End of Summer Savings · Get 10% off any legal service · Ends 31 August

Claim offer

Consent Types and Requirements Under UK GDPR for Businesses

Alex Solo
byAlex Solo11 min read

Many UK businesses ask for consent far more often than they need to, then ask for it in the wrong way.

That creates two problems at once: the consent may be invalid, and the business may also be using the wrong legal basis for its data processing. Common mistakes include bundling consent into terms and conditions, using pre-ticked boxes, and treating silence or inactivity as permission.

This matters most when you are collecting marketing sign-ups, using cookies, handling health or biometric data, or relying on a customer saying “yes” in a form or app. If your consent process is weak, you may struggle to prove permission later, and your privacy notice, cookie policy, customer journey and internal systems can all fall out of step.

This guide explains the main consent types under UK GDPR, when consent is actually needed, what valid consent looks like, and where businesses usually get caught out before they launch online, update a CRM, or sign up customers through a new sales process.

Overview

Under UK GDPR, consent is only one of several lawful bases for processing personal data, and it is not always the best one. Where you do rely on consent, it must be freely given, specific, informed and unambiguous, and in some situations you may need explicit consent because the data or activity is more sensitive.

  • Decide whether you really need consent, or whether another lawful basis is more appropriate.
  • Separate ordinary consent from explicit consent, because they are not the same standard.
  • Make each request clear, granular and easy to refuse.
  • Keep records showing who consented, when, how, and what they were told at the time.
  • Make withdrawal simple and act on opt-outs quickly.
  • Check connected rules, especially PECR for electronic marketing and cookies.

For most businesses, “consent types” really means understanding the different levels and uses of consent across your data collection, marketing and product design.

The key point is simple: consent is not a catch-all permission slip, and using it carelessly can create avoidable compliance risk.

UK GDPR gives businesses several lawful bases for processing personal data. Consent is one of them, alongside options such as contract, legal obligation, legitimate interests, vital interests and public task.

This is where founders often get caught. They assume every form needs a consent box, when the actual legal basis may be that the processing is necessary to perform a contract, comply with a legal duty, or pursue legitimate interests.

For example, if a customer buys from your online store, you do not usually need consent to use their address to deliver the goods or send order updates. That processing is generally necessary for the contract. Asking for consent in that situation can make things messier, because the customer could later withdraw it even though you still need the data to complete the order.

Ordinary consent applies where you rely on a clear affirmative indication from the individual. In practice, this often appears in sign-up forms, marketing preferences and optional data uses.

To be valid, the consent must be:

  • Freely given, with a genuine choice and no unfair pressure.
  • Specific, so the person understands the separate purpose or purposes.
  • Informed, meaning they know who you are, what you will do, and any key consequences.
  • Unambiguous, shown through a clear positive action such as ticking a box or choosing settings.

A pre-ticked box, passive acceptance, or hiding consent inside a long contract or customer terms will usually not meet that standard.

Explicit consent is a higher standard and usually requires a very clear statement of agreement. Businesses most often need to think about explicit consent when processing special category data, such as health data, biometric data used for identification, religious beliefs, sexual orientation or similar sensitive information.

If your app tracks a user’s medical symptoms, your wellness platform collects therapy information, or your workplace system uses facial recognition, ordinary consent language may not be enough. You need a very clear, express statement, and your records should show exactly what the person agreed to.

Explicit consent can also matter for certain other activities, including some international data transfer situations or automated decision-making scenarios, depending on the facts.

Granular consent is not a separate legal basis, but it is a practical requirement built into valid consent. If you ask for one blanket “yes” covering email marketing, SMS promotions, partner offers and product analytics, the request is likely too broad.

Instead, separate the choices where the purposes are genuinely different. A customer might want service emails but not newsletters. A user may accept analytics cookies but reject advertising cookies. Splitting those options reduces legal risk and often gives you cleaner, more reliable permissions.

Businesses sometimes talk about “implied” or “inferred” consent, but under UK GDPR this is risky language. For most personal data processing that relies on consent, you need a clear affirmative action. Mere silence, inactivity, or a vague assumption from someone’s behaviour is usually not enough.

