Consent

A brief summary with sample texts can be found at the end of this article.

You have certainly come across data protection yourself. Whether in everyday life in the form of information banners on websites, in the context of media and political discussions, or when reading and signing consent forms.

Usually, you find yourself in the role of the data subject, as your personal data is being processed. But what happens when you yourself process personal data belonging to third parties? For example, as part of a student project, whilst writing your thesis, when producing alumni newsletters, or when conducting surveys? This shifts your perspective away from that of the data subject to that of the data controller, and raises questions that are, in some cases, entirely new.
For example:

  • What data protection requirements must I observe?
  • When and under what conditions am I permitted to collect, store, and process personal data?
  • What is consent, what is a privacy policy, and when do I need them?
  • What should I bear in mind when creating surveys?
  • What specific considerations apply when data relating to minors is involved?

The following article addresses these questions, amongst others, and aims to provide an initial overview of when and under what conditions the processing of personal data is permitted.

The GDPR applies whenever personal data is processed, either wholly or partly by automated means, or is processed non-automatically but is stored in a filing system.
The following scenarios, in which consent under data protection law is required, may occasionally arise during the course of your studies:

  • A practical project involves working with members of the public. In order to contact them, the participants' names, addresses and telephone numbers are collected and stored digitally in a list.
  • In collaboration with a company, a prototype for a new, innovative product has been developed. To put its usability to the test in a real-world setting, your project partner has asked you to have passers-by test the prototype in Würzburg's pedestrian zone and to document this in a photo report. The planned photographs should clearly show the test subjects' facial expressions and emotions and will be used by the company for analysis and product improvement once the collaboration has been completed.
  • As part of a bachelor's or master's thesis, an online survey is to be conducted to collect information on, amongst other things, the participants' monthly income, place of residence and marital status. If this data can be linked in any way to an individual, you will need a declaration of consent. If the information is collected and processed in anonymised form, you do not need consent. However, in accordance with the principle of transparency, you must still provide information on how you will collect and process the data.

In addition, there are many other scenarios in which you may encounter data protection issues in the context of student projects. If you are unsure whether data processing in your project already falls within the scope of data protection legislation, the following applies: when in doubt, obtain a declaration of consent. This is because, should it transpire that consent was not obtained even though it was necessary, the processing of the data would thereby become unlawful and you could face sanctions.

The GDPR sets out certain requirements for consent1,  Articles 4 No. 11, and 7 of the GDPR:

  • Voluntary nature and prohibition of tying – Consent must be given voluntarily. Furthermore, data processing for the performance of a contract must not be linked to processing that is not necessary for the performance of that contract. The data subject must therefore also be able to refuse or withdraw consent without being disadvantaged as a result2. Consent may also be considered non-voluntary if there is a clear power imbalance or other disparity between the controller and the data subject.
  • Informed consent and unambiguity – The declaration of consent must be understandable to the data subject and contain a minimum level of information regarding data processing (see below)
  • Purpose limitation – The purpose for data collection must be clear to the data subject. If data subjects have consented to the processing of their personal data for this defined purpose, the data must not be used for any other purpose without obtaining renewed consent. (However, if various purposes have already been envisaged in advance, consent may also be obtained for several purposes at the same time3– for example, for the publication of the data both on a website and on social media.)

To ensure that data subjects can give their consent in an informed manner, data controllers must comply with the information requirements set out in Article 13 of the GDPR. A list of the minimum information you must provide to data subjects can be found here (“What information requirements must be met?”)

In line with the principle of transparency and any applicable obligations to provide evidence, it should (or must) be possible, where necessary, to demonstrate that the information mentioned above was provided to the data subject at the time consent was given. It is therefore essential that the information mentioned above is recorded in writing and that the data subject confirms that they have taken note of it, together with their consent.

Data subjects may withdraw consent that has already been given at any time and must be informed of this right at the time they give their consent. The withdrawal takes effect from the time the intention is expressed, with effect for the future. 


This means that the processing of personal data (which was previously permitted on the basis of consent) must be stopped immediately once the data subject notifies the controller of the withdrawal.5

Consent always requires 'active behaviour on the part of the data subject'6. By law, it does not necessarily have to be obtained in writing but may also be given verbally.

