In legal terminology, the concept of the Consent clearly defined as “explicit prior consent”. Retrospective consent constitutes authorisation. The GDPR deliberately uses the term “consent” to make it clear that the data subject must give their consent to the processing of their personal data prior to such processing taking place. The data subject must therefore be clearly informed in advance as to why and to what extent the data is to be collected and processed. In addition, they must be informed of the existence of a right to withdraw consent and how this right can be exercised. The powers to be granted by consent must not constitute a “blank cheque”, but must remain within the limits set by the legal basis for the processing.
Furthermore, consent is regarded as Opt-in to be designed in such a way (i.e. the data subject must actively consent to the processing/collection) and not as an opt-out (the data subject must actively object to the processing or collection). Silence or inaction is not sufficient to constitute valid consent. The data subject must therefore take active steps to demonstrate that consent has been given.
For the consent to be valid, it must also voluntary be explained (without compulsion). It should also be noted that it no linkage may be imposed. This means that the data subject must not suffer any adverse consequences if they do not give their consent (e.g. exclusion from an event or similar).
In addition to consent, there are other legal bases for the processing of personal data (see Article 6 of the GDPR). Consent is required if no other legal basis applies, such as the fulfilment of the University’s tasks, the performance of a contract or legal obligations.
(see Article 4(11) of the GDPR, Article 6(1)(a) of the GDPR and Article 7 of the GDPR)