Consent
In a data protection context, consent means a person freely agrees to let an organization use their personal data for a specific purpose. This agreement should be clear, voluntary, and given without pressure, and the person should be able to withdraw it. The evidence provided here describes consent in general and interpersonal contexts rather than in data protection law, so this entry is limited to the concept of voluntary agreement.
Consent, in general usage, is a voluntary agreement by one person to the proposal or request of another. Within data protection regimes, consent may serve as one of several possible lawful bases for processing personal data, and it should not be conflated with the other lawful bases; the availability, validity conditions, and standard for consent differ across instruments such as the EU GDPR, UK GDPR, and US frameworks including the CCPA and CPRA, and none of these differing standards can be inferred from the sources supplied here. The evidence packet available for this entry addresses consent only in general, relational, medical, and research senses and does not contain data-protection-specific legal instruments; accordingly, this definition does not establish jurisdiction-specific requirements (for example, that consent be freely given, specific, informed, unambiguous, or as easy to withdraw as to give), nor does it cover cross-border transfer mechanics, retention obligations, or the evidentiary demonstrability of consent required under accountability principles. Practitioners should consult the applicable regulatory text before relying on consent as a lawful basis.
Why it matters
Consent is one of the concepts most frequently misunderstood in data protection practice, in part because the word carries strong meanings in everyday, relational, medical, and research contexts. In its general sense, as reflected in the evidence available for this entry, consent describes a voluntary agreement by one person to the proposal or request of another, given clearly and without pressure. That general intuition is useful, but it should not be assumed to map directly onto the legal standard for consent as a lawful basis for processing personal data, which is defined by specific regulatory instruments not present in the sources supplied here.
For practitioners, the stakes lie in treating consent as just one of several possible lawful bases for processing rather than a universal justification. A common expert-level error is to collapse consent into other lawful bases, or to assume a single consent mechanism guarantees compliance across jurisdictions. The validity conditions and available alternatives differ across regimes such as the EU GDPR, UK GDPR, and US frameworks including the CCPA and CPRA, and these differences cannot be inferred from general-usage sources. Relying on consent where another basis is more appropriate, or applying one jurisdiction's standard to another, exposes an organization to challenge.
Because the evidence packet for this entry addresses consent only in general, relational, medical, and research senses, this definition is deliberately limited to the concept of voluntary agreement. It does not establish jurisdiction-specific requirements, evidentiary or accountability obligations, cross-border transfer mechanics, or retention rules. Practitioners should consult the applicable regulatory text before relying on consent as a lawful basis.
Who it's relevant to
Inside Consent
Common questions
Answers to the questions practitioners most commonly ask about Consent.