Chapter 7 Lawful processing criteria Flashcards
Which GDPR articles regulate lawful processing?
Article 6 and 9 (SCPD)
Article 7 - consent
Article 8 - offering of information society services to a child
Lawful bases under GDPR
consent
fulfilling a contractual obligation
complying with legal obligation
protecting DS’s vital interests
performing a task in the public interest
legitimate interests of the controller or third party when balanced against the rights and interests of a DS
Conditions for consent
Freely given
Specific
Informed
Unambiguous indication of wishes (by statement or clear affirmative action signifies agreement to the processing)
Whose responsibility is to demonstrate the DS has given consent?
Controller’s
Criteria if consent is pre-formulated by the controller
the C should be provided in an intelligible, easily accessible form, using clear and plain language, with no unfair terms
When is consent appropriate choice?
DS is offered control and genuine choice on the use of their PD
Explain “freely given consent”
genuine choice
able to refuse or withdraw
How must the request for consent be presented?
in a manner clearly distinguishable from other matters
When the consent is not freely given
when the performance of a contract is conditioned on consent for processing of PD and such processing is not necessary for the performance of the contract
In which situations the consent should not be relied upon?
where there is a clear imbalance between the DS and the controller (e.g. public authority, employment relationship)
What does it mean that the consent must be granular
separate consent mechanism must be provided for each purpose
Specific consent
must be given specifically for the particular processing operation in question - C must explain its proposed use of data, specific processing
multiple purposes - consent should be given for all of them
EDPB guidelines:
- purpose specification as a safeguard against function creep
- granularity in consent requests
- clear separation from information about other matters
What is informed consent
DS must be given all the necessary details of the processing activity in a language and form they can understand
The following information must be provided:
- identity of C
- purpose for each processing operation
- types of data
- automated decision making
- transfers to third countries (if the C is given for transfers) in the absence of the adequacy decision and appropriate safeguards
- right to withdraw
If more than one controller, all must be named. P don’t need to be named
Explain unambiguous indication of wishes
statement or clear affirmative act
there is no doubt of DS’s intention to give consent
in case of doubt it will be construed against the C
pre-ticked boxes not valid consent
must be obtained before the processing begins
consent is not the same as opt-out option (lack of action indicates lack of objection not consent)
Why does a C need to keep a record of consent
to be able to demonstrate that the DS has given consent to processing operation