Valid consent under GDPR: prove the choice, not just the click

Valid consent under GDPR: prove the choice, not just the click

A practical guide to freely given, specific, informed and unambiguous consent, with the evidence and withdrawal controls that make a choice defensible at work.

A product team wants to add behavioural advertising to a photo-editing app. The advertising would help the business, but the location data and tracking are not needed to edit a photo. The team proposes one required "Accept" button so the launch stays simple.
The privacy review should begin with a different question: What, exactly, is the person agreeing to, and what happens when they change their mind? The button is only one event in that chain.
Under the GDPR, consent is a lawful basis for one or more specific purposes. It must be freely given, specific, informed and unambiguous, and it must appear as a statement or clear affirmative action. The controller must also be able to demonstrate that the person consented. 1
That makes consent a lifecycle control. A valid request gives the person a real choice, identifies the purpose clearly, captures a deliberate decision, preserves enough evidence to prove what happened, and supports withdrawal without making the person fight the product.

Start with the purpose, not the checkbox

The app has at least three different processing questions:
  • What data is necessary to provide photo editing?
  • Is location data needed for an optional feature, such as movement-based editing tools?
  • Will the organisation use location or usage data for behavioural advertising?
Those questions may involve different data, purposes, recipients and lawful bases. A single preference called "personalisation" hides the decisions that consent is supposed to give the person. The EDPB uses a comparable photo-editing example: when GPS and behavioural advertising are not necessary for the core service, the provider cannot make access to that service conditional on consent to those extra purposes. 2
The first review artefact should therefore be a purpose map. For each proposed use, record the data, purpose, processing operation, controller, recipients, lawful basis and user-facing outcome. The map should show which use is necessary for the service and which uses are optional. That split prevents a product requirement from quietly turning an optional business use into a condition of service.
Consent is the wrong basis for processing that is objectively necessary to perform the contract. The EDPB says that necessary processing needs a direct and objective link to delivering the contract or service; the controller should not ask for consent where another basis, such as Article 6(1)(b), actually describes the processing. 2

The four tests are cumulative

The four words in Article 4(11) are not four design preferences. They are cumulative conditions. The EDPB's April 2026 summary presents the same structure: if one element is missing, the processing cannot rely on valid consent. 3
TestReviewer questionTypical failure
Freely givenCould the person refuse or withdraw without losing a necessary service or suffering a real disadvantage?The product bundles optional tracking with sign-up or blocks the service behind a cookie wall. 2
SpecificDoes the choice identify one or more defined purposes, with separate options where the purposes differ?One "I agree" covers service analytics, targeted advertising and sharing with commercial partners. 1
InformedDid the person receive enough clear information to understand the choice before acting?The request points to a long privacy policy but does not identify the controller, purpose, data or withdrawal right in an accessible way. 2
UnambiguousDid the person make a deliberate statement or affirmative action that clearly signals agreement to this processing?The organisation treats silence, inactivity, a pre-ticked box, scrolling or blanket acceptance of terms as consent. 1
The tests reinforce one another. A purpose cannot be specific if the request does not explain it. A choice cannot be free if the person cannot refuse it. An affirmative click cannot be informed if the product concealed the purpose until after the click. A consent record cannot repair a request that never gave the person a real choice.

Freely given means real choice

Article 7(4) directs controllers to pay special attention when a contract or service depends on consent for processing that the contract does not need. The EDPB treats this kind of bundling as a strong warning sign. The controller carries the burden of showing that the person still had a genuine choice, and equivalent access must be genuinely equivalent rather than a nominal alternative with worse functionality. 12
A person may receive an incentive for consenting. The loss of an optional benefit does not automatically create unlawful pressure. The controller must still assess the circumstances and show that refusal or later withdrawal does not cause a significant disadvantage. The EDPB contrasts a limited marketing benefit, such as personalised discounts becoming generic discounts after withdrawal, with an app that becomes materially worse when a person withdraws consent to unnecessary tracking. 2
The same concern appears in relationships with an imbalance of power. The EDPB says consent is unlikely to be freely given for much employee monitoring because an employee may fear adverse effects from refusal. A workplace photo project may still support consent if employees receive an equivalent alternative and refusal has no adverse consequence, but the employer must be able to show that fact. 2

