Consent and GDPR: processing data lawfully

Consent is one of the seven lawful bases for processing personal data under Article 6 of the UK GDPR. Although it is probably the best-known lawful basis, it is also one of the most widely misunderstood and misused.

Many organisations assume they should always ask for consent before processing personal data. In reality, consent is simply one of several equally valid lawful bases and is only appropriate where individuals can make a genuine, informed and freely given choice about whether their personal data are processed.

Understanding when consent is appropriate, and when another lawful basis should be used instead, is essential for achieving compliance with the UK GDPR.

  • Consent is one lawful basis for processing personal data—it is not the default.
  • It gives individuals genuine choice and control over how their personal data are used.
  • Consent should only be relied upon where people are genuinely free to decide whether to agree, without pressure or disadvantage.

Periodic Table of the GDPR

What Does the UK GDPR Say?

Consent is one of the several lawful bases for processing personal data set out in Article 6 of the UK GDPR. Article 6(1)(a) states that processing is lawful where:

“the data subject has given consent to the processing of his or her personal data for one or more specific purposes.”

The GDPR also provides a specific definition of consent in Article 4(11). It defines consent as:

Any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.”

These two Articles work together. Article 6 establishes consent as a lawful basis for processing personal data, while Article 4 explains what valid consent looks like in practice. Together they make clear that consent is not simply asking someone to agree. It must be a genuine choice, given voluntarily, for a specific purpose, based on clear information, and demonstrated through a positive action.

Lawful basis: consent

What Is Consent?

Purpose

Consent is one of the most flexible lawful bases under the UK GDPR because it gives individuals direct control over whether their personal data are processed. However, for consent to be valid it must meet a number of strict legal requirements.

In simple terms, consent means that an individual has made a genuine and informed decision to allow an organisation to process their personal data for a specific purpose.

Valid consent means:

  • A genuine choice – individuals must be free to decide whether to agree, without pressure, coercion or fear of disadvantage.
  • A positive action – consent must be demonstrated through a clear affirmative action, such as ticking a box, signing a form or actively selecting a preference.
  • An informed decision – people must understand who is processing their data, why it is being processed and what agreeing means in practice.
  • Ongoing control – individuals must be able to withdraw their consent easily at any time, and organisations must respect that decision.

Just as importantly, the UK GDPR makes clear what consent is not. Consent cannot be assumed from:

  • silence
  • pre-ticked boxes
  • inactivity
  • implied agreement

If an organisation cannot demonstrate that an individual has actively chosen to consent, it is unlikely that consent will satisfy the requirements of the UK GDPR. For example, requiring consent suggests that consent is not the right lawful basis the data processor should be relying on for data processing. 

Invalid consent under the GDPR

 

The Elements of Valid Consent

For consent to be valid under the UK GDPR, it must meet four essential requirements. If any one of these elements is missing, the consent is unlikely to provide a lawful basis for processing personal data.

Freely Given

Consent must be given voluntarily. Unlike the example above iIndividuals should have a genuine choice about whether to agree, without being pressured, misled or disadvantaged if they refuse.

Valid consent should therefore involve:

  • no pressure or coercion
  • no negative consequences for refusing
  • no significant imbalance of power between the organisation and the individual

For example, consent will rarely be appropriate in an employment relationship where an employee may feel unable to refuse a request from their employer.

Specific

Consent must relate to one or more clearly defined purposes. Individuals should know exactly what they are agreeing to, and organisations should avoid using blanket consent to cover multiple, unrelated processing activities.

Where personal data will be used for different purposes, separate consent should normally be obtained for each purpose.

Informed

Individuals can only make a genuine decision if they have enough information about how their personal data will be used.

Before seeking consent, organisations should clearly explain:

  • who is processing the personal data
  • why the data are being processed
  • what personal data will be collected and used
  • who the data may be shared with
  • how consent can be withdrawn

This information should be presented in clear, plain language that is easy to understand.

Unambiguous

Consent must be demonstrated through a clear affirmative action that leaves no doubt about the individual’s wishes.

Examples of valid affirmative actions include:

  • ticking an unticked consent box
  • signing a consent form
  • providing a verbal statement of agreement
  • actively selecting a preference online
  • confirming consent electronically through a positive action

Silence, inactivity or pre-ticked boxes do not constitute valid consent under the UK GDPR because they do not clearly demonstrate the individual’s agreement.

When Is Consent Appropriate?

Consent is most appropriate where individuals have a genuine choice about whether their personal data are processed and where they can refuse or withdraw their agreement without suffering any detriment. In these situations, consent provides people with meaningful control over how their information is used and helps organisations build trust through transparency and respect for individual choice.

