Data Protection HubConcepts and Definitions

Consent (Article 4(11) GDPR)

Article 4(11) GDPR defines consent as a freely given, specific, informed and unambiguous indication of the data subject's wishes to the processing of their personal data.

Article 4(11) GDPR gives consent an independent legal definition: it is any freely given, specific, informed and unambiguous indication of the data subject's wishes in the form of a statement or another clear affirmative action by which the data subject signifies agreement to the processing of personal data relating to him or her.

Key takeaways

  • Consent presupposes four cumulative elements: it must be freely given, specific and informed, and it must be expressed through an unambiguous act.
  • Silence, pre-ticked boxes and mere inactivity do not suffice (Recital 32 GDPR).
  • Consent may be withdrawn at any time without detriment (Article 7(3) GDPR); a retroactive cure of processing that has already begun is excluded.
  • The controller bears the burden of proof for the existence of valid consent (Article 7(1) GDPR).
  • This page addresses the definitional concept. The requirements for validity, the relationship to other legal bases and the practical requirements are set out in detail on the page 1.3.2.1 Consent as a Legal Basis.

1. Overview

1.1 Placement within the GDPR's structure

Consent is one of the six legal bases on which the processing of personal data may be based (Article 6(1)(a) GDPR). It permits the controller to carry out processing for which no statutory legal basis exists. It cannot, however, contract out of the GDPR's mandatory statutory requirements and cannot override a statutory prohibition.

Consent must be in place before the processing begins. Consent obtained only after the processing has commenced does not retroactively cure the processing that was unlawful up to that point.

1.2 Distinction: definition and application

Article 4(11) GDPR determines which elements an indication of wishes must satisfy in order to qualify as consent. The provision answers the question: what is consent? The follow-up questions, whether a specific consent is valid, how it must be documented and what limits it has, are governed by Articles 7 and 8 GDPR as well as by special provisions for specific situations.

2. The four definitional elements

The following table summarizes the four cumulative elements of the legal definition:

ElementCore contentDistinction
Freely givenThe data subject has a genuine choice; there must be no coercion or significant pressure.Not freely given where refusal entails an unreasonable detriment or effectively frustrates participation in social life.
SpecificThe consent relates to a concrete processing purpose; its content, purpose and scope must be sufficiently clear.Where there are several independent purposes, separate consent is required for each purpose (Recital 32 GDPR).
InformedBefore consenting, the data subject must have been informed about the controller, the processing purpose, planned data disclosures, and the possibility and consequences of a refusal.Incomplete or misleading information renders consent invalid; the information must be provided in intelligible language.
UnambiguousThe indication of wishes must be given through an active act, e.g. ticking a box or selecting a technical setting (Recital 32 GDPR).Silence, pre-selected boxes and inactivity do not satisfy the element.

2.1 Freely given (voluntariness)

Being freely given presupposes that the data subject can choose between agreement and refusal without suffering an inappropriate detriment. Where the only way to use a service offering or to take part in a prize competition is to give consent, a genuine choice is lacking.

Whether consent can be given freely within an employment relationship must be assessed separately on account of the structural imbalance of power. Section 26(2) of the German Federal Data Protection Act (BDSG) lays down special standards for this and, as a rule, requires consent in the employment context to be given in written or electronic form.

2.2 Specific (for the specific case)

This element excludes blanket consent intended to cover an unmanageable multitude of future processing operations. At the time of consenting, the data subject must be able to recognize what he or she is agreeing to. Where there are several processing purposes, consent must be obtained separately for each of these purposes (Recital 32 GDPR), so that the data subject can consent selectively.

2.3 Informed (in an informed manner)

Consent presupposes prior information. The data subject must at least know who the controller is, for what purpose the data are processed, whether disclosure to third parties is planned and what consequences a refusal or a withdrawal has. If this information is missing or is worded so unclearly that the data subject cannot assess its scope, there is no informed consent.

2.4 Unambiguous nature and the active act

Article 4(11) GDPR names two equivalent forms: a statement or another clear affirmative action. Recital 32 GDPR specifies that this may include, for example, ticking a box when visiting a website or choosing technical settings for information society services. What is always decisive is an active act by the data subject.

Not sufficient are silence, boxes pre-ticked before the interaction and any form of inactivity (Recital 32 GDPR). In the Planet49 case, the CJEU expressly confirmed that pre-ticked checkboxes do not constitute valid consent (CJEU, judgment of 1 October 2019, C-673/17, Planet49).

3. Burden of proof and the obligation to demonstrate

The controller must be able to demonstrate that consent meeting the requirements of Article 4(11) GDPR was given (Article 7(1) GDPR in conjunction with Article 5(2) GDPR). The burden of proof lies entirely with the controller; the data subject does not have to prove the absence of consent.

In the Orange România case, the CJEU clarified the requirements to be imposed on a pre-formulated declaration of consent and on its documentation: the circumstances of the consent process must be recorded in a comprehensible manner, so that the controller can demonstrate in the event of a dispute that the data subject actively agreed (CJEU, judgment of 11 November 2020, C-61/19, Orange România).

4. Right of withdrawal

Consent may be withdrawn by the data subject at any time, without any detriment arising for the data subject as a result (Article 7(3) GDPR). The withdrawal does not have retroactive effect; it ends the permissibility of the processing for the future. The data subject must be informed of the right to withdraw before giving consent, and it must be as easy to withdraw consent as it is to give it.

Following an effective withdrawal, there is generally a right to erasure under Article 17(1)(b) GDPR where no other legal basis supports the processing. A contractual or other exclusion of the right to withdraw is not possible.

5. Special situations

For certain processing operations, the GDPR requires explicit consent that goes beyond the general requirements of Article 4(11) GDPR:

  • Processing of special categories of personal data (Article 9(2)(a) GDPR)
  • Automated individual decisions, including profiling (Article 22(2)(c) GDPR)
  • Transfers to third countries in certain cases (Article 49(1)(a) GDPR)

For information society services offered to children, consent given by the child itself is valid from the completed age of 16; for younger children, the consent of the holder of parental responsibility is required (Article 8 GDPR). Member States may lower the age limit to as low as 13 years.

5.3 Employment relationship

In the employment context, special requirements apply under Section 26(2) BDSG. On account of the typical imbalance of power between employer and employee, whether consent is freely given must be examined with particular care. As a rule, consent must be obtained in written or electronic form, unless special circumstances justify a different form.

5.4 Cookies and tracking

The accessing of information stored in users' terminal equipment and the storing of such information require, under Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG), consent that must meet the requirements of the GDPR. Exempted under Section 25(2) TDDDG are only those operations that are technically strictly necessary for a service expressly requested by the user.

For the application of consent as a legal basis, the assessment of validity in the individual case, the prohibition on bundling (conditionality) and the relationship to the other grounds for lawful processing under Article 6 GDPR, see the detailed presentation on the page 1.3.2.1 Consent as a Legal Basis.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn