Article 7
Conditions for Consent
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
When relying on consent, be able to demonstrate a freely given, specific, informed, unambiguous choice and make withdrawal as easy as giving consent.
Points of focus
- Record the notice and choice presented at the time of consent
- Keep consent separate from unnecessary service terms
- Honor withdrawal promptly across connected processing
Implementation notes
Store consent as a versioned event rather than a profile boolean, expose granular self-service choices, and publish revocation events that suppress downstream processing without dark patterns. Operationalize record the notice and choice presented at the time of consent in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain consent ledger with notice version, timestamp, scope, and actor with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a single bundled checkbox covers product terms and optional tracking Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample consent ledger with notice version, timestamp, scope, and actor with dates and named reviewers. Be ready to walk through how you detect and correct: a single bundled checkbox covers product terms and optional tracking
Evidence auditors typically request:
- Consent ledger with notice version, timestamp, scope, and actor
- User-interface evidence showing granular choices
- Withdrawal tests across marketing and analytics vendors
Common gaps
- A single bundled checkbox covers product terms and optional tracking
- Withdrawal changes the UI but does not propagate to downstream tools
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 7 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 7: Regulation (EU) 2016/679, Article 7 — Conditions for Consent