Privacy

Consent

Also called user consent.

Consent is a freely given, specific, informed, and unambiguous choice to allow processing. Under GDPR it must be as easy to withdraw as to give.

How it is measured

Valid consent leaves a record: who chose, when, what they were shown, and what they agreed to. Pre-ticked boxes, scrolling, and silence do not count. One choice cannot cover several unrelated purposes.

You check it by looking at the log for a single visitor. If you cannot show the wording and the timestamp for that person, you cannot show consent.

Worked example

A hiking-club newsletter site asks for email marketing consent with an unticked box and a short sentence. 312 of 2,000 form submitters tick it. Only those 312 can receive club offers.

A year later, a member clicks unsubscribe. The club removes them from the marketing list the same day and keeps the order record it needs for tax.

How it differs

Consent is a choice a person makes. Cookie consent is that choice applied to storing or reading data on a device. Consent in general covers any processing you rest on it; cookie consent covers the device-access rule only.

Common errors

Bundling consent with terms of service. Using pre-ticked boxes. Making refusal harder than acceptance. Forgetting to honor a withdrawal. Using consent when another basis, like a contract, fits and then being stuck when people say no.

In practice

List every purpose that relies on consent and check each has its own control. Test withdrawal as a user. Keep the consent record for as long as you rely on it.

See also

Cookie consent, Legitimate interest, GDPR

Sources

Count this on a real site.

Watch my website