CHAPTER IIPRINCIPLES

Article 7Conditions for consent

Official text

(1)Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.

(2)If the data subject’s consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration which constitutes an infringement of this Regulation shall not be binding.

(3)The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.

(4)When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.

Commentary

I. Article 7: The Operational Heart of Consent under the GDPR

Article 7 is perhaps the most misunderstood provision within the GDPR. It is frequently treated as though it defines consent itself. In reality, it does no such thing. The legal definition of consent is contained in Article 4(11), while Article 6(1)(a) establishes consent as one of the lawful bases for processing. Article 9(2)(a) further elevates the standard by requiring explicit consent for processing special categories of personal data. Article 7 performs a different function altogether. It transforms consent from an abstract legal concept into an operational legal mechanism by prescribing the conditions that must exist before consent can legitimately function as a lawful basis for processing.

This distinction is fundamental. Article 4(11) explains what consent is, whereas Article 7 explains how valid consent is obtained, demonstrated, maintained and, where necessary, withdrawn. It is therefore not a definitional provision but an evidentiary and procedural one. It governs the lifecycle of consent rather than its conceptual meaning.

Viewed structurally, Article 7 acts as the bridge between the foundational principles of Article 5 and the lawful basis established by Article 6. Consent does not become legally effective merely because an individual expresses agreement. Instead, Article 7 requires that such agreement satisfy a series of procedural safeguards designed to ensure that consent represents a genuine and autonomous manifestation of the data subject's will. Consent under the GDPR is therefore not measured by the existence of agreement alone but by the quality of the process through which that agreement is obtained.

The provision reflects a broader philosophical shift within European data protection law. Earlier regulatory approaches often focused on the existence of consent as a formal requirement. The GDPR moves beyond formalism. It recognises that individuals frequently consent without reading lengthy privacy notices, without understanding complex processing operations, or because refusing consent would result in economic or practical disadvantage. Article 7 therefore seeks to distinguish between consent that is merely expressed and consent that is genuinely autonomous.

In this respect, Article 7 embodies one of the central values of the GDPR: informational self-determination. The Regulation does not treat consent as a contractual waiver of privacy rights. Rather, it views consent as an ongoing manifestation of individual autonomy that must remain meaningful throughout the processing relationship.

A persistent misconception among organisations is that consent represents the preferred or safest legal basis for processing personal data. This assumption is neither supported by the GDPR nor by the jurisprudence of the Court of Justice of the European Union.

The GDPR establishes six independent legal bases under Article 6, none of which enjoys hierarchical superiority. Consent is merely one lawful basis among several. It is appropriate only where the data subject is capable of exercising genuine freedom of choice. Where processing arises from contractual necessity, compliance with legal obligations, protection of vital interests, public tasks, or legitimate interests, those legal bases should be considered independently.

This architecture reveals an important legislative choice. The GDPR does not encourage controllers to rely on consent wherever possible. On the contrary, consent is intentionally subjected to the most demanding procedural safeguards because it derives its legitimacy from the individual's autonomous decision rather than from an external legal obligation.

The EDPB has repeatedly emphasised that controllers should not rely on consent where another legal basis more accurately reflects the nature of the processing relationship. Doing so may not only invalidate the consent but also undermine transparency by misleading individuals about the true legal basis upon which processing occurs.

Illustration 1

Employment Relationship An employer seeks employees' consent to process payroll information. Although employees may sign a consent form, payroll processing is legally required for the performance of the employment contract and compliance with tax legislation. The appropriate legal bases are contractual necessity and legal obligation, not consent. Using consent in this context is misleading because employees cannot realistically refuse without jeopardising their employment.

Illustration 2

Online Retail Purchase An online retailer asks customers to consent to processing their delivery address before dispatching purchased goods. The processing is objectively necessary for performing the sales contract. Consent adds nothing legally and may create confusion regarding the customer's rights. The retailer should instead rely on Article 6(1)(b).

Illustration 3

Marketing Newsletter A customer purchases a book from an online bookstore. At checkout, the bookstore separately asks whether the customer wishes to receive promotional emails about future releases. Unlike processing the delivery address, sending marketing communications is not necessary for performing the purchase contract. Consent therefore represents an appropriate legal basis because the customer can freely decide whether to receive such communications without affecting the underlying transaction.

III. Article 7 as an Expression of the Accountability Principle

The first paragraph of Article 7 cannot be understood in isolation. It is a direct manifestation of the accountability principle embodied in Article 5(2), which requires controllers not merely to comply with the GDPR but to demonstrate compliance.

This relationship is often overlooked. Article 5(2) establishes accountability as a general principle applicable throughout the Regulation. Article 7(1) translates that principle into a specific evidentiary obligation in the context of consent. The legislature therefore deliberately places the burden of proof upon the controller rather than upon the data subject.

The practical significance of this allocation cannot be overstated. Under traditional civil law principles, the party asserting a fact often bears the burden of proving it. Article 7 reverses any uncertainty that might otherwise arise. Where processing relies upon consent, the controller must affirmatively establish that valid consent existed at the relevant time. The data subject is under no obligation to prove that consent was absent or defective.

This reflects the asymmetry of information between controllers and individuals. Controllers design the consent mechanism, determine the wording of consent requests, choose the technological interface, store the records, and decide how evidence will be retained. They are therefore uniquely positioned to demonstrate compliance. Requiring individuals to prove that they never consented would often be practically impossible and would significantly weaken the protection afforded by the GDPR.

Article 7(1) thus functions as a rule of evidentiary fairness. It allocates responsibility to the party best able to preserve evidence while simultaneously incentivising controllers to establish robust governance mechanisms for consent management.

IV. The Meaning of "Demonstrate"

One of the most significant interpretative questions concerns the legislature's choice of the word "demonstrate."

