A biobank collects and stores biospecimens and associated data for research that, in many cases, has not yet been designed at the point of collection. That structural fact — future use that cannot be fully specified up front — is what makes a single study’s consent model a poor fit for biobanking, and it is why biobank governance has converged on a small number of named consent architectures rather than one default approach. This guide compares the three most widely used: broad consent, tiered (layered) consent, and dynamic consent, and covers how each interacts with ISO 20387 biobank accreditation and GDPR-aligned data governance.
For the underlying definition of a biobank itself, see the Biobank dictionary entry. For the U.S. Common Rule’s specific broad consent pathway, see Broad Consent Under 45 CFR 46.116(d) — that guide goes deep on one regulatory implementation of the broad model; this guide compares all three models against each other and against biobank-specific governance standards.
Why biobanks need a different consent model than a single study
Standard informed consent, as built into most human-subjects regulation, assumes a describable study: a defined purpose, a defined population, defined procedures, and a defined set of risks the subject can weigh before agreeing. A biobank breaks that assumption on purpose — its entire value proposition is that a single collection can support research questions that have not been formulated yet, sometimes for decades after collection, across investigators and institutions the original donor will never meet.
Two workarounds are available under a strict specific-consent model: return to every donor for permission before each new secondary study, or ask a research ethics committee to waive consent for each new use on a case-by-case basis (in the U.S., under the 45 CFR 46.116(f) waiver pathway). Both scale poorly against a biobank holding hundreds of thousands of samples and supporting an open-ended stream of future protocols. Broad, tiered, and dynamic consent are three different answers to the same underlying question: how much specificity can a biobank reasonably ask a donor to forgo at enrollment, and what does it owe the donor in exchange for that flexibility — ongoing information, granular choice, or an easy path to withdraw?
Broad consent: one decision, open scope
Broad consent asks a donor, once, at the point of collection, for prospective permission to store their specimens and associated data and use them for a general category of future research that is not yet specified. In the U.S., this has a specific regulatory form: the 2018 revisions to the Common Rule created a defined broad consent pathway at 45 CFR 46.116(d), with its own required disclosure elements (the general types of research that may be conducted, whether specimens/data may be shared with other institutions, how long they will be stored, and whether individual research results will be returned). Under GDPR, Recital 33 makes a comparable allowance for scientific research specifically: because it is often impossible to fully identify the purpose of processing at the time of collection, the Regulation permits consent to certain areas of scientific research, or parts of a research project, when this is in keeping with recognised ethical standards — provided the data subject can still exercise choice over the actual scope, in a way that is compatible with the purpose-limitation principle at GDPR Article 5(1)(b).
Broad consent’s main advantage is operational: it lets a biobank onboard a specimen once and make it available to a wide, growing research program without re-contacting the donor for every downstream study (secondary use is instead typically gated by an access or ethics committee reviewing fit against the original scope, not by the donor directly). Its main criticism, raised consistently in the bioethics literature, is that a donor cannot meaningfully weigh risks and benefits they cannot foresee — broad consent trades specificity for practicality, and the honesty of that trade depends entirely on how clearly the “general category” of future research is actually described and bounded, and on real institutional oversight (limited ethics-committee review of each downstream use) rather than the consent form alone doing all the work. It is not, and should not be treated as, the same thing as unrestricted “blanket” consent with no defined scope — see Blanket Consent vs. Broad Consent for that specific distinction.
Tiered (layered) consent: donor-selected categories of use
Tiered consent — sometimes called layered consent or categorical consent — breaks the single broad-consent decision into a menu of separately selectable categories. Instead of one yes/no to “future research generally,” a donor is offered a structured set of permitted-use categories and chooses which apply: for example, research into a specific disease area versus research generally, non-commercial versus commercial use, domestic versus international sharing, or identifiable versus de-identified use of their data. The biobank then tracks, per specimen or per donor record, exactly which categories were consented to, and an access or ethics committee checks a proposed new study against that record before approving use of any given specimen.
