Skip to main content
Category: Legal Basis and Consent

Informed Consent

Simply put

Informed consent is a process in which a person is given clear, relevant information about what they are being asked to agree to, including the risks, benefits, and alternatives, so they can make a knowing and voluntary decision. The evidence provided describes this concept primarily in a medical and research setting, where a patient or research subject authorizes a procedure, treatment, or participation in a study after that information has been disclosed. It is framed as an ongoing communication and disclosure process rather than a single signature.

Formal definition

Within the medical and human-subjects research context reflected in the source evidence, informed consent is a disclosure-and-authorization process in which a qualified professional communicates material information, including risks, benefits, and alternatives, to a patient or prospective research subject (or their legally authorized representative), resulting in a knowing, voluntary agreement to undergo a procedure, treatment, or study participation. The sources characterize it as a process of complete disclosure of critical information rather than a one-time formality, and note that it may be legally required in clinical settings. Note that the evidence provided addresses informed consent as a clinical and research ethics concept and does not establish how consent operates as a lawful basis for personal data processing under data protection regimes such as the EU GDPR, UK GDPR, or the CCPA and CPRA; the requirements, validity conditions, and role of consent differ materially between clinical/research ethics and data protection law, and consent is only one of several possible lawful bases in the latter. Cross-border transfer mechanics, retention rules, withdrawal mechanics, and jurisdiction-specific validity standards are out of scope for this entry based on the available evidence.

Why it matters

Informed consent, in the clinical and human-subjects research setting reflected in the source evidence, matters because it operationalizes respect for individual autonomy: a person cannot make a knowing, voluntary decision about a procedure, treatment, or study participation unless the material risks, benefits, and alternatives have been disclosed to them in a way they can understand. The sources characterize it as an ongoing communication and disclosure process rather than a single signature, which means the quality of the conversation, not merely the existence of a signed form, determines whether consent is meaningful. Where the process is treated as a formality, the underlying authorization can be undermined even if paperwork exists.

Who it's relevant to

Healthcare and research professionals
Clinicians, physicians, and researchers are, per the evidence, the parties responsible for educating patients or prospective subjects about the risks, benefits, and alternatives and for obtaining a knowing, voluntary authorization. They bear the disclosure obligation and should treat consent as an ongoing communication process rather than a completed form.
Patients, research subjects, and their representatives
The individual, or their legally authorized representative where applicable, is the party whose knowing and voluntary agreement the process is designed to secure. The evidence frames complete disclosure of critical information as directed toward enabling this person's informed decision.
Data protection officers and privacy professionals
Those working under data protection regimes should note that the clinical and research meaning of informed consent described here is distinct from consent as a lawful basis for processing. The evidence does not establish how consent operates under the EU GDPR, UK GDPR, or CCPA and CPRA, and consent is only one of several lawful bases in those regimes. Do not assume a clinical consent form satisfies data protection consent requirements.
Compliance and legal teams in healthcare settings
Teams overseeing clinical and research operations should recognize, based on the evidence, that informed consent may be legally required in care settings and should ensure the disclosure process is demonstrable rather than assumed. Accountability generally requires evidence of the process, not merely a stated intent to inform. Jurisdiction-specific validity standards and enforcement details are out of scope for this entry.

Inside Informed Consent

Freely Given
Consent must be a genuine choice, offered without coercion, pressure, or significant detriment for refusal. Where there is a clear imbalance of power between the parties, consent is generally harder to establish as freely given.
Specific
Consent must be tied to distinct, clearly defined processing purposes. Bundling multiple purposes under a single consent, or seeking blanket consent for open-ended future use, typically undermines validity.
Informed
The data subject must be given clear information before consenting, generally including the identity of the controller, the purposes of processing, the categories of data involved, and the right to withdraw. Language should be intelligible and accessible.
Unambiguous Indication
Consent requires a clear affirmative action or statement. Silence, pre-ticked boxes, or inactivity do not generally constitute valid consent under regimes such as the EU GDPR and UK GDPR.
Withdrawable
The data subject must be able to withdraw consent at any time, and withdrawal should be as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Demonstrable
Under accountability principles, the controller must be able to show that valid consent was obtained. This generally requires retaining evidence of who consented, when, to what, and on the basis of what information.

Common questions

Answers to the questions practitioners most commonly ask about Informed Consent.

