Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 4 Council drafts · 7 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Recital 45
Commission proposal
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 45
May Presidency compromise
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the data subject, including third party cookie providers.
Recital 45
June Presidency compromise · 10 June
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the information, including third party cookie providers.
Recital 45
June Presidency compromise · 18 June
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
Recital 45
September Presidency compromise
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
Recital 45 4 Council drafts
Recital 45
21 May 2026 · May Presidency compromise
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the data subject, including third party cookie providers.
Recital 45
10 June 2026 · June Presidency compromise · 10 June
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the information, including third party cookie providers.
Recital 45
18 June 2026 · June Presidency compromise · 18 June
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
Recital 45
3 September 2026 · September Presidency compromise
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Alternative wordingAmendment 23 IMCO draft opinion · Alex Agius Saliba (rapporteur)
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. In addition, gatekeepers designated under Regulation (EU) 2022/1925 should not be allowed to prompt data subjects more than once a year to give consent for the same processing purpose in respect of which they did not give consent or withdrew their consent.
Justification
This amendment is inspired by recital 37 of the Digital Markets Act.
Alternative wordingAmendment 182 · David Cormand on behalf of the Verts/ALE Group IMCO
(45) DataConsumerssubjects thatshould have refusedthe opportunity to refuse to have a requestcookie or similar device stored on their terminal equipment. This is particularly important where a user other than the original user have access to the terminal equipment and thereby to any data containing privacy-sensitive information stored on such equipment. Information and the right to refuse may be offered once for consenttheareuseoftenofconfrontedvariouswith a new requestdevices to givebeconsentinstalledeachontimethetheyuser'svisitterminal equipment during the same controller’sconnectiononlineandservicealsoagain.coveringThisany further use that may havebedetrimentalmadeeffectsoftothosethedevicesdataduringsubjectssubsequentwhich may consent just in order to avoid repeating requestsconnections. The controllermethodsshouldforthereforegivingbeinformation,obligedofferingtoarespect the data subject’s choicesright to refuse or requesting consent should be made as user-friendly as possible. Access to specific website content may still be made conditional on the well-informed acceptance of a requestcookie or similar device, if it is used for consentaforlegitimateatpurpose.leastWhen a certainuserperiodhas refused or withdrawn consent, electronic communications service providers and third parties may not seek the user’s consent again until one year has elapsed from the date of the user’s decision.
Alternative wordingAmendment 458 · Irena Joveva, Michael McNamara, Raquel García Hermida-Van Der Walle, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová, Fabienne Keller ITRE · LIBE
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. TheTo enable genuine freedom of choice, the controller should therefore be obliged to respect the data subject’s choices to refuse, withdraw, or receive relavent information to make informed decision regarding a request for consent for at least one year, prevening continuous requests, including via pop-up windows on online interface. Moreover, data subject’s freedom to express a certainrefusalperiodor withdrawal of consent must be as effortless and instantaneous as granting it. Therefore, web browsers and operating systems should enable user-friendly, straightforward and prominently displayed single-click button to refuse or withdraw consent directly alongside any option to accept. Furthermore, users should never be put in the situation of surrendering their data by providers of services denying them access to a service or any functionality of that service, unless it is strictly necessary for the functioning of that service. It is also necesarry to protect users from unsolicited invasive stealth tracking methods. Therefore, online choice architectures should be designed neutrally, and the processing of indentifiers beyond what is strictly to remember a privacy choice when consent is refused or withdrawn should not be permitted. Furthermore, in order to guarantee the validity of user intent, consent obtained through manipulative designs or dark patters that distors free choice should be considered legally invalid.
Alternative wordingAmendment 459 · Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(45) Data subjectsUsers that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects or users which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’susers’ choices to refuse a request for consent and not ask for atconsentleastagain where the user has already expressed their choice for the given purpose. For consistency purposes, this Regulation further specifies that the refusal of a certainrequestperiodfor consent should be as easy as consenting or withdrawing consent, as required under Article 7 of Regulation (EU) 2016/679. The requirements for consent were also strengthened in the case of accessing information already stored or storing information on the terminal equipment of a natural person. Both should be read in conjunction, as the intent is that an option to refuse consent in an easy and intelligible manner is to be provided with a prominently displayed single-click button, especially when there is a possibility to consent to all purposes with a single-click button in the case of Regulation (EU) 2016/679.