The GDPR does not require controllers merely to "claim," "assert," or "record" consent. Nor does it require proof beyond any conceivable doubt. Instead, the obligation is to demonstrate that consent was obtained in accordance with the Regulation.

This terminology suggests something more demanding than maintaining a database of affirmative responses. Demonstrating consent requires evidence capable of establishing not only that an affirmative act occurred but also that the legal conditions for valid consent were satisfied.

A controller must therefore be able to demonstrate, where challenged, that the consent was:

  • freely given;

  • specific;

  • informed;

  • unambiguous;

  • linked to clearly identified purposes;

  • capable of withdrawal;

  • obtained through a transparent mechanism.

A simple database entry stating "consent = yes" proves only that a technical event occurred. It says nothing about whether the data subject understood the request, whether the interface used manipulative design, whether the consent covered the relevant processing activity, or whether the request complied with Article 7(2).

Consequently, demonstrating consent often requires preserving contextual evidence rather than merely recording outcomes.

Illustration 4

Timestamp Without Context A company stores a timestamp showing that a user clicked "Accept" on 12 January 2026. Five years later, the user challenges the validity of that consent. The company produces the timestamp but cannot reconstruct the consent interface, the wording presented to the user, or the privacy notice in force at that time. Although the company has demonstrated that a click occurred, it has not demonstrated that valid consent was obtained. The evidentiary record is incomplete because the legal quality of the consent cannot be assessed.

Illustration 5

Preserved Consent Interface A software company archives:

  • the consent interface displayed;
  • the wording of the request;
  • the applicable privacy notice;
  • the user's affirmative action;
  • the timestamp;

  • the IP address (where appropriate);

  • subsequent withdrawal records.

Several years later, the company can reconstruct precisely what information the user received before consenting. This evidentiary package is far more likely to satisfy Article 7(1) because it demonstrates not only that consent occurred but also the circumstances under which it was obtained.

Illustration 6

Oral Consent A customer gives oral consent during a recorded telephone conversation for participation in a satisfaction survey. The controller retains the recording together with metadata identifying the caller and documenting the purpose of the processing. Article 7 does not require written consent. Provided that the recording reliably establishes the content of the consent request and the customer's affirmative response, oral consent may satisfy the burden of proof. The decisive issue is not the medium through which consent is given but whether the controller can subsequently demonstrate its validity. Among all the safeguards introduced by Article 7, paragraph (2) addresses one of the most pervasive abuses that existed before the GDPR came into force: the practice of concealing consent within lengthy contractual documentation. Prior to the GDPR, privacy notices, licence agreements and standard terms frequently contained a single clause by which individuals purportedly consented to a wide range of processing activities. Such consent was often buried within dozens of pages of contractual text, presented in legal language that few individuals were likely to read, much less understand. The legislature recognised that consent obtained in this manner was not the product of an autonomous decision but rather the consequence of informational overload and contractual inertia. Article 7(2) therefore represents a legislative rejection of what may be described asconstructive consent, the assumption that because an individual signed a contract, every clause within that document necessarily reflected an informed and voluntary decision. The GDPR deliberately dismantles this assumption by requiring that consent requests remain identifiable, comprehensible and independent of unrelated contractual obligations.

The conceptual distinction between a contract and consent lies at the heart of Article 7(2). A contract allocates rights and obligations between parties. Consent, by contrast, legitimises the processing of personal data. Although the same document may contain both contractual provisions and requests for consent, they perform fundamentally different legal functions.

This distinction explains why the GDPR refuses to permit consent to disappear within general contractual language. Contractual clauses are usually negotiated, or, more commonly, accepted, as an indivisible package. Consent, however, requires an individual evaluation of whether a particular processing operation should occur. If consent is absorbed into the contract, the individual may believe that accepting the contract necessarily requires accepting every processing activity described within it. Such a misunderstanding undermines the voluntary nature of consent and blurs the distinction between contractual necessity under Article 6(1)(b) and consent under Article 6(1)(a).

Article 7(2) therefore protects not merely transparency but also the integrity of the legal bases established by Article 6. Controllers must not disguise consent as a contractual obligation nor present optional processing as though it were essential to the contractual relationship.

II. Interpreting "Clearly Distinguishable"

The phrase "clearly distinguishable" is deceptively simple. It does not prescribe a particular design, font size or interface. Instead, it establishes a legal standard whose objective is to ensure that the data subject can immediately recognise that they are being asked to make a separate decision regarding personal data processing.

The requirement should therefore be interpreted functionally rather than mechanically. Whether consent is clearly distinguishable depends upon whether an average data subject can identify, without undue effort, the existence, purpose and consequences of the consent request.

Merely placing the consent clause in a separate paragraph is unlikely to satisfy this requirement if it remains embedded within several pages of contractual terms. Conversely, a well-designed interface using separate headings, independent checkboxes, concise explanations and visual separation may satisfy Article 7(2) even where the consent request appears within a broader contractual document.

The decisive question is not where the consent appears butwhether the individual recognises it as an independent legal choice.

Illustration 1

Hidden Consent in Employment Contract A new employee signs a twenty-page employment agreement. Page seventeen contains a clause stating: "The employee consents to the processing of personal data for marketing, promotional activities, publication of photographs, internal analytics and future business purposes." Although the clause is written in ordinary language, it is surrounded by unrelated provisions concerning salary, leave entitlement and disciplinary procedures. An average employee is unlikely to recognise that this paragraph requests consent rather than merely describing contractual obligations. The consent therefore fails the distinguishability requirement.

Illustration 2

Separate Privacy Section An online software provider presents its subscription agreement first. Once the contractual terms are accepted, the user is shown a separate screen headed:

"Optional Uses of Your Personal Data"

Each processing activity is described individually with an unticked checkbox and a concise explanation. The visual separation immediately signals that the user is making decisions independent of the contract. This arrangement is far more consistent with Article 7(2).

