Author: Ian Aldridge, Progressive Legal
Author: Ian Aldridge, Progressive Legal
One of the biggest changes introduced as a result of the GDPR is the way businesses collect consent from data subjects.
Given that consent is often the most relied upon categories of ‘lawfulness of processing’, it is important that consent is collected in a manner that demonstrates compliance with the GDPR.
Article 7 of the GDPR provides some useful guidance on conditions for consent.
Firstly, where processing is based on consent, the data controller must be able to demonstrate that the data subject has consented to processing of his or her personal data. This means that controllers must keep records of consent from data subjects.
It’s important that a request for consent be presented in an “intelligible and easily accessible form, using clear and plain language”, and must be presented in a manner which is clearly distinguishable from other matters. This means that consent must not be “bundled” or “pre-ticked” but should be offered as an “opt-in” and where necessary, separated from other matters.
Data subjects must have the right to withdraw their consent at any time and must be informed that they have the right to withdraw their consent at the time of giving consent. It must be as easy to withdraw as to give consent.
It’s critical that consent be ‘freely given’ by the data subject. In determining whether consent is freely given, utmost account must be taken of, inter alia, whether the consent is conditional on the performance of a contract, including the provision of a service, and where the processing of that personal data is not necessary for the performance of that contract.
This means that you should ensure that you are not collecting unnecessary personal data from a data subject as a condition of them entering into a contract, for example, a contract for the supply of goods.
The GDPR’s approach to consent collection underscore the importance of compliance through meticulous record-keeping, clarity, and the voluntariness of consent. Businesses must ensure that consent requests are intelligible, easily accessible, and distinguishable from other matters, avoiding pre-ticked boxes to favour explicit opt-in mechanisms.
We charge $700 +GST for a tailored GDPR compliant privacy policy. Get in touch with us below to request your privacy policy today.
Contact us by giving us a call on 1800 820 083 or request our advice today.
REQUEST OUR ADVICEPlease get in touch with us today via phone or the contact form on this page.