Consent is foundational to modern privacy frameworks, but the bar for what qualifies as valid consent varies significantly by jurisdiction. At it’s core, valid consent requires that:
The General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) have different approaches to the concept of consent.
The GDPR was foundational in developing the modern data consent framework. Laying out clear requirements for consent in Article 4, the GDPR states consent must be “freely given, specific, informed, and unambiguous.”
GDPR Article 7 goes on to outline four conditions for valid consent.
Obtaining valid consent is taken very seriously under the GDPR, with some of the largest GDPR fines to date being issued due to problems in a company’s consent management process.
Under the CCPA, sites may place cookies without first obtaining consent. However, users must be able to opt out of cookie tracking at any point. This opt-out consent regime is often seen in the form of a “Do not sell my information” link in a website’s footer menu.
Though the CCPA and CPRA don’t require cookie consent, many organizations under these laws still use cookie banners to minimize risk from third-party advertising.
Consent has grown significantly more complex with AI adoption. Consent captured at the point of data collection has no enforcement value if downstream systems, including AI models, personalization engines, ad platforms, and internal databases, don't receive and respect those signals.
A consent management system that captures preferences on a website but fails to propagate them to the data systems that actually use the data leaves an organization legally exposed regardless of what the banner said. Effective consent management requires end-to-end enforcement, not just front-end capture.