Notice: La función _load_textdomain_just_in_time ha sido llamada de forma incorrecta. La carga de la traducción para el dominio lawgne se activó demasiado pronto. Esto suele ser un indicador de que algún código del plugin o tema se ejecuta demasiado pronto. Las traducciones deberían cargarse en la acción init o más tarde. Por favor, ve depuración en WordPress para más información. (Este mensaje fue añadido en la versión 6.7.0). in /home/kumpri/apps/aphaia-wp3/wp-includes/functions.php on line 6121
GDPR consent further explained by Article 29 Working Party

Blog details

GDPR consent explained by WP29

GDPR consent explained by WP29

GDPR consent requirements, one of the most difficult GDPR areas for businesses to comply with, have been further explained by Article 29 Working Party. This is our choice of highlights from the new GDPR Consent Guidelines.

GDPR consent data protection officer

Imbalance of power does not in all cases preclude valid GDPR consent

Although cases of consent by employee to employer are generally viewed with suspicion by WP29, EU’s top body for data protection clarifies some cases of such consent may be coercion-free. In some cases that do not essentially affect employment relations, employers may be able to offer meaningful, non-punitive alternatives to employees who do not give consent (e.g. alternative desk space of equal quality to people who refuse to consent to being shown on the camera).

Conditionality affecting GDPR consent

In order for GDPR consent to be valid, the provision of the service provided by the business should not be “conditional on consent to the processing of personal data that is not necessary for the performance of that contract”.  This does not fully exclude the possibility of obtaining a valid consent at the point of contracting. However, where consent is refused, the alternative service provided should be “genuinely equivalent” including in terms of “no further costs”.

Layout of a valid GDPR consent

GDPR consent rule prohibits hiding consent in other ‘Terms and Conditions’. But this does not prohibit layered notices as such, especially if one considers ‘small screens’ or otherwise limited space to accommodate information.

Do you require assistance preparing for GDPR and manage your data protection obligations once GDPR becomes applicable? Aphaia provides both GDPR adaptation consultancy services and Data Protection Officer outsourcing.

Prev post
Our client Salve on their fertility app – and health data privacy
noviembre 30, 2017
Next post
WP29 Guidelines on adequacy of data protection by third countries
enero 5, 2018

Leave a Comment