Consent
Consent, according to the GDPR, is one of the six legal bases that authorize the processing of personal data.
For consent to be valid, it must meet several requirements established by Articles 4 and 7 of the GDPR. Consent must be given freely, meaning without coercion; be specific, referring to one or more defined purposes; be informed, ensuring that the data subject clearly understands how their data will be used; and be unambiguous, involving a clear affirmative action by the data subject, such as signing a form or ticking a checkbox.
Article 7 of the GDPR sets the conditions for consent, highlighting that:
- The data controller must be able to demonstrate that the data subject has given their consent.
- If consent is given alongside other declarations, it must be presented in a way that is clearly distinguishable, using simple and clear language.
- The data subject has the right to withdraw their consent at any time, and withdrawal must be as easy as giving consent.
- When assessing whether consent is freely given, it is essential to consider whether the performance of a contract has been made conditional on consent for processing that is not necessary for the execution of that contract.
Consent cannot be presumed or implied; it must always result from an active action by the data subject. Furthermore, the data subject has the right to withdraw their consent at any time, and the data controller is obligated to ensure that withdrawal is as easy to exercise as the initial consent. For these reasons, consent is considered valid only if the accountability principle is adhered to, meaning the data controller must be able to demonstrate at any time that consent has been correctly obtained and documented.
Trust Guardian’s Approach to Consent
Trust Guardian allows companies to collect, manage, and record consents in a compliant and transparent manner. Trust Guardian ensures the traceability of consent throughout the data processing lifecycle, including the possibility of withdrawal, providing companies with a centralized tool to manage consents for each data subject and storing the complete privacy history (i.e., the entire consent and withdrawal timeline) along with all the Proofs of Genuineness needed to demonstrate compliance by the data controller.
Legal, ICT, marketing: comprendiamo le tue necessità
Vogliamo sollevarti dai grattacapi nella gestione di consensi e privacy dei clienti.