how has consent changed under the gdpr?
the gdpr does not fundamentally alter the principles of consent regarding the processing (eg storing) of personal data (eg names and addresses). however, it sets a higher bar for valid consent, emphasising the importance of explicit opt-in which is freely given and the right to withdraw consent at any time. it has also narrowed the legal justification for processing personal data without consent, making valid consent even more crucial.
when is consent necessary?
consent is not always needed to process personal data; there are 5 other lawful bases:
-
contract - if there is a contract with the individual (eg business or employment) that necessitates data processing
-
compliance with legal obligation - if it's legally necessary to process the data
-
vital interests - if data needs to be processed to protect the life of the data subject (who is incapable of providing consent) or someone else
-
public tasks - if the processing is necessary to perform an official task (ie by a public authority)
-
legitimate interests - this requires balancing the 'legitimate interests' of the data controller (ie the oraganisation that on the purposes for and means of processing personal data) against the interests and fundamental rights of the data subject using a legitimate interest assessment
in the absence of meeting one of these other lawful bases, it is necessary to gain explicit consent of the data subject before processing their personal data.
for more information about the other grounds for processing personal data, read processing personal data.
what constitutes valid consent?
there are certain conditions that must be met to ensure that consent is valid:
-
freely given - an individual must be given a genuine choice when providing consent and it should generally be unbundled from other terms and conditions (eg access to a service should not be conditional upon consent being given)
-
specific and informed - this means that data subjects should be provided with information as to the identity of the controller(s), the specific purposes, types of processing, as well as being informed of their right to withdraw consent at any time
-
explicit and unambiguous - the data subject must clearly express their consent (eg by actively ticking a box which confirms they are giving consent - pre-ticked boxes are insufficient)
-
under 13s - children under the age of 13 cannot provide consent and it is, therefore, necessary to obtain consent from their parents
for more information, see the guidance on valid consent provided by the information commissioner’s office (ico).
how should records on consent be managed?
businesses should record each instance of consent provided and manage these records appropriately. the following should be recorded:
-
the identity of the data subject providing their consent
-
the time and date of consent being given
-
the method of consent (eg whether this was given online or in-person)
-
the information provided to the data subject (eg privacy policy and data capture form)
consent should be reviewed at regular intervals to determine whether it is still sufficient for the current purposes of data processing. it is also important to provide individuals with a straightforward method of withdrawing their consent at any time - and records should be updated to reflect any withdrawal of consent.
can i contact previous customers to ask for consent?
as a general rule, if consent to data processing had been properly obtained prior to the gdpr coming into force (ie it had met the standard required under the gdpr) or was not necessary due to a legitimate interest (eg they were an existing customer) there is no need to obtain consent (again). if consent had been obtained in a way that was not compatible with the gdpr (eg with the use of pre-filled tick boxes) then it would be necessary to regain consent. however, if a customer had opted out of email communication, then the act of contacting them to regain consent will potentially contravene the privacy and electronic communications (ec directive) regulations 2003 (pecr).
it is a good idea to familiarise yourself with the laws on marketing and customer communications before contacting customers. for more information, read marketing and the law and considerations for email marketing.
for more information on consent under the gdpr, see the ico website. if you have any questions or concerns about data protection and data processing, do not hesitate to ask a lawyer or use our gdpr compliance service.
for more information on the gdpr and data protection in general, read complying with the gdpr, data protection, processing personal data, general data protection regulation (gdpr) faqs and how to make a business gdpr-compliant checklist.