What is "Consent" under the GDPR?
What makes consent valid under the GDPR? This guide explains the legal requirements for obtaining valid consent, highlights the ICO's practical checklist for requesting consent, and explores the common mistakes that render consent invalid, with practical compliance tips for organizations.
Consent is one of the six lawful bases for processing personal data under Article 6 of the GDPR. It is neither the default nor the preferred lawful basis, and it is not inherently superior to the other lawful bases. Rather, consent should be relied upon only where individuals can make a genuine, informed, and freely given choice about whether their personal data will be processed. If a controller cannot offer that genuine choice, consent is not an appropriate lawful basis. The GDPR also gives consent a broader role than simply legitimizing ordinary processing.
Conditions of Consent
The GDPR establishes four cumulative conditions for valid consent.
- Freely given. Consent is valid only if it reflects the data subject's genuine and voluntary choice. The GDPR requires that individuals be able to refuse or withdraw consent without coercion, intimidation, undue influence, deception, or any significant disadvantage. Consent is presumed not to be freely given where there is a clear imbalance of power between the controller and the data subject, or where the performance of a contract or the provision of a service is made conditional on consent to processing that is not objectively necessary for that contract or service. Consequently, public authorities, employers, educational institutions, healthcare providers, and other organizations in positions of authority should be cautious when relying on consent, as they may be unable to demonstrate that individuals had a real choice and could decline or withdraw consent without detriment
- Informed. Consent must be informed, meaning individuals receive sufficient information to understand the processing and make a meaningful decision about whether to agree. At a minimum, they should be informed of the identity of the controller, the purposes of the processing, the types of personal data to be processed, their right to withdraw consent, and, where relevant, the use of automated decision-making and the risks of certain international data transfers. The information must be provided in clear, plain, and easily accessible language, rather than being buried in lengthy privacy notices or legal terms, so that individuals genuinely understand what they are consenting to. If the request for consent is vague, sweeping or difficult to understand, then it will be invalid. Recital 32 also makes clear that electronic consent requests must not be unnecessarily disruptive to users.
- Specific. Consent must be specific, requiring that each distinct purpose for processing be identified with sufficient precision so that individuals understand exactly what they are authorizing. Where multiple processing purposes exist, consent must be obtained separately for each purpose, allowing individuals to choose which processing activities they accept. Blanket consent for broad or undefined future uses is not sufficient. Likewise, consent should not be bundled with the acceptance of contractual terms or made a precondition for obtaining a product or service unless the processing is genuinely necessary for the performance of that contract. These requirements ensure that consent reflects a real and informed choice rather than a "take it or leave it" condition.
- Unambiguous. Finally, consent must be unambiguous, requiring a clear affirmative statement or deliberate action that unmistakably signifies agreement to a specific processing activity. The act of consenting must be distinguishable from other user actions, such as accepting general terms or simply navigating a website. Silence, inactivity, pre-ticked boxes, default settings, continued browsing, scrolling, or other passive behavior do not satisfy the GDPR standard, and controllers must be able to demonstrate that valid consent was obtained. The idea of an affirmative act does still leave room for implied methods of consent in some circumstances, particularly in more informal offline situations. The key issue is that there must still be a positive action that makes it clear someone is agreeing to the use of their information for a specific and obvious purpose. However, this type of implied method of indicating consent would not extend beyond what was obvious and necessary.
Practical Examples
Example: A user is presented with a clear explanation of why their data will be used and actively checks an unticked box to receive marketing emails. By contrast, consent is not valid where a website relies on a pre-ticked checkbox, default settings, or states that continued browsing or use of the website constitutes consent.
Example: An online furniture store requires customers to consent to their details being shared with other homeware stores as part of the checkout process. The store is making consent a condition of sale – but sharing the data with other stores is not necessary for that sale, so consent is not freely given and is not valid. The store could ask customers to consent to passing their data to named third parties but it must allow them a free choice to opt in or out. The store also requires customers to consent to their details being passed to a third-party courier who will deliver the goods. This is necessary to fulfill the order, so consent can be considered freely given - although ’performance of a contract’ is likely to be the more appropriate lawful basis.
Example: An individual drops their business card into a prize draw box in a coffee shop. This is an affirmative act that clearly indicates they agree to their name and contact number being processed for the purposes of the prize draw. However, this consent does not extend to using those details for marketing or any other purpose and you would need a different lawful basis to do so.
Example: An individual submits an online survey about their eating habits. By submitting the form they are clearly indicating consent to process their data for the purposes of the survey itself. Submitting the form will not, however, be enough by itself to show valid consent for any further uses of the information.

What is "Explicit Consent"?