Illustration 3

Fine Print in Loan Agreement A bank includes, within the final page of a loan agreement, a sentence authorising behavioural advertising and disclosure of customer data to affiliated marketing companies. Because the clause is neither visually separated nor presented as an independent decision, borrowers are likely to perceive it as another contractual obligation. The consent is unlikely to satisfy Article 7(2), irrespective of whether customers technically signed the document.

III. "Intelligible and Easily Accessible": More Than Plain Language

Article 7(2) further requires that consent requests be presented in an intelligible and easily accessible form using clear and plain language. These expressions must not be interpreted as stylistic recommendations. They establish substantive legal obligations designed to ensure that individuals can exercise meaningful control over their personal data.

The notion of intelligibility concerns comprehension. Information is intelligible when an average member of the intended audience can understand its meaning without specialised legal or technical knowledge. Accessibility, by contrast, concerns availability. Information cannot be considered accessible if individuals must navigate multiple webpages, download lengthy documents or search through complex contractual materials before discovering the relevant consent request.

Importantly, intelligibility and accessibility reinforce one another. A perfectly drafted explanation hidden behind multiple hyperlinks is of limited practical value, just as an easily accessible notice written in technical jargon fails to inform the data subject.

This interpretation aligns with Article 12, which establishes transparency as a general principle governing all communications between controllers and data subjects. Article 7(2) therefore represents a specific application of that broader obligation within the context of consent.

Modern digital services frequently overwhelm individuals with information. Privacy notices exceeding twenty pages, multiple hyperlinks, layered policies and technical terminology may technically disclose extensive information while simultaneously preventing meaningful understanding. Article 7(2) rejects this approach.

The provision implicitly recognises an important behavioural reality: excessive information may impair understanding just as effectively as insufficient information. Individuals confronted with lengthy legal documents often cease reading altogether or simply accept the terms to gain access to the desired service. Consent obtained through informational exhaustion cannot genuinely be described as informed or autonomous.

Accordingly, controllers should not equate volume with transparency. Effective communication requires careful prioritisation of information, highlighting the matters that are genuinely relevant to the individual's decision.

Illustration 4

Forty-Page Privacy Notice A mobile application requests consent immediately below a hyperlink labelled "Privacy Policy." The linked document extends to forty pages and contains complex technical descriptions of data analytics, machine learning models and third-party advertising networks. Although the information is technically available, its complexity and length significantly reduce the likelihood that users will understand the processing before consenting. Accessibility exists in a formal sense but not in a practical one.

Illustration 5

Layered Notice A health application presents a concise summary explaining:

  • what information will be collected;
  • why it will be processed;
  • who will receive it;
  • how long it will be retained;
  • how consent may be withdrawn.

Each heading links to additional detail for users who wish to explore the processing further. Essential information is immediately visible, while supplementary detail remains readily available. This layered approach exemplifies the balance envisaged by Article 7(2) and Article 12.

V. The Relationship with Unfair Contract Terms

Recital 42 states that consent should not be regarded as freely given if it does not allow separate consent to different personal data processing operations or if the performance of a contract is dependent upon consent despite such consent not being necessary. Recital 42 further refers to the principles governing unfair contractual terms.

This cross-reference is significant. It demonstrates that consent cannot be isolated from the broader framework of European consumer protection law. A contractual provision that obscures, manipulates or misrepresents the consequences of consent may not only violate the GDPR but also constitute an unfair contractual term under consumer protection legislation.

The two regimes pursue complementary objectives. Consumer law protects contractual fairness, whereas the GDPR protects informational self-determination. Where a consent clause is hidden within standard terms or drafted in a misleading manner, both objectives may be undermined simultaneously.

Consequently, controllers should avoid viewing GDPR compliance and consumer law compliance as separate exercises. A transparent consent mechanism is increasingly expected under both regulatory frameworks.

VI. Can Hyperlinks Satisfy Article 7(2)?

One practical question concerns whether controllers may rely upon hyperlinks to present consent information. The GDPR neither prohibits nor expressly endorses this practice. The answer therefore depends upon whether the hyperlink genuinely contributes to intelligibility and accessibility.

A hyperlink may be appropriate where it supplements information already presented to the user. It is considerably more problematic where essential information is available only after navigating away from the consent request. If users must leave the interface, locate relevant sections and interpret multiple documents before understanding the request, accessibility is compromised.

Accordingly, hyperlinks should function as explanatory tools rather than substitutes for the consent request itself.

VII. Dark Patterns and the Evolution of Article 7(2)

Although Article 7(2) predates widespread regulatory concern regarding digital interface manipulation, its underlying principles readily accommodate modern forms of deceptive design. The EDPB's Guidelines on Dark Patterns illustrate how interface design can undermine distinguishability even where the wording of the consent request appears legally unobjectionable.

Examples

include:

  • visually emphasising the "Accept" button while concealing the refusal option;
  • presenting acceptance through a single click while requiring multiple screens to refuse;
  • repeatedly requesting consent after earlier refusals;
  • interrupting ordinary navigation until consent is provided;
  • framing refusal as risky or disadvantageous. These techniques exploit behavioural tendencies rather than informing autonomous choice. Although Article 7(2) does not expressly refer to interface design, its requirements of distinguishability, intelligibility and accessibility strongly support an interpretation that prohibits such practices. If Article 7(1) establishes how consent is proved, and Article 7(2) governshow consent must be requested, Article 7(3) addresses an equally fundamental question:can consent continue to legitimise processing after the individual no longer wishes to be bound by it? The GDPR answers this unequivocally, no. Unlike many areas of private law, where consent or agreement may become irrevocable once contractual obligations arise, consent under the GDPR remains inherently dynamic. It is not a permanent transfer of control over personal data, nor does it create vested rights in favour of the controller. Instead, it is a continuing manifestation of the data subject's autonomy, which may be withdrawn whenever the individual concludes that continued processing no longer reflects their wishes. This seemingly straightforward principle carries profound legal consequences. Article 7(3) does not merely establish a procedural right to withdraw consent; it embodies one of the GDPR's core philosophical commitments, that individuals retain continuing control over the processing of their personal data.