The appeal of tiered consent is that it preserves most of broad consent’s operational scalability — donors are still asked once, up front, not re-contacted per study — while giving them real, values-based control over categories they may care about (for instance, declining commercial or for-profit use while remaining open to public-health research). The practical cost is definitional: the biobank has to draw clear, durable boundaries around each tier, and new research methods or use cases can emerge that do not map cleanly onto categories defined years earlier, forcing either an awkward reinterpretation of an existing tier or a re-consent exercise the model was partly designed to avoid. Tiered consent also multiplies the administrative burden of tracking permitted use at the specimen level rather than the donor or cohort level, which has direct implications for the traceability infrastructure discussed below under ISO 20387.
Dynamic consent: an ongoing, digital relationship
Dynamic consent treats consent as a continuing relationship rather than a one-time event. Participants are given a personal digital interface — typically a web portal or app — where they can view current and proposed uses of their specimens and data, grant or withdraw permission for specific studies or categories as they arise, and update their preferences at any time rather than being locked into choices made at enrollment. See the Dynamic consent dictionary entry for the operational definition. The model grew out of bioethics and genomics research addressing the same limitation tiered consent only partially solves: that donor preferences and the research landscape both change over years or decades, and a static consent record — however granular — cannot capture that.
Dynamic consent is most commonly deployed in large population biobanks, rare-disease registries, and longitudinal cohorts, where the relationship with participants is expected to run for years and where re-engagement (for example, to invite participants back for follow-up sampling or to disclose new findings) already has to happen regularly. Its operational requirements are heavier than either broad or tiered consent: the biobank must maintain a working digital consent-management system, propagate withdrawal decisions to every downstream user of already-distributed data, preserve a full audit trail of preference changes over time, and ensure the interface itself remains accessible and comprehensible to participants — not just technically functional. Digital-divide and participant-engagement concerns (some donors will not or cannot use an ongoing digital interface) are a genuine, frequently raised limitation, not a solved problem.
How the three models compare
| Dimension | Broad consent | Tiered consent | Dynamic consent |
|---|---|---|---|
| Donor decision point | Once, at enrollment | Once, at enrollment, across multiple categories | Ongoing, revisitable at any time |
| Granularity of control | Low — one broad category | Medium — donor-selected use categories | High — per-study or per-preference, updateable |
| Re-contact requirement | None built in | None built in | Structural — the model depends on an ongoing channel |
| Institutional burden | Lower — one consent event, committee-gated downstream review | Medium — must track and enforce category-level permissions per specimen | Highest — digital platform, audit trail, withdrawal propagation |
| Typical regulatory basis | 45 CFR 46.116(d) (U.S.); GDPR Recital 33 (EU) | Not separately codified — implemented as an operational elaboration of broad or specific consent | Not separately codified — implemented as an operational elaboration of broad or specific consent |
All three remain subject to the same baseline requirements: voluntariness, the right to withdraw, and (where GDPR applies) a valid legal basis and, for specimens and health data that qualify as special category data under GDPR Article 9, an applicable Article 9(2) condition alongside consent. A minority of biobanks rely on a public-task legal basis under GDPR Article 6(1)(e) rather than consent for the processing itself, using consent-like mechanisms mainly for the separate ethical requirement of donor agreement — the consent-model choice and the GDPR legal-basis choice are related but not identical decisions, and conflating them is a common implementation mistake.
Where ISO 20387 and GDPR governance actually fit
ISO 20387:2018, the accreditation standard for biobank general requirements, does not mandate one of the three consent models over another — it does not prescribe broad, tiered, or dynamic consent as a compliance requirement. What it does require is that a biobank operate a documented consent and ethics system: donors must be told the purpose of collection and the nature of the research involved, the possible risks, and their right to refuse or withdraw at any time, and the biobank must maintain full lifecycle traceability of every specimen — including its linkage to the specific permitted and restricted uses that specimen’s consent record actually authorizes, and the ability to act on a withdrawal by locating and excluding that specimen from further use. In practice, that traceability requirement is what makes tiered and dynamic consent operationally demanding to run under ISO 20387 accreditation: the more granular the consent model, the more the biobank’s quality management system has to track at the individual-specimen level, and an accreditation audit will test whether that tracking is actually real rather than just documented in policy.
