What makes consent legal?

What makes consent legal?

In order for consent to be legal it must be: 
  1. informed consent that is data subject must know what they are consenting to.
  2. It must be freely-given in that there must not be an imbalance in relationship between the data subject and the controller.
  3. and it must be specific in that it must describe precisely what the data subject has consented to in the information notice,
The controller cannot request open-ended or blanket consent to cover the possibility of future processing. 
Interpretation of what this means to your organisation is not always easy. For example  consent  must be lawful which means, for example, it must be  informed  and  freely-given.   In order for it to be  freely-given  there must not be an imbalance of power between the controller (i.e. your organisation) and the data subject (e.g. an employee). 

    • Related Articles

    • What is consent?

      Making GDPR compliance easy with Privasee · Consent Types In order for consent to be legal it either needs to be unambiguous consent or explicit consent.  Unambiguous consent is defined in the GDPR as similar to implicit consent but strengthened by a ...
    • What is a legal basis?

      Making GDPR compliance easy with Privasee · When is processing legal? There are 6 ways to process personal data as stipulated in the GDPR in Article 6. Article 6 of the GDPR states that if the collection and/or usage of personal data is not following ...
    • What does having a legal obligation mean?

      Making GDPR compliance easy with Privasee · Article 6c, legal obligation Article 6c, legal obligation. Processing is necessary for compliance with a legal obligation to which the controller is subject. Now, let's take this book you purchased on the ...
    • How do I create a GDPR compliant Cookie Consent Banner?

      According to the GDPR, users must allow website-visitors the ability to change their cookie preferences at any time. The visitor should have the choice on which non-essential cookies are used during the visit. The default should be that the visitor ...
    • There is a vital interest for the collection and processing

      Making GDPR compliance easy with Privasee · There is a vital interest for collection and processing Article 6d, vital interest. Processing is necessary in order to protect the vital interests of the data subject or of another natural person. This is ...