{"id":5915,"date":"2019-01-15T11:35:16","date_gmt":"2019-01-15T10:35:16","guid":{"rendered":"https:\/\/vps-6634360a.vps.ovh.net\/consentement\/"},"modified":"2022-06-09T12:08:24","modified_gmt":"2022-06-09T10:08:24","slug":"consent","status":"publish","type":"page","link":"https:\/\/design.cnil.fr\/en\/concepts\/consent\/","title":{"rendered":"Consent"},"content":{"rendered":"\n<div class=\"alignfull header color\">\n<p class=\"p1\"><span class=\"s1\">Consent should be given by a <strong>clear voluntary act<\/strong> whereby the data subject shows their agreement in a <strong>free, specific, informed and unambiguous way<\/strong> to the processing of their personal data.<\/span><\/p>\n<\/div>\n\n\n\n<div class=\"wrapper principles\">\n  <div class=\"sidebar principles\">\n    <div class=\"theiaStickySidebar\">\n      <div class=\"box\">\n       <div class=\"box-content\">\n\n\n\n<h3 class=\"wp-block-heading\">Summary<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"#why\">Why is consent important?<\/a><\/li><li><a href=\"#free\">Freely given<\/a><\/li><li><a href=\"#specific\">Specific<\/a><\/li><li><a href=\"#unambiguous\">Unambiguous<\/a><\/li><li><a href=\"#informed\">Informed<\/a> <\/li><li><a href=\"#more\">Find out more<\/a><\/li><\/ul>\n\n\n\n<\/div>\n  <\/div>\n\n\n\n<\/div>\n<\/div><div class=\"content examples\">\n    <div class=\"theiaStickySidebar\">\n      <div class=\"box\">\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why\"> Why is consent important? <\/h2>\n\n\n\n<p>Consent <strong>guarantees that data subjects have strong control over their data<\/strong>. Always associated with an obligation to inform, consent allows data subjects to<strong> understand what will be done with their data<\/strong>, to <strong>choose without restriction whether to accept its processing or not<\/strong> and to <strong>freely change their minds afterward<\/strong>. Consent is <strong>gathered prior to processing<\/strong> and <strong>can be withdrawn at any time without deteriorating the service<\/strong>.<\/p>\n\n\n\n<p><strong>Consent is one of the legal bases<\/strong> set out by the GDPR to authorise data processing. It is therefore one of the ways of making a processing lawful. To gather information in a valid way, <strong>four criteria must all be complied with<\/strong>: <strong>free<\/strong>, <strong>specific<\/strong>, <strong>informed<\/strong>, <strong>unambiguous<\/strong>. Compliance with these conditions therefore requires special attention.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"free\"><strong>Consent must be freely given<\/strong><\/h2>\n\n\n\n<p>Consent must not be forced or influenced: the data subject must be offered a <strong>real choice<\/strong>, without suffering negative consequences in the case of refusal. <strong>The data subject must be able to refuse<\/strong> the processing of their data that is not necessary for the operation of the service or product they want to use, <strong>without quality of use being negatively impacted<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><em>Example<\/em><\/h3>\n\n\n\n<p><em>In this example, the user has just completed a form to sign up to a service. The second stage involves the acceptance of the contract as well as use of his personal data for marketing purposes.<\/em><\/p>\n\n\n\n<div class=\"wp-block-columns has-2-columns block-ex-1col is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\"> Focus of attention  (animated example)  <\/h3>\n\n\n\n<div class=\"wp-block-image width576\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"576\" height=\"483\" src=\"https:\/\/design.cnil.fr\/wp-content\/uploads\/2019\/06\/2019-06-19-Concepts-Consent-Dont.gif\" alt=\"Consent - Consent - Attention\" class=\"wp-image-5888\"\/><figcaption><em>In this proposal, <strong>the \u201cContinue\u201d button remains grey and is not clickable as long as the user has not ticked all the boxes<\/strong>. The user has to \u201caccept\u201d all the uses of his personal data for marketing purposes whereas it is not necessary for the service to properly operate. <strong>His consent is therefore not free<\/strong><\/em>.<\/figcaption><\/figure><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\"> Possible approach (animated example) <\/h3>\n\n\n\n<div class=\"wp-block-image width576\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"576\" height=\"483\" src=\"https:\/\/design.cnil.fr\/wp-content\/uploads\/2019\/06\/2019-06-19-Concepts-Consent-Do.gif\" alt=\"Consent - Consent - Possible Approach\" class=\"wp-image-5886\"\/><figcaption><em>In this proposal, <strong>as soon as the user ticks the box corresponding to his contract, the \u201cContinue\u201d button is enabled and becomes clickable<\/strong>. The user can choose not to consent to the processing of his personal data for marketing purposes to use the service. <strong>His consent to the use of their data for marketing purposes is therefore not forced<\/strong>.