Short Reads

Countdown 5 weeks until GDPR : How should valid consent be proven?

Stibbe - How should valid consent be proven?

Countdown 5 weeks until GDPR : How should valid consent be proven?

19.04.2018 EU law

Only 5 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

How should valid consent be proven?

Article 7 of the GDPR reads: “the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data”. However, the GDPR does not contain specific, compulsory provisions in relation to the conditions for proving how the consent was given or obtained.

In that respect, the GDPR is inconsistent with the provisions of certain previous national legislations implementing Directive 95/46/EC (such as, e.g., the Italian Legislative Decree no. 196 of June 30, 2003, whereby the data subject’s consent could be deemed to be effective only if it is “documented in writing”).  

As a consequence, data controllers have the right to demonstrate how the valid consent was obtained by using any means allowed under their legal systems. In that respect, the use of any means for keeping a record of the data subjects’ consent - such as, for example, written statements, also statements stored by electronic means, or tick boxes to be set on internet websites specifically addressing the consent to be sought for the envisaged data processing activities - could be recommended.

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

16.01.2020 BE law
24 January 2020: Carol Evrard participates in a panel session on Global Compliance at the CPDP conference in Brussels

Speaking slot - Stibbe is a long standing partner of the International Computers, Privacy and Data Protection Conference (CPDP) which takes place in Brussels between 22 and 24 January 2020 This year's theme is “Data protection and Artificial intelligence”. Carol Evrard, associate in our TMT team, participates in a panel organised by TrustArc (a privacy compliance technology company based in San Francisco, California) on "Changing Technology and Laws: Can Accountability be a Key to Global Compliance?"

Read more

15.01.2020 NL law
Consultatiereactie 'Wet plan van aanpak witwassen'

Short Reads - Soeradj Ramsanjhal, Karlijn van den Heuvel, Djoe Kuils, Rogier Raas, Judica Krikke en Muriël Rosing hebben een reactie ingediend op het concept wetsvoorstel ‘Wet plan van aanpak witwassen’. Dit wetsvoorstel is 2 december 2019 in consultatie gegaan en bevat verschillende voorgestelde wijzigingen van de Wet ter voorkoming van witwassen en financieren van terrorisme en de Wet op de economische delicten. 

Read more

This website uses cookies. Some of these cookies are essential for the technical functioning of our website and you cannot disable these cookies if you want to read our website. We also use functional cookies to ensure the website functions properly and analytical cookies to personalise content and to analyse our traffic. You can either accept or refuse these functional and analytical cookies.

Privacy – en cookieverklaring