Skip to main content
Category: Consent Requirements

Separate Consent for Distinct Purposes

Also known as: Granular Consent, Granularity of Consent
Simply put

This is the practice of asking people to agree separately to each different use of their personal data, rather than bundling everything into one all-or-nothing agreement. For example, if an organisation wants to use your data both to fulfil an order and to send you marketing, it should let you say yes to one without being forced to accept the other. The aim is to give individuals real, specific choices over how their information is used.

Formal definition

Separate (granular) consent refers to the requirement that, where consent is relied upon as a lawful basis, controllers offer distinct consent options for different processing purposes and, where relevant, different types of processing, rather than seeking a single bundled consent. Under the UK GDPR, the ICO guidance indicates that organisations should provide separate, distinct ('granular') options to consent separately to different purposes and types of processing; equivalent granularity expectations apply under the EU GDPR framework, though practitioners should verify the current text and regulator guidance for the applicable jurisdiction. This concept is closely tied to the conditions for valid consent (consent must generally be specific, informed, freely given, and an unambiguous indication of the data subject's wishes), and it is relevant only where consent is the chosen Article 6 basis; other lawful bases do not require consent, and special category data processing typically requires an additional condition. The precise application can vary by regulator and by processing context, and granularity requirements should be assessed against current official guidance rather than treated as a fixed formula.

Why it matters

Separate consent for distinct purposes is central to whether a consent-based processing operation is lawful at all. Where consent is the chosen Article 6 basis, it must generally be specific, informed, freely given, and an unambiguous indication of the individual's wishes. Bundling several unrelated purposes into a single accept-or-reject choice undermines the 'specific' and 'freely given' elements, because the individual cannot exercise a genuine choice over each use of their data. The ICO's guidance is explicit that organisations should give separate, distinct ('granular') options to consent separately to different purposes and types of processing, and comparable granularity expectations apply under the EU GDPR framework.

Getting this wrong has practical consequences. If consent is found to be invalid because it was bundled, the underlying processing may lack a lawful basis, which can expose an organisation to regulatory action and to challenges from data subjects. It can also cascade: a marketing programme built on defective consent may need to be paused and consent re-collected, and downstream sharing or profiling relying on that consent may be affected. Because granularity is assessed against the specific processing context and the current regulator guidance, organisations cannot treat a one-time consent design as permanently safe.

Granularity is not a universal requirement, and this is where organisations often overreach in the opposite direction. It applies only where consent is the lawful basis being relied on; other Article 6 bases such as contract, legal obligation, or legitimate interests do not require consent and therefore do not require granular consent options. Where special category data is involved, an additional Article 9 condition is generally needed on top of the Article 6 basis. Treating consent as a default for everything, and then having to make it granular, can be less appropriate than selecting a more suitable lawful basis in the first place.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads are typically responsible for confirming that consent mechanisms offer distinct options for distinct purposes where consent is the chosen lawful basis. They should ensure the organisation has first assessed whether consent is the appropriate Article 6 basis at all, and that special category processing carries an additional Article 9 condition. Because granularity expectations are guidance-driven and can vary by regulator, they should review consent designs against current official guidance rather than a fixed template.
Marketing and CRM Teams
Teams running email, profiling, or personalisation programmes are most likely to encounter bundling problems, since marketing is a common purpose that should generally be consented to separately from purposes such as order fulfilment. They should design consent capture so that individuals can opt into each purpose independently and should coordinate with privacy colleagues before relying on consent for new uses.
Product and Engineering Teams
Those building consent flows, preference centres, and consent-management functionality translate granularity requirements into interfaces. They should support separate, distinct options per purpose and avoid patterns such as pre-ticked boxes or all-or-nothing acceptance that undermine specific, freely given consent. Where consent may later change, they may need to accommodate re-consent processes appropriate to the context.
Compliance and Legal Advisers
Advisers assessing whether processing is lawful need to test whether consent was genuinely specific and freely given, which includes examining granularity. They should flag where consent may be the wrong basis, note divergence between UK and EU positions and between regulators, and confirm conclusions against the current applicable text and guidance rather than presenting a single interpretation as settled.
Research and Clinical Organisations
Organisations processing personal data in research or clinical settings should note that ethical informed consent to participate in research is a distinct notion from consent as a data protection lawful basis, and the two should not be conflated. Where re-consenting is needed, established processes describe options such as reviewing a revised consent form in full; the appropriate approach should be assessed against the rules and guidance applicable to the specific study.

Inside Separate Consent for Distinct Purposes

Purpose Specification
Each processing purpose must be identified clearly and separately, so that a data subject can understand and respond to each intended use of their personal data individually rather than being asked to agree to a bundle.
Granularity
Where processing serves multiple distinct purposes, consent should generally be sought for each one, allowing the individual to accept some and decline others rather than facing a single all-or-nothing choice.
Freely Given Consent
For consent to be a valid legal basis under Article 6, it must be freely given; bundling separate purposes into one consent request can undermine this because the individual is not given a genuine choice for each purpose. This reflects the requirement that consent be specific and informed.
Specificity
Consent must relate to specified purposes. A consent worded to cover broad or open-ended future uses generally falls short of the specificity expected, which is why distinct purposes are typically separated.
Relationship to Legal Bases
This concept applies where consent is the chosen Article 6 basis. It is not a universal requirement, since other lawful bases (such as contract, legal obligation, or legitimate interests) may apply to particular purposes and would not rely on consent at all.
Special Category Data Interaction
Where a purpose involves Article 9 special category data, an additional Article 9 condition is required beyond the Article 6 basis; if explicit consent is the condition relied on, the separation of purposes remains relevant and the explicit standard applies.