Specific means purpose by purpose

The word "specific" prevents function creep. A person who agrees to recommendations based on viewing history has not automatically agreed to third-party targeted advertising based on the same history. The EDPB says a changed or additional purpose requires fresh consent unless another lawful basis genuinely fits the new processing and was communicated as such. 2
Granularity is the product expression of that rule. When the purposes differ, the interface should let the person choose between them. "Improve user experience" or "marketing purposes" is too vague without more detail. A useful request names the purpose in terms the person can connect to an action: "Use my viewing history to recommend films" and "Share my viewing history with named advertising partners" are separate decisions.
The organisation should also name every controller that will rely on the consent. The EDPB says processors do not need to be named as part of the consent requirement, although the controller still has separate transparency duties about recipients. The distinction matters because a vendor processing data on the controller's instructions is different from a third-party controller that will use the data for its own purpose. 2

Informed means enough information before the action

The EDPB identifies a minimum set of information for informed consent: the controller's identity, the purpose of each processing operation, the type of data collected and used, and the existence of the right to withdraw. Depending on the processing, the request may also need information about automated decision-making or transfer risks. 2
The request must be prominent, concise, intelligible and separate from unrelated contractual language. A layered notice can keep the first screen readable, but the relevant information must be accessible before the person decides. The consent request and the wider Articles 13 and 14 transparency notice perform different jobs: the first supports a specific decision, while the second supplies the broader privacy information. 12
That distinction gives privacy and product teams a practical test. If a user has to open a general terms page to discover that a consent button also authorises profiling for advertising, the product has made the user reconstruct the choice after the fact. The request should carry the information needed for the decision, even when the full notice remains available in layers.

Unambiguous means deliberate action

A consent action must be distinguishable from ordinary use of the service. The EDPB says that pre-ticked boxes, opt-out constructions, silence, inactivity, continued browsing and merely proceeding with a service do not establish a clear affirmative action. Consent should exist before the controller starts the processing that needs it. 2
A positive action still needs a clear object. A button labelled "Continue" may record navigation, while a button labelled "Allow location for movement tools" communicates the decision. The user action and the purpose should be stored together so a later reviewer can tell what the action meant at that time.
Explicit consent is a separate, higher expression requirement. Article 9(2)(a), for example, refers to explicit consent for one special-category-data exception. The EDPB explains that explicit consent requires an express statement, which may be written, electronic or oral if the controller can prove the statement and the surrounding conditions. A signed paper form is one option, not a universal requirement. 12

Build the decision screen before launch

A consent review should produce working controls, not only approved wording.

1. Separate necessary processing from optional purposes

List the processing required to deliver the product and the processing that serves optional analytics, personalisation, advertising, or sharing. Assign a lawful basis to each purpose before designing the consent screen. Do not ask the person to consent to a use that the organisation says is necessary for the contract, and do not make optional processing a hidden condition of the core service. 1

2. Name the purpose, data and controllers

Write a short statement for each purpose. Identify the controller or controllers that will rely on the consent, the data involved, and the meaningful processing action. A purpose label such as "personalisation" needs enough detail for the person to understand whether the system will rank content, share a profile, or target advertising.

3. Design a separate and readable choice

Keep the consent request separate from terms and conditions. Use plain language, equal prominence for the available choices, and a separate opt-in for each distinct purpose unless the purposes are genuinely connected and bundling remains appropriate. The ICO's operational guidance also recommends concise requests, active opt-in methods, and separate records for granular choices. 4

4. Capture the action before processing starts

Record the deliberate action that signals agreement, not merely the final state of a preference field. A timestamp, the submitted value and a link to the relevant session or account can show what happened. The control should reject default acceptance, and the processing job should check the consent state before it uses the data.

5. Preserve proof of the exact decision

Article 7(1) makes the controller responsible for demonstrating consent. The ICO recommends records that show who consented, when they consented, what they were told, how they consented and whether they later withdrew. The record should preserve the version of the consent wording and the privacy information shown at the time. A current copy of the website is not enough because the flow may have changed after the person acted. 14
Proof does not mean collecting every possible identifier. The EDPB says the controller needs enough information to link the consent to the processing, but should avoid extra data collection that the proof does not require. A session identifier may be sufficient for a short-lived choice if the organisation can enforce and evidence that choice; a durable account link may be necessary when the consent follows the person across devices or vendors. 2

6. Build withdrawal into the same product path

The GDPR gives people the right to withdraw at any time and requires withdrawal to be as easy as giving consent. The EDPB applies that rule to the interface: if a person gave consent with one click in an account or app, the person should be able to withdraw through that interface without undue effort. The ICO likewise describes an accessible, one-step withdrawal path as the practical standard. 124
The withdrawal event must reach every system that carries the consent-based purpose. For advertising, that may include audience membership, profile features, exports, vendor synchronisation, campaign queues and a job that can rebuild the audience. A preference centre that changes one database field while a downstream feed remains active has recorded a preference without enforcing it.