Consent is commonly the appropriate lawful basis for processing activities such as:

  • sending marketing emails or promotional communications
  • subscribing individuals to optional newsletters or mailing lists
  • placing non-essential cookies and similar technologies on websites
  • inviting people to participate in research projects where participation is voluntary
  • using photographs or videos for optional promotional purposes
  • conducting optional surveys or customer feedback exercises

In each of these examples, individuals are free to decide whether they wish to participate, and their decision should not affect their ability to receive a service or exercise their rights.

Before relying on consent, organisations should ask a simple question:

Does the individual have a genuine and meaningful choice?

If the answer is yes, consent may well be the appropriate lawful basis. If the individual is under pressure, cannot realistically refuse, or would suffer a disadvantage by withholding consent, another lawful basis is likely to be more appropriate.

Ultimately, consent works best where individuals have real control over the processing of their personal data and where their decision to agree—or not to agree—is entirely their own.

When Should Consent NOT Be Used?

Although consent is one of the seven lawful bases for processing personal data, it is not always the most appropriate choice. In many situations another lawful basis provides a more accurate reflection of why personal data are being processed and offers greater certainty for both organisations and individuals.

The key question is whether the individual has a genuine and freely given choice. If they cannot realistically refuse or withdraw consent without suffering a disadvantage, consent is unlikely to be valid.

Examples where consent is usually not the appropriate lawful basis include:

Employment

Consent will rarely be valid in an employment relationship because of the imbalance of power between employer and employee. Employees may feel obliged to agree, even when they would prefer not to. In most cases, employers should instead rely on another lawful basis, such as the performance of a contract or compliance with a legal obligation.

Public Authorities

Public authorities should avoid relying on consent when exercising their official functions or statutory powers. Individuals often have little or no choice about whether their personal data are processed in these circumstances, making consent inappropriate. The lawful basis of Public Task will usually be more appropriate.

Healthcare Treatment

Healthcare providers generally do not rely on GDPR consent as the lawful basis for processing personal data when providing treatment. Although patient consent is often required from an ethical or clinical perspective before treatment is given, the processing of personal data will usually rely on another lawful basis, together with an appropriate Article 9 condition where special category data are involved.

Legal Obligations

Where an organisation is required by law to process personal data, consent should not be used. For example, employers must process payroll information to meet their tax and employment law obligations. An individual cannot withdraw consent to prevent an organisation from complying with a legal requirement.

Performance of a Contract

Where personal data are necessary to fulfil a contract with an individual, the appropriate lawful basis will usually be Contract rather than consent. For example, an online retailer does not need consent to process a customer’s name and delivery address in order to deliver goods that have been purchased.

Why Power Imbalance Matters

One of the defining features of valid consent is that it must be freely given. Where there is a significant imbalance of power between the organisation and the individual, it becomes difficult to demonstrate that consent was genuinely voluntary. This is why consent is often inappropriate in relationships where one party exercises authority over another, such as employers, schools, healthcare providers and public authorities.

Before relying on consent, organisations should always ask themselves:

Could this individual realistically refuse or withdraw consent without suffering any disadvantage?

If the answer is no, another lawful basis is likely to be more appropriate.

Consent and Children

The UK GDPR recognises that children can give valid consent in certain circumstances, provided they have the capacity to understand what they are agreeing to. However, because children may be less aware of the risks and consequences of sharing personal information, organisations must take particular care when relying on consent as a lawful basis.

For information society services, such as websites, online platforms and mobile applications offered directly to children, the UK GDPR sets a default age of 13 years. Children aged 13 or over can generally provide their own consent for these services. Where a child is under the age of 13, consent must usually be given or authorised by a person with parental responsibility.

Outside the context of online services, there is no single age at which a child can or cannot consent under the UK GDPR. Instead, organisations should consider whether the child has sufficient maturity and understanding to make an informed decision about the processing of their personal data.

When seeking consent from children, organisations should ensure that all information is presented in language that is clear, concise and age appropriate. Privacy notices, consent requests and explanations of how personal data will be used should be written so that the intended audience can easily understand them.

Where parental consent is required, organisations should take reasonable steps to verify that the person providing consent has parental responsibility.

Ultimately, organisations should remember that children’s personal data deserve particular protection. When relying on consent, they should always consider the child’s best interests, provide information in an accessible format and ensure that consent represents a genuine and informed choice.

Explicit Consent

In most situations, the UK GDPR requires organisations to obtain valid consent, which must be freely given, specific, informed and unambiguous. However, some processing activities require a higher standard known as explicit consent.

Explicit consent is most commonly required when processing special category personal data under Article 9 of the UK GDPR, although it may also be required in certain international data transfer arrangements or for other specific processing activities defined in legislation.

The term explicit means that the individual’s agreement must be expressed in a clear and unequivocal way. There should be no doubt that they intended to give consent for the specific processing activity.

