Consent and GDPR go together naturally. It is one lawful basis for data processing, among many. In this article we will explore consent, and discuss the situations when it works – and when it doesn’t.
Contents
What Does The GDPR Say?
In the context of the General Data Protection Regulation (GDPR), consent is defined as “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.” (Article 4(11) of the GDPR)
What Does This Mean?
To be valid under the GDPR consent must meet the following criteria:
-
Freely given: Consent must be given voluntarily, without coercion or pressure. It must be given with specificity regarding the purposes of processing, and individuals should have the unequivocal right to withdraw their consent at any time.
-
Specific: Consent must be specific to the purpose for which the data is being processed.
-
Informed: Individuals must be informed of the purpose of the data processing, the categories of personal data that will be processed, and their rights under the GDPR.
-
Unambiguous: Consent must be clearly and explicitly expressed.
The GDPR sets a high standard for consent, and organizations must be able to demonstrate that they have obtained valid consent from individuals. This can be done by keeping clear records of when and how consent was obtained.
How to Get Consent
There are a number of ways to obtain consent under the GDPR, including:
-
Written form: Consent can be obtained in writing, such as by filling out a form.
-
Electronic form: Consent can be obtained electronically, such as by clicking a checkbox on a website.
-
Oral form: Consent can be obtained orally, but it must be recorded in writing or electronically.
Organizations should use the method of obtaining consent that is most appropriate for the situation. For example, if an organization is collecting personal data through a website, then it is best to obtain consent electronically.
Remember the GDPR requirement to be an unambiguous indication that people agree. This means you should avoid an “opt out” situation where people check or uncheck a box so explicitly refuse consent. This approach, while not specifically outlawed by GDPR, is unlikely to meet the standard of explicit consent.
Withdrawal of consent
Consent can be withdrawn at any time. If an individual withdraws their consent, then the organization must stop processing their personal data.
Crucially, it must be as easy to withdraw consent as it is to give it.
These are some examples of where we have helped organisations get consent right:
-
should you seek consent in a range of languages, then you should provide a route to withdraw consent in the same languages
-
when people can give consent online it is not fair to ask people to call a number to withdraw consent
-
if you do not ask for proof of identity when seeking consent, it is not appropriate to seek it when people change their minds
Getting Consent Right
The GDPR places a number of obligations on organizations that process personal data with consent. These include:
Providing clear and concise information
Organizations must provide individuals with clear and concise information about the purpose of data processing, the categories of personal data that will be processed, and their rights under the GDPR.
Making Consent Granular
Consent must remain relevant to the specific processing activities. It should not be a catch-all authorization but a targeted agreement for each distinct purpose of data processing. It is important to get consent for each data processing activity where it is needed. You cannot get blanket or open-ended consent.
That means that is you want to process personal data for activities A and B, and you are seeking consent for processing personal data for both activities, you must seek consent for activity A and activity B separately.
Keeping records of consent
Organizations must keep records of when and how consent was obtained. Maintaining comprehensive records of obtained consents is not just a best practice; it’s a legal necessity. Organizations must be able to demonstrate when and how consent was obtained, including what information was provided to the data subject.
Act when people withdraw their consent
Organizations must make it easy for individuals to withdraw their consent.
Organizations that fail to comply with the GDPR’s consent requirements may be subject to fines of up to €20 million or 4% of their global annual turnover, whichever is greater.
Sign Up Here:
Consent is one of six main lawful bases for data processing under the GDPR. Consent is no better or worse than any other. Therefore it is important not to default to consent and instead make sure it is the right lawful basis for you. There are a number of reasons for this. People have a number of rights under the GDPR. They have, for example, the right of access (commonly called making a subject access request). How people’s rights work depends on the lawful basis their data are being processed under. For example: the right to be forgotten: people have the right to have their data deleted in some circumstances. This right is easier to exercise if consent is the lawful basis you have used, because there is often no need to retain data once consent has been withdrawn. Conversely if you need the data to deliver a contract, or because of a statutory obligation, data deletion is harder to justify. the right to object: people can object to their data being processed for certain activities. However, this right does not apply when consent is the lawful basis for data processing. Consent is a good lawful basis when the withdrawal of consent would not have an adverse effect. A good example is consent for marketing activity. Another is participation in a research study. Circumstances when consent is not necessarily the right lawful basis include: delivery of a contract, such as providing goods and services purchased online providing healthcare, because if people refused to have their data processed for healthcare it could cause them harm evaluating the performance of employees. It is necessary to do this even if people do not want you to, to ensure effective and successful business operations The first privacy principles requires that all data processing is lawful, fair and transparent. You can read more about the first privacy principle here. However, for consent to be valid you must provide the following: Transparency is the cornerstone of obtaining valid consent. Organizations must provide individuals with clear and accessible information about the processing of their data. This includes details about the purposes of processing, the types of data involved, and the rights of the data subject. Crafting effective consent notices and privacy policies is an art. These documents must communicate complex information in a manner that is easily understandable by the average person. They should empower individuals to make informed decisions about the use of their data. You must also tell people how they can withdraw consent if they want to. The principle of accountability is crucial in consent management. Organizations must conduct regular reviews, updates, and audits to ensure ongoing compliance. This includes staying abreast of changes in processing activities and updating consents accordingly. You can read more about the principle of accountability here. The GDPR introduces specific considerations and safeguards for obtaining the consent of children. The age of digital consent varies across EU member states, and organizations must ensure that they comply with the age requirements of the respective jurisdictions. In the UK children aged 13 and over can automatically give consent for their data to be processed. Under that age an assessment of the child’s competence must be done before you can use consent as the lawful basis for data processing. If you are seeking consent for data processing from children then your privacy information and other information about how data is used and how people can exercise their rights must be written in a way the child can understand. Special categories of data, such as health or biometric information, demand a higher standard for obtaining consent. Explicit consent is one lawful basis processing such sensitive information. Where you have sought consent for the specific data processing, and are clear about the purposes, then you may rely on consent for the processing of sensitive personal data. The usual standards of consent apply: it must be freely given it must be via unambiguous, affirmative action consent for processing special category data must be separate from any other consent for data processing you are seeking. It is also necessary to be careful not to make consent a precondition of access to services for which sensitive personal data are not necessary. You should also be mindful of not putting people in a position where they feel they cannot say ‘no’. You can see a more in-depth discussion of special categories of data here. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence. In this deep dive into consent and GDPR we have seen organizations find not just a compliance requirement but an opportunity to foster trust, transparency, and a robust data protection culture. As we unravel the layers of consent, it becomes evident that its effective management is not just a legal necessity but a strategic imperative in the landscape of data protection and privacy. Organizations that prioritize clear communication, transparency, and accountability in their consent management practices are better positioned to navigate the GDPR successfully, earning the trust of individuals in an era where data privacy is paramount.Is Consent the Right Lawful Basis?
People’s Rights
When Consent is and isn’t Right
The Role of Transparency and Accountability
Clear Information
Consent Notices
Accountability in Consent Management
Children’s Consent
Consent and Special Categories of Data
Conclusion
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: