Collecting Consent Under The GDPR

Ian Aldridge WebsiteAuthor: Ian Aldridge, Progressive Legal

collecting consent

One of the biggest changes introduced as a result of the GDPR is the way businesses collect consent from data subjects.

Given that consent is often the most relied upon categories of ‘lawfulness of processing’, it is important that consent is collected in a manner that demonstrates compliance with the GDPR.

Need help with the GDPR?

Contact Progressive Legal for expert privacy advice.

How to collect consent from a data subject under the GDPR

Article 7 of the GDPR provides some useful guidance on conditions for consent.

Record-keeping

Firstly, where processing is based on consent, the data controller must be able to demonstrate that the data subject has consented to processing of his or her personal data. This means that controllers must keep records of consent from data subjects.

Clear and Distinguishable

It’s important that a request for consent be presented in an “intelligible and easily accessible form, using clear and plain language”, and must be presented in a manner which is clearly distinguishable from other matters. This means that consent must not be “bundled” or “pre-ticked” but should be offered as an “opt-in” and where necessary, separated from other matters.

Right to Withdraw Consent

Data subjects must have the right to withdraw their consent at any time and must be informed that they have the right to withdraw their consent at the time of giving consent. It must be as easy to withdraw as to give consent.

Freely Given

It’s critical that consent be ‘freely given’ by the data subject. In determining whether consent is freely given, utmost account must be taken of, inter alia, whether the consent is conditional on the performance of a contract, including the provision of a service, and where the processing of that personal data is not necessary for the performance of that contract.

This means that you should ensure that you are not collecting unnecessary personal data from a data subject as a condition of them entering into a contract, for example, a contract for the supply of goods.

Key takeaways

The GDPR’s approach to consent collection underscore the importance of compliance through meticulous record-keeping, clarity, and the voluntariness of consent. Businesses must ensure that consent requests are intelligible, easily accessible, and distinguishable from other matters, avoiding pre-ticked boxes to favour explicit opt-in mechanisms.

We charge $700 +GST for a tailored GDPR compliant privacy policy. Get in touch with us below to request your privacy policy today.

Need help with the GDPR?

Contact us by giving us a call on 1800 820 083 or request our advice today.  

Popular Privacy Links

Contact Us

  • By submitting this form, your information will be dealt with in accordance with our Privacy Policy. You agree to receive emails from us, however you can unsubscribe at any stage.

Need Privacy Help?

Please get in touch with us today via phone or the contact form on this page.

Contact Us

  • By submitting this form, your information will be dealt with in accordance with our Privacy Policy. You agree to receive emails from us, however you can unsubscribe at any stage.