Alternative wordingAmendment 460 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. The single-click modality and the period referred to constitute an ergonomic ideal rather than a mandatory technological standard, their practical implementation being more complex and capable of varying according to context. Data subjects should be able to express and modulate their consent at several levels — terminal equipment, operating system, web browser, application or on a site-by-site basis — and to outsource its management to a consent and agency-enhancing service provider, a data intermediation service provided to data subjects or a personal data space. An automated indication should not preclude the expression of service-specific choices.
Justification
Privacy choices are contextual. A blanket signal imposed without granularity would conflict with the specificity requirement of consent under the Regulation itself. The amendment preserves the anti-fatigue objective while restoring the data subject's ability to modulate.
Alternative wordingAmendment 461 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choicesrefusalto refuse a request forof consent for ataleastreasonable period of time, taking into account the context of the processing, the means by which the data subject accessed the service, and technical feasibility. This obligation should not prevent a certainproviderperiodfrom requesting consent at a later stage, for example if the data subject requests to access the service, through a different device, browser, account or access method, nor should it lead to a disproportionate deterioration of the service or prevent the data subject from accessing the service under different conditions. The provider should also make available effective and easily accessible means for the data subject to withdraw or modify their choice at any time.
Alternative wordingAmendment 462 · Diana Iovanovici Şoşoacă ITRE · LIBE
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. In such cases, a validation or consent request could clarify situations that might add legal uncertainty.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 45
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the data subject, including third party cookie providers.
RemovedAdded
Both texts in full
European Commission proposal
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Council Presidency text · ST 9547/26
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the data subject, including third party cookie providers.
Recital 45
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the data subjectinformation, including third party cookie providers.
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the data subject, including third party cookie providers.
Council Presidency text · ST 10426/26
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the information, including third party cookie providers.
Recital 45
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controllerprovider that accesses or stores personal datainformation in the terminal equipment of theainformationsubscriber or user, including thirdsocalledpartythird-party cookie providers.
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any controller that accesses or stores personal data in the terminal equipment of the information, including third party cookie providers.
Council Presidency text · ST 10677/26
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
Recital 45
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
Council Presidency text · ST 12535/26
Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. This obligation is applicable to any provider that accesses or stores information in the terminal equipment of a subscriber or user, including socalled third-party cookie.
Recital 45
Wording reproduced in the amendment → Amendment 458 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. TheTo enable genuine freedom of choice, the controller should therefore be obliged to respect the data subject’s choices to refuse, withdraw, or receive relavent information to make informed decision regarding a request for consent for at least one year, prevening continuous requests, including via pop-up windows on online interface. Moreover, data subject’s freedom to express a certainrefusalperiodor withdrawal of consent must be as effortless and instantaneous as granting it. Therefore, web browsers and operating systems should enable user-friendly, straightforward and prominently displayed single-click button to refuse or withdraw consent directly alongside any option to accept. Furthermore, users should never be put in the situation of surrendering their data by providers of services denying them access to a service or any functionality of that service, unless it is strictly necessary for the functioning of that service. It is also necesarry to protect users from unsolicited invasive stealth tracking methods. Therefore, online choice architectures should be designed neutrally, and the processing of indentifiers beyond what is strictly to remember a privacy choice when consent is refused or withdrawn should not be permitted. Furthermore, in order to guarantee the validity of user intent, consent obtained through manipulative designs or dark patters that distors free choice should be considered legally invalid.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Amendment 458 · ITRE–LIBE amendments 401–526 to the draft report
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. To enable genuine freedom of choice, the controller should therefore be obliged to respect the data subject’s choices to refuse, withdraw, or receive relavent information to make informed decision regarding a request for consent for at least one year, prevening continuous requests, including via pop-up windows on online interface. Moreover, data subject’s freedom to express a refusal or withdrawal of consent must be as effortless and instantaneous as granting it. Therefore, web browsers and operating systems should enable user-friendly, straightforward and prominently displayed single-click button to refuse or withdraw consent directly alongside any option to accept. Furthermore, users should never be put in the situation of surrendering their data by providers of services denying them access to a service or any functionality of that service, unless it is strictly necessary for the functioning of that service. It is also necesarry to protect users from unsolicited invasive stealth tracking methods. Therefore, online choice architectures should be designed neutrally, and the processing of indentifiers beyond what is strictly to remember a privacy choice when consent is refused or withdrawn should not be permitted. Furthermore, in order to guarantee the validity of user intent, consent obtained through manipulative designs or dark patters that distors free choice should be considered legally invalid.
Wording reproduced in the amendment → Amendment 459 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
(45) Data subjectsUsers that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects or users which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’susers’ choices to refuse a request for consent and not ask for atconsentleastagain where the user has already expressed their choice for the given purpose. For consistency purposes, this Regulation further specifies that the refusal of a certainrequestperiodfor consent should be as easy as consenting or withdrawing consent, as required under Article 7 of Regulation (EU) 2016/679. The requirements for consent were also strengthened in the case of accessing information already stored or storing information on the terminal equipment of a natural person. Both should be read in conjunction, as the intent is that an option to refuse consent in an easy and intelligible manner is to be provided with a prominently displayed single-click button, especially when there is a possibility to consent to all purposes with a single-click button in the case of Regulation (EU) 2016/679.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Amendment 459 · ITRE–LIBE amendments 401–526 to the draft report
(45) Users that have refused a request for consent are often confronted with a new request to give consent each time they visit the same service again. This may have detrimental effects to the data subjects or users which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the users’ choices to refuse a request for consent and not ask for consent again where the user has already expressed their choice for the given purpose. For consistency purposes, this Regulation further specifies that the refusal of a request for consent should be as easy as consenting or withdrawing consent, as required under Article 7 of Regulation (EU) 2016/679. The requirements for consent were also strengthened in the case of accessing information already stored or storing information on the terminal equipment of a natural person. Both should be read in conjunction, as the intent is that an option to refuse consent in an easy and intelligible manner is to be provided with a prominently displayed single-click button, especially when there is a possibility to consent to all purposes with a single-click button in the case of Regulation (EU) 2016/679.
Wording reproduced in the amendment → Amendment 460 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. The single-click modality and the period referred to constitute an ergonomic ideal rather than a mandatory technological standard, their practical implementation being more complex and capable of varying according to context. Data subjects should be able to express and modulate their consent at several levels — terminal equipment, operating system, web browser, application or on a site-by-site basis — and to outsource its management to a consent and agency-enhancing service provider, a data intermediation service provided to data subjects or a personal data space. An automated indication should not preclude the expression of service-specific choices.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Amendment 460 · ITRE–LIBE amendments 401–526 to the draft report
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. The single-click modality and the period referred to constitute an ergonomic ideal rather than a mandatory technological standard, their practical implementation being more complex and capable of varying according to context. Data subjects should be able to express and modulate their consent at several levels — terminal equipment, operating system, web browser, application or on a site-by-site basis — and to outsource its management to a consent and agency-enhancing service provider, a data intermediation service provided to data subjects or a personal data space. An automated indication should not preclude the expression of service-specific choices.
