Three things the law actually requires
A lawful UK GDPR consent form does three things: it names who is collecting the data, states plainly what will happen to it, and records an unambiguous affirmative action by the person giving it. Everything else — layout, field order, the wording of your privacy notice — is craft. Those three elements are the law.
What has changed is the ground underneath them. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and the main data protection changes in Part 5 came into force on 5 February 2026. It amends, but does not replace, the UK GDPR, the Data Protection Act 2018 and PECR, with changes phased in between June 2025 and June 2026. One of its effects is that a lot of the processing organisations were nervously collecting consent for probably never needed consent in the first place.
The most common mistake: asking for consent you don't need
Consent is one of six lawful bases under Article 6. It is not the default, and it is not the safest option. It is the most fragile, because consent can be withdrawn at any time and must be as easy to withdraw as it was to give. If you rely on consent to process data you need in order to deliver a service, and the customer withdraws it, you have built your own problem.
Use consent where the person genuinely has a free choice and saying no costs them nothing: marketing emails, optional cookies, using someone's photograph, adding a client to a newsletter.
Use a different basis where processing is necessary. Contract covers what you need to fulfil an order. Legal obligation covers records HMRC or the HSE require. Legitimate interests covers a wide range of ordinary business activity, provided you weigh your interest against the individual's rights.
The Act added a seventh route. Recognised legitimate interests, at Article 6(1)(ea), remove the Legitimate Interests Assessment requirement for specific activities now deemed automatically lawful. The necessity test still applies — there is simply no need to balance the data subject's interests against the organisation's. Note carefully what is not on that list: direct marketing, intra-group data sharing and network security do not qualify, so an assessment is still required for those. The Act does codify all three as examples of processing that may fall within a controller's legitimate interest.
So your first question should never be "how do we word the consent box". It should be "do we need one here at all".
Template to start from: the Lawful Basis Record gives you a one-page internal form logging which basis applies to each collection point, who decided, and when. Auditors and the ICO both ask for this. Almost nobody has it.
What makes consent valid
Consent must be freely given, specific, informed and unambiguous, indicated by a clear affirmative action. In form terms:
- Unticked by default. A pre-ticked box is not consent. Neither is silence, nor "by submitting this form you agree to receive our newsletter" buried under the button.
- Granular. Bundling everything into one checkbox fails the specificity test. Email marketing, sharing with a partner, and using a testimonial are three decisions and three checkboxes.
- Unbundled. Consent to marketing cannot be a condition of receiving the service. If someone must tick your marketing box to download the guide, it is not freely given.
- Named. Identify your organisation and any third party relying on the consent. "Our carefully selected partners" names nobody.
- Withdrawable. State how to withdraw at the point of collection, and make it genuinely as easy — one click, no phone call.
The Act also amended the Article 4 definition of consent, inserting new provisions that came into force on 5 February 2026 — worth checking your wording against if it has not been reviewed since.
Structuring the form itself
Open with purpose, not fields. One or two lines above the first input explaining what this is and how long it takes. This reduces abandonment more than any design change.
Collect the minimum. Data minimisation is a principle, not a nicety. Every optional field is one you must justify, secure and eventually delete.
Separate identity from permission. Name and email at the top. Consent choices in their own visually distinct block below, under a heading like "How we can contact you". Do not scatter checkboxes among data fields.
Write in the first person. "I agree that Acme Ltd may email me about new products" reads as a decision. "Consent to marketing communications" reads as a legal artefact.
Link the privacy notice, don't paste it. A short plain-English summary plus a link satisfies the informed requirement: who you are, what you'll do, how long you'll keep it, where it goes, how to complain.
Add the complaint route. Data subjects now have a new right to complain directly to controllers where they believe data protection rules have been infringed, with further changes on data subject complaints coming into force on 19 June 2026.
Templates to use here: the Marketing Opt-In Form handles granular channel-by-channel consent for email, SMS and post. The Photo and Media Release Form covers image use including the separate parental path for under-18s.
Special cases that trip people up
Children. A child aged 13 or over can consent to information society services themselves. Below 13, you need verified parental consent. The Act requires controllers to take into account children's higher protection matters set out in the UK GDPR, so build the age gate first and branch from it.
Special category data. Health, ethnicity, religious belief, biometrics, sexual orientation and trade union membership need both an Article 6 basis and an Article 9 condition. For consent that means explicit consent — a clear written statement. A health questionnaire on a gym signup is Article 9 territory.
Employees. Staff consent is rarely valid, because the power imbalance undermines "freely given". Use contract, legal obligation or legitimate interests for HR processing.
Cookies. These sit under PECR. A form consent does not cover your analytics.
Records: the part everyone forgets
If you rely on consent you must be able to demonstrate it. Store, for each consent: who consented, when to the second, what exactly they were shown — the version of the wording, not a paraphrase — how they consented, and whether they have since withdrawn.
The failure mode is almost always the third. Organisations change their wording, keep no version history, and can prove only that somebody ticked something. Version your consent statements and store the version ID alongside the timestamp.
Set a retention decision too. Consent goes stale; many organisations refresh marketing consent every two years.
Template to pair with this: the GDPR Data Subject Access Request Form. A structured intake with identity verification turns a one-month statutory deadline into a workflow rather than a scramble.
Checklist before you publish
- Have you confirmed consent is the right basis, or defaulted to it?
- Is every box unticked and separately meaningful?
- Can someone complete the form without agreeing to marketing?
- Is your organisation named, along with any third party?
- Is the withdrawal method on the form itself?
- Does the form store wording version, timestamp and source?
- Does an under-13 route exist?
- Have you set a retention period and refresh cycle?
Consent forms you can publish today
Consent and data-rights forms to start from
Free to preview, yours to edit — every question, rule and colour stays editable.
Marketing Opt-In Form
Channel-by-channel opt-in boxes, all unticked, with the wording version and timestamp stored against each submission — the three things you have to be able to show.
Photo & Media Release Form
Get written permission to use someone's photo, video or audio, with the usage, duration and territory agreed.
GDPR Data Subject Access Request Form
Structured DSAR intake with identity verification and a request-type branch for access, correction, deletion or portability.
Lawful Basis Record
Internal one-page record of which UK GDPR Article 6 basis applies to a data collection point, decided by whom and when.
Frequently asked questions
- Does the Data (Use and Access) Act mean I need less consent?
- Indirectly, yes. It has not loosened the definition of valid consent — it has widened the alternatives. Review your lawful bases rather than your checkboxes.
- Is a tick box enough, or do I need a signature?
- A tick box is sufficient for ordinary consent. For explicit consent covering special category data, a typed name or e-signature alongside the statement makes it far easier to evidence.
- Do I need consent to email existing customers?
- Not necessarily. The soft opt-in under PECR allows marketing to people who bought a similar product, gave their details during that sale, and were offered an opt-out then and in every message since. It does not extend to prospects who merely enquired.
- How long does consent last?
- There is no statutory expiry. Two years is a common working default; inactive contacts should be re-permissioned or removed.
- Can I use one consent form for the UK and the EU?
- Carefully. Divergence between the two regimes is most pronounced in automated decision-making and international transfers, so do not carry Data (Use and Access) Act relaxations into EU-facing operations.
- What happens if I get it wrong?
- The ICO usually engages before it fines. But the ICO's new powers include compelling witnesses to attend interviews, and it has been clear it will take serious action against organisations not following the guidelines.
General guidance on UK data protection practice, not legal advice. Requirements depend on your circumstances — check the current ICO guidance or take advice before relying on this page.



