Skip to main content
Category: Consent Requirements

Conditions for Consent

Also known as: Article 7 Conditions, Valid Consent Conditions
Simply put

Conditions for consent are the requirements that must be met for an individual's agreement to the use of their personal data to count as valid. Among other things, the organisation asking for consent must be able to show that the person actually agreed, and the request must be clear, easy to understand, and kept separate from other terms and conditions. Consent is only one of several possible legal bases for processing personal data, so it is not always required.

Formal definition

Under GDPR Article 7, where processing relies on consent as the Article 6 legal basis, the controller must be able to demonstrate that the data subject has consented to the processing of their personal data. A request for consent, where it forms part of a written declaration also concerning other matters, should generally be presented in a manner that is clearly distinguishable from those other matters, in an intelligible and easily accessible form, using plain language; per ICO guidance, the request should be prominent, concise, separate from other terms and conditions, and in plain language. Consent must, in most cases, be specific and informed, and mechanisms such as silence or pre-ticked boxes are generally not sufficient to constitute valid consent. Article 7 sets out conditions for consent but should be read together with the definition of consent and, for special category data under Article 9, an additional condition is required. Note that equivalent provisions exist under the UK GDPR and in other implementing frameworks (for example, ADGM's rulebook), and readers should verify the precise text of the applicable instrument, as national derogations and regulator guidance may affect the position.

Why it matters

Consent is one of the six lawful bases for processing personal data under GDPR Article 6, but where an organisation chooses to rely on it, the conditions for consent set the bar that the agreement must clear to be valid. If those conditions are not met, the consent may be treated as invalid, which can leave the underlying processing without a lawful basis. Because consent is only one option among several bases, organisations should first assess whether it is the most appropriate basis for a given activity rather than defaulting to it.

The practical significance lies in the demonstrability requirement: under Article 7, a controller must be able to show that the data subject actually consented. This shifts the burden onto the organisation to keep records that evidence how, when, and to what a person agreed. The requirements that a consent request be prominent, concise, separate from other terms and conditions, and in plain language exist so that agreement is a genuine, informed choice rather than something buried in wider contractual documents.

Subject to assessment, weaknesses such as vague requests, bundled consents, or reliance on silence or pre-ticked boxes can undermine validity. Where special category data under Article 9 is involved, an additional condition is required beyond the Article 6 basis. Readers should note that equivalent provisions exist under the UK GDPR and other frameworks, and that regulator guidance and national derogations may affect the precise position, so the applicable instrument should always be verified.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for selecting and documenting lawful bases need to assess whether consent is the appropriate basis and, where it is used, ensure the organisation can demonstrate valid consent. This includes maintaining records that evidence how and when consent was obtained and confirming that requests are prominent, concise, separate from other terms, and in plain language.
Privacy Lawyers and Advisors
Legal advisors interpreting Article 7 should read it together with the definition of consent and, for special category data, the additional Article 9 condition. They should also flag divergence between the GDPR, the UK GDPR, and other frameworks such as the ADGM rulebook, noting that national derogations and regulator guidance may affect the position and that the applicable instrument's text should be verified.
Engineers and Product Teams
Teams building consent-collection interfaces should design requests that are separate from other terms and conditions and avoid mechanisms such as silence or pre-ticked boxes, which are generally not sufficient. They should also ensure the system captures and retains evidence of consent so the controller can demonstrate it was given.
Marketing and Customer-Facing Teams
Teams that rely on consent for activities such as communications should present requests in plain, intelligible language and avoid bundling consent into broader agreements, since a vague or bundled request may undermine validity subject to assessment.

Inside Conditions for Consent

Freely given
Consent must reflect a genuine, unconstrained choice. Where there is a clear imbalance of power between the controller and the data subject (for example, in some employment contexts), or where consent is bundled as a condition of a service that does not require the processing, consent is generally not considered freely given.
Specific
Consent must relate to defined, particular processing purposes. Separate purposes generally require separate consent options rather than a single blanket agreement covering unrelated processing activities.
Informed
The data subject must be given sufficient information before consenting, typically including the identity of the controller, the purposes of the processing, and the right to withdraw. Without adequate information, consent is generally not valid.
Unambiguous indication
Consent requires a clear affirmative act, such as ticking an unticked box or an equivalent positive action. Silence, inactivity, or pre-ticked boxes do not generally constitute valid consent.
Demonstrability (accountability)
The controller must be able to demonstrate that the data subject consented to the relevant processing. This generally requires keeping records of how and when consent was obtained and what the data subject was told.
Right to withdraw
The data subject has the right to withdraw consent at any time, and it must be as easy to withdraw as to give consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Additional condition for special category data
Where processing involves special category data, consent under the general legal basis is not sufficient on its own; an additional condition applicable to special category data must also be satisfied. Practitioners should verify the applicable provisions against the current official text.

