Glossary

Consent

Free, specific, informed and unambiguous indication of wishes as GDPR basis.

A

B

C

Under the GDPR, consent is one of six lawful bases for processing personal data. Valid consent must be freely given, specific, informed and unambiguous, meaning the data subject must actively opt in through a clear affirmative action. Pre-ticked boxes, silence or inactivity do not constitute valid consent.

Consent must be as easy to withdraw as it is to give, and organisations must maintain records proving that consent was obtained. For special categories of data (such as biometric or health data), explicit consent is required under Article 9. Organisations should carefully evaluate whether consent is the most appropriate legal basis, as it can be withdrawn at any time, potentially disrupting ongoing processing activities.

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z