Back to insights
Checking Compliance Practices

What is an example of consent?

See a real GDPR-compliant consent example from Worqd's booking funnel. Learn the 4 legal pillars of valid consent and how to audit your own forms.

What is an example of consent?

What is an example of consent?

Key Facts

Most consent forms fail because they confuse friction with compliance. Pre-ticked boxes, buried opt-out links, and vague "by using this site you agree" language don't meet the legal threshold — they just create liability. Regulators look for a clear affirmative action that is freely given, specific, informed, and unambiguous, exactly as GDPR Article 4(11) defines it.

The Digital Spy case illustrates the trap: a pre-checked opt-out box hidden in a disclaimer was rejected as invalid because inactivity and default settings never equal consent. That same pattern — treating silence as permission — exposes businesses to fines up to 4% of global turnover or €20 million, whichever is higher. CCPA adds up to $7,500 per violation, and Canada's CASL regime, which applies to Worqd in Halifax, is described as the strictest of all, generally requiring express or implied consent before any outreach.

Valid consent isn't a checkbox exercise; it's a design decision. The booking funnel at Worqd requires the explicit statement "I agree to be contacted about my request" and limits data use to call preparation — no marketing lists, no retargeting, no third-party sharing. That single, purpose-specific opt-in satisfies every criterion the law demands:

  • Freely given — no pre-selection, no coercion
  • Specific — one purpose, one action
  • Informed — the user knows exactly what they're agreeing to
  • Unambiguous — a deliberate tick, not a scroll or a pause
  • Documented — timestamped proof the regulator can audit

Contrast that with the "I Agree" speed traps that rush users through compliance without real choice. When 73% of consumers say they're more concerned about data privacy than a few years ago, the difference between a compliant form and a compliant culture becomes a competitive signal. Permission-aware outreach isn't courtesy — it's the only model that survives scrutiny.

Not every "yes" counts as consent — at least not in the eyes of the law. Before any business contacts a prospect, the permission it holds has to clear a specific, four-part legal bar.

Under GDPR Article 4(11), consent must be freely given, specific, informed, and unambiguous, expressed through "a statement or by a clear affirmative action," according to MailerLite's breakdown of GDPR-compliant opt-in forms. Each pillar matters:

  • Freely given: the person has a genuine choice, with no pressure or bundled conditions.
  • Specific: consent covers one stated purpose, not a blanket catch-all.
  • Informed: the person knows who is collecting their data and how it will be used.
  • Unambiguous: agreement requires a clear affirmative act — never silence or inactivity.

GDPR Recital 32 confirms what that affirmative act looks like in practice: consent "could include ticking a box when visiting an internet website." The flip side is just as clear — Transcend's consent management guidance states plainly that pre-ticked boxes or inactivity don't count as valid consent.

The strictness escalates sharply depending on jurisdiction. A comparison of email marketing and cold email rules notes that the US CAN-SPAM Act permits cold email with an opt-out, while Canada's CASL is the strictest major regime, generally requiring implied or express consent before contact. For a Halifax-based agency like Worqd, that makes CASL's express-consent standard the operative baseline — not a nice-to-have.

The stakes for getting this wrong are real. GDPR violations can reach up to 4% of global turnover or €20 million, whichever is higher, and CCPA breaches carry fines of up to $7,500 each, per Osano's consent management overview.

Consent also doesn't end at the moment of collection. Organizations must keep detailed records of when and how consent was given and offer an easy withdrawal path at any time. Consent management platforms support this by creating a timestamped log of each visitor's consent signal, which regulators increasingly expect as proof.

Put the four pillars together and one conclusion follows: active opt-in is the only mechanism that satisfies every major jurisdiction. An unchecked box that a prospect deliberately ticks — paired with plain language about what happens next — works under GDPR, CASL, and stricter US state laws alike. Opt-out models, pre-checked boxes, and implied consent all fail somewhere on the map.

This is exactly why Worqd's booking funnel asks prospects to actively confirm "I agree to be contacted about my request" and states that details are used only to prepare for the call. It's a single, purpose-specific, affirmative action — a textbook answer to what valid consent actually requires.

When you book a growth call through Worqd's six-step funnel at worqd.com/book, the final step asks you to actively tick a box that reads, "I agree to be contacted about my request." It's a small moment, but it's also a textbook example of valid consent in action.

Here's why. Under GDPR, consent must be "freely given, specific, informed and unambiguous" and expressed through a "clear affirmative action" such as ticking a box. That's exactly what this checkbox does — nothing happens until you deliberately click it. The form arrives unchecked by default, which matters because pre-ticked boxes or inactivity don't count as valid consent.

The language itself does more work than most forms. Alongside the consent statement, Worqd explains that the details you share are used only to prepare for your call. That's purpose limitation in plain English — best-practice forms clearly state what the subscriber is agreeing to receive and how their data will be used, rather than burying broad permissions in a disclaimer.

Breaking the example down against the legal baseline shows how each element fits:

  • Single purpose: consent covers contact about your specific request — not newsletters, retargeting, or unrelated marketing.
  • Unchecked by default: the box starts empty, so consent comes from you, not from a default setting.
  • Clear affirmative action: a deliberate tick signals agreement, matching the GDPR definition of unambiguous consent.
  • Documented timestamp: the submission creates a record of when and how consent was given — the kind of proof regulators expect you to keep.
  • Easy withdrawal path: a reply or email to [email protected] ends contact, honoring the requirement that people can withdraw consent at any time.

