Pre-ticked consent checkbox
Silktide finds checkboxes on your pages that are already ticked before the visitor touches them. If such a checkbox asks for consent, for example to receive marketing emails, that consent is not valid under privacy law.
<!-- Invalid: consent must not be pre-ticked -->
<input type="checkbox" name="newsletter" checked>
<label>Send me marketing emails</label>
<!-- Valid: the visitor actively opts in -->
<input type="checkbox" name="newsletter">
<label>Send me marketing emails</label>
Why this matters
Under the , consent must be a clear, affirmative action: the person has to actively opt in. The Court of Justice of the EU ruled (in the Planet49 case, 2019) that a pre-ticked box does not constitute valid consent, because doing nothing is not agreeing. Consent gathered this way is worthless - marketing sent on the back of it is unlawful, and regulators can fine you for it.
Pre-ticked boxes are also a dark pattern that erodes trust: people notice when they are signed up for something they never chose.
How to fix it
Silktide flags every pre-ticked checkbox because it cannot reliably tell which ones ask for consent - that part is your review.
- For each flagged checkbox, decide whether it relates to consent: marketing opt-ins, accepting data processing, agreeing to cookies or profiling.
- For consent checkboxes, remove the
checkedattribute (or the setting in your form builder that pre-ticks it) so the visitor must actively opt in. - If the checkbox is not about consent - a search filter, a "remember me" option, a default preference - it may be fine. Ignore the finding so it isn't raised again.
How Silktide tests this
- Find every checkbox on each page.
- Report each one that is already ticked when the page loads, with its surrounding text so you can judge what it asks.
Silktide does not attempt to decide whether a checkbox is consent-related; every pre-ticked checkbox is reported for your review.
Troubleshooting
A harmless checkbox is flagged
Expected. Filters, display preferences, and similar controls legitimately default to being ticked. The check exists to surface the ones that shouldn't, and non-consent checkboxes can simply be ignored.
A checkbox becomes ticked after the page loads
Silktide examines the page as it loads. A checkbox that scripts tick later, for example after the visitor makes another choice, may not be detected.