Isn't consent the lawful basis we should rely on for most processing?
No. Consent is only one of several lawful bases available under regimes such as the EU GDPR and UK GDPR, and it is often not the most appropriate one. Other bases, such as contract, legal obligation, vital interests, public task, or legitimate interests, may fit the processing better and can be more stable, since consent can be withdrawn. Treating consent as a default basis is a common error; the correct basis depends on the purpose, context, and jurisdiction, and relying on the wrong basis does not become defensible simply because a consent mechanism exists.
If someone consents, does that guarantee our processing is compliant?
No. Obtaining consent does not, on its own, guarantee compliance. Consent addresses only the lawful basis for a given processing activity; other obligations, such as transparency, purpose limitation, data minimization, security, retention limits, and accountability, still apply independently. In addition, consent must generally meet qualifying conditions (for example, being freely given, specific, informed, and unambiguous under the GDPR framing) to be valid at all. Compliance depends on the overall context and implementation, not on the presence of a consent record alone.
How should we document consent so it is defensible on review?
Accountability under governance and data protection frameworks generally requires demonstrable evidence rather than stated intent, so you should retain records showing who consented, when, what they were told at the time, and to which specific purposes. Capturing the version of the notice or wording presented, the mechanism used, and the scope agreed to helps demonstrate that consent was informed and specific. This entry does not cover retention periods for such records, which depend on your applicable jurisdiction and internal policy.
How do we handle withdrawal of consent in practice?
Where consent is the lawful basis, individuals can generally withdraw it, and withdrawal should be as straightforward as giving it. Practically, this means providing an accessible mechanism, propagating the withdrawal to systems and any relevant recipients, and ceasing the processing that relied on that consent. Note that withdrawal typically does not affect the lawfulness of processing carried out before withdrawal, and processing that rests on a different lawful basis is not necessarily halted by it. The mechanics of downstream propagation and record-keeping depend on your architecture and are not detailed here.
Can one consent request cover multiple processing purposes?
Consent is generally expected to be specific to defined purposes, so bundling several distinct purposes into a single, take-it-or-leave-it request can undermine its validity, particularly where the purposes are not closely related. A more defensible approach is to separate purposes and let individuals consent to each independently. This entry does not address the detailed sufficiency tests applied in any particular jurisdiction, which vary and turn on the specific facts.
Who is responsible for ensuring consent is valid, the controller or the processor?
The obligation to establish a valid lawful basis, including obtaining and evidencing consent, generally rests with the controller, which determines the purposes and means of processing. A processor acting on the controller's instructions does not typically obtain consent on its own account and processes according to the controller's documented instructions. Allocation of these responsibilities should be reflected in the arrangement between the parties. This entry does not cover the full set of contractual terms that govern the controller-processor relationship.

Common misconceptions

Consent is the default or safest lawful basis for processing personal data.
Consent is one of several lawful bases and is not inherently superior. In many contexts another basis, such as contract or legitimate interests under the EU or UK GDPR, may be more appropriate. Relying on consent where it cannot be freely given or withdrawn can make processing more, not less, difficult to defend. This entry does not enumerate or compare all available lawful bases.
Once consent is obtained, it covers any related processing the organization later decides to carry out.
Consent is specific to the purposes disclosed at the time. New or materially different purposes generally require fresh consent or a separate lawful basis. Broad or open-ended consent typically fails the specificity requirement.
A ticked box or accepted terms is sufficient proof and validity of consent.
Validity depends on how consent was requested and whether the conditions of freely given, specific, informed, and unambiguous were met. Pre-ticked boxes or consent bundled into general terms and conditions are generally not valid, and the controller must retain demonstrable evidence rather than merely record acceptance.

Best practices

Confirm that consent is the appropriate lawful basis before relying on it, rather than defaulting to consent when another basis may fit the processing context better.
Present consent requests separately from other terms, using plain, intelligible language that identifies the controller, the specific purposes, and the categories of data involved.
Use clear affirmative mechanisms and avoid pre-ticked boxes, silence, or inactivity as a means of obtaining consent.
Provide and clearly signpost a withdrawal mechanism that is as easy to use as the mechanism for giving consent, and ensure withdrawal is honored going forward.
Retain demonstrable records of consent, capturing who consented, when, to what specific purposes, and on the basis of what information presented at the time.
Obtain fresh consent or identify a separate lawful basis when introducing new or materially different processing purposes, rather than relying on previously obtained consent.