Skip to content

END-USER CONSENT UNDER GDPR

Article by Tsaaro

7 min read

What is consent and types of consent?

If a company wants to collect/process the personal data of any individual, there are certain conditions where such an activity would be considered lawful. GDPR provides six legal bases for the processing of personal data- Contract, legal obligations, vital interests of the data subject, public interest, legitimate interest, and consent of the data subject.

Consent is a complicated part of the GDPR as it is not easy to ensure the validity of consent in practice due to the scope and nature. While GDPR provides control in the hands of the users when it comes to their rights over their private data, Consent goes one more step and provides a stronger hold.

Consent could be implied or expressed. Implied consent essentially means that there exists probable reason to believe that the data subject will provide their consent when asked for it. E.g., a business would assume that a regular customer has consented to receive emails from them. Expressed consent refers to a genuine choice made by the data subject after understanding the process and its implications and consequences. While many various privacy laws recognise both types of consent, GDPR only considers expressed consent. Explicit for sensitive personal data

Essential conditions regarding consent?

GDPR does not recognise implied consent as valid.

Article 7 of the GDPR defines consent as “any freely given, specific, informed and unambiguous […] clear affirmative action

Hence, as per GDPR, there are five elements of consent, namely-

  1. Freely given: consent needs to be voluntarily provided without any pressure or any repercussions of refusal. This implies a genuine choice by the data subject.
  2. Specific: The consent should be clearly defined in clear terms regarding the purpose of processing. 
  3. Informed: The end-user should be provided with complete information regarding the processing activities they are consenting for. The data subject must be informed about the controller’s identity, the type of data collected and processed, the purpose of processing, their rights to withdraw consent, possible risks and consequences etc. 
  4. Unambiguous: The question asked must be in clear and straightforward language in a concise form. Consent cannot be implied. 
  5. Clear affirmative action: Providing consent is an act. It needs to be given in the form of a clear statement.

Consent for children

Children’s consent is a particular case, as there is an additional consent/ authorisation requirement from parents/guardians for children under the age of 16. However, if a service is not explicitly offered to children, it is exempted from this rule. This does not apply to services provided to both children and adults.

Consent Management

When we talk about consent, we also need to talk about consent management. Consent has a lifecycle- it starts from the collection of data and continues throughout the entire duration of the data collection while also providing an option to withdraw said consent. A controller should ensure the maintenance and implementation of a comprehensive consent management system that covers the entire consent lifecycle in compliance with GDPR.

Things to keep in mind

It is essential to implement the five critical elements in consent every time you ask for consent from data subjects.

  • Do not use pre-ticked boxes as they are not considered valid expressed consent.
  • Provide complete information regarding the use of collected data in your privacy policy
  • Consider including a “double opt-in.” 
  • Include an unsubscribe option to withdraw consent easily.
  • Do not try to trick data subjects into consenting, and do not withdraw services in case they choose not to consent.
  • Consent should not be hidden in the privacy policy or terms and conditions; it should be collected in a way distinguishable from other matters.
  • The controller’s identity and purposes of processing shall be informed to the end-user in plain and straightforward language.
  • Silence or inactivity shall not be construed as consent.

Conclusion

While consent is one of the best-known and understood legal grounds for data collection, it is not always the best and most appropriate option. 

Data privacy professionals advise controllers to avoid depending on consent as a sole legal basis for processing personal data. As such, consent can be withdrawn, and end-users can also request to have all their data removed. Further, consent is only one of the six legal grounds that GDPR provides for. 

Knowing when to ask for consent is the key. For example, when you’re processing data which would have minimal impact on individuals but provide benefits to your business and others, then you can use legitimate interests as a legal base, but when you are tracking cookies or sharing personal data with other companies for commercial purposes then asking for consent is the right way to go. 

References

1,218 thoughts on “END-USER CONSENT UNDER GDPR”

  1. Very well written! The points discussed are highly relevant. For further exploration, I recommend visiting: LEARN MORE. Keen to hear everyone’s opinions!

  2. Сауна очищает организм https://sauna-broadway.ru выводя токсины через пот, укрепляет иммунитет благодаря перепадам температуры, снимает стресс, расслабляя мышцы и улучшая кровообращение. Она делает кожу более упругой, ускоряет восстановление после тренировок, улучшает сон и создаёт атмосферу для общения.

  3. Ковры для уюта вашего дома, выберите.
    Лучшие варианты ковров для вашего дома, закажите.
    Ковры для стильного интерьера, открывайте.
    Декорируйте пространство с помощью ковров, уют.
    Ковры для детей, выбирайте.
    Традиционные и современные ковры, выберите.
    Ковры для офиса, добавьте.
    Неприхотливые ковры для занятых людей, подходящий стиль.
    Советы по выбору ковра, узнайте.
    Защита от холода с помощью ковров, лучший вариант.
    Модные ковры 2025 года, следите.
    Создайте уют на даче с коврами, практичность.
    Идеи по использованию ковров, откройте.
    Выбор ковров для любого вкуса, мир ковров.
    Ковры для спальни, попробуйте.
    Премиальные ковры для вашего интерьера, успех.
    Выбор ковров для домашних любимцев, долговечные.
    Согревающие ковры для вашего дома, вдохновение.
    Ковры для создания зонирования, исследуйте.
    хорошие ковры https://kovry-v-moskve.ru/ .

  4. Все о компьютерных играх https://lifeforgame.ru обзоры новых проектов, рейтинги, детальные гайды, новости индустрии, анонсы и системные требования. Разбираем особенности геймплея, помогаем с настройками и прохождением. Следите за игровыми трендами, изучайте секреты и погружайтесь в мир гейминга.

  5. Все о недвижимости https://konsta-ovk.ru покупка, аренда, ипотека. Разбираем рыночные тренды, юридические тонкости, лайфхаки для выгодных сделок. Помогаем выбрать квартиру, рассчитать ипотеку, проверить документы и избежать ошибок при сделках с жильем. Актуальные статьи для покупателей, арендаторов и инвесторов.

  6. Все о недвижимости https://ks-inginiring.ru покупка, аренда, ипотека. Разбираем рыночные тренды, юридические тонкости, лайфхаки для выгодных сделок. Помогаем выбрать квартиру, рассчитать ипотеку, проверить документы и избежать ошибок при сделках с жильем. Актуальные статьи для покупателей, арендаторов и инвесторов.

  7. Покупка, аренда, ипотека https://magnk.ru всё о недвижимости в одном блоге! Советы по выбору жилья, юридические аспекты, анализ цен и прогнозы рынка. Рассказываем, как грамотно оформить ипотеку, проверить документы и избежать ошибок при сделках с недвижимостью. Будьте в курсе всех изменений и трендов!

  8. Покупка недвижимости и ипотека https://vam42.ru что нужно знать? Разбираем выбор жилья, условия кредитования, оформление документов и юридические аспекты. Узнайте, как выгодно купить квартиру и избежать ошибок!

Leave a Reply

Your email address will not be published. Required fields are marked *

Tsaaro Consulting

The evolving digital landscape in the 21st century have placed a challenge for governments and organizations as they attempt to …

Tsaaro Consulting

Introduction  The Digital Personal Data Protection (DPDP) Act, 2023, and the Digital Personal Data Protection Rules, 2025 establish a comprehensive …

Tsaaro Consulting

In today’s interconnected world, cybersecurity plays a crucial role in protecting our digital lives. From protecting personal data to safeguarding …

Tsaaro Consulting

Introduction  A Transfer Impact Assessment (TIA) is a critical evaluation conducted under the General Data Protection Regulation (GDPR) to assess …

Tsaaro Consulting

Introduction The Digital Personal Data Protection Act (DPDPA), 2023 and the Draft DPDP Rules, 2025 have ushered in a new …

SHARE THIS POST

Would you like to read regular updates from Tsaaro.
Subscribe to our newsletter

Our Latest Blogs

Read what the latest hapennings in the cyber world are and learn what the
experts have to say about them

Call Our Experts:

+91 95577 22103

small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png
small_c_popup.png

We’d love to help your organization achieve your Data Protection goals!

Schedule a complimentary consultation with our Team of Experts.