In practice, however, it is advisable to use the written form – if only to be able to provide clear evidence of the consent obtained (pursuant to Article 7 (1) of the GDPR, controllers are under an obligation to maintain records).7
Silence or inaction on the part of the data subject does not constitute valid consent. The decisive factor is that it must be an 'unambiguous expression of will in the form of a statement or other clear affirmative action'8 on the part of the data subject.

If data is collected electronically (e.g. online as part of a survey), consent may also be given by ticking a box. It is important here too that this constitutes active consent. The data subject must therefore tick a box themselves or otherwise actively give their consent (known as an 'opt-in' solution). Pre-ticked consent boxes, which are already ticked by default and which the data subject would have to untick manually in order not to give consent (known as an 'opt-out' solution), are not permitted9 . In order to fulfil the duty of proof in the electronic sphere, consent should also be documented here. This can for example be achieved by creating a survey in a way that ensures that only those individuals who have previously consented to data processing by ticking a consent box can take part, and that those who have not done so are not redirected to the actual survey.10 Verbal consent is generally also permissible; however, in practice, it is only meaningful if it can be verified11  – for example, if it is recorded audibly or via an audio-visual recording.

Depending on the age of the minor, there are two different ways to obtain consent12:

  • Children and young people up to the age of 16: In this age group, the consent of the parents or legal guardians is mandatory, Article 8 (1), Sentence 2 of the GDPR.
  • Young people aged between 16 and the age of majority: In this case, the consent of the minor alone is sufficient, provided that the matter concerns 'an offer of information society services', Article 8 (1) Sentence 1 of the GDPR.

To be on the safe side, consent should, where possible, always be obtained from parents or legal guardians as well as the minors when processing the personal data of minors. It is not advisable (except in the case of very young children) to obtain consent only from legal representatives and not from the minors themselves, as from a certain age the minor's right to privacy requires that they also consent to the processing themselves13.

In addition to standard personal data, such as name and address, there are also categories of personal data that are particularly sensitive and therefore require special protection, as they may pose significant risks to the rights and freedoms of the data subjects. Consequently, stricter regulatory restrictions apply to the processing of such data.

In accordance with Article 9 of the GDPR, these special categories of personal data include all personal data from which conclusions may be drawn regarding the data subject's racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership. In addition, genetic and biometric data used to uniquely identify a natural person, health data, and data relating to a natural person's sex life or sexual orientation are also classified as sensitive personal data. In principle, these categories of personal data may also be processed with the data subject's consent. However, as they generally require a higher level of protection, the processing of such data should only take place where it is strictly necessary.

It is therefore best to ask yourself in advance whether equivalent results can be achieved in your project by using fewer sensitive data. If so, the processing of sensitive data should be avoided and 'ordinary' personal data used instead.

If not, you should pay particular attention to the following when obtaining consent14:

  • All the conditions for consent already listed also apply to consent for the processing of sensitive personal data.
  • In order to fulfil the duty to provide information, it must also be expressly stated that the data for which consent is to be given constitutes sensitive data within the meaning of Article 9 of the GDPR and that the processing of such data may pose a high risk.
  • Particular care should be taken to ensure that consent is genuinely given voluntarily. Ideally, the consent should contain 'an explicit statement confirming its voluntary nature'15.

The processing of sensitive personal data entails greater risks for data subjects and, consequently, places higher demands on you as a data controller, even beyond the requirement for consent. For instance, you may need to carry out a data protection impact assessment, and you may also need to comply with further, sector-specific data protection regulations (in the case of social data, for example, provisions set out in the Social Security Codes).
We would be happy to discuss the specific circumstances and legal requirements for your project with you if you are planning to process sensitive personal data at THWS.

Please contact us directly regarding such projects so that any ambiguities can be identified straight away and resolved as soon as possible.

Further information on the handling of sensitive personal data can be found here (only in German): www.datenschutzkonferenz-online.de/media/kp/dsk_kpnr_17.pdf  and here: www.bfdi.bund.de/SharedDocs/Publikationen/Infobroschueren/INFO3.pdf.

Summary: checklist for consent under data protection law

  • Consent is one of several legal bases under data protection law that permit the collection and processing of personal data.
  • Consent must always be given voluntarily, in an informed manner, and unambiguously; this gives rise to information obligations.
  • In the case of consent given by minors, (additional) consent from parents or legal guardians is generally required.
  • When processing sensitive personal data, additional safeguards must be put in place (e.g. regarding the legal basis of consent).
  • Data subjects have the right to withdraw their consent at any time. If they exercise this right, any processing that was lawful up to that point must cease immediately and any data already collected must be deleted.
  • It must be possible to provide evidence of consent where required (no written form required, but there is a duty to provide evidence). Therefore, the retention and documentation of consent obtained are necessary.

