GDPR – what consent is required?
The Information Commissioner’s Office has posted some useful guidance on the consent that will be required under the General Data Protection Regulations for the use of personal data for marketing purposes:
- Consent requires a positive opt-in. Don’t use pre-ticked boxes or any other method of consent by default.
- Keep your consent requests separate from other terms and conditions.
- Be specific and granular. Vague or blanket consent is not enough.
- Be clear and concise.
- Name any third parties who will rely on the consent.
- Make it easy for people to withdraw consent and tell them how.
- Keep evidence of consent – who, when, how, and what you told people.
They advise us all to start getting ready for the changes that will become law in May 2018.
This update is for general purposes and guidance only and does not constitute legal or professional advice. You should seek legal advice before relying on its content. This update relates to the prevailing circumstances at the date of its original publication and may not have been updated to reflect subsequent developments. If you have general queries about our updates, please email: firstname.lastname@example.org