Blog

Privacy gate as a workflow: what to check on a cookie wall after the DPG case

The Belgian regulator is handling the complaint against DPG's cookie wall. What this means for designing and checking your privacy gate as a workflow.

· By

Desk in two zones: left, paper mock-ups with two equal buttons; centre, notes with arrows; right, a hand-drawn flow leading to a closed storage box.
A privacy gate is a checkable workflow in which refusing must be as easy as accepting and every choice stays traceable.Image: IamVera.ai — original editorial illustration

Treat a privacy gate not as a front-end banner but as a checkable workflow: refusing must be as easy as accepting, consent must be free, specific and informed, and every choice plus later change must be traceable per user journey. The Belgian regulator is examining exactly these design choices at DPG Media.

According to the reporting by Tweakers, the Belgian Data Protection Authority (DPA) decided in early February 2025 to handle NOYB's complaint against DPG Media's cookie wall on its merits. DPG's objection to blocking the case was dismissed. For anyone who designs or manages a consent screen themselves, the practical consequence is clear: the way you request, refuse and withdraw consent is now an enforcement matter and not a ticked-off legal formality.

What did the Belgian regulator decide about DPG Media's cookie wall?

According to Tweakers, the DPA is going to investigate the complaint by privacy organisation NOYB about the cookie wall on outlets including HLN, De Morgen, VTM and 7sur7. In doing so, the regulator questions concrete design choices: the absence of a clear refuse button next to the accept button, the use of colour that can nudge users towards consent, and the effort it takes to withdraw consent previously given.

Important for context: this is a decision to handle the case, not a final verdict on lawfulness. The substantive assessment is still to come. What the step does do is formally put the design choices around consent under scrutiny.

How does DPG Media position its own privacy gate and data vault?

In its own communications, DPG Media presents the privacy gate as a transparency and control instrument. On the company page about responsible data usage and AI, DPG describes a self-developed privacy gate within the DPG Network, a jointly developed data vault and the decision to end the sale of advertising through third parties on certain news apps in favour of its own network. The gist: data that stays within DPG is not sold to third parties and users gain more control.

Here lies the tension that makes this file interesting. DPG presents the privacy gate as proof of responsible data usage, while the DPA and NOYB are examining precisely whether the design of that same screen yields valid consent and easy refusal. In our assessment, this shows that a privacy architecture is not judged on the intention behind it, but on the concrete operation at each moment of choice.

Which consent requirements must a cookie wall meet according to the EDPB?

The benchmark has long been set out in the consent guidelines of the Article 29 Working Party, the predecessor of the EDPB. Those guidelines state that consent must be free, specific, informed and unambiguous, and they criticise forced consent where access is made dependent on accepting tracking. Translated into the design of a cookie wall or privacy gate, this means among other things:

  • Refusing must be as easy as accepting, preferably at the same level and with comparable visibility.
  • Colour, placement and wording must not push the user towards consent; misleading design patterns are not permitted.
  • Consent must be specific per purpose, not a single all-or-nothing button for dissimilar uses.
  • Withdrawing consent must be as low-threshold as giving it.
  • The access decision and the tracking decision must remain clearly separated.

These requirements turn a consent screen into a design question with checkable outcomes, not merely a legal text at the bottom of the page. Anyone who bases AI-generated content or personalised recommendations on the same consent will additionally face marking obligations; see our explanation of marking AI content under the EU AI Act.

Why is a privacy gate a workflow question and not a banner choice?

The privacy gate is the visible head of a deeper chain. Behind the choice screen sit account linking between brands, the recording of consent, later preference changes, access to the data vault and the personalisation and recommendation layer that runs on it. The compliance question thus shifts from "what does the banner look like" to "can every step in this chain be reconstructed per user journey".

That fits a broader movement described by the podcast of Consumer Finance Monitor, in which privacy, cybersecurity and AI governance are treated as one trust architecture. For media organisations this means that a privacy gate does not stand apart from the rest: it is the place where access, consent and data usage converge. Those who manage these parts as separate silos cannot demonstrate the coherence during an investigation. See also our analysis of one governance system for privacy, cyber and AI and the broader topic hub on AI privacy and GDPR.

How do I check whether my privacy gate and data flows do what they promise?

In our assessment, the core question after the DPG case is not whether your consent screen looks tidy, but whether you can show, per workflow, what is happening. A practical checking sequence:

  1. Record, per user journey, which data is collected under which consent.
  2. Log every accept and refuse decision and later changes, with time and context.
  3. Demonstrate which content and advertisements are personalised on the basis of that choice.
  4. Describe how the data vault or comparable storage limits reuse and sharing.
  5. Link AI-driven recommendations explicitly back to the consent given.
  6. Test whether refusing and withdrawing are actually as easy as accepting.

Those who want to support such checks in document-driven work where AI processes sensitive content can deploy a verification layer such as Vera. The Semantic Privacy Shield works such that pre-processing and anonymisation take place on EU infrastructure and nothing is sent onward if a privacy check fails; the workflow is designed to send only anonymised content to the selected AI models. That gives more insight into the steps, but is no guarantee of GDPR compliance or flawless anonymisation, and the final judgement remains with the user. The lesson from the DPG case is broader than one regulator or one company: a privacy gate is only defensible once you can show its operation per user journey.

Sources and references

  1. Belgische toezichthouder gaat cookiemuurklacht tegen DPG Media behandelenTweakers · 2025-02-05
  2. Responsible AI and data usageDPG Media · 2024-10-01
  3. Guidelines on consent under Regulation 2016/679 (WP259 rev.01)Article 29 Working Party · 2018-04-10
  4. The Confidence Advantage: Why Privacy, Cybersecurity, and AI Governance Are Becoming Business ImperativesConsumer Finance Monitor · 2026-08-20

Sources: The article relies on Tweakers for the Belgian Data Protection Authority's decision, DPG Media's own page on responsible data usage and the consent guidelines of the Article 29 Working Party.

← All articles in this topic ← All articles