Pre-checked checkboxes on a landing page form: smart tactic or legal mistake?
Published on 6 August 2026 · 7 min read
A checkbox reading "I want to receive news and offers by email," already ticked when the page loads, sitting right above the submit button: this reflex shows up in dozens of online forms, including French and European landing pages that are supposed to be compliant. The logic is simple and not entirely baseless — a visitor who has to untick a box to opt out signs up more often than one who has to tick it to opt in. The problem is that this practice is explicitly banned under European law the moment it involves consent, and it exposes the business to a risk wildly out of proportion with the extra leads it produces.
A real bias: the default effect
The intuition behind the pre-checked box has a name in behavioral psychology: the default effect, a form of status quo bias where the option preselected by a form or a system becomes, in practice, the majority choice — through inertia, implicit trust in the "recommended" option, or simply because most people don't re-read every field before submitting. A study by Eric Johnson, Steven Bellman and Gerald Lohse published in 2002 in Marketing Letters, "Defaults, Framing and Privacy: Why Opting In-Opting Out," measured this effect across two online experiments built around exactly this kind of contact and permission-marketing form: simply starting from a checked box instead of an unchecked one sharply shifted the share of participants agreeing to be contacted again, an effect that stacked on top of how the text around the box was framed. The bias isn't a marketer's myth — it's documented and measurable, which is precisely why European lawmakers explicitly neutralized it on consent questions.
What GDPR precisely forbids
Article 4(11) of the GDPR defines consent as a "freely given, specific, informed and unambiguous" indication of wishes, expressed "by a statement or by a clear affirmative action." A box that's already checked is, by construction, neither a statement nor an affirmative action from the person — it's the opposite, an action they'd have to take to withdraw from it. The Court of Justice of the European Union settled this unambiguously on 1 October 2019 in the Planet49 case (C-673/17): a pre-ticked box for installing cookies does not amount to valid consent under the ePrivacy Directive and the GDPR, since only an active behavior by the user can satisfy that requirement. France's CNIL applies the same reading, whether for non-exempt cookies, newsletter signups, or sharing data with commercial partners — see our article on GDPR compliance for a landing page form and on the cookie banner, where the same rule — refusing must be as easy as accepting — applies.
Not every pre-checked box is consent
The most common confusion is treating every preselection as suspect. It isn't: GDPR's ban specifically targets boxes tied to personal data processing or marketing communication — newsletter, sharing with third parties, non-exempt audience-measurement cookies. Preselecting the annual plan on a pricing table, a default callback slot on a quote request form, or a quantity of "1" on a product field involves no personal data and constitutes no consent in the legal sense: these are simple default values on a form field or a commercial offer, freely changeable by the visitor. The default effect still fully applies there — it's one of the reasons why preselecting the annual subscription on a pricing page increases how often it's chosen, without raising any legal issue whatsoever.
What replaces the pre-checked box on a landing page
Starting from an unchecked box mechanically lowers the raw opt-in rate — that's exactly the effect the law is designed to correct. The right move isn't to work around the rule with greyed-out boxes, boxes pre-checked then hidden via CSS, or other dark patterns that risk a CNIL sanction on top of eroding trust; it's to compensate with microcopy that gives a real reason to check the box — a stated sending frequency, a concrete content example, an explicit promise not to resell the address — rather than a generic label. Clearly separating the consent checkbox from the form's required fields also helps: the visitor should immediately understand that checking it is optional and doesn't block submission. For the signup itself, pairing an unchecked box with double opt-in by email secures compliance and mechanically improves deliverability by filtering out invalid or unengaged addresses.
| Use case | Pre-checked allowed? | Why |
|---|---|---|
| Newsletter signup / marketing offers | No | Consent under GDPR art. 4(11) and 7: affirmative action required |
| Sharing data with third-party partners | No | Same requirement for explicit, specific consent |
| Non-exempt audience-measurement cookies | No | ePrivacy Directive + CJEU Planet49 case law (2019) |
| Annual plan preselected on a pricing table | Yes | A commercial choice, no personal data or consent involved |
| Default callback slot or contact channel on a quote form | Yes | A simple default field value, freely editable |
In the end, the math heavily favors compliance: a GDPR fine, a CNIL formal notice, or even a simple loss of trust after a complaint all cost far more than the handful of opt-in points gained by gaming a checkbox. LanderKit's Newsletter Creator template starts precisely from an unchecked box by default, with microcopy that earns the signup instead of relying on the bias — its live demo shows the exact structure to reuse. At €89 per template or €229 for the full 10-template pack, starting from a compliant base costs far less than a corrective GDPR audit down the line.
FAQ
Frequently asked questions
Is a pre-checked newsletter box illegal in the EU?
Yes. GDPR requires a clear, affirmative action for any marketing consent, and the CJEU confirmed in the Planet49 case (2019) that a pre-checked box doesn't meet that bar. France's CNIL applies the same rule to newsletter and data-sharing forms.
Does preselecting the annual plan on a pricing page raise the same issue?
No. That preselection involves no personal data or legal consent: it's a default value on a commercial choice, freely changeable by the visitor, and fully allowed.
Does an unchecked-by-default box really lower signup rates?
Generally yes — that's the default effect documented by marketing research. The compliant fix isn't re-checking the box, but tightening the microcopy around it to give a real reason to check it voluntarily.
Is double opt-in required on top of the unchecked box?
It isn't legally mandatory for a simple newsletter in the EU, but it's strongly recommended: it secures proof of consent and improves deliverability by filtering out invalid or unengaged addresses.
Read next
Related articles
- The GDPR consent checkbox: when it's required, when it's pointlessUnder almost every landing page form, the same box waits for the visitor: "I accept the privacy policy." Sometimes it's essential, often it's pointless, and it's almost always badly worded. Here's how to untangle the legal basis, the duty to inform, and consent to marketing — and how to write the notice that actually matches your case.
- GDPR and landing pages: making your form compliant without killing conversionA GDPR-compliant form and a form that converts aren't opposing goals — most compliance mistakes are also UX mistakes. Here's what GDPR actually requires from a landing page, and what it doesn't.
- Landing page for a hearing care center: converting to a free hearing test, not a saleA hearing care specialist doesn't sell a hearing aid the way you'd sell an ebook: the decision runs through an ENT prescription, a hearing test, and a trial period. The landing page has one realistic goal — booking the free hearing test — for an audience that's mostly senior, often assisted by a relative, and a form that brushes against health data.