
Article 6(1)(a) compliance is rarely a legal drafting exercise. It is an enterprise-wide capability requiring governance, architecture, process engineering, records management, privacy operations, security controls, monitoring, and evidence generation. Regulators increasingly assess not only whether consent was obtained, but whether the organisation can continuously demonstrate that every downstream processing activity remains aligned with the consent originally given.