SlideShare a Scribd company logo
1 of 46
Download to read offline
Consent Under the GDPR
Under the GDPR, consent is one of the acceptable
legal bases for collecting and processing personal
data from residents of the EU.
Here’s what the GDPR requires when it comes to
consent.
The GDPR defines consent as follows:
Let’s break down this definition into 4 different
requirements for consent.
Freely given1
For consent to be freely given, users must be given
a choice on whether to provide personal data or
not.
You can no longer count simply using a website as
giving consent.
Specific2
You must get specific consent for each different
use of personal data.
If you want to use personal data for marketing and
for analytics, you must get consent for each.
Informed and unambiguous3
Inform your users what information you’re requesting
and how it will be used.
Then, make sure your request for consent is simple
and straightforward.
Clear affirmative action4
Make your users take a clear affirmative action to
show they consent, such as ticking a checkbox or
clicking a clearly-labeled button.
Article 7 of the GDPR includes 4 conditions for consent:
Here’s what each section of this article sets forth:
Keep a record of each instance of consent you obtain
from EU residents and be able to provide proof.1
If you are currently unable to do so, you may need
to do a re-permission campaign.
This is when you send an email to all currently-sub-
scribed users asking them to actively re-opt-in to
establish proof of consent.
If consent is given within a page or interface that
contains a number of elements (such as a registration
form), the request for consent should be separate and
easily distinguishable from other subject matter using
clear and plain language.
2
Note how these consent checkboxes stand out
with placement and uppercase font.
Always provide a way for users to revoke consent.3
Revoking consent should be as easy as giving it.
Consent will not be considered as “freely given” if the
consumer is required to provide information that is not
necessary to complete a service.
4
Don’t collect any information that you do not need
in order to provide your services.
So, how exactly should you go about obtaining consent
from EU residents to be compliant with the GDPR?
Make sure you do not use browsewrap to get consent.
Browsewrap -- a common and widespread method for
getting consent -- is not valid under the GDPR.
Browsewrap is when you include a statement in
your Privacy Policy or Terms and Conditions that
says something like, “By using this website, you’re
consenting to the collection and use of your
personal information.”
Here’s an example of browsewrap in action in an
old Privacy Policy from Novartis:
With this method, most users won’t have any idea
that they’ve consented to anything just by using a
website.
It doesn’t inform users, and doesn’t give web-
site/app owners documentable consent.
Note that after the GDPR took effect, Novartis updated its
Privacy Policy to remove this language:
In contrast to browsewrap is clickwrap, which is the best
way to get clear, affirmative consent.
Clickwrap is when a user must actively click or do some
affirmative action to show they agree or consent.
In this example, users are tapping “I Agree,” and a short
explanation makes it clear what they’re agreeing to by
doing so.
Clickwrap helps keep users informed as to exactly what
they’re agreeing and consenting to.
It also helps website/app owners obtain recordable
agreement/consent from users.
So, what should your consent requests look like?
First, remember what they should not look like.
Don’t use browsewrap statements in your legal agreements
and assume that’s good enough. It isn’t.
Don’t use pre-checked boxes when getting consent.
Boxes must be left empty so a user is only opting in or
agreeing if he takes an affirmative action to check the
box.
Now let’s look at a few Do’s for getting
GDPR-compliant consent.
Consent for your Privacy Policy and other legal agreements
Before you collect any personal information -- typically
at the time of account registration or sign-up -- present
users with links to your legal agreements and a clear
way for them to agree to them.
Here’s how PayPal does this with
agreement links, a short statement
and a checkbox.
Consent for Collection of Personal Information via Cookies
If you place cookies that collect personal information,
you need to get consent for this.
Do this in a banner or pop-up notification that:
Identifies what types of cookies you use, what
information they collect and why
Lets users access additional information
(Privacy/Cookies Policy, Cookie Settings, etc.)
Gets clear, affirmative consent to place these
cookies
Note that you don’t have to get consent to place
functionality and other non-personally-identifying
cookies, but you still need to disclose their use.
Consent for your Marketing Communications
It is a common practice for businesses to say that by
signing up for an account, you’re agreeing to receive
marketing communications from them.
However, under the GDPR, this is not acceptable.
You must get clear and affirmative consent to send marketing
communications.
Offer granular options if you have multiple communications or
marketing methods.
Remember:
Consent is one of the legal bases for collecting
personal information under the GDPR.
It must be freely given, specific, informed and
unambiguous, with a clear affirmative action.
Browsewrap is out. Go with clickwrap.
No pre-checked boxes.
Remember:
Keep records of consent.
Get consent before collecting any personal
information.
Get consent before placing any cookies that
collect personal information.
Allow consent to be easily withdrawn.
Consent Under the GDPR

