GDPR consent is a freely given, specific, informed, and unambiguous indication of a data subject wish, expressed through a clear affirmative action. Defined in Article 4(11) and governed by Article 7, it is one of six lawful bases for processing personal data, and the most demanding to get right.
The Four Pillars of Valid Consent
Article 4(11) packs four requirements into one sentence. Miss any of them and the consent is invalid, which means the processing has no lawful basis at all.
- Freely given: there must be a genuine choice, with no coercion, bundling, or detriment for saying no
- Specific: consent covers a defined purpose, not a vague catch-all for anything you might do later
- Informed: the person knows who is processing their data, what for, and that they can withdraw
- Unambiguous: a clear affirmative act is required, so silence, inactivity, and pre-ticked boxes do not count
The unambiguous requirement is where many cookie banners fail. A pre-checked box or a design where scrolling is treated as agreement is not a clear affirmative action. The person must do something deliberate, such as clicking Accept, to signal consent.
Conditions for Consent Under Article 7
Article 7 adds operational conditions on top of the definition. First, you must be able to demonstrate that the individual consented, so record keeping is not optional. Second, if consent is sought within a document that deals with other matters, the request must be clearly distinguishable, in plain language, and easy to access.
Freely given also has a specific test. Article 7(4) says that when assessing whether consent is free, you take utmost account of whether performing a contract is conditional on consent to processing that is not necessary for that contract. Forcing a user to accept marketing tracking to use a service they paid for is the classic example of consent that is not freely given.
On 19 March 2026 the EDPB launched its fifth Coordinated Enforcement Framework, focused on transparency obligations under Articles 12 to 14, with national authorities across the EU running parallel investigations (EDPB, 2026). Consent notices that are unclear or buried are squarely in scope.
Withdrawal Must Be As Easy As Giving
Article 7(3) gives individuals the right to withdraw consent at any time, and it must be as easy to withdraw as it was to give. If a single click enrolled someone, a single click must let them leave. A design that takes one tap to opt in but a phone call and a written request to opt out is non-compliant.
Withdrawal is not retroactive. Processing that happened before withdrawal remains lawful, but you must stop the consent-based processing once consent is pulled. You must also tell people about the right to withdraw before they consent, not afterwards.
When Consent Is the Wrong Lawful Basis
Consent is often the wrong choice. If you cannot offer a real choice, do not dress the processing up as consent. Where there is a power imbalance, for example between an employer and an employee, consent is rarely valid because refusal carries risk. Where processing is necessary to perform a contract, to comply with a legal obligation, or to pursue a legitimate interest, one of those bases is usually stronger and more durable.
Picking the right basis is a foundational step in any programme, which we walk through in our guide to implementing GDPR step by step. Choose consent only when you can genuinely honour a no, including an easy withdrawal.
Children, Cookies, and the ePrivacy Overlap
Article 8 sets a special rule for information society services offered directly to children. Processing based on consent is lawful where the child is at least 16, though member states may lower this to no younger than 13. Below that age, consent must be given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify it using available technology.
Cookies add another layer. The ePrivacy Directive, at Article 5(3), requires consent before any non-essential cookie or tracker is placed on a device, regardless of the user age. That consent must meet the GDPR standard. So a cookie banner is not just a formality; it is where ePrivacy and GDPR consent rules meet, and it is one of the most heavily enforced areas in practice.
Running a Consent Management Platform
A consent management platform, or CMP, is the system that captures, stores, and honours consent decisions across your website and services. Done well, it is your evidence of compliance under Article 7(1). Done badly, it becomes a liability that regulators can point to directly.
Use this checklist to judge whether your consent management is compliant.
- Reject is as prominent and easy as Accept, with no dark patterns nudging agreement
- No non-essential cookies or trackers fire before an affirmative choice is made
- Each purpose can be consented to separately rather than as a single bundle
- A timestamped record shows who consented, to what, and when, for the demonstrability requirement
- Withdrawal is available through the same interface and is as easy as the original opt-in
- A child-aware flow adjusts the age gate and seeks parental consent where required
Consent records also connect to the wider machinery of privacy compliance. When someone exercises a data subject access request, you need to show the basis on which their data was processed, and your records of processing activities should reflect where consent is the chosen basis. We cover both in our guides to handling DSARs and building a records of processing register.