Granular Consent
Granular consent is the practice of asking individuals to agree separately to each distinct use of their personal data, rather than bundling everything into a single blanket permission. For example, a person might agree to one purpose while declining another. This approach is intended to give people meaningful, specific choices over how their data is handled.
Granular consent refers to obtaining separate, purpose-specific consent for distinct processing operations rather than relying on vague, bundled, or blanket consent. Under the UK GDPR, the ICO frames granularity as a component of valid consent, which Article 4(11) defines as any freely given, specific, informed and unambiguous indication of the data subject's wishes; granularity supports the 'specific' element by ensuring separate consent is captured for separate purposes and by naming relevant third parties. Where consent is the chosen lawful basis, granularity is one requirement among several, and consent is only one of the lawful bases available under the UK GDPR; it should not be assumed to be required or appropriate for all processing. This entry addresses the concept of granularity within consent and does not cover consent withdrawal mechanics, records-of-consent obligations, cross-border transfer requirements, retention rules, or the treatment of consent under other regimes such as the EU GDPR, CCPA/CPRA, or sector-specific frameworks, where requirements may differ.
Why it matters
Granular consent matters because, where consent is the lawful basis relied upon, its validity depends on the individual's agreement being specific to each distinct processing purpose. Under the UK GDPR, the ICO frames granularity as a component of valid consent: vague or blanket consent generally does not satisfy the requirement that consent be 'specific' as set out in the Article 4(11) definition. Bundling multiple purposes into a single permission, or forcing an all-or-nothing choice, undermines the meaningful control that consent is intended to provide, and can render the consent invalid as a lawful basis.
For organisations, this shapes how consent interfaces and workflows are designed. The ICO guidance indicates that separate consent should be captured for separate things and that relevant third parties should be named, so that individuals understand and can choose between the specific uses of their data. Getting this wrong does not simply weaken the user experience; it can mean the processing lacks a valid lawful basis where consent was the chosen basis, exposing the organisation to compliance risk.
It is important to keep the concept in proportion. Consent is only one of the lawful bases available under the UK GDPR, and granularity is one requirement among several that a valid consent must satisfy. Granular consent should not be assumed to be required or appropriate for all processing, and it does not by itself guarantee compliance. This entry does not address consent withdrawal mechanics, records-of-consent obligations, retention, cross-border transfers, or how consent is treated under other regimes such as the EU GDPR, CCPA/CPRA, or sector-specific frameworks, where requirements may differ.
Who it's relevant to
Inside Granular Consent
Common questions
Answers to the questions practitioners most commonly ask about Granular Consent.