Data Protection HubIndividual TopicsLegal Bases for Processing

Consent (Article 6(1)(a) GDPR)

Consent as a legal basis for processing: significance, conditions for validity, relationship to the statutory grounds for lawful processing and to contractual declarations of agreement.

Consent heads the list of grounds for lawful processing set out in Article 6(1) GDPR. It gives expression to informational self-determination: whoever gives valid consent decides on their own responsibility about the disclosure and use of the data relating to them. As regards requirements and legal consequences, Article 6(1)(a) GDPR refers to Article 4(11) and Article 7 GDPR, which define and give substance to the concept of consent.

Key takeaways

  • Valid consent must, under Article 4(11) GDPR, be cumulatively freely given, specific, informed and unambiguous, and must be expressed by a clear affirmative action.
  • Consent ranks equally with the statutory grounds for lawful processing; subsequently swapping the legal basis is as a rule not possible.
  • The controller bears the burden of demonstrating that consent was given (Article 7(1) GDPR).
  • Consent may be withdrawn at any time under Article 7(3) GDPR; upon withdrawal, the legal basis for future processing ceases to exist.
  • Where a statutory legal basis applies, it is as a rule more robust than consent, given the requirements as to voluntariness, information and demonstrability.

1 Overview

Valid consent supports any processing that remains within the purposes it defines. It takes the place of a statutory legal basis and gives the controller room for arrangements beyond the catalog of statutory grounds for lawful processing.

1.2 Role within the scheme of Article 6 GDPR

Consent ranks equally with the statutory grounds for lawful processing (points (b) to (f)). Neither a statutory legal basis nor consent enjoys priority over the other. Before processing begins, the controller must determine which legal basis the processing is to rest on. Subsequently "swapping" the legal basis is as a rule not possible, because of the consequences this entails for information obligations and data subject rights (in particular the right to withdraw consent under Article 7(3) GDPR and the right to object under Article 21 GDPR).

Under Article 4(11) GDPR, valid consent must cumulatively be given:

  • freely,
  • for one or more specific purposes,
  • in an informed manner and
  • unambiguously.

In addition, there must be a clear affirmative action constituting an express declaration of intent. Silence, pre-ticked boxes or inactivity do not suffice (CJEU, judgment of 1 October 2019, C-673/17, Planet49, para. 62).

2.1 Freely given

Consent must rest on a genuine choice by the data subject. Article 7(4) GDPR gives substance to the criterion of free choice through the prohibition on bundling: where consent is made conditional on the performance of a contract even though the processing is not necessary for that performance, this militates against consent having been freely given.

Particular caution is required where structural imbalances of power exist. This applies in particular to the relationship between public authorities and citizens and, as the national legislature assumes in § 26(2) of the German Federal Data Protection Act (BDSG), to the employment relationship. The question of free choice also arises in the online context, where access to a service is made dependent, without any alternative, on consent to far-reaching processing operations. So-called "cookie walls", in which access to services and functions is made conditional on agreement to the storage of, or access to, information on the terminal equipment, are in the EDPB's view generally incompatible with the requirement that consent be freely given (EDPB, Guidelines 05/2020 on consent, para. 39).

A dominant market position on the part of the controller does not automatically preclude valid consent, but it is an important factor in assessing whether consent was in fact freely given, a matter on which the controller bears the burden of proof (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 154).

Consent must relate to one or more concrete processing purposes. Blanket consent to "all conceivable processing operations" is invalid. Where the controller wishes to use data for several purposes, it must request consent separately for each purpose and leave the data subject the choice as to which purposes to accept.

For the definition of purposes, the EDPB has developed a triad of three cumulative requirements: definition of a specific purpose, granularity in obtaining consent (separate consent for different processing operations) and clear separation of the consent information from other information (EDPB, Guidelines 05/2020 on consent under Regulation 2016/679, version 1.1, para. 55 et seq.). Recital 33 allows a broader definition of purposes for scientific research purposes; by way of a converse inference, it follows that outside the research context the requirements as to the specificity of the purpose definition are to be construed narrowly. A pre-formulated declaration of consent that is not clearly distinguished from the remaining contractual clauses does not meet these requirements (CJEU, judgment of 11 November 2020, C-61/19, Orange România, para. 38 et seq.).

2.3 Informed nature

The data subject must give consent in knowledge of the essential circumstances of the processing. These include the identity of the controller, the specific purposes, the categories of data processed, any recipients and the existence of the right to withdraw consent. In substance and in language, the information must be designed so as to be intelligible to an average informed user.

Specifically with regard to cookies and comparable tracking technologies, the CJEU has clarified that the information must also cover the duration of the operation of the cookies and any recipients (CJEU, judgment of 1 October 2019, C-673/17, Planet49, para. 78 et seq.).

2.4 Unambiguous indication

Consent must be expressed by a clear action or statement. An "opt-out" model, in which consent is presumed for as long as the data subject does not object, does not suffice. Nor does the mere continued use of a service ("implied consent") satisfy the requirement of an affirmative action.

2.5 Demonstrating consent (Article 7(1) GDPR)

The controller bears the burden of proving that the data subject has consented. Demonstrability is of considerable practical significance: it calls for a documented declaration of intent evidencing the specific wording of the consent text, the point in time and the technical sequence of events.

3 Relationship to the statutory grounds for lawful processing

3.1 Equal ranking rather than priority

Consent and the statutory grounds for lawful processing stand alongside one another on an equal footing in principle. The controller is neither obliged to look first for a statutory legal basis, nor may it deploy consent as a fallback where a statutory legal basis applies in any event. What matters is that the legal basis chosen fits the specific processing operation.

3.2 Risk of circumventing the prohibition on bundling

The combination of several legal bases is problematic where it is used to undermine the requirement of a genuine choice. Taking Meta as an example, the CJEU has emphasized that the controller may not choose freely between the legal bases where the factual conditions are not met; the necessity of processing for the performance of a contract under Article 6(1)(b) GDPR cannot be replaced by assuming hypothetical consent (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 98 et seq.).

Consent under data protection law must be distinguished from contractual agreement to clauses in which the data subject declares a willingness to disclose certain data. Such contractual agreement is not consent within the meaning of Article 6(1)(a) GDPR, but part of the content of the contract, which is to be justified under Article 6(1)(b) GDPR. The difference matters in practice: whereas consent may be withdrawn at any time under Article 7(3) GDPR, contractual agreement has binding contractual effect.

4.1 Special categories of personal data

For the processing of special categories under Article 9(1) GDPR, Article 9(2)(a) GDPR requires explicit consent. The requirements go beyond those for general consent, but remain within the framework laid down by Article 4(11) and Article 7 GDPR.

Article 8 GDPR lays down special requirements for the consent of children in relation to information society services. The age threshold is in principle 16 years; Member States may lower it to as little as 13 years. Germany has not made use of this opening clause, so that the threshold of 16 years applies.

4.3 Withdrawal

Under Article 7(3) GDPR, consent may be withdrawn at any time with effect for the future. It must be as easy to withdraw consent as to give it. Upon withdrawal, the legal basis for future processing ceases to exist; processing already carried out remains lawful in so far as it was completed before the withdrawal.

Consent is often not the "simplest" legal basis. Because of the requirements as to voluntariness, information and demonstrability, and because of the right to withdraw at any time, it creates structural uncertainty. Where a statutory legal basis applies, it is as a rule more robust.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn