Growth Marketing Glossary

Consent (GDPR)

con·sentnoun

A real, active opt-in. Under the GDPR, consent must be freely given, specific, informed, and unambiguous — a clear affirmative action, never a pre-ticked box or inferred from silence.

a clear requestask, inform, opt invalid permission
Schematic — an affirmative opt-in that meets four conditions
Term
Consent under the General Data Protection Regulation (GDPR)
Must be
Freely given, specific, informed, unambiguous
Form
A clear affirmative opt-in action
Contrast
Other lawful bases like legitimate interest

Parts of speech & senses

consent · noun
  1. Consent under the General Data Protection Regulation (GDPR) is a freely given, specific, informed, and unambiguous agreement — a clear affirmative opt-in — by which a person permits an organization to process their personal data. "They relied on consent to send the marketing emails."

What consent under the GDPR is

Consent under the General Data Protection Regulation (GDPR) is one of the lawful bases an organization can use to justify processing someone's personal data, and it is the one that puts the choice squarely with the individual. The regulation defines it as a freely given, specific, informed, and unambiguous indication of a person's wishes, expressed through a clear affirmative action. Each word carries weight. 'Freely given' means a real choice with no penalty for refusing. 'Specific' means tied to a defined purpose, not a blanket permission. 'Informed' means the person knows who is processing what and why. 'Unambiguous' means an active, deliberate opt-in — ticking an unticked box, not inferred from silence. Consent is described here for general understanding, not as legal advice, and organizations should take qualified counsel.

Several practical rules flow from that definition. Consent cannot be bundled — you cannot make access to a service conditional on agreeing to unrelated data processing, because that is not freely given. It cannot rely on pre-ticked boxes or default opt-ins, since silence and inactivity do not count as a clear affirmative act. It must be as easy to withdraw as it was to give, and withdrawal must be honored going forward. Organizations also have to keep records showing that valid consent was obtained. Because the bar is high, consent is not always the best lawful basis; where processing is necessary for a contract or a legitimate interest, another basis may fit better. But when an organization does rely on consent, it must meet every element or the consent is not valid.

Consent versus the other lawful bases

Consent is only one of six lawful bases the GDPR provides, and treating it as the default is a common error. The others include performance of a contract, compliance with a legal obligation, protection of someone's vital interests, a task in the public interest, and legitimate interests. Each fits different situations. You do not need consent to charge a customer for something they ordered — that is contract. You do not need consent to keep tax records — that is legal obligation. Legitimate interests can cover processing a person would reasonably expect, balanced against their rights. Choosing the right basis matters because consent brings the strictest conditions and the right to withdraw, so leaning on it where another basis fits creates fragile, revocable permission for processing that did not need it.

The distinction sharpens around marketing and tracking. Sending marketing to someone, dropping non-essential cookies, or building tracking-based profiles typically leans on consent, because those are not necessary to deliver a service the person asked for. But routine, expected processing — fulfilling an order, securing an account — usually rests on contract or legitimate interests instead. Getting this wrong cuts both ways: relying on consent you never validly obtained leaves the processing unlawful, while demanding consent for things that did not need it annoys people and clutters the experience with needless pop-ups. The skill is matching each processing activity to the basis that genuinely fits, using consent where the law requires a real choice and reserving the other bases for processing that stands on its own footing.

Getting consent right

Valid consent is designed, not bolted on. Ask for it in plain language, separated from other terms, so the person understands exactly what they are agreeing to and for which purpose. Use unticked boxes and require a genuine action; never infer agreement from a pre-checked option or from continued use of a site. Keep purposes granular — separate consent for email marketing from consent for profiling — rather than one all-or-nothing switch. Make withdrawal simple and obvious, and stop the processing when someone withdraws. Keep records of when and how consent was captured, and what the person was told, so you can demonstrate it. Where consent is not the natural fit, choose a more appropriate lawful basis instead of forcing a fragile opt-in onto processing that did not need one. This is a summary, not legal advice.

The failures are familiar from years of clumsy cookie banners. Pre-ticked boxes, 'consent walls' that block a service unless you agree to unrelated tracking, and vague bundled requests all fail the freely-given and unambiguous tests. Burying consent in a long terms-of-service document defeats 'informed'. Making it hard to withdraw — or ignoring withdrawal — breaches the rules and erodes trust. Treating consent as a one-time formality, when it should be specific and current, leaves organizations relying on stale or invalid permission. The discipline is to make consent a genuine, granular, revocable choice, keep evidence of it, and use it only where the law calls for it. Consent that is not truly free, specific, informed, and unambiguous is, under the GDPR, no consent at all.

Worked example. An online store wants to send promotional emails and run analytics that profile visitors. For the emails, it presents an unticked box in plain language, separate from the terms of sale, so signing up for an account does not force marketing on anyone. For non-essential analytics, it asks through a cookie banner where 'reject' is as easy as 'accept', with no pre-ticked options. It records what each person was told and when they agreed, and it offers a one-click unsubscribe and a clear way to change cookie choices. For order fulfilment and fraud checks, it relies on contract and legitimate interests instead of consent, since those do not need a separate opt-in. (Illustrative; RGM analysis.)
Failure modes to watch. Using pre-ticked boxes or inferring agreement from silence, which fail the unambiguous test; bundling unrelated processing into one request or blocking a service unless the user consents, which fail freely-given; burying the ask in long terms so it is not informed; and making consent hard to withdraw or treating it as a one-time formality.

Synonyms & antonyms

Synonyms

opt-in consentGDPR consentexplicit consent

Antonyms

legitimate interestimplied consent

Origin & history

The requirement stems from the EU's General Data Protection Regulation (GDPR), effective 2018, which in Articles 4 and 7 defines consent and the conditions for it to be valid.

Etymology: source.

Usage trends

Search interest for this term over the last five years:

View interest-over-time on Google Trends →

Common questions

What is consent under the GDPR?
Under the General Data Protection Regulation, consent is a freely given, specific, informed, and unambiguous opt-in — a clear affirmative action by which a person permits the processing of their personal data. Silence, pre-ticked boxes, and inactivity do not count. This is not legal advice.
Is consent always required to process data?
No. Consent is one of six lawful bases. Processing can also rest on a contract, a legal obligation, vital interests, a public task, or legitimate interests. Consent brings the strictest conditions, so it suits marketing and tracking more than routine, expected processing.
Can GDPR consent be withdrawn?
Yes. It must be as easy to withdraw as it was to give, and the organization must stop the relevant processing once someone withdraws. Consent should be specific and current, and organizations must be able to demonstrate that valid consent was obtained.

Resources & people to follow

Curated, non-competitor resources verified per term.

Related training

Disciplines

Areas of marketing where consent (gdpr) is a core concern:

Sources

  1. trendsGoogle Trends — "gdpr consent"