Consent Not Freely Given
Consent is one of the ways an organisation can be allowed to use someone's personal data, but it only counts if the person had a real, unpressured choice to say yes or no. Consent is treated as 'not freely given' when the individual has no genuine choice, cannot refuse, or cannot withdraw their agreement without suffering some disadvantage. In such cases the consent is generally not valid, and the organisation typically cannot rely on it to justify the processing.
"Consent not freely given" describes a failure of one of the cumulative requirements for valid consent under the GDPR framework, where consent must be freely given, specific, informed and unambiguous. According to ICO guidance, consent should not be regarded as freely given where the data subject has no genuine or free choice, or is unable to refuse or withdraw consent without detriment. Recital 43 indicates consent is presumed not to be freely given where a controller does not permit separate consent for distinct processing operations, and imbalances of power or conditionality (for example, tying consent to the performance of a service that does not require the processing) are commonly cited factors weighing against free choice, though such assessments are fact-specific. Where the free-choice element fails, the consent is generally invalid as an Article 6 lawful basis, and a controller may need to consider whether another lawful basis applies; special category data would additionally require a separate condition. This definition addresses only the 'freely given' element and does not cover the specific, informed, or unambiguous requirements, and practitioners should verify the precise conditions and any national or UK GDPR variations against the current official text and applicable regulatory guidance.
Why it matters
Consent is only one of several lawful bases available under Article 6 of the GDPR, but it is often the most fragile because it depends entirely on the quality of the individual's choice. When consent is not freely given, it is generally invalid, which means the processing it was meant to justify may have no lawful basis at all. An organisation that has relied on consent and later finds that consent was not freely given typically faces a gap: it must either identify an alternative lawful basis that genuinely applies or stop the processing. For special category data under Article 9, a separate condition would also be required, so the exposure can be compounded.
The 'freely given' element is particularly sensitive to power imbalances and conditionality. ICO guidance indicates that consent should not be regarded as freely given where the data subject has no genuine or free choice, or is unable to refuse or withdraw consent without detriment. Recital 43 goes further by treating consent as presumed not freely given where a controller does not permit separate consent for distinct processing operations, or where consent is bundled or tied to a service in a way that removes real choice. Because these assessments are fact-specific, the same design pattern may pass or fail depending on context, so organisations cannot assume that a consent mechanism that worked in one setting will be valid in another.
The practical stakes are high because consent-based processing that later collapses can undermine an entire product feature, marketing programme, or data-sharing arrangement retrospectively. Practitioners should note that regulatory interpretation and national or UK GDPR variations can affect where the boundary lies, and the precise conditions should be verified against the current official text and applicable guidance rather than treated as settled.
Who it's relevant to
Inside Consent Not Freely Given
Common questions
Answers to the questions practitioners most commonly ask about Consent Not Freely Given.