UK GDPR: Consent Requirements (Article 7)
Consent Requirements [Art 7]
Citation: Article 7 (Art 7), UK GDPR
Rule: Consent must be demonstrable, freely given, and easy to withdraw.
Requirements for valid consent:
| Requirement | What it means | Citation |
|---|---|---|
| Demonstrable | Controller must be able to prove consent was given | Art 7(1) |
| Clear & distinguishable | Consent request must stand out from other text | Art 7(2) |
| Plain language | Must be intelligible and easily accessible | Art 7(2) |
| Easy to withdraw | Withdrawal must be as easy as giving consent | Art 7(3) |
| Freely given | Cannot be conditional on unnecessary data collection | Art 7(4) |
Key point: Withdrawal does not affect lawfulness of processing that occurred before withdrawal.
Withdrawal {#withdrawal}
It must be as easy to withdraw consent as to give it.
Source Text
Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.
If the data subject’s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.
The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.