Privacy & Data Protection

GDPR Consent: Rules, Withdrawal, and Management

Standarity Editorial Team·GDPR and privacy management practitioners
··7 min read

GDPR consent is a freely given, specific, informed, and unambiguous indication of a data subject wish, expressed through a clear affirmative action. Defined in Article 4(11) and governed by Article 7, it is one of six lawful bases for processing personal data, and the most demanding to get right.

The Four Pillars of Valid Consent

Article 4(11) packs four requirements into one sentence. Miss any of them and the consent is invalid, which means the processing has no lawful basis at all.

  • Freely given: there must be a genuine choice, with no coercion, bundling, or detriment for saying no
  • Specific: consent covers a defined purpose, not a vague catch-all for anything you might do later
  • Informed: the person knows who is processing their data, what for, and that they can withdraw
  • Unambiguous: a clear affirmative act is required, so silence, inactivity, and pre-ticked boxes do not count

The unambiguous requirement is where many cookie banners fail. A pre-checked box or a design where scrolling is treated as agreement is not a clear affirmative action. The person must do something deliberate, such as clicking Accept, to signal consent.

Conditions for Consent Under Article 7

Article 7 adds operational conditions on top of the definition. First, you must be able to demonstrate that the individual consented, so record keeping is not optional. Second, if consent is sought within a document that deals with other matters, the request must be clearly distinguishable, in plain language, and easy to access.

Freely given also has a specific test. Article 7(4) says that when assessing whether consent is free, you take utmost account of whether performing a contract is conditional on consent to processing that is not necessary for that contract. Forcing a user to accept marketing tracking to use a service they paid for is the classic example of consent that is not freely given.

On 19 March 2026 the EDPB launched its fifth Coordinated Enforcement Framework, focused on transparency obligations under Articles 12 to 14, with national authorities across the EU running parallel investigations (EDPB, 2026). Consent notices that are unclear or buried are squarely in scope.

Withdrawal Must Be As Easy As Giving

Article 7(3) gives individuals the right to withdraw consent at any time, and it must be as easy to withdraw as it was to give. If a single click enrolled someone, a single click must let them leave. A design that takes one tap to opt in but a phone call and a written request to opt out is non-compliant.

Withdrawal is not retroactive. Processing that happened before withdrawal remains lawful, but you must stop the consent-based processing once consent is pulled. You must also tell people about the right to withdraw before they consent, not afterwards.

When Consent Is the Wrong Lawful Basis

Consent is often the wrong choice. If you cannot offer a real choice, do not dress the processing up as consent. Where there is a power imbalance, for example between an employer and an employee, consent is rarely valid because refusal carries risk. Where processing is necessary to perform a contract, to comply with a legal obligation, or to pursue a legitimate interest, one of those bases is usually stronger and more durable.

Picking the right basis is a foundational step in any programme, which we walk through in our guide to implementing GDPR step by step. Choose consent only when you can genuinely honour a no, including an easy withdrawal.

Children, Cookies, and the ePrivacy Overlap

Article 8 sets a special rule for information society services offered directly to children. Processing based on consent is lawful where the child is at least 16, though member states may lower this to no younger than 13. Below that age, consent must be given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify it using available technology.

Cookies add another layer. The ePrivacy Directive, at Article 5(3), requires consent before any non-essential cookie or tracker is placed on a device, regardless of the user age. That consent must meet the GDPR standard. So a cookie banner is not just a formality; it is where ePrivacy and GDPR consent rules meet, and it is one of the most heavily enforced areas in practice.

Running a Consent Management Platform

A consent management platform, or CMP, is the system that captures, stores, and honours consent decisions across your website and services. Done well, it is your evidence of compliance under Article 7(1). Done badly, it becomes a liability that regulators can point to directly.

Use this checklist to judge whether your consent management is compliant.

  • Reject is as prominent and easy as Accept, with no dark patterns nudging agreement
  • No non-essential cookies or trackers fire before an affirmative choice is made
  • Each purpose can be consented to separately rather than as a single bundle
  • A timestamped record shows who consented, to what, and when, for the demonstrability requirement
  • Withdrawal is available through the same interface and is as easy as the original opt-in
  • A child-aware flow adjusts the age gate and seeks parental consent where required

Consent records also connect to the wider machinery of privacy compliance. When someone exercises a data subject access request, you need to show the basis on which their data was processed, and your records of processing activities should reflect where consent is the chosen basis. We cover both in our guides to handling DSARs and building a records of processing register.

Frequently Asked Questions

What makes consent valid under GDPR?

Valid consent must be freely given, specific, informed, and unambiguous, and it must be expressed through a clear affirmative action. Article 7 adds that you must be able to demonstrate consent was given and that the person can withdraw it as easily as they gave it.

Are pre-ticked boxes allowed for GDPR consent?

No. Consent requires a clear affirmative action, so silence, inactivity, and pre-ticked or default-selected boxes do not qualify. The individual must take a deliberate step, such as actively clicking to accept, for consent to be valid.

How easy must it be to withdraw GDPR consent?

Article 7(3) requires that withdrawing consent is as easy as giving it. If one click enrolled the person, one click should let them withdraw. Withdrawal does not undo processing that was lawful beforehand, but it must stop future consent-based processing.

What age can a child give consent under GDPR?

For information society services offered directly to children, consent is lawful from age 16 by default. Member states may set a lower age, but not below 13. Under the applicable age, a holder of parental responsibility must give or authorise consent.

Is consent always required for cookies?

Consent is required for non-essential cookies and trackers under the ePrivacy Directive Article 5(3), and that consent must meet the GDPR standard. Strictly necessary cookies, such as those needed to make a site function, do not require consent.

When should I not use consent as a lawful basis?

Avoid consent when you cannot offer a genuine choice, such as where there is a power imbalance or where processing is necessary anyway. In those cases a basis like contract, legal obligation, or legitimate interests is usually more appropriate and more durable.

Explore Courses on Udemy

Intermediate

Implement GDPR Step by Step with Templates

Intermediate

Implement CCPA (California Consumer Privacy Act) Step by Step

Intermediate

ISO/IEC 27701: Implement Privacy Management Step by Step