Informed consent is a legal and ethical doctrine requiring that an individual voluntarily agrees to a procedure, treatment, data use, or research participation after receiving and comprehending all material information about its nature, risks, benefits, and alternatives. It rests on four elements: disclosure of relevant information, comprehension by the consenting party, voluntariness free from coercion, and capacity to make the decision. Codified in post-Nuremberg biomedical ethics (Belmont Report, Declaration of Helsinki), GDPR data protection law, and clinical trials regulations, informed consent is the foundational mechanism protecting individual autonomy across medical, research, and digital data contexts.

Content

  • The doctrine of informed consent developed from a series of medical ethics catastrophes in the twentieth century. The Nuremberg Doctors’ Trial (1946–47) established the Nuremberg Code, which articulated voluntary consent as “absolutely essential” for human experimentation. The Declaration of Helsinki (1964, regularly updated) extended these principles to clinical research globally. In the United States, the Tuskegee Syphilis Study (1932–1972), in which Black men with syphilis were left untreated without knowledge or consent, triggered the National Research Act of 1974 and the Belmont Report (1979), which codified three principles—respect for persons, beneficence, and justice—and required informed consent as the primary mechanism protecting research subjects. These frameworks were incorporated into the Common Rule (45 CFR Part 46), the US federal regulation governing human subjects research.
  • Valid informed consent comprises four elements as defined in bioethics and case law. Disclosure requires that the practitioner or investigator communicate the nature of the proposed action, foreseeable risks and benefits, alternatives, and the right to refuse or withdraw without penalty. Comprehension requires that the information be communicated in a form the individual can understand, considering literacy, language, and cognitive capacity. Voluntariness requires freedom from coercion, undue inducement, or manipulation. Capacity (or competence) requires that the individual possess the cognitive and legal ability to make the decision; proxy consent mechanisms apply where capacity is absent (minors, individuals with cognitive impairment). In clinical practice, consent is documented in writing with signature, though verbal consent is legally sufficient in some contexts.
  • In data protection law, informed consent has been formalised as one of six lawful bases for processing personal data under GDPR (Article 6(1)(a)), with specific conditions defined in Article 7: consent must be freely given, specific, informed, and unambiguous; withdrawal must be as easy as giving consent; and consent cannot be bundled with other agreements. Special category data (health, genetic, biometric, religious, political) requires explicit consent (Article 9). The European Data Protection Board guidance on consent emphasises that pre-ticked boxes, silence, and bundled terms do not constitute valid consent. GDPR’s territorial reach—applying to any processing of EU residents’ data regardless of processor location—made informed consent a global data governance obligation for technology companies.
  • Through 2024–2025, informed consent faces significant challenges from AI and digital health contexts. AI training on public or clinical datasets raises questions about whether individuals who generated that data consented to its use in model training—a gap being addressed through data trust frameworks, federated learning, and synthetic data generation. The FDA’s framework for AI-enabled medical devices includes consent considerations for algorithm updates post-approval. The EU AI Act (effective 2024) imposes transparency requirements for high-risk AI systems that interact with individuals, effectively mandating disclosure elements similar to informed consent for consequential automated decisions. Research into dynamic or just-in-time consent models—where individuals receive contextualised consent requests at the point of data use rather than blanket upfront agreements—is advancing, enabled by consent management platforms that implement Granular Consent Control at per-purpose, per-processor granularity.