The most important interpretative point is that consent under the GDPR is never a one-time event.

Many controllers mistakenly conceptualise consent as a transaction completed when the individual clicks "Accept." Article 7(3) rejects this contractual understanding. Consent is better understood as a continuing legal condition that legitimises processing only for so long as the individual wishes that processing to continue.

The consequence is significant.

Unlike contractual consideration, consent does not permanently vest rights in the controller.

Rather, the controller's authority to process personal data remains conditional upon the continued existence of valid consent.

Consequently, withdrawal is not an exception to consent.

It is one of its defining characteristics.

Without the possibility of withdrawal, consent would become indistinguishable from contractual authorisation, fundamentally undermining the principle of informational self-determination.

II. Why Did the Legislature Make Withdrawal Unlimited?

Unlike consumer law, which frequently limits withdrawal rights to specified cooling-off periods (for example fourteen days), Article 7 deliberately imposes no temporal restriction whatsoever.

The omission is neither accidental nor insignificant.

The legislature recognised that individuals' expectations regarding privacy frequently evolve over time.

Processing that appears acceptable today may become unacceptable tomorrow because:

  • technology changes;

  • the purposes of processing evolve;

  • personal circumstances change;

  • trust in the controller diminishes;

  • risks become apparent only after prolonged processing.

If withdrawal were subject to a fixed limitation period, controllers could continue processing indefinitely despite the data subject's changed wishes.

This would contradict the GDPR's objective of maintaining individual control over personal information.

The unlimited nature of withdrawal therefore reflects the continuing character of informational autonomy.

Illustration 1

Fitness Application A user installs a fitness application and consents to the collection of health metrics for personalised exercise recommendations. Three years later the application expands its services and begins sharing aggregated health information with pharmaceutical companies. Although the original processing may have been acceptable to the user, the commercial expansion fundamentally alters their perception of privacy. Article 7(3) permits withdrawal at that moment rather than confining it to the date on which consent was originally granted.

Illustration 2

Social Media Platform A teenager consents to targeted advertising when opening an account. Ten years later, after entering professional employment, the individual no longer wishes their behavioural profile to be used for personalised advertising. Article 7(3) enables withdrawal irrespective of the length of time that has elapsed since consent was originally provided.

Illustration 3

Research Project A university receives consent from participants for a long-term medical study. Several years into the project, one participant develops concerns regarding genetic privacy and decides to withdraw. The passage of time does not diminish the legal effectiveness of withdrawal.

III. "At Any Time": A Continuing Right Rather Than a Periodic Opportunity

The expression "at any time" deserves careful interpretation.

It means considerably more than "whenever convenient."

The phrase reflects two distinct principles.

First, withdrawal cannot be restricted to predetermined intervals established by the controller.

Second, controllers cannot postpone or suspend withdrawal until administrative processes become convenient.

Suppose a controller permits withdrawal only once every six months.

Such a policy would clearly conflict with Article 7(3).

Similarly, requiring individuals to wait until the expiry of annual subscriptions before revoking consent would undermine the continuing nature of the right.

The legislature intentionally refrained from recognising any administrative exceptions.

Controllers must therefore organise their systems so that withdrawal can take effect whenever the data subject decides to exercise the right.

IV. Withdrawal Does Not Retroactively Invalidate Earlier Processing

One of the most misunderstood aspects of Article 7(3) concerns the legal effect of withdrawal.

The GDPR expressly states that withdrawal shall not affect the lawfulness of processing based on consent before its withdrawal.

The provision therefore adopts the principle of ex nunc effect.

Withdrawal operates prospectively.

It does not rewrite history.

This distinction is essential.

If withdrawal invalidated all previous processing retrospectively (ex tunc), almost every consent-based processing operation would become legally unstable.

Controllers would constantly face uncertainty regarding historical records, completed transactions and regulatory compliance.

Instead, the GDPR preserves legal certainty.

Processing lawfully undertaken before withdrawal remains lawful.

Only future processing loses its legal basis.

Illustration 4

Newsletter Subscription A customer consents to receive promotional newsletters. For eighteen months the company sends marketing emails. The customer subsequently withdraws consent. The newsletters already sent remain lawful. The controller is merely prohibited from sending future communications.

Illustration 5

Event Photography An attendee consents to photographs being taken during a conference. The organiser publishes several photographs while consent remains valid. Months later the attendee withdraws consent. The photographs lawfully published before withdrawal do not automatically become unlawful. However, future publication or continued processing requires independent legal justification.

Illustration 6

Educational Research Participants consent to anonymised statistical analysis. The university completes several published studies before one participant withdraws consent. Withdrawal does not invalidate research already conducted while consent remained effective. Future identifiable processing, however, must cease unless another lawful basis exists.

V. Does Withdrawal Automatically Require Erasure?

This question has generated considerable debate.

The intuitive answer appears to be yes.

However, the GDPR adopts a more nuanced position.

Withdrawal eliminates consent as the legal basis.

It does not necessarily eliminate every possible legal basis.

If another lawful basis independently authorises continued processing, the controller may rely upon that basis provided the requirements of Article 6 are genuinely satisfied.

Accordingly, withdrawal does not automatically require deletion.

Instead, the controller must reassess whether any lawful basis continues to support the relevant processing activity.

If none exists, Article 17 ordinarily requires erasure.

