Skip to content
compliancebase
GDPRChapter II — Conditions for Consent

Article 7

Conditions for Consent

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

When relying on consent, be able to demonstrate a freely given, specific, informed, unambiguous choice and make withdrawal as easy as giving consent.

Points of focus

  • Record the notice and choice presented at the time of consent
  • Keep consent separate from unnecessary service terms
  • Honor withdrawal promptly across connected processing

Implementation notes

Store consent as a versioned event rather than a profile boolean, expose granular self-service choices, and publish revocation events that suppress downstream processing without dark patterns. Operationalize record the notice and choice presented at the time of consent in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain consent ledger with notice version, timestamp, scope, and actor with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a single bundled checkbox covers product terms and optional tracking Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample consent ledger with notice version, timestamp, scope, and actor with dates and named reviewers. Be ready to walk through how you detect and correct: a single bundled checkbox covers product terms and optional tracking

Evidence auditors typically request:

  • Consent ledger with notice version, timestamp, scope, and actor
  • User-interface evidence showing granular choices
  • Withdrawal tests across marketing and analytics vendors

Common gaps

  • A single bundled checkbox covers product terms and optional tracking
  • Withdrawal changes the UI but does not propagate to downstream tools

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 7This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Conditions for Consent applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — record the notice and choice presented at the time of consent — with evidence stored where auditors and customers can sample it.

Lead with consent ledger with notice version, timestamp, scope, and actor and pair it with user-interface evidence showing granular choices. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a single bundled checkbox covers product terms and optional tracking Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above