Glossary | GDPR & Data Privacy
Consent (GDPR)
What is Consent (GDPR)?
Under Regulation (EU) 2016/679 (GDPR), consent is one of six lawful bases that permits a Data Controller to process personal data. For consent to be valid under the GDPR, it must be freely given, specific, informed, and unambiguous. It must be indicated by a clear affirmative action — pre-ticked boxes, silence, or inactivity do not constitute valid consent.
Why It Matters
Consent is one of the most commonly relied upon — and most commonly misused — lawful bases under the GDPR. Many organisations assume consent is always required, or obtain it in ways that do not meet the regulation’s standards, leaving their processing activities on shaky legal ground.
Invalid consent is no consent at all. Where consent does not meet GDPR requirements, the processing it was intended to justify becomes unlawful, exposing the organisation to enforcement action and reputational risk. Individuals also have the right to withdraw consent at any time, and controllers must be prepared to action this promptly.
For businesses that rely on consent to process customer or user data — for example, for marketing communications or cookies — ensuring consent is obtained and managed correctly is a critical compliance obligation.

Key Requirements
When Is Consent the Appropriate Lawful Basis?
Consent may be the appropriate lawful basis when:
- No other lawful basis applies to the processing activity, or
- The processing is genuinely optional and the data subject has a real choice.
For consent to be valid under the GDPR, it must meet all of the following conditions:
- Freely given – The data subject must have a genuine choice, with no detriment for refusing or withdrawing consent.
- Specific – Consent must be obtained separately for each distinct processing purpose.
- Informed – The data subject must be provided with clear information about who is processing their data and why.
- Unambiguous – Consent must be indicated by a clear affirmative action, such as ticking a box or clicking a button.
This requirement applies under:
Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR), Articles 6 and 7
Responsibilities Relating to Consent
Data Controllers relying on consent as their lawful basis are commonly required to:
- Obtain consent through a clear affirmative action before processing begins
- Keep records demonstrating when, how, and what consent was obtained
- Provide data subjects with an easy mechanism to withdraw consent at any time
- Act on withdrawal of consent promptly and without detriment to the individual
- Avoid bundling consent for multiple purposes into a single request
- Review and refresh consent where it is no longer recent or clearly documented
Consent and the Right to Withdraw
One of the key implications of relying on consent is that data subjects may withdraw it at any time. Controllers must make withdrawal as easy as giving consent in the first place, and must stop processing the relevant data once consent is withdrawn — unless another lawful basis applies to the processing.
This ongoing obligation means that consent is not always the most practical lawful basis, particularly for processing activities that are core to a business’s operations.
Frequently Asked Questions
No. Consent is only appropriate where the processing is genuinely optional and the data subject has a real choice. For processing that is necessary to fulfil a contract or comply with a legal obligation, other lawful bases are more appropriate and more straightforward to rely upon.
No. The GDPR requires a clear affirmative action to indicate consent. Pre-ticked boxes, implied consent, or silence do not meet this standard and will render any consent obtained invalid.
Controllers must be able to demonstrate that consent was given, including who consented, when, what they were told, and how consent was obtained. Consent records should be maintained for as long as the data is processed on that basis.
Need GDPR Representative Services?
Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.
Related Terms
Further Reading