The classic trap
Recital 171 is often overlooked, yet it carries a silent risk: the validity of consents collected under Directive 95/46/EC. Many organisations migrated to the GDPR in 2018 assuming all their legacy consents were valid, without verifying they met the GDPR's reinforced conditions (freely given, specific, informed, unambiguous, demonstrable). The CNPD and CNIL regularly sanction prospecting or newsletter databases relying on pre-2018 consents obtained via pre-ticked boxes, bundled wording or absence of traceability. The EDPB confirmed in its Guidelines 05/2020 that any consent not meeting Article 7 GDPR criteria must be re-collected.
The retroactive validity test for a legacy consent
For a pre-GDPR consent to remain valid today, it must cumulatively meet the following conditions:
- Positive action by the data subject (no pre-ticked boxes, no implicit consent through inaction)
- Specific consent for each purpose (no global consent through ToS acceptance)
- Prior clear information on the controller's identity and purposes
- Preserved proof: date, form version, exact wording, IP or technical identifier
- Withdrawal as easy as the original consent
- No manifest imbalance (employer, public authority)
Regarding Commission adequacy decisions and supervisory authority authorisations predating 2018, they remain in force until amended. This mechanism preserved decisions such as those for Canada or Switzerland, but also allowed the Privacy Shield to fall via Schrems II in 2020. Any organisation relying on an old decision must verify it is still active.
How Luxgap automates this risk
Our Luxgap Consent Legacy Auditor eliminates the grey zone of legacy consents by performing a complete retroactive audit of your consent database, cross-checking each record against the GDPR's reinforced criteria to identify those that must be re-collected before a supervisory authority discovers it during an audit. The tool connects directly to your CRM (Salesforce, HubSpot, Odoo), your email platform (Mailchimp, Brevo, ActiveCampaign) and your web forms to reconstruct the real traceability of each consent, not the declared one.
- Automatically detects each consent collected before 25 May 2018 and evaluates its compliance with the six Article 7 GDPR criteria.
- Classifies each record as green (valid), amber (to document) or red (to re-collect immediately) with opposable legal justification.
- Generates targeted re-collection campaigns with wording aligned to EDPB Guidelines 05/2020, ready to inject into your email tool.
- Verifies the current validity of adequacy decisions and prior authorisations still cited in your records of processing and privacy policies.
- Produces a timestamped PDF report opposable to the CNPD demonstrating you have audited and cleansed your legacy consent estate.
Available as a complement to a Luxgap DPO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your actual consent database, with a free 48-hour blind audit to measure the percentage of at-risk consents before any commitment.