Consent
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Freely given, specific, informed indication of data subject wishes
Overview
21 sources · Jul 15, 2026Legal Framework
Consent under the GDPR is governed primarily by Articles 4(11), 6(1)(a), 7, and 8. Article 4(11) defines consent as a freely given, specific, informed, and unambiguous indication of the data subject's wishes, expressed by a statement or clear affirmative action. Article 7 sets the conditions for valid consent: the controller must demonstrate that consent was obtained, consent must be as easy to withdraw as to give, and where processing is conditional on consent, the controller must be able to show that the data subject's freedom of choice was genuine. Article 8 imposes additional protections for children below the age of 16 (or lower where Member State law permits) in the context of information society services offered directly to children.
The requirement that consent be freely given means the data subject must have a real and free choice — the ability to refuse or withdraw consent without suffering adverse consequences. Consent cannot be considered freely given where separate consent cannot be given for different personal data processing operations that serve different purposes. This granularity requirement prevents bundling: a data subject must be able to consent to one processing activity while declining another.
Key Developments
The CJEU's ruling in Fashion ID GmbH & Co. KG v. Verbraucherzentrale NRW (C-40/17) established that where multiple parties are involved in processing — such as a website operator embedding a social plugin — consent need only be obtained by a controller for the specific operations in respect of which it determines the purposes and means. This narrows the scope of consent obligations for joint controllers to their actual sphere of control, but also clarifies that each controller bears responsibility for informing data subjects about the processing it alone determines.
In Schrems II (C-311/18), the CJEU confirmed that Article 49(1)(a) GDPR permits transfers to third countries based on the data subject's explicit consent, but only after the data subject has been informed of the specific risks arising from the absence of an adequacy decision or appropriate safeguards. This creates a heightened informed-consent standard for international data transfers.
Enforcement actions confirm that consent failures attract significant penalties. The ICO fined MediaLab.AI €284,450 for failures on the Imgur platform, while the Hellenic DPA imposed an €80,000 fine on ONE WAY Private Company. The EDPB's Guidelines 05/2020 on consent remain the central interpretive reference, supplemented by Guidelines 06/2020 addressing the interplay between PSD2 and the GDPR.
Practical Guidance
- Implement granular consent mechanisms: Separate consent toggles must be provided for each distinct processing purpose. Pre-ticked boxes, silence, or inactivity never constitute valid consent under Article 4(11).
- Document the consent record: Under Article 7(1), the controller bears the burden of demonstrating valid consent. Maintain logs showing what was presented, when consent was given, what information accompanied it, and the specific purposes acknowledged.
- Ensure withdrawal is frictionless: Article 7(3) requires that withdrawal be as easy as giving consent. A withdrawal mechanism must be accessible at all times, without requiring account login barriers or multi-step processes disproportionate to the original consent flow.
- Apply heightened standards for transfers: Where relying on Article 49(1)(a) for third-country transfers, obtain explicit (not merely unambiguous) consent and document that the data subject was specifically informed of the risks of transfers without adequacy decisions or safeguards.
- Verify age for information society services: Under Article 8, implement reasonable age verification measures for services offered to children, and obtain parental authorization where the data subject is below the applicable national age threshold.