Section 30 of the Data Protection Act provides for nine lawful bases for processing personal data. Of these nine, consent is arguably the most important—and the most contentious. The vast majority of the 31 reported determinations of the Office of the Data Protection Commissioner (ODPC) in 2023 dealt with situations where a data subject objected to the processing of their personal data because it was done without their consent. Most of these 31 determinations involved digital lenders or microfinance institutions whose clients provided the contact details of proposed guarantors without the consent of the latter. Upon the loanee’s default, these “guarantors” then received multiple messages urging them to ensure the payment of the loan. A few other determinations involved educational institutions’ use of the images of students for marketing purposes without the consent of their parents.
Probably recognizing the importance of consent and a widespread lack of understanding of what consent requires, the ODPC issued several guidance notes in December 2023: a Guidance Note on Consent, a Guidance Note for Digital Credit Providers, a Guidance Note for the Education Sector, and a Guidance Note for the Communications Sector.
However, the problematic nature of data processing was not limited to digital lenders and microfinance institutions. One determination involved a former employee of a law firm sharing internal documents. Another involved a bank’s recording of telephone conversations of an employee as part of a disciplinary investigation. Yet another involved allegations (eventually shown to be groundless) that another bank disclosed the financial information of clients to a well-known social commentator looking into possible corruption. For these reasons, it is worth taking a closer look at the ODPC Guidance Note on Consent.
As defined in Section 2 of the Data Protection Act, consent must be an (1) express, (2) unequivocal, (3) free, (4) specific, and (5) informed indication of the wishes of a data subject, signifying agreement to processing of his or her personal data. The Guidance Note clarifies each element of consent.
For consent to be “free,” the data subject must not feel compelled to consent, and must not be subject to negative consequences if they do not consent—they must not be subject to inappropriate pressure or influence that prevents them from exercising their free will. Section 32 of the Data Protection Act provides an interpretive aid here: in determining whether consent was freely given, account shall be taken of, inter alia, whether the performance of a contract by a data controller or data processor was made conditional on consent to the processing of personal data that was not necessary for the performance of the contract. Of course, this does not exhaust the possible situations that could fall under “inappropriate pressure or influence.”
Furthermore, consent will not be considered “free” if the data subject may not withdraw their consent without detriment. Section 32 of the Data Protection Act expressly states that a data subject has the right to withdraw consent at any time, even though the withdrawal of this consent does not invalidate any processing of personal data that occurred prior to withdrawal.
Consent is “informed” if it is based on an understanding of the data processing activities and their implications for the rights of the data subject. Data controllers and data processors have an obligation to ensure that accurate and full information is availed to the data subject regarding the nature of the personal data to be processed, the purpose for processing it, consequences for not consenting to such processing, and the rights of the data subject. Moreover, this information must be provided clearly and simply, in plain language; and the request for consent needs to be prominent, concise, and kept separate from other terms and conditions.
For consent to be “specific,” data controllers and processors must, at the minimum, provide:
- information on the identity of the data controller/processor and of any third party who will be relying on the consent,
- specific information on the purposes for which consent is sought,
- “granular consent options” for each separate type of processing unless those activities are clearly interdependent, and
- information on how to withdraw consent.
Pursuant to the Act, consent must be “express, … by a statement or clear affirmative action.” This means that the data subject must have taken a deliberate action to consent to the processing of their personal data. “Consent by default,” for instance—i.e., a situation where the data subject is presumed to consent to the processing of their personal data unless they opt out—would be invalid.
The ODPC appears to take the “unequivocal” nature of consent as self-explanatory.
Section 32 of the Data Protection Act provides that, in the event of a dispute, the burden of proving valid consent lies on the data controller/processor. This, taken together with the ODPC’s emphasis in its determinations on the implementation of data protection principles in the design of systems and organizations, means that data controllers and data processors would be well advised to review their internal processes and structures to ensure that they seek valid consent before processing any personal data.
Implementation by design may mean, for instance, putting in place measures to continuously confirm the correctness of contact information listed in one’s databases (ODPC Complaint 574 of 2023, ODPC Complaint 781 of 2023), offering to clients diagrammatic representations of consensual processes for complex transactions (Worldcoin Determination), ensuring the presence of inbuilt opt-out mechanisms to promotional messages (ODPC Complaint 624 of 2023), or offering automatic notification to proposed guarantors, and listing them as guarantors only upon obtaining their consent (see ODPC Complaint 860 of 2023, consolidated with ODPC Complaint 978 of 2023).
All of this notwithstanding, as the ODPC states at the conclusion of the Guidance Note, “consent is not a silver bullet.” Obtaining a data subject’s consent in no way waives the legal obligations of data controllers and data processors under the Act.
Please contact us if you require legal consultation.