Illustration 7

Accounting Records A customer withdraws consent for marketing communications. The retailer must stop marketing immediately. However, purchase records required for tax compliance remain lawfully retained under legal obligation. Withdrawal affects only processing based upon consent.

Illustration 8

Security Logs A visitor withdraws consent to receive personalised recommendations. The organisation may nevertheless retain limited security logs necessary for cybersecurity and fraud prevention if another lawful basis applies. The withdrawal eliminates behavioural profiling, not necessarily every record relating to the user.

Illustration 9

Loyalty Programme A supermarket operates a loyalty programme entirely on the basis of consent. Once the customer withdraws consent, no independent legal basis exists. Unless statutory obligations require retention of specific records, the customer's profiling data should ordinarily be erased.

VI. "As Easy to Withdraw as to Give"

This is arguably the most innovative aspect of Article 7(3).

The legislature recognised that formal withdrawal rights are meaningless if controllers design systems that discourage individuals from exercising them.

Accordingly, Article 7(3) establishes functional equivalence between giving consent and withdrawing it.

The requirement should not be interpreted literally.

It does not require identical technical mechanisms.

Instead, it requires equivalent practical accessibility.

Withdrawal must not involve substantially greater effort than consent.

Controllers therefore cannot exploit behavioural biases by making acceptance effortless while rendering withdrawal burdensome.

Illustration 10

Single Click Acceptance A website allows visitors to accept marketing cookies with one click. To withdraw consent users must:

  • create an account,
  • verify their identity,
  • contact customer support,
  • complete a downloadable PDF,

  • wait thirty days.

The imbalance is obvious.

Although withdrawal remains theoretically possible, it is considerably more burdensome than giving consent.

Article 7(3) is unlikely to be satisfied.

Illustration 11

Privacy Dashboard Users activate personalised advertising through account settings. The same settings page contains a clearly labelled switch allowing advertising personalisation to be disabled immediately. The process mirrors the original consent mechanism and demonstrates compliance with Article 7(3).

Illustration 12

Telephone Consent An insurance company obtains marketing consent during recorded telephone calls. Withdrawal requires only a telephone call to the same customer service line. No written correspondence or additional administrative formalities are imposed. The withdrawal mechanism reflects the simplicity of the original consent process.

VII. Dark Patterns and Withdrawal

Modern interface design presents new challenges that were not explicitly contemplated when the GDPR was drafted.

Controllers increasingly employ behavioural techniques that preserve formal withdrawal rights while discouraging their practical exercise.

Examples

include:

  • repeatedly asking users whether they are "sure";
  • highlighting adverse consequences of withdrawal while minimising its benefits;
  • hiding withdrawal options within multiple settings menus;
  • using emotionally loaded language such as "Don't miss personalised experiences";
  • presenting withdrawal as an abnormal decision. The EDPB has correctly observed that such interface manipulation may undermine the practical effectiveness of Article 7(3). The GDPR protects not only legal rights but also their effective exercise. Consequently, withdrawal mechanisms should be evaluated from the perspective of actual user behaviour rather than purely technical availability.

VIII. The Broader Constitutional Significance of Article 7(3)

Article 7(3) ultimately reflects a constitutional principle extending far beyond consent itself.

European data protection law treats informational autonomy as an ongoing condition rather than a one-time waiver.

Individuals are not expected to predict every future consequence of processing when they first consent.

Nor are they expected to remain bound by decisions that no longer reflect their preferences or circumstances.

Withdrawal therefore reinforces the dynamic nature of privacy rights.

It reminds controllers that personal data remains connected to the individual throughout its lifecycle.

Consent authorises processing only so long as the individual continues to permit it.

The moment that permission is withdrawn, the controller must justify continued processing under another lawful basis or cease the relevant activity altogether.

This continuing obligation distinguishes GDPR consent from almost every other form of legal authorisation in European private law and confirms that personal data protection is fundamentally concerned with preserving the individual's enduring control over information relating to them.

If Article 7(3) protects an individual's continuing control over personal data, Article 7(4) protects the authenticity of the individual's initial choice. It answers one of the most difficult questions in data protection law:

When is consent truly voluntary?

The answer is deceptively complex. Most individuals technically have a choice, they can click "Accept" or "Decline." Yet the GDPR recognises that legal freedom is not synonymous with genuine freedom. Economic dependency, informational asymmetry, market dominance, social pressure, contractual necessity, and manipulative interface design can all influence decision-making without eliminating formal choice.

Article 7(4) is therefore one of the GDPR's most sophisticated provisions. It moves beyond traditional contract law, which often assumes that parties negotiate as equals, and instead acknowledges the realities of modern digital markets, where individuals routinely interact with organisations possessing overwhelming economic, technological and informational power.

Rather than asking "Did the person say yes?", Article 7(4) asks a more profound question:

"Was the person genuinely free to say no?"

This shift from formal agreement to substantive autonomy is the defining contribution of Article 7(4).

I. Why Did the GDPR Introduce Article 7(4)?

Before the GDPR, organisations frequently relied on what might be described as coercive consent. Access to employment, banking services, healthcare, online platforms or essential digital services was often made conditional upon accepting processing operations that bore little or no relationship to the service requested.

Legally, individuals consented.

Practically, they had no realistic alternative.

The legislature recognised that such consent was not an exercise of autonomy but rather an acceptance of necessity.

Article 7(4) was therefore enacted to prevent controllers from exploiting their superior bargaining position by presenting individuals with artificial choices.

The provision seeks to ensure that consent remains a genuine manifestation of individual will rather than the unavoidable price of obtaining unrelated goods or services.

II. Interpreting the Phrase "Utmost Account Shall Be Taken"

Perhaps the most debated expression in Article 7(4) is:

"Utmost account shall be taken..."

At first glance, this appears to be weak legislative language.

Why did the GDPR not simply state:

"Consent shall not be valid where..."

