You need consent when the data is not needed to perform a contract or to meet a legal obligation, and no other basis fits, or when the law requires consent directly, for example for advertising by email to individuals (Article 81(1) ERĮ). Your own customers whose email address you obtained when selling goods or services can be sent email advertising of your own similar goods or services without consent, if they were offered an opt-out when the address was collected and in every message (Article 81(2) ERĮ). Consent is invalid if it was not freely given, specific, informed and unambiguous (Article 4(11) GDPR) or if the person could not get a service without it although the data was not needed for that service (Article 7(4) and Recital 43 GDPR). And if the controller cannot prove it obtained consent, it cannot rely on it (Article 7(1) GDPR).
A common mistake in practice is not missing consent, but asking for consent where it does not fit. Then a withdrawal stops processing the organisation actually needs. This article covers when consent is the right basis, what makes it invalid, what happens when it is withdrawn and how to prove it.
When you need consent, and when asking for it is a mistake
Article 6(1) GDPR lists six lawful bases. Consent is only one of them: the person agrees to the processing of their data for one or more specific purposes (Article 6(1)(a) GDPR). In its Guidelines 05/2020 on consent, the European Data Protection Board (EDPB) says consent is appropriate only when the person has a real choice and can refuse without detriment (paragraph 3).
A simple test: if you would process the data anyway after the person said “no”, consent does not fit. You need another basis.
An enquiry form on a website. One company had a mandatory tick box on its website consultation form: “I agree that my personal data will be processed in accordance with the privacy policy”. The form could not be sent without it. Our lawyer replied that the wrong basis had been chosen. The person is asking for a service, so the basis is steps taken at their request before entering into a contract (Article 6(1)(b) GDPR). And a mandatory tick box is not free consent, because without it you do not get the service. We suggested two parts: an information sentence with a link to the privacy policy, and a separate, optional tick box if the company wants to collect consent for a newsletter.
A gift added to an order. An online shop asked whether it needed the buyer’s consent to put a gift in the parcel. The answer: no. Consent is needed for advertising sent by electronic means. On another form, a person could enter their email address to receive the result of a test. That consent is not consent to receive advertising later. Marketing needs a separate tick box that is not pre-ticked. When advertising needs consent and when an opt-out is enough is covered in our article on direct marketing by email and SMS.
When the law requires the processing, or when there is a clear imbalance between the parties, consent usually does not fit. Recital 43 GDPR gives public authorities as the example. In employment the same principle applies almost always – why, we explained in our article on employee consent. If you are considering legitimate interest, see when it is enough.
When consent really is needed: electronic advertising to individuals, except under the own-customer exception (Article 81(1) and (2) ERĮ), special categories of data where no other exception applies and the person gives explicit consent (Article 9(2)(a) GDPR), and other cases where the decision must stay with the person. When cookies need consent and how a consent banner is judged is covered in Cookies and consent banners: what the ERĮ and the GDPR require.
When consent is invalid
It was not free. Utmost account is taken of whether the performance of a contract or a service is made conditional on consent to process data that is not necessary for it (Article 7(4) GDPR). Consent is also not regarded as free if separate consent cannot be given to separate processing operations although that would be appropriate (Recital 43 GDPR).
It was not a clear act. Silence, pre-ticked boxes or inactivity are not consent (Recital 32 GDPR). The EDPB adds that merely continuing to use a service cannot be regarded as consent either (paragraph 79 of the guidelines). So a notice at an event saying that by attending people agree to be photographed does not create consent. It is only information. Employee photos are covered in Employee photos on the website and social media.
It was hidden among other matters. If consent is given in a written declaration that also concerns other matters, the request must be clearly distinguishable from the other matters (Article 7(2) GDPR). General terms with consent built into them do not meet this requirement.
The person did not know what they were agreeing to. They must at least know the identity of the controller and the purposes of the processing (Recital 42 GDPR). The person must be told about the right to withdraw before giving consent (Article 7(3) GDPR).
The consent was given by a child. When information society services are offered directly to a child, such as an app or an account, in Lithuania the child’s consent is valid from the age of 14 (Article 6 ADTAĮ). For a younger child, consent is given or authorised by the holder of parental responsibility (Article 8(1) GDPR). The controller must make reasonable efforts to verify this (Article 8(2) GDPR).