Examples of explicit consent include:

  • signing a written consent form
  • completing an electronic declaration
  • giving a clear verbal statement that is recorded
  • actively confirming agreement through a dedicated consent statement

Explicit consent requires a more direct expression of agreement than ordinary consent. Simply relying on implied agreement or inferring consent from an individual’s actions is unlikely to be sufficient.

Because explicit consent is often relied upon when processing more sensitive types of personal data, organisations should ensure that the request for consent clearly explains:

  • what personal data will be processed
  • why the processing is necessary
  • any risks associated with the processing
  • who will receive the information
  • how consent can be withdrawn

As with all forms of consent, organisations should keep appropriate records demonstrating when explicit consent was obtained, what information was provided to the individual at the time, and how consent can be withdrawn if the individual later changes their mind.

Managing Consent

Obtaining consent is only the beginning of the process. Organisations that rely on consent as a lawful basis must have appropriate systems in place to manage that consent throughout the entire information lifecycle. This helps ensure that consent remains valid, can be demonstrated when required and continues to reflect the individual’s wishes.

Effective consent management should include the following activities:

Record Consent

Organisations should keep clear records of when consent was obtained, who gave it, what information was provided at the time and exactly what the individual agreed to. These records provide important evidence of compliance with the accountability principle and may be required if the organisation is asked to demonstrate that valid consent was obtained.

Review Consent

Consent should not simply be collected and forgotten. Organisations should periodically review existing consent arrangements to ensure they remain appropriate, particularly where processing activities change or where long periods have passed since consent was obtained.

Refresh Consent Where Appropriate

There is no fixed expiry date for consent under the UK GDPR. However, where the original consent may no longer reflect the individual’s reasonable expectations, or where the purpose of the processing has changed, organisations should seek fresh consent before continuing the processing.

Document Withdrawals

Individuals have the right to withdraw their consent at any time. Organisations should have straightforward procedures for recording when consent has been withdrawn and ensuring that any processing based solely on that consent stops promptly, unless another lawful basis applies.

Link Consent to Processing Activities

Consent should be linked directly to the processing activity for which it was obtained. Organisations should always be able to identify which processing activities rely on consent, whose consent has been obtained and how that consent is managed. This makes it easier to demonstrate compliance, respond to individuals’ requests and ensure that personal data are processed only in accordance with the individual’s wishes.

Good consent management is an essential part of the accountability principle. It enables organisations to demonstrate that consent is not treated as a one-off event, but as an ongoing process that respects individuals’ choices and supports lawful, transparent and responsible data processing.

Withdrawing Consent

One of the defining characteristics of consent under the UK GDPR is that it is not permanent. Individuals have the right to withdraw their consent at any time, and organisations that rely on consent as their lawful basis must make this process straightforward and effective.

Withdrawing consent should be:

  • Easy: It should be as simple to withdraw consent as it was to give it. Individuals should not have to navigate complicated processes or contact multiple departments simply to change their mind.
  • Free: Organisations should never charge individuals for withdrawing their consent or create unnecessary barriers that discourage them from exercising this right.
  • Honoured Promptly: Once consent has been withdrawn, organisations should stop any processing that relies solely on that consent as soon as reasonably practicable, unless another lawful basis exists for continuing the processing.

It is important to remember that withdrawing consent does not make earlier processing unlawful. Processing carried out before consent was withdrawn remains lawful, provided the consent was valid at the time. Withdrawal only affects future processing and requires organisations to stop any activities that continue to rely on consent as their lawful basis.

Organisations should therefore have clear procedures for recording withdrawals of consent, updating their systems and ensuring that processing ceases promptly. Making it easy for individuals to change their minds is an essential part of respecting their rights and demonstrating accountability under the UK GDPR.

Practical Examples

Understanding when consent is—and is not—the appropriate lawful basis is easier when considered in the context of real-world scenarios.

Marketing

A customer signs up to receive a company’s newsletter by entering their email address and actively ticking an unticked box agreeing to receive marketing communications. Because receiving the newsletter is optional and the customer is free to refuse without affecting other services, consent is usually the appropriate lawful basis.

Human Resources

An employer asks employees to consent to the processing of their payroll information. In most cases, consent is unlikely to be valid because employees may feel unable to refuse. Instead, the employer would normally rely on the lawful bases of Contract and Legal Obligation to process the personal data needed to employ and pay staff.

Healthcare

A patient agrees to undergo a medical procedure. Although their consent is essential from an ethical and clinical perspective, healthcare providers will usually rely on lawful bases other than GDPR consent when processing the patient’s personal data. This reflects the fact that the processing is necessary to provide healthcare services and is supported by the appropriate legal provisions under the UK GDPR.

