What are the four conditions for valid consent?
GDPR's four consent conditions: freely given, specific, informed, unambiguous. US compliance focuses on proof, like per-lead evidence. TCPA penalties up...

What are the four conditions for valid consent?
Key Facts
- Valid consent requires four GDPR conditions: freely given, specific, informed, and unambiguous — no US equivalent exists per consent research.
- TCPA violations cost $500 per call, trebled to $1,500 for willful conduct, with a four-year statute of limitations per consent verification guidance.
- Sephora paid $1.2 million under CCPA largely for ignoring Global Privacy Control opt-out signals per IAPP reporting.
- Healthline's $1.55 million settlement is the largest CCPA penalty to date, driven by sensitive data leaking into analytics tools per 2025 enforcement data.
- Pre-ticked boxes, silence, scrolling, and bundled terms-of-service consent all fail GDPR's validity test per GDPR guidance.
- A single lead sold to five buyers can generate five separate TCPA claims, each demanding proof per consent verification research.
- The global consent management market is projected to grow from $400 million to $2.5 billion by 2032, a 21.1% CAGR per TrustArc market analysis.
Why Consent Gets Companies Sued: The Enforcement Reality
Consent mistakes are no longer theoretical risks—they are legal landmines with real financial consequences. Companies face escalating penalties for failing to prove valid consent, with TCPA violations carrying up to $1,500 per incident and a four-year statute of limitations . The stakes are clear: Sephora paid $1.2 million for CCPA violations, while Healthline settled for $1.55 million .
The burden of proof lies squarely on businesses. Courts demand more than a vendor’s assurance or spreadsheet timestamps—companies must document the exact moment consent was given, link it to a specific consumer, and retain records for years . This means raw data like browser interactions, viewport activity, and real-time submissions are critical. A single misstep, such as bundling marketing consent with terms of service, can invalidate permissions under GDPR .
US regulations lack a formal "four conditions" framework, but the GDPR’s standards—freely given, specific, informed, and unambiguous—offer a practical benchmark . For US compliance, focus on:
- Proving consent through verifiable, per-lead evidence
- Respecting opt-out mechanisms like Global Privacy Control
- Adhering to evolving rules, such as the FCC’s 2027 TCPA revocation changes
Worqd’s booking funnel exemplifies this approach, using explicit consent prompts and retaining records to meet legal thresholds . As enforcement intensifies, companies must prioritize compliance over convenience—because "the publisher told us consent was good" is no longer a defense.
The Four Conditions for Valid Consent: What They Are and Where They Come From
Most teams can recite their opt-in rate. Far fewer can say with confidence whether their consent would actually hold up if a regulator — or a plaintiff's lawyer — came asking.
Here is the direct answer: valid consent must be freely given, specific, informed, and unambiguous. But there is an important caveat. That four-condition framework comes from GDPR Article 4(11), not US law — a distinction that matters because consent research finds no equivalent four-condition list in US regulations, where rules instead live in the TCPA, CCPA, and CAN-SPAM.
Still, the GDPR standard is the best audit checklist available, because regulators everywhere are converging on the same ideas. Under GDPR consent guidance, each condition carries concrete operational requirements you can check your own forms against:
- Freely given — no dark patterns. Hidden reject buttons, extra steps to refuse, or bundling marketing consent into your terms of service all invalidate consent.
- Specific and informed — one purpose per checkbox, named clearly, with your privacy policy linked. "The words next to the checkbox are the compliance."
- Unambiguous — clear affirmative action only. Pre-ticked boxes, silence, scrolling, or closing a banner do not qualify.
- Withdrawable — opting out must be as easy as opting in, and every consent event needs a timestamp you can produce later.
The documentation requirement is where US companies most often get caught. In TCPA litigation, the burden of proof sits with the company making contact, and consent verification guidance notes that spreadsheet timestamps and "the publisher told us it was good" arguments fail in court — with statutory damages of $500 per violation, trebled to $1,500 for willful conduct, and a four-year statute of limitations.
The stakes are not theoretical. Sephora paid a $1.2 million CCPA fine for misrepresenting its data practices and ignoring Global Privacy Control opt-out signals. And 2025 state enforcement data shows penalties climbing — Healthline's $1.55 million settlement is the largest CCPA penalty to date.
This is also why, when you evaluate any growth partner, their consent practices deserve a look alongside their results. At Worqd, our booking funnel requires an explicit, unchecked opt-in — "I agree to be contacted about my request" — with details used only to prepare for the call, and our B2B outreach is personalized and permission-aware rather than a template blast. When you are choosing a provider, ask the same of anyone touching your leads: a consent standard like this one is the floor, not the ceiling.
The US Picture: Proving Consent Beats Defining It
In the US, the question shifts from "what makes consent valid?" to something harder: "can you prove it?" Under the Telephone Consumer Protection Act, the burden of proof sits entirely with the company making contact — and courts have made clear what that evidence must look like.