<\/em><\/figcaption><\/figure><\/div>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"specific\"><strong>Consent must be given specifically<\/strong><\/h2>\n\n\n\n<p><strong>Consent must be given for a determined purpose<\/strong>. If data are used for several uses, the data subject must be able to specifically give their consent for each purpose.  &nbsp; <\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><em>Example<\/em><\/h3>\n\n\n\n<p><em>In this example, the user enters contact and payment information to buy tickets for a concert. To move to the purchasing stage by clicking on the ticket purchase button, the user is asked if he wants to save his information for easier future purchases.<\/em><\/p>\n\n\n\n<div class=\"wp-block-columns has-2-columns block-ex-1col is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\"> Focus of attention<\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"576\" height=\"541\" src=\"https:\/\/design.cnil.fr\/wp-content\/uploads\/2019\/06\/2019-06-19-Concepts-Consent-Dont-1.gif\" alt=\"Consent - Specific - Attention\" class=\"wp-image-5892\"\/><figcaption><em>In this proposal, <strong>as soon as the user ticks the box, he accepts the collection of his data for two different purposes<\/strong>: marketing for the email address and easier future payments for the credit card. One single consent action here allows acceptance of the two different uses of personal data. <strong>Consent is therefore not specific<\/strong> as it covers two different purposes.<\/em><\/figcaption><\/figure><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\">Possible approach (animated example) <\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"576\" height=\"541\" src=\"https:\/\/design.cnil.fr\/wp-content\/uploads\/2019\/06\/2019-06-19-Concepts-Consent-Do-1.gif\" alt=\"Consent - Specific - Possible Approach\" class=\"wp-image-5890\"\/><figcaption><em>In this proposal, <strong>the user can choose between ticking two different boxes, each corresponding to one purpose<\/strong>. He can thus accept the use of his email address for marketing purposes or the saving of his credit card details for easier future payments, or both. <strong>His consent is specific to each purpose<\/strong>.<\/em><\/figcaption><\/figure><\/div>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"unambiguous\"><strong>Consent must be unambiguous<\/strong><\/h2>\n\n\n\n<p><strong>Consent requires a declaration or any other clear positive action<\/strong> from the data subject. She needs to <strong>take voluntary and active action to give her consent<\/strong> which demonstrates that she has really consented to the processing.<\/p>\n\n\n\n<p>Consent is therefore <strong>not unambiguous<\/strong> <strong>in the presence of pre-ticked or pre-enabled boxes or an inaction<\/strong> (e.g. the absence of reply to an email requesting consent).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><em>Example<\/em><\/h3>\n\n\n\n<p><em>In this example, the user registers for a personal assistant service through a related chatbot. At the end of the registration, the chatbot proposes to regularly send marketing emails to the email address communicated by the user.&nbsp; <\/em><\/p>\n\n\n\n<div class=\"wp-block-columns has-2-columns block-ex-2col is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\"> Focus of attention<\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"375\" height=\"812\" src=\"https:\/\/design.cnil.fr\/wp-content\/uploads\/2019\/06\/2019-06-19-Concepts-Consent-Dont-2.gif\" alt=\"Consent - Unambiguous - Attention\" class=\"wp-image-5894\"\/><figcaption><em><strong>The user does not reply to the chatbot\u2019s request<\/strong>. However, the chatbot once more contacts the data subject and tells her that she will receive commercial prospection in her inbox. <strong>Her consent is therefore not unambiguous as she has performed no action to accept the use of her email address<\/strong>.<\/em><\/figcaption><\/figure><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<h3 class=\"wp-block-heading\"> Possible approach (animated example)<\/h3>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"375\" height=\"812\" src=\"https:\/\/design.cnil.fr\/wp-content\/uploads\/2019\/06\/2019-06-19-Concepts-Consent-Do-Minimised.gif\" alt=\"Consent - Unambiguous - Possible Approach\" class=\"wp-image-5896\"\/><figcaption><em>Here,<strong> the user accepts the use of her email address for marketing purposes by clicking on the \u201cyes\u201d button<\/strong>. Consent is here validly collected as <strong>the data subject has clearly signified<\/strong>, by acting in the interface, that she wanted to receive marketing emails.