Withdrawal: what it means for the controller
A person can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it, and it must be as easy to withdraw as to give consent (Article 7(3) GDPR). The EDPB says that if consent was given on a website or in an app, it must be possible to withdraw it through the same interface (paragraph 114 of the guidelines). A phone call to a customer centre during business hours does not meet this (paragraph 115, example 22).
Once consent is withdrawn, processing for that purpose must stop. If there is no other legal basis, the data must be erased (Article 17(1)(b) GDPR).
This is where the biggest risk lies. The EDPB says clearly that a controller cannot replace consent with another basis for the same processing. In particular, it cannot rely on legitimate interest retrospectively when it turns out that the consent is invalid (paragraph 123 of the guidelines). Processing can continue on another basis only for data that was also processed for another purpose from the start, such as performing a contract, and the person must be told (paragraphs 118, 120 and 121). Telling people that processing is based on consent while actually relying on another basis is, in the EDPB’s words, fundamentally unfair (paragraph 122). So the basis must be chosen before collecting the data, separately for each purpose.
How to prove consent
The controller must prove it, not the person (Article 7(1) GDPR). The Regulation does not say how. The EDPB suggests keeping a record showing how and when consent was obtained and what information the person saw at the time. Online, that means session data and a copy of the consent text as it was then. Merely referring to the current structure of the website is not enough (paragraph 108 of the guidelines).
Keep the proof for as long as the processing continues. After that, no longer than needed to meet a legal obligation or to defend legal claims (paragraph 107). There is no fixed period of validity for consent: it depends on the circumstances, the scope of the consent and the person’s expectations. But if the processing changes or expands significantly, you need new consent (paragraph 110).
What happens when consent is the wrong basis
The first risk is processing without a basis. If consent is invalid, the person has only illusory control and the processing itself is unlawful (paragraph 3 of the EDPB guidelines). In practice, a marketing list built up over several years may become unusable, and the data has to be erased.
The second risk is proof. When VDAI or the person asks when and how consent was obtained, it is you who has to answer. A form that no longer exists and a text nobody saved prove nothing.
The third risk is fines. Infringing the basic principles for processing, including the conditions for consent under Articles 5, 6, 7 and 9 GDPR, falls in the highest tier of fines: up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR).
When to call a lawyer
- when you are not sure whether consent, a contract or legitimate interest fits the processing;
- when consent is tied to a service, a contract, a discount or taking part in an event;
- when you process health data or other special categories of data;
- when your service is also aimed at children;
- when a person has withdrawn consent and you would like to keep processing the data;
- when VDAI has asked you to prove that consent was obtained.
Frequently asked questions
Does consent have to be in writing?
No. Recital 32 GDPR allows a written statement, including by electronic means, or an oral statement, and also ticking a box on a website. But the controller must be able to demonstrate that consent was given (Article 7(1) GDPR), so oral consent without a record proves almost nothing in practice.
Can we ask for consent “just in case” while relying on another basis?
No. The EDPB says that telling people processing is based on consent while actually relying on another basis is fundamentally unfair. The basis must be chosen in advance. If consent turns out to be invalid, you cannot rely on legitimate interest retrospectively, and after a withdrawal you cannot silently switch to another basis.
How long is consent valid?
The Regulation sets no period. How long consent lasts depends on the circumstances, on what it was given for and on what the person reasonably expects (paragraph 110 of the EDPB guidelines). It ends in any case when the person withdraws it or when the processing changes or expands significantly. The EDPB recommends refreshing consent at appropriate intervals (paragraph 111).
Do we have to erase the data after consent is withdrawn?
Yes, if there is no other legal basis for processing it (Article 17(1)(b) GDPR). What was done before the withdrawal remains lawful (Article 7(3) GDPR). If the same data is also processed for another purpose, for example to perform a contract, it can still be processed for that purpose.
How to start
List where you ask for consent today: forms, contracts, events, the app. Next to each, write what would happen if the person said “no” or withdrew consent. Send us these forms – we will tell you where consent fits, where the basis should change and what is missing for proof.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit, compliance documents and consultations.