Consent may be used as a legal ground for processing personal data only if the data subject has a genuine choice as to whether to accept or reject the conditions, without this leading to adverse consequences for him.
Owing to the fact that consent may be withdrawn at any time, it is regarded as the "most fragile" ground for processing. For this reason, personal data controllers should consider the possibility of applying another legal ground for the lawful processing of the data.
Period of Validity of the Consent
Consent must be obtained before the controller begins processing personal data, where this is the legal ground for the processing.
The General Data Protection Regulation (GDPR) does not lay down a specific period of validity for the consent given. Nevertheless, the supervisory authorities recommend its periodic renewal as good practice.
Requirements for the Validity of the Consent
In order to be legally valid, the data subject's consent must satisfy several basic requirements, which the controller is obliged to demonstrate in the event of an inspection by the supervisory authority.
The Consent Must Be Freely Given
In order to be regarded as freely given, consent must afford the data subject genuine choice and control.
Consent will not be valid if the data subject feels compelled to give it, out of fear of adverse consequences.
For example, within an employment relationship, an employee may not feel free to refuse to give his consent to the processing of his personal data, owing to the risk of negative consequences. For this reason, the supervisory authorities recommend that employers use another legal ground for the processing of the personal data of their current or prospective employees.
This does not mean, however, that employers can never rely on consent as a legal ground.
Likewise, it is not considered permissible for consent to be included in the general terms and conditions "as a bundle" when providing a service or signing a contract, if the processing of the data is not necessary for the performance of that contract.
In the case of websites, for the consent to be freely given, access to the services must not be made conditional upon the requirement that the user give consent to the processing of his personal data.
For example, if the user cannot view the content of the website without clicking "I accept cookies", this is not regarded as freely given consent.
The Consent Must Be Specific
The data subject must give his consent for a specific purpose or purposes of the processing.
If the controller processes personal data on the basis of consent, but subsequently decides to process the data for another purpose as well, he is obliged to request additional consent, unless another legal ground is more appropriate to the situation.
The Consent Must Be Informed
Before obtaining the data subject's consent, the controller is obliged to provide certain information, which includes:
- Details of the controller;
- The purpose of each processing operation for which consent is required;
- The types of personal data that will be processed;
- The right of the data subject to withdraw his consent at any time;
- Whether the data are used for automated decision-making;
- Whether the data will be transferred to controllers outside the EU, and what the associated safeguards and risks are.
If the data are to be provided to other controllers who will rely on the consent originally given, they must be clearly identified.
The provision of this information may be made in writing, orally, or by means of an audio or video message. It is important that it be expressed in comprehensible and clear language.
The privacy statement (Privacy Notice) must be short, accurate, and clear, so as not to burden the user.
In the case of websites, a layered presentation of the information is recommended, in order to avoid overburdening the user.
The Consent Must Be Given by a Statement or by a Clear Affirmative Action
The data subject must express his consent by a declaration or an active action.
Consent may be given by:
- Completing an electronic form;
- Sending an e-mail;
- Uploading a scanned document bearing a signature;
- An electronic signature.
"Tacit consent" is not valid!
Continued use of the service is not regarded as consent!
The use of pre-ticked boxes is likewise not valid under the GDPR!
If you need advice, the drafting of documents, or training in connection with the protection of personal data, please contact us on 0887550706 or by e-mail: [email protected]