The answer lies in the legislative design.

The European legislature deliberately avoided creating an automatic prohibition.

Instead, it established a strong presumption requiring controllers and supervisory authorities to scrutinise situations where consent is tied to contractual performance.

The wording allows flexibility because not every contractual condition necessarily destroys voluntariness.

Some processing operations are genuinely indispensable for delivering the requested service.

Others are merely commercially convenient.

Article 7(4) therefore requires an individual assessment, not an automatic conclusion.

This drafting choice reflects the principle of proportionality embedded throughout EU law.

Instead of rigid rules, the GDPR frequently adopts contextual standards that permit nuanced assessment while remaining guided by fundamental rights.

III. Is Article 7(4) a Prohibition or a Presumption?

One of the most significant interpretative questions is whether Article 7(4):

  • absolutely prohibits bundled consent; or

  • merely creates a rebuttable presumption against validity.

The wording strongly supports the latter interpretation.

Had the legislature intended an absolute prohibition, it could easily have adopted mandatory language such as:

"Consent shall be invalid..."

Instead, it instructs decision-makers to take "utmost account" of contractual conditionality.

This wording suggests that conditionality is an exceptionally important factor, but not necessarily the only factor.

Consequently, a controller may, in exceptional circumstances, demonstrate that consent remains genuinely voluntary despite some relationship between processing and contractual performance.

However, the burden of overcoming this presumption is substantial.

IV. The Meaning of "Not Necessary"

Another critical phrase is:

"...processing that is not necessary for the performance of that contract."

Necessity does not mean:

  • useful,

  • profitable,

  • efficient,

  • commercially desirable,

  • technologically convenient.

The GDPR consistently interprets necessity narrowly.

Processing is necessary only where the contract cannot realistically be performed without it.

Controllers frequently attempt to expand necessity beyond this narrow meaning.

Article 7(4) rejects that approach.

Illustration 1

Delivery Address An online retailer processes a customer's address to deliver purchased goods. Without the address, delivery is impossible. The processing is objectively necessary. Article 7(4) is not engaged.

Illustration 2

Marketing Profile The same retailer refuses to complete the purchase unless the customer agrees to behavioural advertising. Advertising has no intrinsic relationship with delivering purchased goods. The consent therefore becomes conditional upon unrelated processing. Article 7(4) strongly suggests that such consent is not freely given.

Illustration 3

Streaming Platform A video streaming service requires payment information to process subscription fees. Processing payment details is necessary. However, requiring consent for voice analysis to improve recommendation algorithms is unrelated to the contractual obligation of providing streaming access. The additional processing cannot automatically be justified through contractual necessity.

One of the most persistent compliance errors involves equating business interests with contractual necessity.

Controllers frequently argue:

"This improves our service."

"Customers benefit."

"The business model depends upon advertising."

None of these considerations answers the legal question.

The question is not whether processing benefits the controller.

Nor whether it improves efficiency.

The question is:

Can the contractual obligation be fulfilled without this processing?

If the answer is yes, the processing is unlikely to be necessary.

Illustration 4

Smart Television A manufacturer requires purchasers to consent to detailed viewing analytics before activating the television. The television can plainly function without collecting behavioural analytics. The analytics may improve commercial insight. They are not necessary for supplying the product purchased.

Illustration 5

Airline Loyalty Programme Passengers purchasing flights are required to consent to sharing travel history with commercial partners. The airline can transport passengers without sharing marketing information. The additional processing therefore lacks contractual necessity.

Illustration 6

University Admission A university requires applicants to consent to promotional use of their academic achievements. Admission decisions do not require advertising. The consent concerns an entirely separate objective.

VI. Imbalance of Power

Recital 43 introduces another crucial consideration.

Even where no contractual condition exists, consent may nevertheless fail because of an imbalance between controller and data subject.

Power imbalances need not involve overt coercion.

Dependence alone may undermine voluntariness.

The GDPR therefore recognises several situations where consent deserves heightened scrutiny.

Employment

Employment represents the classic example.

Employees depend upon employers for income, promotion and career progression.

Even absent explicit pressure, employees may reasonably fear adverse consequences if they refuse consent.

Illustration 7

A company requests consent for facial recognition attendance monitoring. Management repeatedly states that participation is voluntary. Nevertheless, employees worry refusal will influence future performance assessments. The legal problem lies not in explicit threats but in the objective imbalance inherent in employment.

Public Authorities

Citizens frequently depend upon government bodies for licences, benefits or essential services.

Consent requested in these circumstances may not represent genuine autonomy.

Illustration 8

A municipal authority asks residents to consent to receiving personalised political communications before processing housing applications. Applicants may perceive refusal as jeopardising their application. The imbalance undermines voluntariness.

Educational Institutions

Universities occupy a comparable position regarding students.

Illustration 9

A university requests students' consent for promotional videos. Although formally optional, students fear refusal could influence academic opportunities. Such concerns illustrate why consent within educational settings requires careful scrutiny.

VII. Economic Pressure

Article 7(4) also recognises that economic pressure can compromise voluntariness even without legal compulsion.

Controllers increasingly operate ecosystems where refusing consent results in financial disadvantage.

Whether such arrangements invalidate consent depends upon proportionality, market alternatives and the practical significance of the disadvantage.

Illustration 10

Loyalty Discount A supermarket offers loyalty discounts to customers consenting to behavioural profiling. The issue is not whether discounts are unlawful. Rather, the question is whether refusing profiling imposes such economic disadvantage that the choice becomes illusory.

Illustration 11

Insurance Premium An insurer offers significantly lower premiums only to customers consenting to continuous location tracking. The larger the economic penalty for refusal, the more doubtful the voluntariness of consent.

