Definition
Voluntary, specific, informed, unambiguous indication that a data subject agrees to processing of their personal data (GDPR Art. 4(11)). Must be granular, freely-given, easily withdrawable. Consent receipt provides proof. Foundation for lawful processing under GDPR, CCPA, PDPA-SG.
- Application
- Implementations: consent management platforms (OneTrust, TrustArc, Cookiebot, DataGrail), consent receipt records, granular consent UX (separate purposes), easy withdrawal mechanisms. Critical for CIAM and marketing analytics.
- Standards & regulations
-
- ISO/IEC 29184:2020 «ISO/IEC 29184:2020 specifies requirements for online privacy notices and for requesting and obtaining consent in online environments, including when using social media. It also provides guidance for b»
- I‑D.vcon-consent-00 «This document defines a consent attachment type for Virtualized Conversations (vCon) that enables automated consent detection, structured consent recording, and the expression of consent-related requi»
- I‑D.howe-vcon-lawful-basis-02 «Under regulations like the GDPR, there are six lawful bases for processing personal data. Consent is unique in that it is a permission granted by the data subject for a specific purpose and can be wit»
- W3C DPV CG-FINAL-dpv-20240801 «dpv:Consent: Consent of the Data Subject for specified process or activity. Consent in DPV is a specific legal basis representing information associated with consent rather than only given consent, in»
- Sources
-
- GDPR Article 4(11) and Recital 32 (Consent) primary source
Related terms
-
CCPA / CPRA (California Consumer Privacy Act / Privacy Rights Act) (CCPA)
California state privacy law (CCPA 2018, expanded by CPRA 2020 effective 2023) granting California residents rights over …
-
Confidentiality
Security principle ensuring data is accessible only to authorized identities. One of the CIA triad (Confidentiality, Int …
-
GDPR (GDPR)
EU General Data Protection Regulation (Regulation 2016/679) — landmark privacy law applicable from May 2018. Establishes …
-
HITRUST CSF (Common Security Framework) (HITRUST)
Healthcare-focused certifiable framework consolidating HIPAA, HITECH, NIST, ISO 27001, PCI DSS, GDPR, and 40+ other auth …
-
Integrity
Security principle ensuring data is accurate, complete, and not modified by unauthorized parties. One of the CIA triad. …
-
Access Object
Access Object — a unit of an information resource for which access is regulated by access control rules. May be a file, …