Short Reads

Countdown 6 weeks until GDPR: How freely given must the consent be under the GDPR?

Stibbe - How freely given must the consent be under the GDPR?

Countdown 6 weeks until GDPR: How freely given must the consent be under the GDPR?

12.04.2018 EU law

Only 6 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

How freely given, specific, informed, and unambiguous must the consent be under the GDPR?

The GDPR qualifies the data subject’s consent as consent that is freely given, specific, informed, and unambiguous. These requirements are substantial elements of a valid consent under the GDPR, which is necessary for the related personal data processing to be lawful. An effective and actual consent to personal data processing by the data subject is, in fact, a core principle of the GDPR.

In light of the above, it is worth clarifying that consent is considered:

a)        freely given if the data subject is (i) actually aware of the elements based on which they give their consent to the data processing; (ii) not conditioned by external circumstantial influences; and (iii) aware of his or her right to withdraw the consent at any time;

b)        specific if the data subject explicitly gives his or her consent to each separate data processing activity envisaged by the data controller;

c)         informed if the data subject - before giving his or her consent - is informed through an intelligible and easily accessible form about the data processing activities envisaged by the data controller; and

d)        unambiguous if there is an objective certainty both regarding the actual existence of the data subject’s consent and the contents of that consent, meaning that the consent must be given through a clear, affirmative act of the data subject (i.e., an ex silentio consent is not a clear, affirmative act, hence not acceptable).

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

02.07.2019 NL law
Debate night: HR Analytics: opportunity or threat?

Seminar - On 2 July 2019, Stibbe's Digital Economy Group will host a debate night in Amsterdam on the hot topic of HR analytics. During Stibbe's debate night, speakers from the world of business, politics, science and law will exchange views on HR analytics, how they can be used in practice, and their development in the context of employment and privacy law.

Read more

15.07.2019 EU law
ICO to impose record-breaking fines for inadequate security measures and data breaches

Short Reads - Though the European data protection authorities have taken their time in enforcing the GDPR, two announcements by the ICO in the UK regarding proposed fines for British Airways and Marriott demonstrate that large fines are about to start landing regularly. Both of the substantial fines are to be handed out as a result of shortcomings in handling data breaches caused by cyber-attacks.

Read more

27.06.2019 NL law
Stibbe launches website about Digital Economy

Inside Stibbe - Stibbe's Digital Economy group published a new website this week: Stibbedigital.com With this new website we aim to view technological developments including artificial intelligence (AI), blockchain, the Internet of Things, smart mobility and the rise of digital platforms from a legal perspective.

Read more

05.07.2019 EU law
The two sides of the ECS coin

Articles - The concept of ‘electronic communications service’ (“ECS”) defined in Article 2(c) of Directive 2002/21/EC (“Framework Directive”) has been interpreted in two decisions of the ECJ in June 2019: C‑142/18 Skype communications and C-193/18 Google LLC.

Read more

21.06.2019 NL law
Nieuw boetebeleid van de Autoriteit Persoonsgegevens

Short Reads - Op 14 maart 2019 zijn de nieuwe Boetebeleidsregels Autoriteit Persoonsgegevens 2019 ("Boetebeleidsregels") van de Autoriteit Persoonsgegevens ("AP") gepubliceerd. Dit boetebeleid heeft de AP opgesteld vanwege de inwerkingtreding van de Algemene verordening gegevensverwerking ("AVG") en omdat er op Europees niveau nog geen boeterichtsnoeren zijn opgesteld.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring