision gives concrete shape to the validity requirements of Article 4(11) and Article 7 GDPR in the context of pre-formulated contracts and standard terms and conditions. It draws a clear line between contractual declarations of agreement and consent within the meaning of data protection law, and it is of practical significance for every business model that collects consent in standard-form contracts. The decision forms part of a line of case law that began with [Planet49](/docs/dsgvo-hub/rechtsprechung/1.4.10-eugh-planet49) and was continued in [Meta Platforms/Bundeskartellamt](/docs/dsgvo-hub/rechtsprechung/1.4.16-eugh-meta-bundeskartellamt).

<Cards>
  <Card title="Consent" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.1-einwilligung" description="Article 6(1)(a) GDPR." />

  <Card title="CJEU Planet49" href="/docs/dsgvo-hub/rechtsprechung/1.4.10-eugh-planet49" description="Active consent in the online context." />

  <Card title="CJEU Meta/Bundeskartellamt" href="/docs/dsgvo-hub/rechtsprechung/1.4.16-eugh-meta-bundeskartellamt" description="Consent in the case of market power." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.