But please note: data protection does not end with obtaining consent! There are also important data protection principles that must be observed throughout the entire process.16

For further information (in German) on consent under data protection law please see here:


We are happy to receive your suggestions and feedback, and to answer any individual questions or address any issues you may have; please contact us at datenschutzbeauftragter(at)thws.de. We look forward to a lively exchange.

Sample text: consent under data protection law

To give you an idea of what consent forms might look like, we have compiled some suggestions below. You can adapt these to suit your specific data processing requirements and use them for your project.

Sample form for declaration of consent

1) Bretthauer in: Specht, Louisa/Mantz, Reto (eds.): Handbuch Europäisches und deutsches Datenschutzrecht, § 2 marginal no. 18 et seq., Munich, 2019; Fechner, Frank: Medienrecht, chapter 6 marginal no. 37 et seq., Tübingen, 2018.

2) DSK (ed.): Kurzpapier Nr. 20. Einwilligung nach der DS-GVO, p. 1, online accessible at: www.datenschutzkonferenz-online.de/kurzpapiere.html, last accessed on 10 June 2020.

3) Mantz/Marosi in: Specht, Louisa/Mantz, Reto (eds.): Handbuch Europäisches und deutsches Datenschutzrecht, § 3 marginal no. 55,  Munich, 2019.

4) DSK (ed.): Kurzpapier Nr. 10. Informationspflichten bei Dritt- und Direkterhebung, p. 1 et seq., accessible online at: www.datenschutzkonferenz-online.de/kurzpapiere.html, last accessed on 10 June 2020; DSK (ed.): Kurzpapier Nr. 20. Einwilligung nach der DS-GVO, p. 2, accessible online at: www.datenschutzkonferenz-online.de/kurzpapiere.html, last accessed on 10 June 2020.

5) Fechner, Frank: Medienrecht, chapter 6 marginal no. 40, Tübingen, 2018.

6) DSK (ed.): Kurzpapier Nr. 20. Einwilligung nach der DS-GVO, p. 1, accessible online at: www.datenschutzkonferenz-online.de/kurzpapiere.html, last accessed on 10 June 2020.

7) Mantz/Marosi in: Specht, Louisa/Mantz, Reto: Handbuch Europäisches und deutsches Datenschutzrechts, § 3 marginal no. 56; Lauber-Rönsberg in: ibid., § 4 marginal no. 77.

8) DSK (ed.): Kurzpapier Nr. 20. Einwilligung nach der DS-GVO, p. 1, accessible online at: www.datenschutzkonferenz-online.de/kurzpapiere.html, last accessed on 10 June 2020.

9) EuGH C-673/17 – Planet 49.

10) DSK (ed.): Kurzpapier Nr. 20. Einwilligung nach der DS-GVO, p. 1 et seq., accessible online at: www.datenschutzkonferenz-online.de/kurzpapiere.html, last accessed on 10 June 2020.

11) BfDI (ed.): Sozialdatenschutz, p. 20, accessible online at: www.bfdi.bund.de/SharedDocs/Publikationen/Infobroschueren/INFO3.pdf, last accessed on 15 June 2020.

12) Lauber-Rönseberg in: Specht, Louisa/Mantz, Reto (eds.): Handbuch Europäisches und deutsches Datenschutzrecht, § 4 marginal no. 78 et. seq., Munich, 2019.

13) Fechner, Frank: Medienrecht, chapter 4 marginal no. 40, Tübingen, 2018.

14) BfDI (ed.): Sozialdatenschutz, p. 20, accessible online at: www.bfdi.bund.de/SharedDocs/Publikationen/Infobroschueren/INFO3.pdf, last accessed on 15 June 2020.

15) Kipker/Pollmann in: Specht, Louisa/Mantz, Reto (eds.): Handbuch Europäisches und deutsches Datenschutzrecht, § 26 marginal no. 42, Munich, 2019.

16) Based on: DSK (ed.): Kurzpapier Nr. 20. Einwilligung nach der DS-GVO, p. 2, accessible online at: www.datenschutzkonferenz-online.de/kurzpapiere.html, last accessed on 10 June 2020.