Skip to content
Topic Contested in court

Consent

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Freely given, specific, informed indication of data subject wishes

1,032 linked items 27 Laws180 Case Law110 Guidance508 Enforcement138 News

Overview

28 sources · Aug 27, 2026

Legal Framework

Consent under the GDPR is governed primarily by Article 7 (conditions for consent), Article 8 (child's consent for information society services), and Article 9 (explicit consent for special categories). The definitional anchor sits in Article 4(11), which frames consent as a freely given, specific, informed, and unambiguous indication of the data subject's wishes.

Article 7 imposes four operational burdens on controllers. First, the controller bears the burden of demonstrating valid consent. Second, when consent is embedded in a written declaration covering other matters, it must be presented separately, in clear and plain language. Third, withdrawal must be as straightforward as giving consent:

"It shall be as easy to withdraw as to give consent."
— GDPR Art. 7(3)

Fourth, Article 7(4) instructs assessors to weigh whether consent is genuinely freely given — particularly when performance of a contract is conditioned on consent to processing that is not necessary for that contract. This provision targets bundling and imbalance of power.

Article 8 raises the age threshold for independent consent to 16 for information society services offered directly to children, with a floor of 13 where Member States legislate a lower age. Controllers must make reasonable efforts to verify parental authorisation. Article 9(2)(a) introduces a heightened standard — explicit consent — for special category data, requiring an express affirmative act rather than implied agreement.

Key Developments

Enforcement decisions have crystallised several practical thresholds. The Belgian DPA's decision against a legal information website addressed pre-ticked cookie consent boxes, finding that:

"the consent was obtained on the basis of already ticked windows,"
— Belgian DPA, Website providing legal information §5

This confirms that opt-out or pre-ticked mechanisms do not constitute valid consent. The Swedish DPA's Skellefteå school decision addressed the power-imbangle dimension directly, fining a school for deploying facial recognition to track attendance. The authority held that:

"consent can not be applied since students and their guardians cannot freely decide if they/their children want to be monitored for attendance purposes"
— Swedish DPA, School in Skellefteå §1

This signals that dependency relationships — school-student, employer-employee — frequently vitiate the "freely given" element, regardless of whether consent is formally obtained. The German DPA's police officer enforcement further illustrates that consent cannot cure processing undertaken without any legitimate basis or purpose specification.

Status of the Debate

Consent is actively contested in court. While the core statutory requirements are well-established, their application to novel processing contexts — workplace monitoring, biometric attendance, cookie walls, and bundled service consent — remains fought over. Courts and DPAs diverge on where the line between valid consent and coerced acquiescence falls, particularly in relationships involving dependency or service necessity. The unresolved question is how far Article 7(4)'s conditionality test extends: does it invalidate consent whenever any non-essential processing is bundled with a service, or only when the bundling creates genuine detriment? A CJEU referral on granular consent for separate processing purposes would resolve the open boundary.

Practical Guidance

  • Document the affirmative act: Maintain records showing who consented, when, to what specific purposes, and via what interface — Article 7(1) places the burden of proof squarely on the controller.
  • Separate consent from terms: Present consent requests distinctly from terms of service, privacy policies, and contractual clauses, using clear and plain language per Article 7(2).
  • Engineer symmetric withdrawal: Implement a withdrawal mechanism that is technically and operationally as simple as the consent mechanism — a one-click opt-out accessible from the same surface where consent was given.
  • Assess power dynamics before relying on consent: In employment, education, and public-authority contexts, evaluate whether the data subject can refuse without detriment; if not, identify an alternative lawful basis under Article 6(1).
  • Avoid pre-ticked boxes and bundled purposes: Ensure each processing purpose receives separate, unambiguous affirmation; granular toggles for distinct purposes are the safest configuration.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 7 Conditions for consent Laws GDPR Apr 2016 Conditions for valid consent
why this is here
Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.

The provision directly sets out the core requirements for consent as a lawful basis for processing, making it a primary source for this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB Guidance EDPB May 2020 consent definition and conditions
why this is here
any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

The entire document is about consent under GDPR, making it central to this topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 06/2020 interplay of the Second Payment Services Directive and the GDPR Guidelines on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR Guidelines ·EDPB Guidance EDPB Dec 2020 Consent as legal basis
why this is here
the data subject has given consent to the processing of his or her personal data for one or more specific purposes

The document includes a section 'Explicit Consent' discussing consent under GDPR and PSD2, including differences.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

art 8 Conditions applicable to child's consent in relation to information society services Laws GDPR Apr 2016 consent as lawful basis for children
why this is here
such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility

The provision operationalises consent as a lawful basis specifically for children, but it does not define or elaborate the general conditions of consent, which are set out in Article 4(11) and Article 7, so it bears on the topic without being central.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 2/2018 derogations of Article 49 under Regulation 2016/679 Guidelines on derogations of Article 49 Guidelines ·EDPB Guidance EDPB May 2018 Explicit consent as derogation
why this is here
the “explicit consent derogation”

The document identifies explicit consent as one of the Article 49 derogations.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 5/2019 criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) Guidelines ·EDPB Guidance EDPB Jul 2020 Consent withdrawal ground
why this is here
the data subject withdraws consent on which the processing is based (Article 17.1.b)

The document lists consent withdrawal as a ground for erasure but notes it is rarely used in delisting.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Consent mention
why this is here
The underlying processing of personal data which results in the delivery of a targeted message is often opaque.

Mentions user control but not consent as a lawful basis.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2019 Codes of Conduct and Monitoring Bodies under Regulation 2016/679 Guidelines on codes of conduct and monitoring bodies Guidelines ·EDPB Guidance EDPB Jun 2019 parental consent as code topic
why this is here
mechanisms for obtaining parental consent

The document lists parental consent mechanisms as a topic that codes may cover, but does not discuss consent as a lawful basis.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 27 Laws · all 110 Guidance · all 180 Case Law · all 508 Enforcement · all 138 News · all 68 Literature