Do cookie banners with pre-ticked boxes hold up under GDPR?
No. Under GDPR, consent must be freely given, specific, informed, and unambiguous, and regulators have said repeatedly that pre-ticked boxes do not meet that bar. If your banner pre-selects optional categories, the consent it collects is not valid.
What valid consent requires
GDPR sets a high bar on purpose. Consent has to be a clear affirmative action: the person must do something that signals agreement, like clicking an accept button for a specific purpose. Silence, inactivity, and pre-ticked boxes do not count. The consent also has to be granular, meaning analytics, marketing, and functional cookies need separate choices, not one bundled accept-everything button as the only real option.
Why pre-ticked boxes fail
A pre-ticked box asks the visitor to opt out rather than opt in. European regulators and courts have rejected this pattern because it reverses the burden: the default state processes data the person never agreed to share. Enforcement actions across several EU countries have fined companies for exactly this, and the pattern shows up in regulator guidance as a textbook example of invalid consent.
What a compliant banner looks like
Start from reject-by-default. Optional categories begin unticked, accept and reject are equally easy to reach, and withdrawing consent later is as simple as giving it. Keep a record of what each visitor chose and when, because accountability is part of the requirement, not a nice extra. If you cannot produce the consent record, you cannot prove the consent existed.
Check your own banner this week
Open your site in a fresh browser session and look at what is ticked before you click anything. If optional categories start selected, you have a known-broken pattern collecting invalid consent right now. Fixing it is usually a configuration change, not a rebuild, which makes it one of the cheaper compliance wins available.