This matters in customer onboarding, event registrations and web sign-ups. If someone downloads a guide, that does not automatically mean they consent to unrelated marketing. If a customer keeps using your website, that does not automatically mean they agreed to all cookies.

Many businesses focus only on UK GDPR and miss the separate privacy rules that sit beside it. The Privacy and Electronic Communications Regulations, usually called PECR, affect electronic direct marketing and cookies.

For marketing by email or text to individuals, consent is often required unless a limited exception applies, such as the soft opt-in for existing customer marketing in certain cases. For non-essential cookies and similar tracking technologies, consent is generally needed before those tools are placed or accessed.

That means your consent types may differ across your business. One rule may apply to account administration, another to email campaigns, and another to website tracking tools.

If your service is aimed at children, or you know children are using it, consent becomes more sensitive. Online services offered directly to children may require parental consent below the relevant age threshold in the UK, depending on the service and processing activity.

Even where parental consent is not the central issue, your wording still needs to be clear and age-appropriate. Dense legal text is unlikely to work well where younger users are involved.

When This Issue Comes Up

Consent problems usually appear when a business changes how it collects data, not when it writes its first privacy notice. The real pressure points are product launches, marketing changes, new software tools and customer journey redesigns.

Marketing sign-ups and CRM growth

A common founder moment is building a mailing list before a launch or after a funding round. Someone imports business cards from an event, adds old leads into a CRM, or asks one sales team to start emailing contacts gathered for a different purpose.

This is where the original consent, if any, matters. You need to know:

  • How the contact details were collected.
  • What the person was told at the time.
  • Whether marketing consent was actually given.
  • Whether PECR allows the planned method of contact.

If your records are thin, you may not be able to show that the outreach is lawful.

Website cookies, analytics and ad tech

Website rebuilds often create hidden consent issues. A developer installs analytics tools, ad pixels, session replay software or personalisation features before anyone checks what cookies are firing and whether consent is needed.

Before you spend money on setup, review what your website actually does. Businesses often assume a cookie banner solves everything, but banners fail when they are misleading, when all options are turned on by default, or when the “reject” route is harder than the “accept” route.

Health, HR and sensitive data collection

Sensitive data raises the stakes. This can come up in health tech, wellness businesses, recruitment tools, occupational health processes, or access systems using biometric data.

Here, the business needs to ask two questions, not one:

  1. What is the lawful basis under UK GDPR for the general processing?
  2. If special category data is involved, what additional condition applies, and is explicit consent the right one?

In employment contexts, consent is often difficult to rely on because of the imbalance of power between employer and worker. A business might be better served by another lawful route where the law allows it.

App onboarding and product features

Consent issues also appear when an app adds optional features such as location tracking, behavioural profiling, friend invitations, or personalised recommendations. Product teams often want a single click that covers everything, but legal and UX reality pull the other way.

When features are optional, permissions should usually be separated and easy to manage later. If users cannot easily revisit their settings, the business may struggle to honour withdrawals of consent.

Data sharing with third parties

Another common trigger is a proposed partnership. A retailer wants to share customer lists with a delivery partner for joint offers, or a software business wants to pass user information to a related brand for cross-selling.

Before you sign a contract or data sharing agreement, check whether the original notice and consent actually covered that sharing. A broad statement that data may be shared with “trusted partners” may not be enough if the purpose is vague or unexpected.

Practical Steps And Common Mistakes

The safest approach is to map each data use to its proper legal basis, then design consent only where consent is genuinely required. Businesses that do this well usually keep their forms simpler, their records cleaner and their customer communications more reliable.

1. Match each processing activity to a lawful basis

Start with a data map. List the personal data you collect, why you collect it, where it comes from, who you share it with, and how long you keep it.

Then assign a lawful basis to each activity. Your list may include:

  • Customer orders and account management.
  • Email newsletters and SMS promotions.
  • Recruitment and onboarding checks.
  • Website analytics and advertising cookies.
  • Product improvement and user research.
  • Sensitive health or biometric features.

This exercise often reveals that only some activities need consent at all.

If you rely on consent, ask for it in plain English and keep it away from core contract terms. A person should not have to accept marketing just to buy a product, unless the marketing is genuinely necessary to provide that service, which is uncommon.

