DPG Media's Privacy Gate centralises and clarifies data choices, but on its own it is no proof of valid consent. According to the EDPB and the Dutch Data Protection Authority, a publisher must demonstrate that choices are free, specific, informed and revocable and that a real alternative without behavioural advertising exists.
On its own page about responsible data and AI usage, DPG Media describes that it deploys a self-developed Privacy Gate within the DPG Network to welcome visitors more personally and to explain more simply how it handles data. The reason to assess this now is the 2026-2027 work programme of the European Data Protection Board, in which the EDPB announces that it is working on broader guidelines for consent-or-pay models. The interpretation is therefore still developing.
What exactly is DPG Media's Privacy Gate?
According to DPG Media, the Privacy Gate is a mechanism that explains to visitors of the media network in plain language how DPG handles data and that brings user choices together in one place. On its Dutch-language page about responsible data usage, DPG links the gate to transparency and responsible data and AI usage.
In our assessment, that is a recognisable governance pattern for digital publishers: a visible layer that replaces fragmented cookie and consent choices with a single interface. That can increase transparency and make choices easier to find. On its own, however, it says nothing about the legal validity of the consent that results from it.
Does the Privacy Gate on its own meet the GDPR requirements for consent?
No, not automatically. In its explanation of the legal basis of consent, the Autoriteit Persoonsgegevens explains that valid consent must be free, unambiguous, informed and specific, and that the organisation must be able to demonstrate that consent was obtained. An interface that displays choices is not yet proof that those requirements have been met.
The AP criteria translate into a practical test for any data-choice interface:
- Specific: each purpose — personalisation, measurement, advertising — has its own, separate choice instead of one combined button.
- Informed: the visitor sees in advance which purposes and which recipients a choice activates.
- Free: refusing or choosing an alternative is as easy as accepting, without steering design.
- Demonstrable: the publisher can reconstruct afterwards which choice a user made, when, and whether it was withdrawn.
These points are an editorial operationalisation of the AP's explanation, not a literal list from the supervisory authority.
What requirement does the EDPB set for a consent-or-pay alternative?
In Opinion 08/2024 on valid consent in consent-or-pay models, the EDPB holds that large online platforms offering a choice between behavioural advertising in exchange for consent or payment will in most cases not obtain valid consent. The EDPB points out that alternatives must be equivalent and that, where payment is required for an equivalent alternative, an additional free alternative should be considered — for example advertising with less or no processing of personal data.
The open question that the sources do not answer is whether DPG Media's Privacy Gate offers such a real, equivalent alternative without behavioural advertising. DPG's own pages describe the transparency purpose, but contain no assessment against the EDPB standard. In our assessment, that is precisely the point on which publishers must test themselves: the visibility of the choice says nothing about its freedom.
How does a publisher link data choices to AI processing per workflow?
In the work programme, the EDPB emphasises that the regulation around consent-or-pay is still being worked out. That means a publisher must retain evidence of its own design choices rather than treat a gate as completed compliance. In our assessment, the same documentation principle applies to every AI-related processing in a publisher environment.
A workable approach is to record, per publication workflow:
- which AI processing purpose is at play — personalisation, recommendation, audience measurement, content moderation, fraud detection or model improvement;
- on which legal basis that purpose rests;
- which explanation the user receives about it;
- which data-minimisation choice has been made;
- which user choice activates or blocks the purpose, and how withdrawal or objection is honoured.
This mapping touches more broadly on governance of AI agents and delegated processing. Those who want more on the accountability of AI choices under the GDPR will find context in our analysis of GDPR accountability for autonomous AI agents and of linking DSA obligations to the GDPR fining methodology. The broader theme is in our hub on AI privacy and GDPR, and for demonstrating human oversight of automated choices, a logging layer per high-risk decision for human oversight is relevant.
What does this mean in practice for digital publishers?
The practical consequence is that a Privacy Gate can be a useful governance control, but not conclusive proof. Its value depends on whether the choices are truly free, granular, informed and reversible, and on whether the publisher can demonstrate which data-processing purposes and underlying services each choice sets in motion. As long as the EDPB is working on broader guidelines, it is more prudent to document design choices, purposes, alternatives and consent flows than to treat the interface as an endpoint.
Sources and references
Sources: The article draws on DPG Media Group's own pages about responsible data and AI usage, on Opinion 08/2024 and the 2026-2027 work programme of the European Data Protection Board, and on the explanation of consent by the Autoriteit Persoonsgegevens.