When is consent under the GDPR valid?

Cindy Stefanet
by Cindy Stefanet · 27.09.2026

Requirements for effective consent at a glance

Consent is a key legal basis in data protection. However, it is often unclear for companies and those responsible for data processing when data processing can actually be based on consent and what specific legal requirements must be met in this regard.

Given the significant legal and economic risks in the event of a lack of consent or invalid consent, it is crucial to obtain consent from the outset in a legally secure manner.

Consent as a possible legal basis for data processing

Consent is governed by Article 6(1)(a) of the GDPR as one of six possible legal bases for the processing of personal data. It is an expression of the right to informational self-determination: each person should in principle be able to decide for themselves who may use their data for what purpose.

In practice, however, consent is only the right choice when no other legal basis under Article 6 of the GDPR applies. If personal data are processed for contract performance (lit. b) to fulfill legal obligations (lit. c) or on the basis of legitimate interests (lit. f), consent is neither required nor meaningful.

Consent is typically the appropriate legal basis for processing that is voluntary and goes beyond the contractual requirements.

Typical application examples are:

  • the sending of newsletters or personalized advertising,
  • the use of tracking and analysis tools, or
  • the publication of images and videos of people.

Legal requirements for effective consent

The GDPR defines consent in Art. 4 No. 11 GDPR as „any freely given expression of will [..] in an informed and unequivocal manner for the specific case“. This results in four key prerequisites that must be met cumulatively.

1. Volunteering

Consent must first be based on a genuine and free decision by the person concerned. The person concerned must therefore be able to refuse or withdraw consent without incurring any disadvantages. In particular, consent must not be obtained under duress or coercion.

Special importance in this context is given to the prohibition on linking pursuant to Article 7(4) of the GDPR. According to that provision, the provision of a service may not, in principle, be made subject to consent that is not required for the performance of the contract.

Also misleading wording, over-the-top language, an excessive amount of information, and visual design that deliberately directs users to consent (so-called dark patterns) can all undermine voluntary consent.

2. Awareness

Effective consent still requires that the data subject be informed in advance comprehensively and in a clear manner about the intended data processing.

The information must be easily accessible, transparent and formulated in clear language, and in particular make it clear who processes the data and for what specific purposes this is done. According to the current guidelines of the European Data Protection Board on consent, the data subject must also be provided with information about the nature of the data processed, the right to withdraw consent, as well as about possible automated decisions and transfers to third countries.

Additional information can be provided in a privacy policy that is clearly and unambiguously referenced.

3. Determination

Furthermore, consent must relate to a clearly defined processing purpose. Blanket or overly broad consents are inadmissible.

If several purposes are pursued, separate consent is generally required for each purpose.

Aggregation is only permissible in exceptional cases when the purposes are so closely related in content that a separate query is not feasible.

4. Indisputable confirmatory action

Finally, there must be an unequivocal declaration of intent through the active action of the person concerned (so-called opt-in).

The GDPR generally provides for freedom of form. Therefore, consent can be given in writing, but also electronically, e.g. by clicking a check box or button, selecting technical settings, or through other declarations or active behavior (e.g., verbally).

Silence, pre-filled checkboxes (so-called opt-out) or mere inaction, such as the continued use of a service, do not constitute consent. Likewise, it is not sufficient for a consent to be included in general terms of use without being specifically highlighted.

According to Article 7(1) of the GDPR, the responsible person must be able to prove that there is valid consent. The chosen form must therefore allow for reliable documentation.

Special cases and special requirements

In certain constellations, there are increased requirements for consent.

1. Processing of sensitive data

The processing of special categories of data within the meaning of Article 9 of the GDPR generally requires „express“ consent (see below).

2. Automated decision-making

If automated decision-making (Article 22 GDPR) is to be based on consent, an „express“ consent is also required.

3rd employee

According to § 26(2) of the BDSG, consent should in principle be given in writing, unless a different form is appropriate due to special circumstances.

Due to the existing dependency relationship, consent in employment relationships is regularly subject to critical scrutiny. Effective consent is only considered in exceptional cases, particularly when employees receive a legal or economic advantage through data processing, or when both parties pursue a mutually beneficial interest.

4th children

Children enjoy special protection in data protection, as they are often less aware of the risks and consequences of data processing.

For data processing related to information society services, Article 8 of the GDPR sets out specific conditions for consent. According to this provision, consent is only valid if the child has reached the specified minimum age or if the consent of the legal guardians is present. In Germany, the age limit is 16 years.

The GDPR does not specify any explicit age limits for other data processing. However, it follows from the reasons for the regulation that information must be provided in a clear and understandable language for children.

5. Research

In the field of scientific research, consent can be granted under certain conditions if the specific processing purpose is not yet fully established at the time of data collection. However, the scope of processing must remain discernible.

Requirements for an „express“ consent

„Expressive“ consent requires a particularly clear and unambiguous explanation from the person concerned. Silence or tacit consent are not sufficient. Furthermore, the consent must be formulated in a particularly precise manner, particularly with regard to the specific processing purpose and the sensitivity of the data concerned.

Revocation of consent

The right of withdrawal is the necessary counterpart to consent. The data subject may revoke their consent at any time in accordance with Article 7(3) GDPR, without giving reasons and with effect for the future.

This right must be mentioned even before consent is given. The withdrawal of consent must also be as easy to obtain as the granting of consent. It must therefore not be unnecessarily complicated and should in principle be able to be done in the same way (e.g. by clicking, email or a corresponding function in the user account).

Processing that took place until the revocation remains lawful; however, as of the date of the revocation, data processing based on consent may no longer be continued.

Time of consent

The GDPR does not stipulate a fixed validity period. Therefore, consent remains valid in principle as long as it is not revoked, the processing purpose continues and the circumstances have not changed significantly.

However, consent may lose its validity if it is not used for an extended period of time and the person concerned no longer has to expect its use. In case law, periods of approximately 1.5 to 2 years without contact are considered critical, cf. LG Berlin (Order of 2.7.2004 – 15 O 653/03); LG Hamburg (Order of 17.2.2004 – 312 O 645/02); LG Munich (Judgment of 8.4.2010 – 17 HK O 138/10).

Therefore, before using it, it should always be checked whether the consent is still valid. Furthermore, it is advisable to clarify in the wording that the consent generally remains valid until revoked, in order to make its temporal validity transparent.

Conclusion

Consent is a legally demanding instrument with clear legal requirements. Its effectiveness depends largely on a clear legal framework, transparent design, and consistent implementation. In practice, it should be used purposefully and not be considered a standard solution.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

When is consent actually the correct legal basis?


What conditions must an effective consent meet?


When does lack of voluntary consent become a problem?

Does a pre-filled checkbox suffice for effective consent?


What special requirements apply for sensitive data, employees, and children?


How must the withdrawal of consent be formalized?