Good consent language usually answers:

  • Who is asking for consent.
  • What data will be used.
  • What the business will do with it.
  • Whether third parties are involved.
  • How the person can withdraw consent.

Where there are multiple purposes, use separate boxes or toggles.

3. Build a reliable evidence trail

You should be able to prove consent later. That means keeping records of the wording used, the date and time of consent, the method used, and the individual’s choices.

If you change your sign-up wording, keep version history. If consent is collected through a phone sale or in-person event, make sure your process captures what was said and what choice the person made.

The main risk is not just getting the wording wrong. It is having no evidence at all when a complaint arrives six months later.

4. Make withdrawal easy

Under UK GDPR, people must be able to withdraw consent easily. If opting out is hard, hidden or slower than opting in, the consent model is weak.

For businesses, this usually means:

  • Visible unsubscribe options in marketing messages.
  • Account settings that can be changed without friction.
  • Internal processes to update CRM and marketing tools promptly.
  • Clear handover between marketing, support and tech teams.

Do not continue using data for a consent-based purpose once consent has been withdrawn, unless another lawful basis genuinely applies for a different purpose.

5. Align your privacy notice with your real process

Your privacy notice should reflect what actually happens. If the notice says users can choose cookie categories, but your site drops advertising cookies before any choice is made, there is a mismatch. If the notice says marketing is optional, but your checkout page forces a marketing box to proceed, there is another mismatch.

Founders often treat the notice as a drafting task at the end. In practice, it should be checked against the live customer journey, the CRM settings, the cookie tools and the product UI.

6. Watch for these common mistakes

Businesses repeat the same consent errors, especially during rapid growth, rebranding or platform changes.

  • Using pre-ticked boxes or assuming silence counts as agreement.
  • Bundling several unrelated purposes into one yes or no choice.
  • Relying on consent where contract or legitimate interests would be more suitable.
  • Trying to rely on employee consent where the power imbalance makes it unreliable.
  • Collecting explicit consent language for sensitive data, but failing to identify the wider legal condition needed.
  • Importing old contact lists without checking how those contacts were obtained.
  • Installing analytics or marketing cookies before consent is captured.
  • Making opt-out harder than opt-in.
  • Failing to keep records of what wording the person saw.

Consent sits across legal, product, sales and marketing. If one team changes a form, another changes the CRM logic, and another updates the privacy notice, the whole system can drift.

A practical internal process often includes:

  • Approval before new forms, cookie tools or sign-up flows go live.
  • Ownership for consent records and suppression lists.
  • Checks before sharing data with a new supplier or partner.
  • Regular reviews after website rebuilds or app releases.

This is especially useful before you launch online, expand into a new channel, or sign a supplier agreement for martech, adtech or analytics tools.

FAQs

No. Consent is only one lawful basis under UK GDPR. Many routine business activities rely on contract, legal obligation or legitimate interests instead.

Explicit consent is a higher standard that requires a very clear statement of agreement. It is often relevant when processing special category data, such as health or biometric information.

Usually, that is not the best approach. Consent should be separate from core contract terms and presented clearly, so the person has a real choice.

No, not for UK GDPR consent. The individual must take a clear affirmative action, such as ticking an empty box or actively choosing a setting.

Often yes, especially for emails or texts to individuals, but PECR rules and limited exceptions can apply. You should check both UK GDPR and PECR before sending campaigns.

Key Takeaways

  • Consent is not the default lawful basis for all personal data processing.
  • Valid UK GDPR consent must be freely given, specific, informed and unambiguous.
  • Explicit consent is a higher standard and often matters for special category data.
  • Marketing and cookies raise separate PECR issues that businesses should not overlook.
  • Consent requests should be clear, granular, easy to refuse and easy to withdraw.
  • Records matter, you should be able to prove who consented, when, how and to what wording.
  • Weak consent often comes from product, marketing and legal processes falling out of sync.

If your business is dealing with consent types and wants help with privacy notices, marketing consent wording, cookie compliance, and data processing reviews, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.

Build privacy controls around the real data flow

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Build privacy controls around the real data flow

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.