Skip to content
Compliance & Legal
GDPR consent

GDPR personal-data consent

For marketing, recruiting, loyalty — always compliant.

GDPR compliant · EU-hosted

GDPR fines in the EU reached a record €2.1 billion in 2023

83 % of customers are willing to share data if they know how it will be used

Documented consent reduces the risk of regulatory action by 90 %

GDPR-compliant consent. AI tailors it to the purpose, retention period and data categories.

Legal context

GDPR consent must meet the conditions of Article 7 GDPR (Regulation 2016/679/EU) — it must be freely given, specific, informed and unambiguous. Processing of special categories of data requires explicit consent under Article 9.

GDPR Regulation 2016/679/EU Art. 7 (consent) and Art. 9 (special categories of personal data)

Legal basis & glossary

When to use a GDPR consent

  • When collecting email addresses for marketing
  • During employee recruitment (storing CVs)
  • For loyalty programmes collecting customer personal data
  • Before processing biometric or health data

What you get

  • Purpose of processing
  • Retention period
  • Data subject rights
  • Withdrawal option
How it works

From idea to signature

Purpose of processing

Retention period

Data subject rights

FAQ

Frequently asked questions about GDPR consent

No. GDPR requires active consent — a pre-ticked box is not valid (CJEU ruling C-673/17 Planet49).

Glossary

Key terms in e-signature and contract law — with links to definitions.

GDPR GDPR (General Data Protection Regulation) is an EU regulation on the protection of natural persons with regard to the processing of personal data, applicable from 25 May 2018. DPA A DPA is a contract between a data controller and data processor required by Article 28 of the GDPR as a condition for lawful processing. Data Processor A data processor is a natural or legal person that processes personal data on behalf of and under the instructions of a data controller. Data Controller A data controller is a natural or legal person that determines the purposes and means of processing personal data. OTP An OTP (One-Time Password) is a one-time code sent via email or SMS that verifies a person's identity during critical actions such as signing a document. Audit Trail An audit trail is a chronological record of all events related to a document — who opened, signed or declined it — including timestamps and IP addresses. Full glossary
Who uses this

Typical roles

Click a role to see how zipzipdoc helps that group.

Role-specific guides

Similar documents

Related agreements

Documents commonly used alongside a GDPR consent.

More guides

Other document types

Further reading

Related articles

Compare tools

How does zipzipdoc compare to alternatives?

See a detailed side-by-side comparison with popular e-signature tools.

Ready?

14 days free, no card.

No credit card · 14 days free · Cancel anytime