Common questions

Answers to the questions practitioners most commonly ask about Separate Consent for Distinct Purposes.

Does bundling consent for several purposes into a single opt-in make my processing more efficient and compliant?
No. Bundling distinct purposes into one all-or-nothing opt-in generally undermines the validity of consent, because consent must typically be specific to each purpose. Where processing serves multiple distinct purposes, guidance from the European Data Protection Board indicates that consent should be sought separately (granular consent) so that the individual can agree to some purposes and refuse others. A single combined checkbox risks rendering the consent insufficiently specific and freely given. Note that consent is only one of the Article 6 legal bases, and whether it is the appropriate basis at all depends on the context; you should assess each purpose against the available bases rather than defaulting to consent.
If a data subject has consented to one purpose, can I rely on that consent to process the same data for a further, unrelated purpose?
Generally no. Consent obtained for one specified purpose does not extend to a different, distinct purpose that was not covered by the original request. Re-using consent for an unrelated purpose typically requires a fresh, separate consent that clearly identifies the new purpose. Separately, EU data protection law contains a distinct compatibility assessment for further processing, but where you are relying on consent as your legal basis you should not treat a prior consent as a general-purpose authorisation. The precise boundary between related and distinct purposes can be a matter of assessment, and regulator interpretations may vary, so this should be evaluated case by case.
How should I present separate consents in an interface without overwhelming the user?
The general expectation is that each distinct purpose is presented in a way that lets the individual make a genuine, purpose-specific choice, typically through granular controls such as individual toggles or checkboxes rather than one aggregated acceptance. Layered information can help: a concise description of each purpose at the point of choice, with fuller detail accessible in a privacy notice. Non-essential purposes should generally not be pre-ticked or defaulted to on. Balancing usability against granularity is a design and assessment exercise, and the acceptable approach may depend on the sensitivity of the data and applicable national or regulator guidance.
How do I document separate consents to demonstrate accountability?
In most cases you should keep records that show, for each purpose, what the individual was told, what they agreed to, and when. This typically includes the specific wording presented, the granular choices available, the option state the individual selected, and a timestamp, so you can evidence that consent for each purpose was specific, informed, and unbundled. Because withdrawal must generally be as easy as giving consent, your records should also capture withdrawals per purpose. The exact record-keeping expectations can be shaped by regulator guidance and your own risk assessment, so verify against current official sources.
What happens if a user consents to some purposes but declines others?
Granular consent means the individual can accept some purposes and refuse others, and your systems should honour that partial position. You should process data only for the purposes the individual actually agreed to and refrain from the declined ones. Access to a core service should generally not be conditioned on consenting to purposes that are not necessary for that service, since conditionality can affect whether consent is freely given. Where a declined purpose was the only intended basis for a particular feature, that feature may simply be unavailable for that individual; assess this on a per-purpose basis.
How should separate consents be handled when purposes change or a new purpose is added?
If you introduce a new, distinct purpose, you generally need to obtain a fresh, separate consent for that purpose rather than relying on existing consents. Material changes to an existing purpose may likewise require renewed, specific consent, depending on how significantly the purpose or processing differs from what the individual originally agreed to. You should also reflect the change in your consent records and privacy information. Whether a change is significant enough to require re-consent is a matter of assessment and may be informed by regulator guidance, so evaluate each change on its facts.

Common misconceptions

A single consent checkbox covering all of an organisation's uses of data is sufficient as long as the individual clicks it.
Bundling multiple distinct purposes into one consent request can generally undermine whether consent is freely given, specific, and informed. Practitioners should assess whether purposes are genuinely separable and, where they are, seek consent for each. This is context dependent and the precise expectation may be shaped by regulator guidance, which should be verified against current sources.
Separating consent by purpose is always legally required for any processing.
Separate consent is relevant only where consent is the legal basis relied upon. Many processing activities are more appropriately grounded in other Article 6 bases, in which case consent, and therefore its separation, does not apply. The correct approach depends on identifying the right basis for each purpose.
Once separate consent is obtained for distinct purposes, the data can later be reused for new purposes under the same consent.
Consent is tied to the specified purposes for which it was given. Using data for a materially new purpose generally requires fresh consideration of the lawful basis, which may include obtaining new consent. Compatibility of any further processing is subject to assessment.

Best practices

Map each intended processing purpose separately before designing consent mechanisms, and confirm whether consent is the appropriate Article 6 basis for each purpose or whether another basis fits better.
Where multiple distinct purposes rely on consent, present them as separate, unbundled choices so the individual can accept or decline each independently.
Draft purpose descriptions in clear, specific language that allows the data subject to understand what each consent covers; avoid broad or open-ended wording.
For any purpose involving special category data, identify and document the additional Article 9 condition, and apply the explicit consent standard where explicit consent is the chosen condition.
Maintain records demonstrating that each consent was freely given, specific, and informed for its purpose, and provide an equally accessible means to withdraw consent per purpose.
Reassess the lawful basis and consent scope whenever a new or materially changed purpose arises, rather than relying on previously obtained consent, and verify current regulator guidance as expectations in this area can evolve.