Skip to main content

News story

April 5, 2018

GDPR: The concept of consent

Consent is one of the core elements of data protection legislation, however it is not the only basis for processing personal data

Despite Brexit, the General Data Protection Regulation (GDPR) will come into effect on 25 May 2018 and will soon be enveloped into UK law under the proposed Data Protection Bill. The GDPR clarifies the concept of consent and ensures that the concept will be interpreted consistently across all jurisdictions.

The GDPR sets a high standard for consent and defines it as: “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”.

This expands upon the existing definition of consent under the Data Protection Act 1998 (DPA). The additional requirements are that it must be:

  • freely given;
  • unambiguous; and
  • made by a statement or clear affirmative action.

But what does that mean?

Freely given: whilst already a requirement of the DPA, the GDPR specifically clarifies that consent is not freely given if:

  • there is a clear imbalance between the controller and the data subject (such as the relationship between employer and employee); and/or
  • the data subject has no genuine or free choice and is unable to withdraw consent without detriment.

Unambiguous: there must be a clear indication that the data subject is positively consenting to the processing of their personal data. Where consent is obtained for a single processing activity, such as subscribing to a newsletter, this will be easier. However, where personal data is collected for multiple purposes, this will be much harder. Further, it should be kept separate from any other terms and conditions and should not be made a precondition of any kind (see more below).

Statement or clear affirmative action: as suggested, any indication of consent must involve a clear, affirmative action or statement by the data subject. This could include:

  • ticking a box or opt-in when visiting a website;
  • choosing technical settings for online services; or
  • any other statement or conduct which clearly indicates the data subject’s acceptance of the proposed processing of his or her personal data.

The GDPR specifically prohibits pre-ticked opt-in boxes and requires individual (‘granular’) consent options for distinct processing operations. Therefore, silence will not satisfy this condition. Further, it must be as easy to withdraw as it is to give.

Consent is appropriate if the data controller can offer data subjects actual choice and control over how their data will be used. If the data controller cannot offer genuine or real choice, then consent is not an appropriate lawful basis for processing, as asking for consent would be misleading and inherently unfair to the data subject.

According to the Information Commissioner’s Office (ICO), if consent is made a precondition of providing a service, it is unlikely to be the most appropriate lawful basis for processing personal data and data controllers should rely on another lawful basis provided under the GDPR. This should be well documented.

Further, public authorities, employers and other organisations in a position of power over individuals should avoid relying on consent unless they are confident they can demonstrate it is freely given.

Other lawful bases for processing personal data

There is a general misconception that personal data can only be processed on the basis of consent. This is not true. Under the GDPR, there are five other ways to lawfully process personal data. For instance, if the processing is necessary:

  • for the performance of a contract;
  • for compliance with a legal obligation;
  • to protect the vital interests of the data subject;
  • for the performance of a task carried out in the public interest;
  • for the purposes of a legitimate interest.

Note: the lawful basis for processing can affect which rights are available to individuals. For example, some rights will not apply:

 Right to erasureRight to portabilityRight to object
Consent  X (but right to withdraw consent)
Contract  X
Legal obligationXXX
Vital interests XX
Public taskXX 
Legitimate interests X 

Whilst it may be true that businesses usually rely on consent as a lawful basis for processing personal data; it may be best to combine it with some other lawful basis.

According to the ICO, no single basis is better than the other, and which basis is best, depends on the purpose and relationship between the data controller and the individual.

Conclusion

Whilst businesses are not required to “repaper” or refresh all existing consents obtained under the DPA; when relying on consent it is vital to ensure that it meets the GDPR standards. If not, the consent mechanism should be altered and existing consent be refreshed and documented accordingly.

Given the additional obligations relating to consent under the GDPR, it may also be sensible for data controllers to look towards an alternative lawful basis for processing personal data.

If you have any questions regarding data protection, please contact corporate solicitor, Karen Cole.

Note: This is not legal advice; it is intended to provide information of general interest about current legal issues.

Stay in touch

Subscribe to our newsletter

Stay in touch

By completing your details and submitting this form you confirm you are happy for us to send you marketing communications and that you agree to our Website Privacy Policy and Legal Notice and to us using Mailchimp to process your data.


Sending

News/Insight

  • Buying a commercial unit: what you need to know
    Buying a commercial unit can be a valuable step for your business, but it comes with legal, tax, planning and property risks. Brinda Granthrai explains what buyers should consider before committing.


    Read more
  • Pension and inheritance tax changes from April 2027: why now is the time to review your will and estate plan
    From 6 April 2027, most unused pension funds and pension death benefits are expected to be included in a person’s estate for inheritance tax purposes. This article explains what the changes could mean for families, pension nominations, wills, chari


    Read more
  • What happens when company owners disagree? The key to keeping private companies running smoothly
    Director and shareholder disagreements can quickly disrupt a business if they are not addressed early. This article explains what disputes can mean for a private company, how they can be avoided, and how legal advice can help protect stability and su


    Read more
  • SMEs urged to review risks as liability rules expand
    New criminal liability rules taking effect on 29 June 2026 will make it easier to prosecute businesses of any size where senior managers commit offences while acting on the organisation’s behalf.


    Read more
  • AI-written grievances add new pressure for employers
    AI is making it easier for employees to produce detailed, formal-looking grievances that refer to legal concepts and workplace rights. For employers, the key is to look beyond the language, identify the core concern and follow a fair, consistent grie


    Read more

What they say...

  • Client, July 2026
    Pragmatic, but commercially astute support “Genuinely, we valued your pragmatic, but commercially astute support. It has helped us get this tricky deal over the line in a manner that we both feel supports our needs in a balanced way and gives L

  • Chey, July 2026
    Professional and speedy “I’m extremely happy with the service provided by RIAA Barker Gillette. They were very professional, dealt with my matter at speed and were very accommodating with my disability. I wouldn’t hesitate to use th

  • Client, June 2026
    Thank you “I had a call with Pippa that was not only factual and to the point but also reassuring and very helpful. Would highly recommend.”

  • Client, June 2026
    Trusts services “Very helpful service which solved our problem.”

  • Client, June 2026
    Probate Services “We used Patrice Lawrence to deal with our parents’ probate, and she handled the case promptly, professionally and with the respect due for a matter of this nature.”

Read more
Send this to a friend