What it is
Implied consent is consent a regime is willing to infer without an explicit act, because the individual was told clearly what would happen, the purpose is within their reasonable expectations, the information is not sensitive, and a simple means of refusing was available and effective.
It is not the absence of a rule. Regimes that permit inferred consent attach conditions; an implementation cannot assume the inference holds without checking and meeting them.
How it looks in a consent engine
StrongPrivacy’s opt-out model can implement a notice-and-refuse design where your legal analysis permits that posture: optional technologies load, the banner explains the processing, and refusal takes effect and is remembered. That does not make every opt-out regime “implied consent.” California’s sale/share opt-out, for example, is a statutory right to stop defined processing rather than consent inferred from silence.
Express it, do not fall into it
A property that resolves to opt-out for a region because nobody chose a profile deliberately is indistinguishable, in the record, from one where somebody reasoned it through. Use a region rule so the decision is visible in the configuration.
Common questions
Is implied consent valid under the GDPR?
Not for storage and access on a device. Article 5(3) of the ePrivacy Directive requires consent, and the GDPR requires a clear affirmative action for it. Scrolling, continued browsing and inactivity do not qualify.
Does StrongPrivacy default to implied consent anywhere?
No built-in jurisdiction is labelled as a legal finding of implied consent. California resolves to the product’s opt-out model under regional profiles, but that implements a statutory sale/share opt-out rather than inferring consent. The other built-in regimes resolve to opt-in as a conservative product default.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Regulation (EU) 2016/679 (GDPR)
Legislation
Checked
- California Department of Justice: CCPA
Regulator guidance
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.