Illustration 12

Digital Newspaper A newspaper offers two alternatives:

  • behavioural advertising;
  • reasonably priced subscription. The assessment requires balancing economic realities, market practice and genuine availability of alternatives. This remains one of the most debated questions in contemporary European data protection law.

No issue better illustrates the complexity of Article 7(4).

Controllers argue:

"Users still have a choice."

Privacy advocates respond:

"A choice that requires payment is not necessarily free."

The GDPR provides no categorical answer.

Instead, Article 7(4) requires evaluating:

  • availability of genuine alternatives;

  • proportionality of charges;

  • market dominance;

  • indispensability of the service;

  • practical ability to refuse.

Recent CJEU jurisprudence and EDPB guidance indicate that these assessments are highly fact-specific rather than governed by bright-line rules.

Bundling occurs where several unrelated processing operations are presented as one indivisible choice.

Bundling undermines autonomy because individuals cannot selectively consent.

Illustration 13

A mobile application asks users to agree simultaneously to:

  • location tracking;
  • targeted advertising;
  • sharing data with affiliates;
  • product improvement. One checkbox authorises everything.

The user cannot distinguish essential processing from optional processing.

This strongly indicates invalid consent.

Illustration 14

The same application instead provides independent choices for each purpose. The user accepts location services while refusing advertising. Granularity preserves autonomy.

Illustration 15

A healthcare application combines consent for treatment with consent for pharmaceutical marketing. The two purposes are unrelated. Bundling destroys meaningful choice.

X. Behavioural Manipulation

Modern coercion rarely involves direct threats.

Instead, controllers increasingly influence behaviour through interface design.

Examples

include:

  • countdown timers;
  • emotionally loaded language;
  • repeated prompts after refusal;
  • hiding rejection buttons;
  • colour asymmetry;
  • default acceptance;
  • guilt-inducing messages. These techniques do not eliminate choice. They distort it. Article 7(4) must therefore be interpreted alongside the EDPB's guidance on dark patterns to preserve genuine autonomy.

XI. Critical Observation

Article 7(4) represents one of the GDPR's greatest conceptual achievements because it rejects the simplistic assumption that legal consent exists whenever someone clicks "I Agree."

Instead, it recognises that autonomy is shaped by context.

Freedom may be undermined by dependency, economic incentives, market structure, psychological manipulation or contractual design even where no explicit coercion exists.

The provision therefore transforms consent from a formal declaration into a substantive inquiry concerning the authenticity of individual choice.

This contextual approach explains why Article 7(4) continues to generate complex litigation and remains one of the most dynamic areas of European data protection law. Its application demands not only technical compliance but also a careful appreciation of human behaviour, power relationships and the realities of digital markets.

Although Article 7 establishes the conditions for consent, it cannot be interpreted in isolation. Its operation depends fundamentally upon the definition of consent in Article 4(11), which requires that consent befreely given, specific, informed and unambiguous, and, in particular situations under Article 9,explicit.

These are not merely descriptive adjectives. They are independent legal requirements. Failure to satisfy even one of them is sufficient to invalidate consent. A controller cannot compensate for the absence of one element by demonstrating stronger compliance with another. For example, consent may be highly informed but not freely given, or entirely voluntary but insufficiently specific. In either case, the legal basis fails.

The cumulative nature of these requirements reflects the GDPR's conception of consent as an expression of autonomous, informed, and deliberate decision-making, rather than a procedural formality.

I. "Freely Given" - The Protection of Individual Autonomy

The requirement that consent be "freely given" is not concerned with the existence of a choice in the abstract, but with the quality of that choice. The GDPR recognises that consent obtained through coercion, dependency, manipulation or significant disadvantage cannot meaningfully represent an individual's autonomous will.

The question is therefore not:

"Did the individual agree?"

but rather:

"Could the individual reasonably have refused?"

This distinction is crucial. A person may voluntarily click an "Accept" button while simultaneously lacking any realistic practical alternative. In such circumstances, the appearance of consent conceals an absence of genuine freedom.

Consent is unlikely to be freely given where:

  • refusal results in denial of an unrelated service;

  • there is a clear imbalance of bargaining power;

  • the controller employs deceptive interface design;

  • individuals suffer significant economic disadvantage upon refusal;

  • several unrelated processing operations are bundled together;

  • withdrawal becomes difficult or punitive.

Illustration 1

Employment A law firm asks employees to consent to the publication of their personal profiles and photographs on the firm's website. Although participation is described as voluntary, junior associates fear that refusing may negatively affect promotion prospects. The concern need not be objectively justified. The mere existence of an employment relationship creates an imbalance capable of undermining genuine voluntariness.

Illustration 2

Hospital Registration A private hospital requires patients to consent to receiving promotional health newsletters before permitting appointment booking. The marketing activity bears no relationship to the provision of medical treatment. Patients seeking healthcare may feel compelled to consent because refusal prevents access to essential services. The consent is therefore unlikely to be freely given.

Illustration 3

Mobile Application A weather application requires continuous location tracking for behavioural advertising rather than merely for providing weather forecasts. Because weather information could be delivered without extensive advertising profiling, making advertising consent a condition of access undermines the voluntariness of the decision.

Common Compliance Mistake

Many organisations assume that the absence of physical coercion automatically establishes voluntariness.

The GDPR adopts a much broader conception of coercion.

Economic pressure, dependence, interface manipulation and practical necessity may all compromise freedom even where no explicit threats are made.

Specificity embodies the principle of purpose limitation contained in Article 5(1)(b).

Individuals cannot meaningfully consent unless they understand precisely what processing activity they are authorising.

Consequently, one blanket consent cannot ordinarily legitimise numerous unrelated processing operations.

The controller must identify sufficiently precise purposes before consent is obtained.

Importantly, specificity differs from granularity.

Specificity concerns the definition of purposes.

Granularity concerns the ability to choose between those purposes.

