<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GPDR Templates for Client Consent in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/GPDR-Templates-for-Client-Consent/m-p/7895#M358</link>
    <description>&lt;P&gt;Oops - clicked too soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another post was for employee consent.&amp;nbsp; We are a US law firm looking for ideas for a template for client consent.&amp;nbsp; An example would be an EU citizen enlisting our firm to negotiate a property deal in the US.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2018 18:08:25 GMT</pubDate>
    <dc:creator>pheisinger</dc:creator>
    <dc:date>2018-02-27T18:08:25Z</dc:date>
    <item>
      <title>GPDR Templates for Client Consent</title>
      <link>https://community.isc2.org/t5/Privacy/GPDR-Templates-for-Client-Consent/m-p/7894#M357</link>
      <description />
      <pubDate>Tue, 27 Feb 2018 18:05:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GPDR-Templates-for-Client-Consent/m-p/7894#M357</guid>
      <dc:creator>pheisinger</dc:creator>
      <dc:date>2018-02-27T18:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: GPDR Templates for Client Consent</title>
      <link>https://community.isc2.org/t5/Privacy/GPDR-Templates-for-Client-Consent/m-p/7895#M358</link>
      <description>&lt;P&gt;Oops - clicked too soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another post was for employee consent.&amp;nbsp; We are a US law firm looking for ideas for a template for client consent.&amp;nbsp; An example would be an EU citizen enlisting our firm to negotiate a property deal in the US.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 18:08:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GPDR-Templates-for-Client-Consent/m-p/7895#M358</guid>
      <dc:creator>pheisinger</dc:creator>
      <dc:date>2018-02-27T18:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: GPDR Templates for Client Consent</title>
      <link>https://community.isc2.org/t5/Privacy/GPDR-Templates-for-Client-Consent/m-p/7906#M359</link>
      <description>&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not a template, but it does have checklists, and ICO UK have other guidance&amp;nbsp;on their&amp;nbsp;site:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/" target="_self"&gt;https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Templatizing&amp;nbsp;this would make sense, remember no pre-checked&amp;nbsp;tick boxes. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checklists Asking for consent&lt;/P&gt;&lt;DIV class="example example-letter"&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We have checked that consent is the most appropriate lawful basis for processing.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We have made the request for consent prominent and separate from our terms and conditions.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We ask people to positively opt in.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We don’t use pre-ticked boxes or any other type of default consent.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We use clear, plain language that is easy to understand.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We specify why we want the data and what we’re going to do with it.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We give individual (‘granular’) options to consent separately to different purposes and types of processing.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We name our organisation and any third party controllers who will be relying on the consent.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We tell individuals they can withdraw their consent.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We ensure that individuals can refuse to consent without detriment.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We avoid making consent a precondition of a service.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; If we offer online services directly to children, we only seek consent if we have age-verification measures (and parental-consent measures for younger children) in place.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;Recording consent&lt;/P&gt;&lt;DIV class="example example-letter"&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We keep a record of when and how we got consent from the individual.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We keep a record of exactly what they were told at the time.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;Managing consent&lt;/P&gt;&lt;DIV class="example example-letter"&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We regularly review consents to check that the relationship, the processing and the purposes have not changed.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We have processes in place to refresh consent at appropriate intervals, including any parental consents.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We consider using privacy dashboards or other preference-management tools as a matter of good practice.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We make it easy for individuals to withdraw their consent at any time, and publicise how to do so.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We act on withdrawals of consent as soon as we can.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;☐&lt;/SPAN&gt; We don’t penalise individuals who wish to withdraw consent.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 28 Feb 2018 04:31:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/GPDR-Templates-for-Client-Consent/m-p/7906#M359</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2018-02-28T04:31:38Z</dc:date>
    </item>
  </channel>
</rss>