For the purposes of Article 6, consent can be implied so long as it is unambiguous. The GDPR requires explicit consent only in a limited number of situations, including the processing of special categories of personal data (Article 9), certain automated individual decision-making (Article 22), and some transfers of personal data to third countries under Article 49. Although the GDPR does not define the term "explicit consent," it clearly requires a higher standard than ordinary consent.
The key distinction between ordinary and explicit consent lies in how consent is expressed. Ordinary consent may be demonstrated through a clear affirmative action, such as selecting an unticked checkbox or adjusting privacy settings. By contrast, explicit consent requires an express statement—whether written or oral—that leaves no doubt about the individual's intention to agree to the specific processing. Consent inferred solely from an individual's conduct, however obvious, is not explicit consent.
Controllers do not need individuals to draft their own consent statements. Instead, they may provide a clear consent statement for the individual to affirm by, for example, signing a form, ticking a checkbox next to an express declaration, or providing an equivalent affirmative statement electronically. Where explicit consent is required, the statement should specifically identify the processing activity that requires the higher standard of consent, such as the processing of special category data, an automated decision with legal or similarly significant effects, or an international transfer of personal data. The request for explicit consent should also be presented separately from other consent requests, allowing individuals to consent independently to each distinct processing activity.
Explicit consent may also be obtained orally, provided the controller can demonstrate that it was given. Organizations relying on oral explicit consent should therefore maintain an appropriate record of the consent statement and the individual's affirmative response.
Example: A beauty spa asks customers to complete an optional form describing their skin type and any skin conditions. If customers simply provide this information after being told it will be used to recommend suitable beauty products, they have likely given ordinary consent through a clear affirmative action. However, if the form instead includes the statement:
"I explicitly consent to the processing of my skin condition information to recommend appropriate beauty products." ☐
and the customer actively ticks the box, the spa has obtained explicit consent because the customer has expressly confirmed agreement to the processing of special category personal data.
How Long Does Consent Last?
There is no fixed duration for consent under the GDPR, but controllers should periodically review whether existing consent remains valid and renew it whenever circumstances materially change. If the processing evolves beyond what individuals originally agreed to, the original consent cannot be stretched to cover the new activities simply because the individual did not object. In those circumstances, the controller must either obtain fresh consent or identify another lawful basis for the new processing.
Whether consent remains valid depends on the context in which it was obtained, the scope of the original consent, the reasonable expectations of the individual, and whether the processing continues to reflect the purposes that were originally explained. As time passes, consent may no longer remain sufficiently specific or informed, particularly if the controller changes the nature, scope, or purpose of the processing.
Where consent was originally provided by a parent or legal guardian on behalf of a child, that consent does not automatically expire once the child reaches the age at which they can provide their own consent under Article 8. Nevertheless, controllers should consider whether it is appropriate to refresh consent as the child matures, particularly where the processing is ongoing or the nature of the service changes.
Example: A fitness center invites members to opt in to receive emails with nutrition and exercise tips to help them prepare for their summer vacation. Because the request clearly links the processing to a specific seasonal campaign, individuals would reasonably expect the emails to stop once the summer ends. Continuing to send similar marketing messages in subsequent years would require the fitness center to obtain fresh consent or rely on another valid lawful basis.
Withdrawing Consent
Consent is not a one-time event but an ongoing compliance obligation. Individuals have the right to withdraw consent at any time, and withdrawing consent must be as easy as giving it. Controllers must clearly inform individuals of this right before consent is obtained and provide practical mechanisms for exercising it. Although withdrawal does not affect processing already carried out lawfully before the withdrawal, the controller must stop any future processing that relied solely on consent. Because individuals have a right to withdraw consent at any time, if consent is the lawful basis for processing individuals do not have (or need) a right to restrict the processing.
Consent and Accountability
Finally, the accountability principle requires controllers to be able to demonstrate that valid consent was obtained. Organizations should therefore maintain appropriate records showing when consent was obtained, what information was provided to the individual at that time, how consent was expressed, and the specific processing activities covered. Where consent is relied upon for information society services offered directly to children, Article 8 requires parental authorization for children below the applicable age threshold established by Member State law (which may not be lower than 13 years).

Consent and Advertising
Profiling an individual's interests or preferences based on products purchased is generally not considered necessary for the performance of a contract. Although personalized advertising or product recommendations may enhance the customer experience and support the controller's business model, European data protection authorities have consistently taken the position that such processing is not objectively necessary to perform the underlying contract for the sale of goods or services. Controllers wishing to engage in profiling or targeted advertising must therefore identify another appropriate lawful basis, such as consent or legitimate interests, rather than relying on contractual necessity.
Further reading
ICO on Consent
The European Data Protection Board (EDPB) has produced Guidance on Consent.