The two concepts frequently overlap but remain analytically distinct.

Illustration 1

Blanket Marketing Consent An online retailer asks customers to agree that their data may be used: "for improving our services, research, future innovation, commercial opportunities, strategic partnerships and other business purposes." The listed purposes are vague, open-ended and insufficiently defined. The individual cannot reasonably understand the scope of the processing being authorised.

Illustration 2

Separate Choices A fitness application requests independent consent for:

  • personalised nutrition advice;
  • marketing communications;
  • participation in scientific research;
  • sharing anonymised statistics.

Each purpose is clearly identified and separately accepted or refused.

This reflects both specificity and granularity.

Illustration 3

University Alumni Office Graduating students are asked to consent simultaneously to:

  • receiving alumni newsletters;
  • publication of success stories;
  • fundraising communications;
  • sharing contact details with corporate sponsors.

These are distinct purposes.

Combining them into a single consent deprives students of meaningful choice.

Difficult Interpretative Question

Can one consent cover future processing activities not yet fully identified?

Generally, the answer is no.

Consent legitimises identifiable purposes existing when consent is obtained.

Future unspecified purposes cannot ordinarily be authorised through broad language such as:

"any future business activities."

Such wording undermines both specificity and transparency.

Consent has little value unless individuals appreciate the consequences of agreeing.

The GDPR therefore treats information as the foundation of autonomy.

The requirement is not satisfied merely because information exists somewhere within a privacy policy.

Instead, the relevant question is:

Could the average member of the intended audience reasonably understand the decision they were making?

Information must therefore be:

  • relevant;

  • comprehensible;

  • timely;

  • accessible;

  • proportionate.

An excessively technical explanation may be no more informative than complete silence.

Essential Information

Although Articles 12, 14 elaborate transparency obligations, informed consent ordinarily requires individuals to understand at least:

  • the controller's identity;

  • the processing purposes;

  • categories of personal data involved;

  • recipients or categories of recipients;

  • possibility of withdrawal;

  • consequences of consenting or refusing.

Illustration 1

Artificial Intelligence Service An AI platform merely informs users: "Your data will improve our systems." This statement conceals crucial information concerning model training, retention, third-party access and automated decision-making. The explanation is too vague to support informed consent.

Illustration 2

Layered Privacy Notice A banking application provides a concise explanation summarising the essential processing immediately beside the consent request, together with links to additional information. The user receives sufficient information to make an immediate decision while retaining access to greater detail if desired.

Illustration 3

Technical Language A cybersecurity platform requests consent using terminology such as: "probabilistic behavioural telemetry analysis employing federated learning optimisation." Most users cannot reasonably understand such language. Consent cannot be regarded as informed merely because technically accurate terminology has been employed.

Important

Nuance The GDPR protects understanding, not disclosure. Providing enormous quantities of information does not necessarily improve comprehension. Indeed, information overload may actively undermine informed decision-making. Controllers should therefore prioritise clarity over volume.

The requirement that consent be unambiguous represents one of the GDPR's clearest departures from earlier practices.

The legislature intentionally abandoned implied consent based upon silence, inactivity or pre-selected options.

Consent must instead be communicated through behaviour that clearly indicates agreement.

The decisive issue is whether an objective observer could confidently conclude that the individual intended to consent.

Valid Affirmative Actions

Examples

include:

  • selecting an unticked checkbox;
  • clicking an "Accept" button;
  • signing a written declaration;
  • providing a verbal confirmation;
  • adjusting account settings to activate optional processing. The common feature is that the action unmistakably communicates agreement.

Illustration 1

Continued Browsing A website states: "By continuing to use this site you consent to cookies." The visitor merely scrolls further. Scrolling demonstrates website use. It does not necessarily demonstrate consent.

Illustration 2

Unticked Checkbox A user actively selects: ☐ I agree to receive promotional emails. The deliberate selection clearly communicates agreement.

Illustration 3

Pre-Ticked Checkbox A subscription form contains: ☑ I agree to personalised advertising. The user simply submits the form. The affirmative act concerns registration, not advertising consent. The consent therefore lacks an independent, unambiguous indication of agreement.

Common Misunderstanding

Some controllers assume that any user interaction demonstrates consent.

This is incorrect.

The interaction must objectively relate to the specific processing activity for which consent is requested.

Explicit consent is not required for every processing operation.

However, where the GDPR demands explicit consent, most notably under Article 9, the standard becomes considerably more demanding.

Explicit consent requires an express statement leaving little or no doubt regarding the individual's intention.

It therefore exceeds ordinary unambiguous consent.

Typical Examples

  • signed declaration;

  • typed statement;

  • electronic signature;

  • recorded verbal affirmation;

  • two-step electronic confirmation.

The common characteristic is that the individual expressly confirms agreement rather than merely implying it through conduct.

Illustration 1

Medical Research Participants electronically sign a declaration stating: "I explicitly consent to the processing of my genetic information for this research project." The declaration directly addresses the relevant processing.

Illustration 2

Biometric Access Employees provide a separate written declaration authorising the use of fingerprint authentication. The employer preserves the signed record. The express wording satisfies the higher evidentiary threshold.

Illustration 3

Health Application Users activate an unticked checkbox specifically stating: "I explicitly consent to the processing of my health information." Immediately afterwards they confirm the decision through a second verification screen. The two-stage confirmation substantially strengthens evidence that explicit consent was genuinely intended.

Perhaps the most important lesson emerging from Article 7 is that consent should never be viewed as a document.

It is a governance process.

Controllers frequently concentrate upon obtaining consent while neglecting:

  • documenting consent;

  • updating consent records;

  • monitoring processing purposes;

  • enabling withdrawal;

  • reviewing whether consent remains appropriate.

The GDPR expects controllers to manage consent throughout its lifecycle rather than treating it as a one-time administrative event.