Skip to main content
Category: Legal Basis and Consent

Freely Given Consent

Also known as: Freely Given (as a condition of valid consent)
Simply put

Freely given consent means a person has a genuine, real choice about whether their personal data is used, without being pressured, penalised, or forced into agreeing. If someone has no real alternative, or if refusing would deny them a service they are otherwise entitled to, their consent is generally not considered freely given. It is one of several conditions that must all be met for consent to be valid.

Formal definition

Under the EU GDPR and the UK GDPR, 'freely given' is one of the required qualities of valid consent, alongside 'specific', 'informed', and 'unambiguous'. Consent is generally not regarded as freely given where the data subject lacks genuine choice or control, is unable to refuse or withdraw without detriment, or where there is a clear imbalance of power between the parties. In assessing this quality, GDPR guidance (including Article 7 and Recital 43) directs that utmost account be taken of factors such as whether the performance of a contract has been made conditional on consent to processing that is not necessary for that contract. Consent is only one of the available lawful bases for processing, and freely given consent should be relied upon only where such genuine choice can be demonstrated; where a controller cannot offer a real alternative, another lawful basis may be more appropriate. Under the accountability principle, controllers must be able to demonstrate that valid consent was obtained. This entry addresses the 'freely given' condition specifically and does not cover the mechanics of withdrawal, the granularity of specific consent, evidential record-keeping requirements, special category data conditions, children's consent, or the treatment of consent under regimes outside the EU and UK GDPR (such as the CCPA/CPRA or HIPAA), where consent requirements differ.

Why it matters

Freely given consent is a gatekeeping condition for one of the lawful bases available under the EU GDPR and the UK GDPR. Where an organisation chooses to rely on consent, and that consent is not freely given, the consent is generally invalid, which means the processing it purported to authorise may have no lawful basis at all. This is why the 'freely given' requirement matters disproportionately: it is not a minor procedural detail but a condition that can retroactively undermine an entire processing activity if genuine choice was never present.

A recurring practical failure is bundling or conditionality. When the performance of a contract or the provision of a service is made conditional on consent to processing that is not necessary for that contract, GDPR guidance directs that utmost account be taken of this factor, and such consent is generally not considered freely given. The same concern arises where there is a clear imbalance of power between the parties, such that the individual cannot realistically refuse or withdraw without detriment. In these situations, consent is often the wrong tool, and controllers should consider whether another lawful basis is more appropriate rather than forcing consent to carry weight it cannot bear.

Under the accountability principle, it is not enough to assert that consent was freely given; controllers must be able to demonstrate it. This entry addresses the 'freely given' condition specifically and does not cover the mechanics of withdrawal, evidential record-keeping, special category data conditions, children's consent, or how consent is treated under regimes outside the EU and UK GDPR, such as the CCPA/CPRA or HIPAA, where requirements differ.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads advising on lawful basis selection need to test whether consent can genuinely be freely given before an organisation relies on it. Where genuine choice is absent, due to conditionality, bundling, or a power imbalance, they should steer the organisation toward a more appropriate lawful basis rather than defaulting to consent.
Product and Service Designers
Teams designing sign-up flows, consent interfaces, and service terms must avoid making a service conditional on consent to processing that is not necessary for that service. Building in a real, non-detrimental option to refuse is central to keeping any consent relied upon valid under the EU and UK GDPR.
Compliance and Legal Teams
Under the accountability principle, these teams are responsible for being able to demonstrate that consent was validly obtained, including that it was freely given. They should assess relationships involving imbalances of power and document why consent was an appropriate basis, or select an alternative where it was not.
Employers Processing Employee Data
Employment relationships often involve a clear imbalance of power, which makes freely given consent difficult to establish for many workplace processing activities. Those responsible for HR and workforce data should be cautious about relying on employee consent and consider whether another lawful basis is more defensible.

Inside Freely Given Consent

Genuine Choice and Absence of Detriment
Under the EU GDPR and UK GDPR, consent is generally regarded as freely given only where the data subject has a real, non-coerced choice and is not exposed to negative consequences for refusing or later withdrawing. Where refusal leads to a meaningful detriment, consent is typically not considered freely given.
No Conditionality (Bundling Prohibition)
Consent is generally not freely given where the performance of a contract or provision of a service is made conditional on consent to processing that is not necessary for that contract or service. This is often described as the prohibition on 'bundling' or 'tying' consent to unrelated processing.
Absence of Imbalance of Power
Where there is a clear imbalance between the controller and the data subject, consent is less likely to be regarded as freely given. This is commonly cited in the employer-employee context and in relation to public authorities, where the dependent position of the individual can undermine the voluntariness of consent.
Granularity
Where processing serves multiple purposes, consent should generally be capable of being given separately for each purpose rather than as a single all-or-nothing option, so that the individual retains genuine choice over each distinct processing activity.
Withdrawability Without Penalty
The freely given character of consent is closely linked to the ability to withdraw it as easily as it was given, and without detriment. A consent that is difficult or disadvantageous to withdraw is less likely to be treated as freely given.
One of Several Conditions for Valid Consent
Being freely given is one component of valid consent, which under the EU and UK GDPR is generally described as freely given, specific, informed, and an unambiguous indication of the data subject's wishes. Freely given addresses voluntariness specifically and does not on its own satisfy the other conditions.