GDPR shapes the same choice from the data-protection side rather than the accreditation side. Recital 33’s allowance for broad consent to “certain areas of scientific research” is not an unconditional license — it still has to be exercised consistently with purpose limitation under Article 5(1)(b) and with the data subject’s rights, including the right to withdraw consent as easily as it was given. A biobank relying on GDPR consent as its legal basis for processing has a practical incentive to build in some mechanism for donors to exercise real, ongoing choice — which is part of why tiered and especially dynamic consent have gained traction at EU-based and EU-linked biobanks specifically, even though GDPR itself does not name either model. For the general GDPR compliance framework this sits inside, see GDPR and Data Protection Compliance in Research Involving Personal Data.
Choosing and implementing a consent model: practical guidance
Research administrators evaluating or redesigning a biobank’s consent architecture should treat this as an operational decision as much as an ethical one — the model has to be one the biobank can actually run correctly at scale, not just one that reads well in a protocol.
- Match the model to the biobank’s actual re-contact capacity. Dynamic consent only delivers its promised participant control if withdrawal and preference changes genuinely propagate to every downstream data/specimen user in practice — committing to the model without the platform and process to back that up creates a compliance gap, not a compliance advantage.
- Size the tiering scheme to what the biobank can actually enforce. A tiered consent form with categories the access-review process cannot reliably check against at approval time produces the same practical result as broad consent, with added administrative overhead and a false impression of donor control.
- Treat traceability as the real constraint, not the consent form’s wording. Whichever model is chosen, ISO 20387 accreditation (and good practice regardless of formal accreditation) depends on being able to answer, for any given specimen, exactly what it was consented for and whether that consent is still current — build the specimen-tracking system before finalizing the consent language, not after.
- Separate the ethical consent decision from the GDPR legal-basis decision where GDPR applies, and document both explicitly — a biobank using a public-task legal basis under Article 6(1)(e) still needs a genuine ethical consent process even though consent is not doing the data-protection legal-basis work.
- Don’t assume one model has to apply biobank-wide. A cohort collected for one program with strong participant-engagement infrastructure may reasonably run on dynamic consent, while an older legacy collection may remain on the broad or tiered consent it was originally collected under — mixed-model governance across a biobank’s holdings is common and should be documented as such rather than papered over.
- Look to real governance precedent where a comparable biobank or biorepository consortium has published its access and consent framework — see, for example, H3Africa’s Data and Biospecimen Access Committee (DBAC) for one worked governance model built around consent-scoped access review, and ISBER vs. NCI Best Practices for Biorepositories for how the two leading biobanking best-practice frameworks treat consent and access alongside operational quality.
Frequently asked questions
What is the main difference between broad consent and dynamic consent?
Broad consent is a single decision made once, at enrollment, covering a general category of future research. Dynamic consent replaces that single decision with an ongoing relationship — participants can view current and proposed uses and change their permissions at any time through a digital interface, rather than being locked into an enrollment-time choice.
What is tiered consent in biobanking?
Tiered (or layered) consent lets a donor select from a structured menu of permitted-use categories at enrollment — for example, specific disease areas, commercial versus non-commercial use, or domestic versus international data sharing — rather than giving one broad yes/no to future research generally.
Does GDPR require biobanks to use dynamic consent?
No. GDPR Recital 33 explicitly allows broad consent to areas of scientific research, and does not name or require dynamic consent. Some EU-based biobanks adopt dynamic or tiered consent anyway because it gives participants a more concrete way to exercise the ongoing rights GDPR grants (including easy withdrawal), but this is an implementation choice, not a GDPR mandate.
Does ISO 20387 specify which consent model a biobank must use?
No. ISO 20387:2018 requires a documented consent and ethics process, full specimen traceability, and the ability to act on a withdrawal, but it does not mandate broad, tiered, or dynamic consent specifically — any of the three (or another model) can satisfy the standard if the biobank’s quality management system and traceability actually support it.
Can a biobank use more than one consent model at the same time?
Yes, and it is common in practice. A biobank with specimens collected across different programs or time periods will often hold specimens under different consent models simultaneously — for example, a legacy collection under broad consent alongside a newer cohort recruited under dynamic consent — provided each specimen’s actual consent scope remains correctly tracked and enforced.







