small-logo
ProfessionalsCapabilitiesInsights & NewsCareersLocations
About UsAlumniOpportunity & InclusionPro BonoCorporate Social Responsibility
Stay Connected:
facebookinstagramlinkedintwitteryoutube
  1. Privacy & Data Security

Blog

EU Releases Guidance on GDPR Consent

  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page
  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page

Blog

EU Releases Guidance on GDPR Consent

  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page

1 Min Read

Related Locations

Houston

Related Topics

Europe Privacy
Data Breach

Related Capabilities

Privacy & Data Security

Related Regions

Europe

June 27, 2018

The European Union’s General Data Protection Regulation (GDPR), which went into effect in May 2018, governs how companies and organizations must protect EU citizens’ personal data, including the use of consent. The European Data Protection Board (EDPB), the EU decision making body charged with ensuring a consistent application of the GDPR, has released The Article 29 Working Party Guidelines on Consent, which contains guidance on the GDPR consent requirements.

Under the GDPR, consent is one of the lawful bases to access and process personal data. The GDPR defines consent in Article 4(11) as “any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.” The Article 29 Working Party Guidelines on Consent explains the elements of consent and provides guidance to data controllers as to how to fulfill the new requirements for consent established by the GDPR. Additionally, the Guidelines provide direction for obtaining explicit consent in situations in which serious data protection risks may occur, as well as specific information for consent matters involving children.

TIP: As the GDPR is now in effect, companies should monitor and review any guidance issued by the EU relating to the application and enforcement of GDPR provisions.

This entry has been created for information and planning purposes. It is not intended to be, nor should it be substituted for, legal advice, which turns on specific facts.

Logo
facebookinstagramlinkedintwitteryoutube

Copyright © 2025. Winston & Strawn LLP

AlumniCorporate Transparency Act Task ForceDEI Compliance Task ForceEqual Rights AmendmentLaw GlossaryThe Oval UpdateWinston MinutePrivacy PolicyCookie PolicyFraud & Scam AlertsNoticesSubscribeAttorney Advertising