What changes after withdrawal?

Withdrawal does not make earlier processing unlawful if the organisation processed the data lawfully before the withdrawal. It does require the organisation to stop the processing actions that relied on consent. If no other purpose and lawful basis justify continued storage or use, the controller should delete the data. 2
A separate purpose may continue when it already has its own lawful basis. An organisation may need a customer record to perform a contract while stopping an optional advertising use, but the purpose map must have separated those operations before the withdrawal. The EDPB says a controller cannot silently move from consent to another lawful basis after withdrawal. That change needs its own transparency analysis, and a later switch cannot repair a consent mechanism that was invalid from the start. 2
This is why withdrawal is a validity test, not merely a customer-service feature. If the organisation cannot identify which records, models, exports and vendors depend on a consent event, it cannot reliably stop the purpose when the person withdraws. The missing map weakens both the original consent record and the later response.
Contract necessity. A service may need an address to deliver an order or payment details to process a purchase. That processing calls for a contract analysis, not a decorative consent checkbox. Optional marketing or sharing should not ride inside the same required action. 2
Transparency. A privacy notice explains how an organisation processes personal data and meets wider information duties. A consent request asks for a defined choice. Linking to a long notice does not replace a clear, purpose-specific request. 1
Erasure. Withdrawal stops processing based on consent. It does not automatically erase every record held under a different purpose and basis. The organisation must assess continued storage and use against the purpose map and the separate right to erasure. 2
Legitimate interests. A controller cannot present consent as a choice and then keep the same processing alive by retrospectively invoking legitimate interests when the consent fails or is withdrawn. The controller must choose and disclose the lawful basis before processing begins. 2

Failure modes that should stop sign-off

One button covers unrelated purposes

A single "Accept" action for core service delivery, analytics, targeted advertising and third-party sharing gives the person no meaningful way to choose among the purposes. Separate the purposes and provide separate opt-ins where appropriate. Granularity is a legal control, not just an interface preference. 2
That field cannot show what the person agreed to, which version they saw, when the action occurred, or whether they later withdrew. Link the event to the purpose, request version, information shown, action and timestamp. 4
Reading a privacy notice, scrolling through a page, or continuing to use a service does not itself show a deliberate agreement to a specific processing purpose. The consent action must be distinguishable from ordinary navigation. 2

Withdrawal is harder than opt-in

A one-click opt-in followed by a support ticket, phone call during limited hours, or paper request fails the equal-effort test. Provide a withdrawal path through the same product surface where practical, and test the downstream propagation rather than only the screen.
A consent for recommendations does not automatically cover advertising, model training, sharing, or a new category of recipient. Reopen the purpose analysis when the processing changes. Ask for fresh consent or select a different lawful basis before the new processing begins. 2

A later lawful basis is used as a rescue plan

An organisation cannot use consent as a user-control promise and then quietly keep the same activity under legitimate interests after the person withdraws. A separate lawful basis may support a separate purpose that was already mapped, but it cannot erase the original choice. 2

The record a reviewer can use

A compact review record should answer these questions:
  1. What processing purpose and data does the consent cover?
  2. Which controller or controllers will rely on it?
  3. Which processing is necessary for the service, and which processing is optional?
  4. What exact wording and privacy-information version did the person see?
  5. What affirmative action did the person take, and when?
  6. What identifier or session link lets the organisation connect the event to the processing without collecting unnecessary data?
  7. Where does the consent-based purpose travel across internal systems, processors, controllers, exports and models?
  8. How can the person withdraw, and is that path as easy as the opt-in?
  9. What stops, is deleted, or continues under a separately documented purpose when withdrawal arrives?
  10. Who owns the control, what evidence proves it was tested, and what change triggers a fresh review?
The record should be attached to the product decision, not created only after a complaint. Product, engineering, security, procurement and privacy teams should be able to follow the same purpose map from the request screen to the final downstream system.
When a consent mechanism passes review, the answer is more precise than "the user clicked yes." The organisation can show the purpose the person chose, the information that made the choice meaningful, the action that recorded it, and the path that will stop the use when consent ends. That is the standard a working consent control has to meet.

This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.

Related content

More from this channel