Photography

An organisation wishes to use staff photographs on its website or in promotional material. Because participation is optional and employees should be free to decline without any adverse consequences, consent is often the most appropriate lawful basis for this type of processing.

Schools

A school asks parents or carers for permission to use photographs of pupils in promotional materials or on its website. As participation is entirely optional and not necessary for providing education, consent is generally the appropriate lawful basis. Parents or carers should be able to refuse or withdraw consent at any time without affecting the child’s education or participation in school activities.

Common Mistakes

Even organisations with good intentions can misuse consent as a lawful basis for processing personal data. Many of the most common problems arise because consent is chosen when another lawful basis would be more appropriate, or because organisations fail to manage consent properly once it has been obtained.

Some of the most common mistakes include:

Using Consent Because “It Sounds Safest”

Consent is not the default lawful basis under the UK GDPR. Organisations should choose the lawful basis that best reflects the reason for the processing. Using consent where another lawful basis is more appropriate can create unnecessary obligations and may undermine compliance.

Making Consent Mandatory

Consent must be freely given. If individuals are forced to consent in order to receive a service that does not genuinely require the processing, the consent is unlikely to be valid.

Bundling Multiple Purposes Together

Consent should be specific. Asking individuals to agree to several unrelated processing activities through a single consent statement makes it difficult for them to exercise genuine choice. Separate purposes should normally require separate consent.

No Process for Withdrawing Consent

Individuals must be able to withdraw their consent as easily as they gave it. Organisations that make withdrawal difficult, slow or unclear are unlikely to meet the requirements of the UK GDPR.

No Records of Consent

The accountability principle requires organisations to demonstrate that valid consent has been obtained. Without appropriate records showing who consented, when, how and for what purpose, it may be impossible to prove that consent was valid.

Using Pre-Ticked Boxes or Implied Consent

Consent requires a clear affirmative action. Pre-ticked boxes, silence, inactivity or implied agreement do not demonstrate the unambiguous indication of wishes required by the UK GDPR.

Assuming Consent Lasts Forever

There is no fixed expiry date for consent, but it should not be treated as permanent. Organisations should review consent periodically and seek fresh consent where processing changes or where the original consent no longer reflects the individual’s reasonable expectations.

Using Consent Where Another Lawful Basis Applies

Consent should not be relied upon where individuals do not have a genuine choice, such as in many employment relationships, when complying with legal obligations or when performing a contract. In these situations, another lawful basis will usually provide a more accurate and robust legal foundation for the processing.

Avoiding these common mistakes helps ensure that consent remains valid, individuals retain meaningful control over their personal data, and organisations can demonstrate compliance with the accountability principle.

Demonstrating Compliance

The accountability principle requires organisations not only to obtain valid consent, but also to be able to demonstrate that consent has been obtained and managed in accordance with the UK GDPR. Maintaining appropriate records provides evidence of compliance and helps organisations respond confidently to enquiries from regulators or individuals.

Evidence of compliance may include:

  • Consent records, showing who gave consent, when it was obtained and what processing activities it covered.
  • Privacy notices, explaining how personal data will be used before consent is requested.
  • Consent wording, demonstrating that requests for consent are clear, specific and easy to understand.
  • Withdrawal logs, recording when individuals withdraw their consent and the actions taken in response.
  • Preference centres, allowing individuals to manage their communication preferences and consent choices easily.
  • Marketing systems, maintaining accurate records of marketing permissions and ensuring communications are sent only where appropriate consent exists.
  • Audit logs, providing evidence of how consent has been recorded, updated and managed over time.
  • Training records, demonstrating that staff understand how to obtain, record and manage consent correctly.
  • Data Protection Impact Assessments (DPIAs), where appropriate, showing that the organisation has considered privacy risks before relying on consent for higher-risk processing activities.

Taken together, these records demonstrate that consent is not treated as a one-off event but as an ongoing process that is actively managed throughout the information lifecycle. They also provide the evidence needed to satisfy the accountability principle by showing not only that valid consent has been obtained, but that it continues to be respected and managed appropriately.

Practical Consent Checklist

Ask:

  • Is consent the correct lawful basis?
  • Is there genuine choice?
  • Is consent freely given?
  • Is it specific?
  • Is it informed?
  • Is it unambiguous?
  • Can people withdraw easily?
  • Can we prove consent?

Conclusion

Consent gives individuals meaningful control over how their personal data are used, but it is only appropriate where people have a genuine and informed choice. Organisations should not view consent as the default lawful basis. Instead, they should carefully assess whether it is the most appropriate legal basis for the processing activity, ensure that any consent obtained meets the GDPR’s strict requirements, and maintain clear evidence that it has been given and can be withdrawn.