Contrast this with a pattern that got a publisher in trouble: a form using a pre-checked opt-out box, where silence was treated as permission. That approach fails the standard because explicit consent requires a clear and affirmative signal from the user — the opposite of asking people to uncheck a box they never touched.

The stakes are higher for a Canadian company, too. CASL, the law governing Worqd from its Halifax, Nova Scotia base, is the strictest of the major regimes, generally requiring implied or express consent before outreach. Getting explicit permission before the first contact isn't just courtesy — it's the compliance floor.

And it fits the broader philosophy. Worqd describes its B2B outreach as "personalized, permission-aware outreach to relevant accounts — the opposite of a template blast." A consent checkbox that names its purpose, waits for an affirmative click, and keeps a record is what that promise looks like in practice.

You do not need a lawyer to spot a broken consent form — you need a checklist and ten minutes. With GDPR fines reaching up to 4% of global turnover or €20 million, whichever is higher, according to compliance guidance for B2B lead generation, a sloppy checkbox is an expensive habit.

Start by auditing what you already have. Pull up every form, landing page, and booking funnel that collects contact details, and test each one against the elements of valid consent: freely given, specific, informed, and unambiguous, given through a clear affirmative action like ticking a box, as outlined in MailerLite's breakdown of GDPR-compliant opt-in forms.

Then walk through this fix-it checklist:

  • One checkbox per purpose — separate boxes for separate uses, and no unnecessary boxes that create signup friction
  • Nothing pre-selected — consent management guidance is clear that pre-ticked boxes or inactivity do not count as valid consent
  • A plain-language purpose statement beside each box explaining exactly what the person is agreeing to and how their data will be used
  • Proof capture on every submission — IP address, date, time, and subscription source, mirroring the record-keeping documented consent practices recommend
  • A withdrawal path in every follow-up message, since organizations must keep detailed consent records and let users withdraw at any time, per transcend.io's consent management overview

The proof-capture step is the one most teams skip. Consent management platforms exist largely to create a timestamped log of each visitor's consent signal — because if you cannot prove when and how someone agreed, the consent effectively does not exist.

If you want a working template, look at how Worqd handles it. The booking funnel requires an explicit, unticked-by-default statement — "I agree to be contacted about my request" — and states that details are only used to prepare for the call. That is one checkbox, one purpose, zero ambiguity, and it matters doubly in Canada, where CASL is the strictest major regime and generally requires implied or express consent before contact, as Emercury's comparison of email marketing and cold email explains.

Run your own forms against that same standard. If a stranger could not tell you exactly what they agreed to, when, and how to undo it, you have found your fix.

Frequently Asked Questions

What is a real example of valid consent?
A textbook example is Worqd's booking funnel at worqd.com/book, which requires you to actively tick a box reading "I agree to be contacted about my request" and states your details are only used to prepare for the call. It's a single, purpose-specific opt-in that satisfies the GDPR standard of consent that is freely given, specific, informed, and unambiguous.
Do pre-ticked boxes count as consent?
No — pre-ticked boxes or inactivity don't count as valid consent, since the law requires a clear affirmative action from the user. The Digital Spy case is a cautionary example: a pre-checked opt-out box hidden in a disclaimer was rejected as invalid because silence never equals permission.
What are the four legal requirements for consent?
Under GDPR Article 4(11), consent must be freely given, specific, informed, and unambiguous, expressed through a statement or clear affirmative action like ticking a box. If any one pillar is missing — for example, a vague "by using this site you agree" notice — the consent doesn't meet the legal threshold.
What happens if my consent form doesn't comply?
GDPR violations can reach fines of up to 4% of global turnover or €20 million, whichever is higher, and CCPA breaches carry fines of up to $7,500 per violation. Canada's CASL is even stricter for outreach, generally requiring express or implied consent before any contact.
Do I need to keep records proving someone consented?
Yes — organizations must keep detailed records of when and how consent was given, and offer an easy way to withdraw it at any time. Consent management platforms exist largely to create a timestamped log of each visitor's consent signal, because if you can't prove consent, it effectively doesn't exist.
How can I quickly check if my own consent form is compliant?
Run each form against a simple checklist: one checkbox per purpose, nothing pre-selected, a plain-language purpose statement, proof capture (IP, date, time, source) on every submission, and a withdrawal path in every follow-up. If a stranger couldn't tell you exactly what they agreed to, when, and how to undo it, you've found your fix.

One Checkbox, One Purpose, Zero Ambiguity

Consent isn't a legal formality you bolt onto a form — it's the difference between a pipeline built on permission and a liability waiting for an audit. The standard is consistent everywhere that matters: freely given, specific, informed, and unambiguous, proven by a clear affirmative action like an unticked box someone deliberately checks. Pre-checked boxes, buried opt-outs, and silence-as-agreement all fail that test, and with GDPR fines reaching up to 4% of global turnover or €20 million, failure is expensive. Your next step is simple: audit every form against the checklist above — one purpose per box, nothing pre-selected, plain language, timestamped proof, and an easy way to withdraw. If you'd rather see the standard in action than guess at it, book a free growth call with Worqd. You'll experience the exact consent mechanism described here — and leave with a clearer picture of how permission-aware outreach can fill your calendar.

Want help putting this into action?

Book a Growth Call
Topicsvalid consent exampleGDPR consent requirementsconsent form best practicesCASL express consentconsent audit checklist

Stay in the Loop