Consent
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Freely given, specific, informed indication of data subject wishes
Overview
28 sources · Aug 27, 2026Legal Framework
Consent under the GDPR is governed primarily by Article 7 (conditions for consent), Article 8 (child's consent for information society services), and Article 9 (explicit consent for special categories). The definitional anchor sits in Article 4(11), which frames consent as a freely given, specific, informed, and unambiguous indication of the data subject's wishes.
Article 7 imposes four operational burdens on controllers. First, the controller bears the burden of demonstrating valid consent. Second, when consent is embedded in a written declaration covering other matters, it must be presented separately, in clear and plain language. Third, withdrawal must be as straightforward as giving consent:
"It shall be as easy to withdraw as to give consent."
— GDPR Art. 7(3)
Fourth, Article 7(4) instructs assessors to weigh whether consent is genuinely freely given — particularly when performance of a contract is conditioned on consent to processing that is not necessary for that contract. This provision targets bundling and imbalance of power.
Article 8 raises the age threshold for independent consent to 16 for information society services offered directly to children, with a floor of 13 where Member States legislate a lower age. Controllers must make reasonable efforts to verify parental authorisation. Article 9(2)(a) introduces a heightened standard — explicit consent — for special category data, requiring an express affirmative act rather than implied agreement.
Key Developments
Enforcement decisions have crystallised several practical thresholds. The Belgian DPA's decision against a legal information website addressed pre-ticked cookie consent boxes, finding that:
"the consent was obtained on the basis of already ticked windows,"
— Belgian DPA, Website providing legal information §5
This confirms that opt-out or pre-ticked mechanisms do not constitute valid consent. The Swedish DPA's Skellefteå school decision addressed the power-imbangle dimension directly, fining a school for deploying facial recognition to track attendance. The authority held that:
"consent can not be applied since students and their guardians cannot freely decide if they/their children want to be monitored for attendance purposes"
— Swedish DPA, School in Skellefteå §1
This signals that dependency relationships — school-student, employer-employee — frequently vitiate the "freely given" element, regardless of whether consent is formally obtained. The German DPA's police officer enforcement further illustrates that consent cannot cure processing undertaken without any legitimate basis or purpose specification.
Status of the Debate
Consent is actively contested in court. While the core statutory requirements are well-established, their application to novel processing contexts — workplace monitoring, biometric attendance, cookie walls, and bundled service consent — remains fought over. Courts and DPAs diverge on where the line between valid consent and coerced acquiescence falls, particularly in relationships involving dependency or service necessity. The unresolved question is how far Article 7(4)'s conditionality test extends: does it invalidate consent whenever any non-essential processing is bundled with a service, or only when the bundling creates genuine detriment? A CJEU referral on granular consent for separate processing purposes would resolve the open boundary.
Practical Guidance
- Document the affirmative act: Maintain records showing who consented, when, to what specific purposes, and via what interface — Article 7(1) places the burden of proof squarely on the controller.
- Separate consent from terms: Present consent requests distinctly from terms of service, privacy policies, and contractual clauses, using clear and plain language per Article 7(2).
- Engineer symmetric withdrawal: Implement a withdrawal mechanism that is technically and operationally as simple as the consent mechanism — a one-click opt-out accessible from the same surface where consent was given.
- Assess power dynamics before relying on consent: In employment, education, and public-authority contexts, evaluate whether the data subject can refuse without detriment; if not, identify an alternative lawful basis under Article 6(1).
- Avoid pre-ticked boxes and bundled purposes: Ensure each processing purpose receives separate, unambiguous affirmation; granular toggles for distinct purposes are the safest configuration.
why this is here
Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.
The provision directly sets out the core requirements for consent as a lawful basis for processing, making it a primary source for this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
The entire document is about consent under GDPR, making it central to this topic.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the data subject has given consent to the processing of his or her personal data for one or more specific purposes
The document includes a section 'Explicit Consent' discussing consent under GDPR and PSD2, including differences.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
such processing shall be lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility
The provision operationalises consent as a lawful basis specifically for children, but it does not define or elaborate the general conditions of consent, which are set out in Article 4(11) and Article 7, so it bears on the topic without being central.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
the “explicit consent derogation”
The document identifies explicit consent as one of the Article 49 derogations.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the data subject withdraws consent on which the processing is based (Article 17.1.b)
The document lists consent withdrawal as a ground for erasure but notes it is rarely used in delisting.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
The underlying processing of personal data which results in the delivery of a targeted message is often opaque.
Mentions user control but not consent as a lawful basis.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
mechanisms for obtaining parental consent
The document lists parental consent mechanisms as a topic that codes may cover, but does not discuss consent as a lawful basis.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 27 Laws · all 110 Guidance · all 180 Case Law · all 508 Enforcement · all 138 News · all 68 Literature