The battleground in TCPA litigation isn't defining consent — it's documenting it. According to consent verification guidance, "the publisher told us the consent was good" and spreadsheet timestamps don't survive scrutiny. Courts prefer evidence that is specific (per-lead), authentic (captured contemporaneously), from the consumer's perspective, and independent. Consumer-perspective evidence — the rendered page and viewport at the moment of submission — is the hardest to rebut.
The stakes are real. TCPA statutory damages run $500 per violation, trebled to $1,500 for willful conduct, and a single lead sold to five buyers can generate five separate claims. With a four-year statute of limitations, companies must retain consent records for the full window.
True verification — the layer between collecting permission and proving it later — breaks into four components:
- Capture — what actually happened at the moment of consent
- Attribution — tying that event to a specific consumer and lead
- Retention — storing evidence for the full statute of limitations
- Retrieval — producing evidence on demand when challenged
This is why choosing a growth partner matters as much as choosing a lead source. Any agency can fill your pipeline; fewer can show you, per lead, exactly what the consumer saw and agreed to. At Worqd, our own booking funnel requires explicit opt-in — "I agree to be contacted about my request" — because the words next to the checkbox are the compliance, as marketing consent guidance puts it: unchecked, named, specific, one purpose per box.
Email operates under a different logic. Under CAN-SPAM, prior consent isn't strictly required — compliance hinges on transparency, accurate identification, and prompt unsubscribe handling. No deceptive subject lines, honest sender details, and working opt-outs carry the weight that opt-in carries elsewhere.
The rules are actively shifting. The FCC released a draft Report and Order on Sept. 9, 2026 that would substantially revise TCPA consent and opt-out requirements, including narrowing the "revoke-all" requirement and allowing callers to designate an exclusive opt-out method, per legal analysis from Greenberg Traurig. The 2024 revoke-all requirement is currently set to take effect Jan. 31, 2027 — and the revised rules govern FCC enforcement but may not conclusively determine liability in private TCPA litigation.
Translation: build your consent documentation now, and don't wait for the rulebook to settle.
How to Make Your Consent Compliant and Convert-Ready
Consent language fails quietly. A checkbox nobody reads, a pre-ticked box, a vague "I agree to everything" — each one can turn a working funnel into a liability when a regulator or plaintiff's attorney comes knocking.
The good news: compliant consent is mostly a writing and plumbing problem. One vendor principle sums it up well: "the words next to the checkbox are the compliance" — unchecked, named, specific, one purpose per box, withdrawal mentioned, privacy policy linked. That's the whole checklist, and it's worth printing out and taping to your form builder.
In practice, that means:
- Every consent box starts unchecked — silence and pre-ticked boxes don't count as consent.
- The language names the party and the purpose, with one purpose per box — no bundling marketing consent into terms of service.
- Withdrawal is mentioned and honored, because consent must be as easy to take back as it was to give.
- Your privacy policy is linked right there, not buried three clicks deep.
This is exactly how Worqd handles its own booking funnel: a single explicit line — "I agree to be contacted about my request" — with a note that details are only used to prepare for the call. Unchecked by default, specific to one purpose, no dark patterns. It's a small example, but it shows the standard is achievable on any form, at any budget.
Two operational details matter as much as the words. First, honor opt-outs, including Global Privacy Control signals — Sephora's $1.2 million fine came largely from failing to process GPC opt-outs, and California's AG was blunt: "There are no more excuses." Second, keep sensitive form fields out of your analytics tools, since data that leaks into third-party tracking is what turned Healthline's settlement into the largest CCPA penalty to date at $1.55 million.
Finally, retain your consent records. The TCPA carries a four-year statute of limitations with statutory damages of $500 per violation — trebled to $1,500 for willful conduct — and the burden of proving consent sits with you, not the consumer. Courts want per-lead, contemporaneous evidence of the actual consent event, not spreadsheet timestamps or "the publisher told us it was good."
Get the words right, honor the opt-outs, keep the records, and your consent stops being a compliance risk — it becomes a trust signal that helps conversion instead of hurting it.
Frequently Asked Questions
What are the four conditions for valid consent?
Does US law require the same four consent conditions as GDPR?
What happens if my consent forms don't meet the standard?
What makes a consent checkbox legally valid?
How long do I need to keep consent records?
Is prior consent required for marketing emails in the US?
Beyond the Four Conditions: Navigating Consent Compliance in a Shifting Legal Landscape
While the GDPR’s four conditions for valid consent—freely given, specific, informed, and unambiguous—are widely referenced, they are not legally binding in the US. Instead, US compliance hinges on proving consent through verifiable, per-lead evidence, as seen in TCPA and CCPA enforcement actions. Courts demand more than generic assurances; they require contemporaneous, consumer-perspective documentation to withstand scrutiny. For businesses, this means prioritizing explicit opt-ins, clear language, and robust record-keeping to avoid costly penalties. Worqd’s approach—using unchecked, purpose-specific consent prompts and retaining detailed records—demonstrates how compliance can align with operational efficiency. As regulations evolve, especially with upcoming FCC changes, proactive verification is no longer optional. Audit your consent processes today, ensure opt-outs are honored, and stay ahead of enforcement trends. Learn more about how to align your practices with evolving standards here.
Want help putting this into action?
Book a Growth Call