Separate Consent for Distinct Purposes
This is the practice of asking people to agree separately to each different use of their personal data, rather than bundling everything into one all-or-nothing agreement. For example, if an organisation wants to use your data both to fulfil an order and to send you marketing, it should let you say yes to one without being forced to accept the other. The aim is to give individuals real, specific choices over how their information is used.
Separate (granular) consent refers to the requirement that, where consent is relied upon as a lawful basis, controllers offer distinct consent options for different processing purposes and, where relevant, different types of processing, rather than seeking a single bundled consent. Under the UK GDPR, the ICO guidance indicates that organisations should provide separate, distinct ('granular') options to consent separately to different purposes and types of processing; equivalent granularity expectations apply under the EU GDPR framework, though practitioners should verify the current text and regulator guidance for the applicable jurisdiction. This concept is closely tied to the conditions for valid consent (consent must generally be specific, informed, freely given, and an unambiguous indication of the data subject's wishes), and it is relevant only where consent is the chosen Article 6 basis; other lawful bases do not require consent, and special category data processing typically requires an additional condition. The precise application can vary by regulator and by processing context, and granularity requirements should be assessed against current official guidance rather than treated as a fixed formula.
Why it matters
Separate consent for distinct purposes is central to whether a consent-based processing operation is lawful at all. Where consent is the chosen Article 6 basis, it must generally be specific, informed, freely given, and an unambiguous indication of the individual's wishes. Bundling several unrelated purposes into a single accept-or-reject choice undermines the 'specific' and 'freely given' elements, because the individual cannot exercise a genuine choice over each use of their data. The ICO's guidance is explicit that organisations should give separate, distinct ('granular') options to consent separately to different purposes and types of processing, and comparable granularity expectations apply under the EU GDPR framework.
Getting this wrong has practical consequences. If consent is found to be invalid because it was bundled, the underlying processing may lack a lawful basis, which can expose an organisation to regulatory action and to challenges from data subjects. It can also cascade: a marketing programme built on defective consent may need to be paused and consent re-collected, and downstream sharing or profiling relying on that consent may be affected. Because granularity is assessed against the specific processing context and the current regulator guidance, organisations cannot treat a one-time consent design as permanently safe.
Granularity is not a universal requirement, and this is where organisations often overreach in the opposite direction. It applies only where consent is the lawful basis being relied on; other Article 6 bases such as contract, legal obligation, or legitimate interests do not require consent and therefore do not require granular consent options. Where special category data is involved, an additional Article 9 condition is generally needed on top of the Article 6 basis. Treating consent as a default for everything, and then having to make it granular, can be less appropriate than selecting a more suitable lawful basis in the first place.
Who it's relevant to
Inside Separate Consent for Distinct Purposes
Common questions
Answers to the questions practitioners most commonly ask about Separate Consent for Distinct Purposes.