More Related Content

More from termsfeed

FTC Disclosures
FTC DisclosuresFTC Disclosures
FTC Disclosurestermsfeed
 
Australia Privacy Act of 1988
Australia Privacy Act of 1988Australia Privacy Act of 1988
Australia Privacy Act of 1988termsfeed
 
The Digital Millennium Copyright Act
The Digital Millennium Copyright ActThe Digital Millennium Copyright Act
The Digital Millennium Copyright Acttermsfeed
 
Disclosures for Affiliate Links
Disclosures for Affiliate LinksDisclosures for Affiliate Links
Disclosures for Affiliate Linkstermsfeed
 
Disclaimer Examples
Disclaimer ExamplesDisclaimer Examples
Disclaimer Examplestermsfeed
 
How to Comply with CAN-SPAM
How to Comply with CAN-SPAMHow to Comply with CAN-SPAM
How to Comply with CAN-SPAMtermsfeed
 
Privacy Policy for Flurry
Privacy Policy for FlurryPrivacy Policy for Flurry
Privacy Policy for Flurrytermsfeed
 
Termination Clause in Terms and Conditions
Termination Clause in Terms and ConditionsTermination Clause in Terms and Conditions
Termination Clause in Terms and Conditionstermsfeed
 
Click to Accept: A Method of Clickwrap
Click to Accept: A Method of ClickwrapClick to Accept: A Method of Clickwrap
Click to Accept: A Method of Clickwraptermsfeed
 
Privacy Policy for Wistia
Privacy Policy for WistiaPrivacy Policy for Wistia
Privacy Policy for Wistiatermsfeed
 
The "Your California Privacy Rights" clause
The "Your California Privacy Rights" clauseThe "Your California Privacy Rights" clause
The "Your California Privacy Rights" clausetermsfeed
 
Terms & Conditions Generator
Terms & Conditions GeneratorTerms & Conditions Generator
Terms & Conditions Generatortermsfeed
 
Terms & Conditions FAQ
Terms & Conditions FAQTerms & Conditions FAQ
Terms & Conditions FAQtermsfeed
 
Software License Agreements
Software License AgreementsSoftware License Agreements
Software License Agreementstermsfeed
 
Why use End-User License Agreement (EULA)
Why use End-User License Agreement (EULA)Why use End-User License Agreement (EULA)
Why use End-User License Agreement (EULA)termsfeed
 
Rules for Sweepstakes
Rules for SweepstakesRules for Sweepstakes
Rules for Sweepstakestermsfeed
 
Definition of a Cookies Policy
Definition of a Cookies PolicyDefinition of a Cookies Policy
Definition of a Cookies Policytermsfeed
 
What are Return & Refund Policies
What are Return & Refund PoliciesWhat are Return & Refund Policies
What are Return & Refund Policiestermsfeed
 
Terms & Conditions for mobile apps (iOS, Android, Windows)
Terms & Conditions for mobile apps (iOS, Android, Windows)Terms & Conditions for mobile apps (iOS, Android, Windows)
Terms & Conditions for mobile apps (iOS, Android, Windows)termsfeed
 
What's an Opt-Out Policy
What's an Opt-Out PolicyWhat's an Opt-Out Policy
What's an Opt-Out Policytermsfeed
 

More from termsfeed (20)

FTC Disclosures
FTC DisclosuresFTC Disclosures
FTC Disclosures
 
Australia Privacy Act of 1988
Australia Privacy Act of 1988Australia Privacy Act of 1988
Australia Privacy Act of 1988
 
The Digital Millennium Copyright Act
The Digital Millennium Copyright ActThe Digital Millennium Copyright Act
The Digital Millennium Copyright Act
 
Disclosures for Affiliate Links
Disclosures for Affiliate LinksDisclosures for Affiliate Links
Disclosures for Affiliate Links
 
Disclaimer Examples
Disclaimer ExamplesDisclaimer Examples
Disclaimer Examples
 
How to Comply with CAN-SPAM
How to Comply with CAN-SPAMHow to Comply with CAN-SPAM
How to Comply with CAN-SPAM
 
Privacy Policy for Flurry
Privacy Policy for FlurryPrivacy Policy for Flurry
Privacy Policy for Flurry
 
