Freely Given Consent
Freely given consent means a person has a genuine, real choice about whether their personal data is used, without being pressured, penalised, or forced into agreeing. If someone has no real alternative, or if refusing would deny them a service they are otherwise entitled to, their consent is generally not considered freely given. It is one of several conditions that must all be met for consent to be valid.
Under the EU GDPR and the UK GDPR, 'freely given' is one of the required qualities of valid consent, alongside 'specific', 'informed', and 'unambiguous'. Consent is generally not regarded as freely given where the data subject lacks genuine choice or control, is unable to refuse or withdraw without detriment, or where there is a clear imbalance of power between the parties. In assessing this quality, GDPR guidance (including Article 7 and Recital 43) directs that utmost account be taken of factors such as whether the performance of a contract has been made conditional on consent to processing that is not necessary for that contract. Consent is only one of the available lawful bases for processing, and freely given consent should be relied upon only where such genuine choice can be demonstrated; where a controller cannot offer a real alternative, another lawful basis may be more appropriate. Under the accountability principle, controllers must be able to demonstrate that valid consent was obtained. This entry addresses the 'freely given' condition specifically and does not cover the mechanics of withdrawal, the granularity of specific consent, evidential record-keeping requirements, special category data conditions, children's consent, or the treatment of consent under regimes outside the EU and UK GDPR (such as the CCPA/CPRA or HIPAA), where consent requirements differ.
Why it matters
Freely given consent is a gatekeeping condition for one of the lawful bases available under the EU GDPR and the UK GDPR. Where an organisation chooses to rely on consent, and that consent is not freely given, the consent is generally invalid, which means the processing it purported to authorise may have no lawful basis at all. This is why the 'freely given' requirement matters disproportionately: it is not a minor procedural detail but a condition that can retroactively undermine an entire processing activity if genuine choice was never present.
A recurring practical failure is bundling or conditionality. When the performance of a contract or the provision of a service is made conditional on consent to processing that is not necessary for that contract, GDPR guidance directs that utmost account be taken of this factor, and such consent is generally not considered freely given. The same concern arises where there is a clear imbalance of power between the parties, such that the individual cannot realistically refuse or withdraw without detriment. In these situations, consent is often the wrong tool, and controllers should consider whether another lawful basis is more appropriate rather than forcing consent to carry weight it cannot bear.
Under the accountability principle, it is not enough to assert that consent was freely given; controllers must be able to demonstrate it. This entry addresses the 'freely given' condition specifically and does not cover the mechanics of withdrawal, evidential record-keeping, special category data conditions, children's consent, or how consent is treated under regimes outside the EU and UK GDPR, such as the CCPA/CPRA or HIPAA, where requirements differ.
Who it's relevant to
Inside Freely Given Consent
Common questions
Answers to the questions practitioners most commonly ask about Freely Given Consent.