<\/em><\/figcaption><\/figure><\/div>\n\n\n\n<p><\/p>\n<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"informed\"><strong>Consent must be informed<\/strong><\/h2>\n\n\n\n<p>Providing <strong>information <\/strong>to the data subjects before obtaining their consent is necessary to allow them to take decisions with full knowledge of the facts, to understand what they are consenting to and to <strong>know how to withdraw their consent<\/strong>. If the controller does not provide accessible information, the user\u2019s control over her data may be insufficient. <\/p>\n\n\n\n<p>The user must in particular know who is providing the service (data controller), the purposes of processing, the categories of collected data, the right to withdraw consent, etc. <\/p>\n\n\n\n<p>To learn more about how to transfer information to the user, consult the page on <a href=\"https:\/\/design.cnil.fr\/en\/information\/\">how to inform data subjects<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"more\">Find out more <\/h2>\n\n\n\n<p>If you want to find out more about consent, you can consult the links below: <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"link-baselegale\">Legal Basis <em><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679&amp;from=EN#d1e1888-1-1\">GDPR<\/a><\/em><\/h3>\n\n\n\n<p>Article 6 of the GDPR bearing on the \u201clawfulness of processing\u201d presents the six legal bases possible on which data processing should be based to be lawful.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(fr) How to gather data subjects\u2019 consent <a href=\"https:\/\/www.cnil.fr\/fr\/conformite-rgpd-comment-recueillir-le-consentement-des-personnes\"><em>cnil.fr<\/em><\/a><\/h3>\n\n\n\n<p>A point-by-point explanation of the meaning of the notion of consent and information to be taken into consideration to ensure its validity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">(fr) Marketing by electronic means <a href=\"https:\/\/www.cnil.fr\/fr\/la-prospection-commerciale-par-courrier-electronique\"><em>cnil.fr<\/em><\/a><\/h3>\n\n\n\n<p>An explanation of the conditions and principles of setting up consent in a marketing context (B-to-C and B-to-B).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Guidelines on consent <a href=\"https:\/\/ec.europa.eu\/newsroom\/article29\/document.cfm?action=display&amp;doc_id=51030\">pdf<\/a><\/h3>\n\n\n\n<p>Produced by the EDPB, this comprehensive document explains the concept of consent with a set of examples.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Explicit consent <a href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/consent\/what-is-valid-consent\/#what5\"><em>ico.org.uk<\/em><\/a><br><\/h3>\n\n\n\n<p> <em>[consulted the 20 May 2019] <\/em> An explanation of the concept of explicit consent by the ICO and illustrated by an example. This characteristic of consent is required in special cases, linked to the type of data processed or type of processing set up.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Consent should be given by a clear voluntary act whereby the data subject shows their agreement in a free, specific, informed and unambiguous way to the processing of their personal data. Summary Why is consent important? Freely given Specific Unambiguous Informed Find out more Why is consent important? Consent guarantees that data subjects have strong &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/design.cnil.fr\/en\/concepts\/consent\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Consent&#8221;<\/span><\/a><\/p>\n","protected":false},"author":7,"featured_media":0,"parent":5954,"menu_order":16,"comment_status":"closed","ping_status":"closed","template":"template-parts\/page-principles-subpage.php","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-5915","page","type-page","status-publish","hentry","entry"],"_links":{"self":[{"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/pages\/5915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/comments?post=5915"}],"version-history":[{"count":18,"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/pages\/5915\/revisions"}],"predecessor-version":[{"id":6781,"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/pages\/5915\/revisions\/6781"}],"up":[{"embeddable":true,"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/pages\/5954"}],"wp:attachment":[{"href":"https:\/\/design.cnil.fr\/en\/wp-json\/wp\/v2\/media?parent=5915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}