Termination Clause in Terms and Conditions
Termination Clause in Terms and ConditionsTermination Clause in Terms and Conditions
Termination Clause in Terms and Conditions
 
Click to Accept: A Method of Clickwrap
Click to Accept: A Method of ClickwrapClick to Accept: A Method of Clickwrap
Click to Accept: A Method of Clickwrap
 
Privacy Policy for Wistia
Privacy Policy for WistiaPrivacy Policy for Wistia
Privacy Policy for Wistia
 
The "Your California Privacy Rights" clause
The "Your California Privacy Rights" clauseThe "Your California Privacy Rights" clause
The "Your California Privacy Rights" clause
 
Terms & Conditions Generator
Terms & Conditions GeneratorTerms & Conditions Generator
Terms & Conditions Generator
 
Terms & Conditions FAQ
Terms & Conditions FAQTerms & Conditions FAQ
Terms & Conditions FAQ
 
Software License Agreements
Software License AgreementsSoftware License Agreements
Software License Agreements
 
Why use End-User License Agreement (EULA)
Why use End-User License Agreement (EULA)Why use End-User License Agreement (EULA)
Why use End-User License Agreement (EULA)
 
Rules for Sweepstakes
Rules for SweepstakesRules for Sweepstakes
Rules for Sweepstakes
 
Definition of a Cookies Policy
Definition of a Cookies PolicyDefinition of a Cookies Policy
Definition of a Cookies Policy
 
What are Return & Refund Policies
What are Return & Refund PoliciesWhat are Return & Refund Policies
What are Return & Refund Policies
 
Terms & Conditions for mobile apps (iOS, Android, Windows)
Terms & Conditions for mobile apps (iOS, Android, Windows)Terms & Conditions for mobile apps (iOS, Android, Windows)
Terms & Conditions for mobile apps (iOS, Android, Windows)
 
What's an Opt-Out Policy
What's an Opt-Out PolicyWhat's an Opt-Out Policy
What's an Opt-Out Policy
 

Recently uploaded

A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxPKrishna18
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxsrikarna235
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书E LSS
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaNafiaNazim
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书Sir Lt
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一jr6r07mb
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书Fir L
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书SD DS
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm2020000445musaib
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书SD DS
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书Fir L
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》o8wvnojp
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 

Recently uploaded (20)

A Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptxA Short-ppt on new gst laws in india.pptx
A Short-ppt on new gst laws in india.pptx
 
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptxConstitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
Constitutional Values & Fundamental Principles of the ConstitutionPPT.pptx
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书
 
Arbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in IndiaArbitration, mediation and conciliation in India
Arbitration, mediation and conciliation in India
 
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书 如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
如何办理(MSU文凭证书)密歇根州立大学毕业证学位证书
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
定制(WMU毕业证书)美国西密歇根大学毕业证成绩单原版一比一
 
如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书如何办理提赛德大学毕业证(本硕)Teesside学位证书
如何办理提赛德大学毕业证(本硕)Teesside学位证书
 
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
Russian Call Girls Service Gomti Nagar \ 9548273370 Indian Call Girls Service...
 
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
如何办理(Curtin毕业证书)科廷科技大学毕业证学位证书
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm
 
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
如何办理(uOttawa毕业证书)渥太华大学毕业证学位证书
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
Cleades Robinson's Commitment to Service
Cleades Robinson's Commitment to ServiceCleades Robinson's Commitment to Service
Cleades Robinson's Commitment to Service
 
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS LiveVip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
Vip Call Girls Greater Noida ➡️ Delhi ➡️ 9999965857 No Advance 24HRS Live
 
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in  Pusa Road🔝 9953330565 🔝 escort Serviceyoung Call Girls in  Pusa Road🔝 9953330565 🔝 escort Service
young Call Girls in Pusa Road🔝 9953330565 🔝 escort Service
 
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
如何办理美国加州大学欧文分校毕业证(本硕)UCI学位证书
 
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
国外大学毕业证《奥克兰大学毕业证办理成绩单GPA修改》
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 

