Understanding Consent Under GDPR: Challenges and Misconceptions

Consent is a cornerstone of the EU General Data Protection Regulation (GDPR) and one of its six legal bases for processing personal data. However, organisations must treat carefully when relying on consent, as it carries strict requirements and limitations. A common misconception is that all data processing requires consent, which often leads to improper practices and regulatory penalties. Furthermore, the challenges of obtaining and demonstrating valid consent, distinguishing it from other legal bases, and effectively managing withdrawal requests can create significant compliance risks.

What is Consent?

According to the Article 4 of the GDPR, consent is  “any manifestation of free, specific, informed and unambiguous will by which the data subject accepts, by a declaration or by a clear positive act, that personal data relating to him or her may be processed”. In other words, valid consent should meet those 4 criterias:

1- Consent must be freely given. Data subjects should be free to make their decision without pressure or undue influence. Their choice to consent or not to the processing of their personal data must not affect their relationship with the company.

2- Consent must be specific. This means that it must be obtained for a specific purpose, meaning a single consent cannot cover multiple processing activities. If there are several purposes for processing, organisations must colllect separate consents for each data processing unit.

3- Consent must be informed. Data subjects must be supported by comprehensive information to ensure transparency. This includes details such as the identity of the data controller, the purposes of processing, the types of data collected, and the right to withdraw consent.

4- Consent must be unambiguous. Consent must be explicit; implied or passive consent is not allowed. It must be demonstrated through a clear, affirmative action by the data subject, such as clicking a link or checking a box to indicate agreement.

Failing to meet any of these criteria renders consent invalid. Additionally, consent must be demonstrable, and individuals must have the ability to withdraw it as easily as they provided it. These strict requirements aim to ensure that consent is meaningful and not merely a formality.

More detailed information can be found in the European Data Protection Board (EDPB) Guidelines 05/2020 on consent under Regulation 2016/679

Common Misconceptions About Consent

Many organisations wrongly believe they must always seek consent for processing personal data. However, GDPR provides several other legal bases for processing, such as contractual necessity and legitimate interest. Over-reliance on consent can lead to non-compliance if other legal bases are more suitable. Organisations need to assess each data processing activity and choose the most appropriate legal basis to ensure compliance.

Demonstrating and Withdrawing Consent

Demonstrable consent is another challenge. While written consent is common, oral consent can also suffice, provided it is adequately recorded. Organisations must strike a balance between retaining enough evidence to prove consent and avoiding excessive data collection.

The process of revoking consent often confuses organisations. Revocation applies only to data processing based on prior consent. In contrast, an opt-out mechanism generally applies to processing based on legitimate interests, such as unsubscribing from marketing emails.

The Role of Consent in GDPR Compliance

Consent should be viewed as a last resort—a legal basis to be used only when no other option is available. Over-reliance on consent can expose organizations to enforcement actions and damage trust with customers or employees.

To ensure compliance, organisations should:

  • Audit all processing activities to determine the appropriate legal basis.
  • Inform individuals about their rights and the implications of consent.
  • Facilitate easy withdrawal of consent and prepare for its operational consequences.

How Can Symmetry Compliance Help?

At Symmetry Compliance, we specialize in guiding businesses through the intricacies of GDPR compliance. Our experienced team transforms complex regulatory requirements into practical, actionable steps.

Contact us for customized guidance on GDPR compliance and data governance tailored to your organisational needs.

2025-02-18T12:24:26+01:00February 18th, 2025|Uncategorized|