Wording reproduced in the amendment → Amendment 461 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choicesrefusalto refuse a request forof consent for ataleastreasonable period of time, taking into account the context of the processing, the means by which the data subject accessed the service, and technical feasibility. This obligation should not prevent a certainproviderperiodfrom requesting consent at a later stage, for example if the data subject requests to access the service, through a different device, browser, account or access method, nor should it lead to a disproportionate deterioration of the service or prevent the data subject from accessing the service under different conditions. The provider should also make available effective and easily accessible means for the data subject to withdraw or modify their choice at any time.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Amendment 461 · ITRE–LIBE amendments 401–526 to the draft report
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s refusal of consent for a reasonable period of time, taking into account the context of the processing, the means by which the data subject accessed the service, and technical feasibility. This obligation should not prevent a provider from requesting consent at a later stage, for example if the data subject requests to access the service, through a different device, browser, account or access method, nor should it lead to a disproportionate deterioration of the service or prevent the data subject from accessing the service under different conditions. The provider should also make available effective and easily accessible means for the data subject to withdraw or modify their choice at any time.
Wording reproduced in the amendment → Amendment 462 · ITRE–LIBE amendments 401–526 to the draft report
Changes in context
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. In such cases, a validation or consent request could clarify situations that might add legal uncertainty.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Amendment 462 · ITRE–LIBE amendments 401–526 to the draft report
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. In such cases, a validation or consent request could clarify situations that might add legal uncertainty.
Wording reproduced in the amendment → Amendment 182 · IMCO amendments 125–328 to the draft opinion
Changes in context
(45) DataConsumerssubjects thatshould have refusedthe opportunity to refuse to have a requestcookie or similar device stored on their terminal equipment. This is particularly important where a user other than the original user have access to the terminal equipment and thereby to any data containing privacy-sensitive information stored on such equipment. Information and the right to refuse may be offered once for consenttheareuseoftenofconfrontedvariouswith a new requestdevices to givebeconsentinstalledeachontimethetheyuser'svisitterminal equipment during the same controller’sconnectiononlineandservicealsoagain.coveringThisany further use that may havebedetrimentalmadeeffectsoftothosethedevicesdataduringsubjectssubsequentwhich may consent just in order to avoid repeating requestsconnections. The controllermethodsshouldforthereforegivingbeinformation,obligedofferingtoarespect the data subject’s choicesright to refuse or requesting consent should be made as user-friendly as possible. Access to specific website content may still be made conditional on the well-informed acceptance of a requestcookie or similar device, if it is used for consentaforlegitimateatpurpose.leastWhen a certainuserperiodhas refused or withdrawn consent, electronic communications service providers and third parties may not seek the user’s consent again until one year has elapsed from the date of the user’s decision.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
Amendment 182 · IMCO amendments 125–328 to the draft opinion
(45) Consumers should have the opportunity to refuse to have a cookie or similar device stored on their terminal equipment. This is particularly important where a user other than the original user have access to the terminal equipment and thereby to any data containing privacy-sensitive information stored on such equipment. Information and the right to refuse may be offered once for the use of various devices to be installed on the user's terminal equipment during the same connection and also covering any further use that may be made of those devices during subsequent connections. The methods for giving information, offering a right to refuse or requesting consent should be made as user-friendly as possible. Access to specific website content may still be made conditional on the well-informed acceptance of a cookie or similar device, if it is used for a legitimate purpose. When a user has refused or withdrawn consent, electronic communications service providers and third parties may not seek the user’s consent again until one year has elapsed from the date of the user’s decision.
Wording reproduced in the amendment → Amendment 23 · IMCO draft opinion · Alex Agius Saliba (rapporteur)
Changes in context
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. In addition, gatekeepers designated under Regulation (EU) 2022/1925 should not be allowed to prompt data subjects more than once a year to give consent for the same processing purpose in respect of which they did not give consent or withdrew their consent.
RemovedAdded
Both texts in full
Wording reproduced in the amendment
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period.
(45) Data subjects that have refused a request for consent are often confronted with a new request to give consent each time they visit the same controller’s online service again. This may have detrimental effects to the data subjects which may consent just in order to avoid repeating requests. The controller should therefore be obliged to respect the data subject’s choices to refuse a request for consent for at least a certain period. In addition, gatekeepers designated under Regulation (EU) 2022/1925 should not be allowed to prompt data subjects more than once a year to give consent for the same processing purpose in respect of which they did not give consent or withdrew their consent.