Consent Under the GDPR

  • 2. Under the GDPR, consent is one of the acceptable legal bases for collecting and processing personal data from residents of the EU. Here’s what the GDPR requires when it comes to consent.
  • 3. The GDPR defines consent as follows:
  • 4. Let’s break down this definition into 4 different requirements for consent.
  • 5. Freely given1 For consent to be freely given, users must be given a choice on whether to provide personal data or not. You can no longer count simply using a website as giving consent.
  • 6. Specific2 You must get specific consent for each different use of personal data. If you want to use personal data for marketing and for analytics, you must get consent for each.
  • 7. Informed and unambiguous3 Inform your users what information you’re requesting and how it will be used. Then, make sure your request for consent is simple and straightforward.
  • 8. Clear affirmative action4 Make your users take a clear affirmative action to show they consent, such as ticking a checkbox or clicking a clearly-labeled button.
  • 9. Article 7 of the GDPR includes 4 conditions for consent:
  • 10. Here’s what each section of this article sets forth:
  • 11. Keep a record of each instance of consent you obtain from EU residents and be able to provide proof.1 If you are currently unable to do so, you may need to do a re-permission campaign. This is when you send an email to all currently-sub- scribed users asking them to actively re-opt-in to establish proof of consent.
  • 12.
  • 13. If consent is given within a page or interface that contains a number of elements (such as a registration form), the request for consent should be separate and easily distinguishable from other subject matter using clear and plain language. 2 Note how these consent checkboxes stand out with placement and uppercase font.
  • 14.
  • 15. Always provide a way for users to revoke consent.3 Revoking consent should be as easy as giving it.
  • 16.
  • 17. Consent will not be considered as “freely given” if the consumer is required to provide information that is not necessary to complete a service. 4 Don’t collect any information that you do not need in order to provide your services.
  • 18. So, how exactly should you go about obtaining consent from EU residents to be compliant with the GDPR?
  • 19. Make sure you do not use browsewrap to get consent. Browsewrap -- a common and widespread method for getting consent -- is not valid under the GDPR.
  • 20. Browsewrap is when you include a statement in your Privacy Policy or Terms and Conditions that says something like, “By using this website, you’re consenting to the collection and use of your personal information.” Here’s an example of browsewrap in action in an old Privacy Policy from Novartis:
  • 21.
  • 22. With this method, most users won’t have any idea that they’ve consented to anything just by using a website. It doesn’t inform users, and doesn’t give web- site/app owners documentable consent.
  • 23. Note that after the GDPR took effect, Novartis updated its Privacy Policy to remove this language:
  • 24. In contrast to browsewrap is clickwrap, which is the best way to get clear, affirmative consent. Clickwrap is when a user must actively click or do some affirmative action to show they agree or consent. In this example, users are tapping “I Agree,” and a short explanation makes it clear what they’re agreeing to by doing so.
  • 25.
  • 26. Clickwrap helps keep users informed as to exactly what they’re agreeing and consenting to. It also helps website/app owners obtain recordable agreement/consent from users.
  • 27. So, what should your consent requests look like?
  • 28. First, remember what they should not look like. Don’t use browsewrap statements in your legal agreements and assume that’s good enough. It isn’t.
  • 29.
  • 30. Don’t use pre-checked boxes when getting consent. Boxes must be left empty so a user is only opting in or agreeing if he takes an affirmative action to check the box.
  • 31.
  • 32. Now let’s look at a few Do’s for getting GDPR-compliant consent.
  • 33. Consent for your Privacy Policy and other legal agreements Before you collect any personal information -- typically at the time of account registration or sign-up -- present users with links to your legal agreements and a clear way for them to agree to them.
  • 34. Here’s how PayPal does this with agreement links, a short statement and a checkbox.
  • 35. Consent for Collection of Personal Information via Cookies If you place cookies that collect personal information, you need to get consent for this. Do this in a banner or pop-up notification that:
  • 36. Identifies what types of cookies you use, what information they collect and why Lets users access additional information (Privacy/Cookies Policy, Cookie Settings, etc.) Gets clear, affirmative consent to place these cookies
  • 37.
  • 38.
  • 39. Note that you don’t have to get consent to place functionality and other non-personally-identifying cookies, but you still need to disclose their use.
  • 40. Consent for your Marketing Communications It is a common practice for businesses to say that by signing up for an account, you’re agreeing to receive marketing communications from them. However, under the GDPR, this is not acceptable.
  • 41.
  • 42. You must get clear and affirmative consent to send marketing communications.
  • 43. Offer granular options if you have multiple communications or marketing methods.
  • 44. Remember: Consent is one of the legal bases for collecting personal information under the GDPR. It must be freely given, specific, informed and unambiguous, with a clear affirmative action. Browsewrap is out. Go with clickwrap. No pre-checked boxes.
  • 45. Remember: Keep records of consent. Get consent before collecting any personal information. Get consent before placing any cookies that collect personal information. Allow consent to be easily withdrawn.