Common questions

Answers to the questions practitioners most commonly ask about Freely Given Consent.

Does obtaining consent guarantee that our processing is lawful and compliant?
No. Consent is only one of several lawful bases for processing under regimes such as the EU GDPR and UK GDPR, and it is not inherently superior to the others. Even validly obtained consent does not guarantee overall compliance, which depends on context, jurisdiction, and implementation, including satisfying other principles such as purpose limitation, transparency, and data minimization. Consent should not be conflated with other lawful bases, and in many situations a basis such as contractual necessity or legitimate interests may be more appropriate. Whether consent is the correct basis is a case-by-case determination.
Is consent always the appropriate lawful basis, so should we default to asking for it?
Generally, no. Defaulting to consent is a common mistake. Consent is one of multiple lawful bases, and choosing it where another basis fits better can create difficulties, because consent must be freely given and can typically be withdrawn. In particular, where there is a clear imbalance of power between the parties, consent may not be regarded as freely given and therefore may not be a valid basis at all. The appropriate basis depends on the purpose and circumstances of the processing and should be identified before collection rather than assumed.
How do we design a consent request so that it can be considered freely given?
In most jurisdictions that recognize this standard, a consent request should allow a genuine choice without detriment for declining, and should avoid making a service conditional on consent to processing that is not necessary for that service. Where feasible, granular options for distinct processing purposes generally support the freely given standard, rather than bundling multiple purposes into a single request. This entry addresses the freely given element specifically and does not cover the separate requirements that consent also be informed, specific, and unambiguous, nor the mechanics of recording consent.
What situations tend to undermine whether consent is freely given?
A clear imbalance of power between the controller and the individual is a common concern, for example in some employment or public-authority contexts, where an individual may not feel able to refuse. Making access to a product or service conditional on consent to non-necessary processing can also undermine the freely given standard. Pre-ticked boxes and default opt-in settings are generally not consistent with a freely given, affirmative choice. Whether any specific arrangement meets the standard depends on the jurisdiction and the facts.
What evidence should we retain to demonstrate that consent was freely given?
Under accountability-oriented frameworks, demonstrable evidence is generally expected rather than stated intent. This typically includes records of what the individual was presented with, the choices available to them, and the affirmative action taken, so the voluntary nature of the choice can be reconstructed. The controller ordinarily bears responsibility for maintaining such records. This entry does not prescribe specific retention periods or logging tools, which depend on the applicable regime and implementation.
If someone withdraws consent, what does that mean for processing already carried out?
In regimes recognizing this standard, withdrawing consent should generally be as easy as giving it, and consent that cannot be withdrawn without detriment may not be considered freely given. Withdrawal typically stops further processing that relies on that consent but does not, on its own, affect the lawfulness of processing already carried out on the basis of consent before withdrawal. This entry does not address the mechanics of erasure, retention obligations, or how processing may continue under a different lawful basis where one applies.

Common misconceptions

If a data subject clicks 'I agree', consent is automatically freely given and therefore a valid lawful basis for the processing.
A recorded agreement does not by itself establish that consent was freely given. Under the EU and UK GDPR, factors such as conditionality, an imbalance of power, or detriment for refusal can render consent invalid regardless of a click or signature. Freely given is also only one element of valid consent, and consent is only one of several lawful bases; it is not the appropriate basis for every processing activity.
Freely given consent is a universal concept that applies the same way across all privacy regimes.
The 'freely given' framing described here is drawn primarily from the EU GDPR and UK GDPR. Other regimes such as the CCPA and CPRA, HIPAA, and standards like ISO/IEC 27701 or the NIST Privacy Framework treat consent and choice differently, and some rely on opt-out or authorization models rather than this specific conditions-for-consent structure. Treatment should not be assumed to be identical across jurisdictions.
Consent obtained in an employment relationship is freely given as long as the employee signs the form.
Because of the imbalance of power between an employer (controller) and an employee (data subject), consent in this context is often difficult to regard as freely given under the EU and UK GDPR. In many cases another lawful basis is more appropriate, and reliance on consent may be challenged even where a signed form exists.

Best practices

Do not make provision of a service or performance of a contract conditional on consent to processing that is not necessary for that service or contract; separate necessary processing from optional processing.
Offer granular consent options for distinct processing purposes rather than presenting a single bundled opt-in, so that individuals retain genuine choice over each purpose.
Where a clear imbalance of power exists, such as employer-employee or public authority relationships, critically assess whether consent can be freely given and consider whether another lawful basis is more appropriate.
Make withdrawal of consent as easy as giving it and ensure that neither refusal nor withdrawal results in detriment to the individual.
Retain demonstrable evidence of how and when consent was obtained and of the choices presented, since accountability requires demonstrable evidence rather than stated intent.
Confirm that consent is the correct lawful basis for the processing before relying on it, recognising that freely given is only one condition of valid consent and that consent is only one of several lawful bases, with treatment differing across jurisdictions such as the EU GDPR, UK GDPR, and CCPA/CPRA.