<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Article 29 WP publishes a new Guideline on Consent under the GDPR in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Article-29-WP-publishes-a-new-Guideline-on-Consent-under-the/m-p/4293#M155</link>
    <description>&lt;P&gt;&lt;A href="https://www.securityprivacybytes.com/files/2017/12/wp259_enpdf-Consent-draft-guidance.pdf" target="_self"&gt;These Guidelines&lt;/A&gt; provide a thorough analysis of the notion of consent in Regulation 2016/679, the&lt;BR /&gt;General Data Protection Regulation (hereafter: GDPR).&lt;/P&gt;&lt;P&gt;The concept of consent as used in the Data Protection Directive (hereafter: Directive 95/46/EC) and in the e-Privacy Directive to date, has evolved. The GDPR provides further clarification and specification of the requirements for obtaining and demonstrating valid consent. These Guidelines focus on these changes, providing practical guidance to ensure compliance with the GDPR and building upon Opinion 15/2011 on consent.&lt;BR /&gt;Consent remains one of six lawful bases to process personal data, as listed in Article 6 of the&lt;BR /&gt;GDPR.&amp;nbsp; When initiating activities that involve processing of personal data, a controller must always&lt;BR /&gt;take time to consider whether consent is the appropriate lawful ground for the envisaged processing&lt;BR /&gt;or whether another ground should be chosen instead.&lt;BR /&gt;Generally, consent can only be an appropriate lawful basis if a data subject is offered control and is&lt;BR /&gt;offered a genuine choice with regard to accepting or declining the terms offered or declining them&lt;BR /&gt;without detriment. When asking for consent, a controller has the duty to assess whether it will meet&lt;BR /&gt;all the requirements to obtain valid consent. If obtained in full compliance with the GDPR, consent&lt;BR /&gt;is a tool that gives data subjects control over whether or not personal data concerning them will be&lt;BR /&gt;processed. If not, the data subject’s control becomes illusory and consent will be an invalid basis for&lt;BR /&gt;processing, rendering the processing activity unlawful.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 08:22:36 GMT</pubDate>
    <dc:creator>leroux</dc:creator>
    <dc:date>2023-10-09T08:22:36Z</dc:date>
    <item>
      <title>Article 29 WP publishes a new Guideline on Consent under the GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Article-29-WP-publishes-a-new-Guideline-on-Consent-under-the/m-p/4293#M155</link>
      <description>&lt;P&gt;&lt;A href="https://www.securityprivacybytes.com/files/2017/12/wp259_enpdf-Consent-draft-guidance.pdf" target="_self"&gt;These Guidelines&lt;/A&gt; provide a thorough analysis of the notion of consent in Regulation 2016/679, the&lt;BR /&gt;General Data Protection Regulation (hereafter: GDPR).&lt;/P&gt;&lt;P&gt;The concept of consent as used in the Data Protection Directive (hereafter: Directive 95/46/EC) and in the e-Privacy Directive to date, has evolved. The GDPR provides further clarification and specification of the requirements for obtaining and demonstrating valid consent. These Guidelines focus on these changes, providing practical guidance to ensure compliance with the GDPR and building upon Opinion 15/2011 on consent.&lt;BR /&gt;Consent remains one of six lawful bases to process personal data, as listed in Article 6 of the&lt;BR /&gt;GDPR.&amp;nbsp; When initiating activities that involve processing of personal data, a controller must always&lt;BR /&gt;take time to consider whether consent is the appropriate lawful ground for the envisaged processing&lt;BR /&gt;or whether another ground should be chosen instead.&lt;BR /&gt;Generally, consent can only be an appropriate lawful basis if a data subject is offered control and is&lt;BR /&gt;offered a genuine choice with regard to accepting or declining the terms offered or declining them&lt;BR /&gt;without detriment. When asking for consent, a controller has the duty to assess whether it will meet&lt;BR /&gt;all the requirements to obtain valid consent. If obtained in full compliance with the GDPR, consent&lt;BR /&gt;is a tool that gives data subjects control over whether or not personal data concerning them will be&lt;BR /&gt;processed. If not, the data subject’s control becomes illusory and consent will be an invalid basis for&lt;BR /&gt;processing, rendering the processing activity unlawful.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:22:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Article-29-WP-publishes-a-new-Guideline-on-Consent-under-the/m-p/4293#M155</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2023-10-09T08:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Article 29 WP publishes a new Guideline on Consent under the GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Article-29-WP-publishes-a-new-Guideline-on-Consent-under-the/m-p/4306#M156</link>
      <description>I suspect that consent will be one of the more difficult articles to comply with in GDPR, the choice would be offered at every step of the processing, so it should ideally be embedded into the applications so the data owner has visibility and the control to deny access at any point.</description>
      <pubDate>Thu, 14 Dec 2017 19:02:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Article-29-WP-publishes-a-new-Guideline-on-Consent-under-the/m-p/4306#M156</guid>
      <dc:creator>Joewgreen</dc:creator>
      <dc:date>2017-12-14T19:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Article 29 WP publishes a new Guideline on Consent under the GDPR</title>
      <link>https://community.isc2.org/t5/Privacy/Article-29-WP-publishes-a-new-Guideline-on-Consent-under-the/m-p/4310#M157</link>
      <description>&lt;P&gt;GDPR defines ‘consent’ of the data subject means any &lt;STRONG&gt;freely given&lt;/STRONG&gt;, &lt;STRONG&gt;specific&lt;/STRONG&gt;, &lt;STRONG&gt;informed&lt;/STRONG&gt; and &lt;STRONG&gt;unambiguous &lt;/STRONG&gt;indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. On top of that, there are conditions for consent to be valid listed in Article 7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The guidance from WP29&amp;nbsp;amplifies the importance of demonstrating these for consent to be lawfully leveraged upon.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 22:21:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Article-29-WP-publishes-a-new-Guideline-on-Consent-under-the/m-p/4310#M157</guid>
      <dc:creator>flyingboy</dc:creator>
      <dc:date>2017-12-14T22:21:47Z</dc:date>
    </item>
  </channel>
</rss>

