Statement of Guidance

Consent Guidance

Office of the Data Protection Authority (Guernsey) (ODPA) · Guernsey

Status not confirmed

Current version last checked: 2026-07-30

Summary

This is guidance from the Guernsey Office of the Data Protection Authority explaining how organisations should use 'consent' as a lawful basis for processing personal data under the Data Protection (Bailiwick of Guernsey) Law, 2017. It sets out the high standard the Law requires for consent to be valid and gives practical checklists for obtaining, recording and managing consent.

  • Freely given and specific: Consent must involve genuine choice, be unbundled from other terms and conditions, and be granular so separate consents are obtained for separate purposes.
  • Opt-in only: Consent requires a clear affirmative action; pre-ticked boxes or other default/opt-out mechanisms are not valid.
  • Named parties and purpose: Requests must name the controller and any third party controllers relying on the consent, and explain why the data is wanted and how it will be used.
  • Explicit consent: Where 'explicit consent' is required, it must be expressly confirmed by the individual in written words, not by another positive action.
  • Withdrawal rights: Individuals must be told they can withdraw consent at any time, given an easy way to do so, and must not be disadvantaged for withdrawing or refusing consent.
  • Record keeping: Organisations must keep records showing who consented, when, how, and what they were told.
  • Ongoing review: Consents and consent mechanisms should be reviewed and refreshed periodically, and consents obtained before the Law's standard applied should be checked and updated or replaced with another lawful basis if inadequate.
  • Criminal data: Consent to processing criminal data is only valid where the processing is required or authorised by law.
  • Power imbalance situations: Public authorities, employers and other organisations with power over individuals should take extra care and generally avoid over-reliance on consent.

The guidance is not itself a binding rule but interprets statutory requirements; organisations relying on consent as their lawful processing condition are expected to align their practices with these standards to remain compliant with the Law.

Key obligations

  • Ensure consent requests involve a clear, positive opt-in action and do not use pre-ticked boxes or default consent settings
  • Keep consent requests separate ('unbundled') from other terms and conditions
  • Provide granular, purpose-specific consent options rather than blanket consent
  • Name the organisation and any third party controllers relying on the consent
  • Keep records evidencing who consented, when, how and what they were told
  • Inform individuals of their right to withdraw consent at any time and provide an easy mechanism to do so
  • Ensure individuals are not disadvantaged or penalised for withdrawing or refusing consent
  • Immediately stop the specific processing activity when an individual withdraws consent for it
  • Regularly review and refresh existing consents to ensure they continue to meet the Law's standard
  • Review consents obtained before the Law's higher standard applied and either obtain fresh consent or identify an alternative lawful basis if they do not meet the standard
  • Only rely on consent for processing criminal data where such processing is required or authorised by law
  • Obtain explicit consent via express written confirmation, not merely another positive action, where explicit consent is required

Applies to

data controllers, public authorities, employers, organisations processing personal data in the Bailiwick of Guernsey

Deadlines

  • 25 May 2018: Consents obtained before the Law's commencement on this date should be reviewed against the Law's higher standard; if they do not meet it, fresh consent must be sought or an alternative lawful basis identified.

Topics

Version history

2026-07-30

source file (current)