Glossary Terms

Consent

A clear and informed indication that a person agrees to a specific use of their personal data.
On this page

What is consent in data protection?

Consent is a person’s clear affirmative agreement to a specific processing activity after receiving understandable information. Under frameworks such as the GDPR, valid consent generally needs to be freely given, specific, informed and unambiguous. For certain sensitive activities, an explicit form of consent may be required. Consent should reflect a genuine choice rather than pressure, hidden conditions or a bundled acceptance of unrelated purposes.

The organisation must be able to demonstrate what the person agreed to, when the consent was given, which notice was presented and how the choice was expressed. Silence, inactivity or pre-ticked boxes are not normally sufficient for a valid affirmative choice.

When is consent an appropriate lawful basis?

Consent is most appropriate when the person has meaningful control and can refuse without suffering an unfair disadvantage. It is often used for optional marketing, certain cookies, research participation or additional features that are not necessary to provide the core service.

Consent may be unsuitable where there is a significant imbalance, such as some employment or public-authority contexts, or where the processing must continue regardless of the individual’s choice. Organisations should select the lawful basis that honestly reflects the activity rather than using consent as a universal solution.

How should consent be collected?

The request should use plain language, identify the organisation, describe each purpose and explain the data or activity involved. Separate purposes should normally have separate choices. The design should avoid dark patterns, misleading button hierarchy, unnecessary friction for refusal or withdrawal and default settings that favour collection.

Consent records should capture the person or identifier, timestamp, source, notice version, purposes and status. Where a choice affects multiple systems or partners, the update should be propagated consistently.

How does withdrawal of consent work?

Withdrawing consent should be as easy as giving it. Once withdrawn, processing based on consent should stop unless another valid legal basis applies and the person has been informed appropriately. Withdrawal does not necessarily make earlier lawful processing invalid, but data may need to be deleted when no other retention basis exists.

Organisations should test whether preference centres, marketing tools, analytics systems, vendors and backups respond correctly. A visible withdrawal link is not enough if downstream processing continues.

Frequently asked questions

Can consent be included in general terms and conditions?

Consent should be distinguishable from other matters and specific to the processing. Bundling it into broad terms may prevent the choice from being informed or freely given.

Can children provide consent?

Rules vary by jurisdiction, age and service. Organisations may need parental authorisation, age-appropriate notices and additional design safeguards.

Does consent last forever?

No fixed universal period applies, but consent should remain connected to the stated purpose and context. Material changes may require a new choice, and records should be reviewed.

Can an organisation switch to another lawful basis after withdrawal?

It should not change basis simply to avoid the withdrawal. Any alternative basis must genuinely apply and should have been assessed and communicated appropriately.

Is cookie consent the same as consent for all personal-data processing?

No. A cookie choice may address storage or access on a device and related purposes. Other processing may require separate transparency and a different lawful basis.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.