Specific Consent
Specific consent means agreeing to a clearly defined, particular use of your data rather than giving a blanket approval that covers many different purposes at once. In a cookie context, this generally means a person should be able to say yes (or no) to each separate purpose, such as analytics or advertising, rather than being asked to accept everything together. Saying yes to one purpose does not imply agreement to others.
Specificity is one of the core conditions of valid consent under the GDPR, which requires consent to be freely given, specific, informed, and unambiguous. In most EU jurisdictions, 'specific' is generally interpreted to mean that consent must be tied to each distinct processing purpose and gathered on a granular, purpose-by-purpose basis, so that agreement to one purpose (for example, functional or analytics cookies) cannot be construed as agreement to unrelated purposes (for example, advertising or profiling). Note that the placing of and access to cookies and similar technologies is primarily governed by the ePrivacy Directive and its national implementations, while the specificity standard as a consent condition derives from the GDPR where personal data is processed; the two frameworks operate together but are distinct. The evidence packet does not address how specificity is applied to cookie consent under UK or US state privacy frameworks, which may adopt different approaches (including opt-out models), so the scope of this definition is limited accordingly. The precise degree of granularity required and how bundled purposes are assessed can depend on facts, evolving supervisory authority guidance, and the design of a given consent interface, and are not fully resolved by the sources provided.
Why it matters
Specificity is one of the load-bearing conditions of valid consent under the GDPR, alongside the requirements that consent be freely given, informed, and unambiguous. If a cookie banner bundles distinct purposes together, forcing a user to accept analytics, advertising, and profiling in a single click, the consent obtained may fail the specificity standard in most EU jurisdictions, meaning the underlying processing of personal data could lack a valid legal basis. For privacy officers and legal counsel, this is not a cosmetic design point: a defect in specificity can undermine the lawfulness of the entire consent-based data flow that follows.
The requirement also shapes how consent interfaces are built. Because saying yes to one purpose cannot be construed as agreement to unrelated purposes, consent management must allow users to make separate choices on a purpose-by-purpose basis. This has direct implications for web developers and marketing compliance teams who design and deploy cookie banners, as well as for the vendors and tags that fire only after consent is recorded for their specific purpose.
It is important to keep the two applicable frameworks distinct. The placing of and access to cookies and similar technologies is primarily governed by the ePrivacy Directive and its national implementations, while the specificity standard as a consent condition derives from the GDPR where personal data is processed. The sources provided do not address how specificity is applied under the UK or US state privacy frameworks, which may take different approaches, including opt-out models; readers should not assume the EU interpretation described here transfers directly to those regimes.
Who it's relevant to
Inside Specific Consent
Common questions
Answers to the questions practitioners most commonly ask about Specific Consent.