Powrót do bloga
Compliance

GDPR Article 7: The Nuances of Valid Consent (and how CMPs achieve it)

Rachel Torres, Privacy CounselDecember 1, 202515 min czytania
GDPRConsentLegalCMP

TLDR: GDPR Article 7 defines valid consent: freely given, specific, informed, unambiguous. Pre-ticked boxes? Invalid. Cookie walls? Non-compliant. Reject harder than accept? That's a fine waiting to happen.

Read full summary Deep dive into GDPR Article 7's four conditions for valid consent and how they apply to consent management platforms. Covers cookie walls, granular controls, withdrawal mechanisms, and the design requirements that regulators actually enforce. *Summary by Claude AI*
## The Four Words That Define Compliance Every GDPR consent fine traces back to the same four words: freely given, specific, informed, unambiguous. Meta's €60 million French fine? Their cookie banner wasn't "freely given"—rejection required five clicks while acceptance took one. TikTok's €345 million penalty? Their defaults weren't "unambiguous"—children's accounts were public unless kids actively changed settings. Criteo's €40 million? Consent wasn't "informed"—users didn't know which of 700 advertising partners would receive their data. GDPR Article 7 doesn't just define consent abstractly. It creates a four-part test that regulators apply with increasing precision. Every click, every button, every word in your consent flow gets measured against these four requirements. Your CMP isn't just a banner. It's evidence of whether you meet Article 7's conditions. Get any of the four wrong, and you're in the enforcement queue. ## The Four Conditions, Explained ### Freely Given Consent: No Coercion Allowed **What it means:** Users must have a genuine choice. They should not feel pressured or suffer negative consequences if they refuse consent. **CMP application:** * **No cookie walls**: Websites cannot block access to content for users who refuse consent (unless the data processing is strictly necessary for the service). * **Granular options**: Users must be able to consent to different processing purposes separately. A "take it or leave it" approach to all cookies is non-compliant. * **Easy withdrawal**: Withdrawing consent must be as easy as giving it. Your CMP should offer a clear and accessible mechanism (e.g., a floating icon, a link in the footer) for users to change their minds at any time. ### Specific Consent: Clearly Defined Purposes **What it means:** Consent must be given for a specific purpose or purposes. Vague or catch-all consent is invalid. **CMP application:** * **Detailed categories**: Your CMP must clearly define different categories of cookies and data processing (e.g., "Analytics," "Marketing," "Personalization"). * **Purpose-based consent**: Users should opt-in to each specific purpose. Grouping unrelated purposes under a single consent request (bundling) is generally non-compliant. * **Vendor transparency**: For third-party cookies, the CMP should ideally list specific vendors and their purposes, allowing users to make informed choices. ### Informed Consent: Transparency is Key **What it means:** Users must understand what they are consenting to. This requires clear, concise, and easily accessible information. **CMP application:** * **Plain language**: Avoid legal jargon. Your CMP's consent banner and preference center should use clear, simple language (8th-grade reading level recommended) to explain each data processing purpose. * **Accessible information**: The consent banner should link directly to your detailed privacy and cookie policies, where users can find more in-depth information. * **"Read more" options**: Provide expandable sections within the banner or preference center for users who want more detail on a specific purpose or cookie without leaving the page. ### Unambiguous Indication: Active Affirmation **What it means:** Consent must be explicit, usually requiring an affirmative action from the user (e.g., clicking an "Accept" button, toggling a switch). Implied consent (e.g., by scrolling or continuing to browse) is generally not valid for non-essential cookies. **CMP application:** * **Opt-in by default**: All non-essential cookie categories must be deselected by default in the preference center. * **Clear affirmative action**: The user must actively click "Accept All," "Save Preferences," or individual toggles to indicate consent. Pre-ticked boxes are non-compliant. * **Separate options**: Provide distinct "Accept All" and "Reject All" (or "Continue without accepting") buttons with equal prominence to ensure a genuine choice. ## Practical Steps for CMP Compliance with Article 7 1. **Audit your data processing**: Know exactly what data you collect, why, and which third parties receive it. 2. **Map purposes and vendors**: Clearly define each purpose for data processing and list all associated vendors. 3. **Implement layered consent**: Start with a concise banner and offer a more detailed preference center. 4. **Test for dark patterns**: Ensure your design does not subtly coerce users into accepting cookies. 5. **Maintain consent records**: Your CMP must log all consent decisions for auditability (who, when, what, how). 6. **Re-consent when things change**: Refresh consent if you add new purposes, introduce special-category data, or change vendors in ways that materially impact users. ### Common pitfalls to avoid * **Bundling unrelated purposes**: Asking for one click to cover analytics, ads, personalization, and geolocation still fails the specificity test. * **Unbalanced buttons**: Making "Accept All" bright and "Reject All" muted has been cited by regulators as nudging users unfairly. * **Implied consent for minors**: For services likely accessed by children, use age-appropriate language and avoid any form of implied consent. * **Poorly labeled toggles**: If users cannot tell what turning on "Marketing partners" entails, it is not informed consent. ## What this means for your CMP roadmap GDPR Article 7 sets a high bar for consent, and regulators are enforcing it. Recent decisions from DPAs in France (CNIL) and Belgium have highlighted design patterns that obscure rejection choices, and the Irish DPC has focused on inadequate consent refresh cycles. A strong CMP is not just a banner; it is a governance layer that documents lawful bases, keeps vendor disclosures accurate, and makes withdrawing consent effortless. Bake these requirements into your product backlog now so you can show auditors clear records, minimize legal exposure, and build user trust through transparent choices.

Najczęściej zadawane pytania

What are the four key conditions for valid consent under GDPR?
Consent must be freely given, specific, informed, and an unambiguous indication of the data subject\s wishes. Each condition is crucial for compliance.
Can scrolling or continuing to browse imply consent under GDPR?
No, for non-essential cookies and personal data processing, GDPR generally requires an explicit, affirmative action. Implied consent through passive actions like scrolling is usually non-compliant.
How does a CMP help ensure "freely given" consent?
A compliant CMP avoids cookie walls, offers granular consent options, and makes it as easy to withdraw consent as it is to give it, ensuring users have genuine choice.
R

Rachel Torres, Privacy Counsel

Autor w GetCookies, specjalizujący się w zgodności z ochroną prywatności, zarządzaniu zgodą i optymalizacji marketingu cyfrowego.

Gotowy, aby uprościć zgodę na pliki cookie?

GetCookies sprawia, że zgodność z RODO, CCPA i globalną ochroną prywatności jest bezwysiłkowa. Zacznij dziś.