Common questions

Answers to the questions practitioners most commonly ask about Conditions for Consent.

Is consent always required to process personal data under the GDPR?
No. Consent is only one of the six lawful bases set out in Article 6 (alongside contract, legal obligation, vital interests, public task, and legitimate interests). It is a common misconception that every processing activity needs consent. In many cases another basis is more appropriate, and selecting the correct basis depends on the context and purpose of the processing. Note that processing special category data under Article 9 requires an additional condition beyond the Article 6 basis, so consent for that purpose is a distinct question that should be assessed separately.
Does pre-ticked box or continued use of a website count as valid consent?
Generally, no. The conditions for consent require a clear affirmative action, so silence, pre-ticked boxes, or inactivity typically do not constitute valid consent. Consent must generally be freely given, specific, informed, and unambiguous. Relying on assumed agreement rather than a genuine, positive choice is a frequent misconception, and regulators and guidance have consistently emphasised the need for an active indication of the individual's wishes. Readers should verify the specific requirements against the current official text and applicable regulatory guidance.
How can an organisation demonstrate that it obtained valid consent?
The controller generally bears the burden of demonstrating that consent was given, so it is typically advisable to keep records of what the individual was told, when and how consent was obtained, and what they consented to. In practice this often involves retaining the version of the consent notice presented, timestamps, and the mechanism used. The appropriate level of record-keeping depends on the context and risk of the processing, and specific expectations may vary between regulators, so readers should confirm against current guidance.
How should consent be structured when there are multiple processing purposes?
Consent should generally be specific to each purpose. Where processing serves several distinct purposes, it is typically expected that individuals can consent to each one separately rather than being asked to agree to a bundle. Combining unrelated purposes into a single request may undermine the requirement that consent be specific and freely given. The precise approach depends on the purposes involved and should be assessed case by case, subject to applicable guidance.
How do the conditions for consent affect withdrawal mechanisms?
It should generally be as easy to withdraw consent as it was to give it, and individuals should typically be informed of the right to withdraw before consent is given. Withdrawal does not, in most cases, affect the lawfulness of processing carried out before withdrawal. Organisations often need to design withdrawal mechanisms and downstream processes so that a withdrawal is acted upon appropriately. The operational details depend on the systems and context involved.
What special considerations apply when relying on consent for children or in an employment context?
Consent can be more difficult to rely on where there is an imbalance of power, such as between an employer and employee, because it may not be considered freely given; another lawful basis is often more appropriate in such cases, subject to assessment. For children, additional conditions can apply, and the relevant age threshold may vary because member states can set their own within the range permitted by the Regulation. Because national implementing law and derogations can vary the position, readers should verify the applicable rules for their jurisdiction against the current official text.

Common misconceptions

Consent is always required to process personal data.
Consent is only one of several distinct legal bases. Depending on the context, processing may instead rely on contract, legal obligation, vital interests, public task, or legitimate interests. Consent should not be treated as a default or universal requirement, and the appropriate basis depends on the specific processing.
Once consent is obtained it is permanent and covers future processing.
Consent can be withdrawn by the data subject at any time, and it is tied to the specific purposes for which it was given. New or materially different purposes generally require a fresh basis, and controllers should not rely on old consent to justify unrelated processing.
A pre-ticked box or continued use of a service counts as consent.
Valid consent generally requires a clear affirmative act. Pre-ticked boxes, silence, or inactivity do not meet the unambiguous indication requirement, and bundling consent into a service condition can undermine whether it is freely given.

Best practices

Before relying on consent, confirm it is the most appropriate legal basis rather than defaulting to it, since another Article 6 basis may fit the processing better and be more sustainable.
Use clear affirmative mechanisms such as unticked opt-in boxes, and avoid pre-ticked boxes, bundling, or reliance on silence or continued use.
Separate consent requests by purpose so data subjects can agree to some processing without being forced to accept all of it.
Provide, at the point of consent, the information needed for it to be informed, including the controller's identity, the processing purposes, and how to withdraw.
Maintain records demonstrating what each data subject was told and when and how consent was obtained, to satisfy the accountability requirement.
Make withdrawal of consent as easy as giving it, and ensure that where special category data is involved an additional applicable condition is identified and documented, verifying the requirements against the current official text.