I. Article 7: The Operational Heart of Consent under the GDPR
Article 7 is perhaps the most misunderstood provision within the GDPR. It is frequently treated as though it defines consent itself. In reality, it does no such thing. The legal definition of consent is contained in Article 4(11), while Article 6(1)(a) establishes consent as one of the lawful bases for processing. Article 9(2)(a) further elevates the standard by requiring explicit consent for processing special categories of personal data. Article 7 performs a different function altogether. It transforms consent from an abstract legal concept into an operational legal mechanism by prescribing the conditions that must exist before consent can legitimately function as a lawful basis for processing.
This distinction is fundamental. Article 4(11) explains what consent is, whereas Article 7 explains how valid consent is obtained, demonstrated, maintained and, where necessary, withdrawn. It is therefore not a definitional provision but an evidentiary and procedural one. It governs the lifecycle of consent rather than its conceptual meaning.
Viewed structurally, Article 7 acts as the bridge between the foundational principles of Article 5 and the lawful basis established by Article 6. Consent does not become legally effective merely because an individual expresses agreement. Instead, Article 7 requires that such agreement satisfy a series of procedural safeguards designed to ensure that consent represents a genuine and autonomous manifestation of the data subject's will. Consent under the GDPR is therefore not measured by the existence of agreement alone but by the quality of the process through which that agreement is obtained.
The provision reflects a broader philosophical shift within European data protection law. Earlier regulatory approaches often focused on the existence of consent as a formal requirement. The GDPR moves beyond formalism. It recognises that individuals frequently consent without reading lengthy privacy notices, without understanding complex processing operations, or because refusing consent would result in economic or practical disadvantage. Article 7 therefore seeks to distinguish between consent that is merely expressed and consent that is genuinely autonomous.
In this respect, Article 7 embodies one of the central values of the GDPR: informational self-determination. The Regulation does not treat consent as a contractual waiver of privacy rights. Rather, it views consent as an ongoing manifestation of individual autonomy that must remain meaningful throughout the processing relationship.