GDPR
Chapter II - Principles

GDPR GDPR-Art.7: Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Inform the data subject before consenting that consent may be withdrawn at any time, make withdrawal as easy as giving consent, and treat processing carried out before withdrawal as still lawful. Consent is not freely given where performance of a contract, including provision of a service, is made conditional on consent to processing that the contract does not require.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 85 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CDR-CON-1 Voluntary Consent
  • CDR-CON-2 Express Consent
  • CDR-CON-3 Informed Consent
  • CDR-CON-4 Specific Consent
  • CDR-CON-6 Withdrawable Consent and Authorisation

Canadian PIPEDA · 4 controls

CCPA/CPRA · 3 controls

  • CCR 7004 Design request and consent flows without dark patterns
  • CCR 7028 Opt back in through a two-step process only
  • §1798.125 Non-Discrimination for Exercise of Rights
  • PIPL-Art14 Consent Requirements
  • PIPL-Art15 Right to Withdraw Consent
  • PIPL-Art16 No Coerced Consent / No Service Refusal
  • ePD-Art.13 Unsolicited communications (Article 13)
  • ePD-Art.5 Confidentiality of communications including the Article 5(3) cookie consent rule
  • ePD-Art.9 Location data other than traffic data (Article 9)

ISO 27701:2019 · 3 controls

  • 7.2.3 Determine when and how consent is to be obtained
  • 7.2.4 Obtain and record consent
  • 7.3.4 Providing mechanism to modify or withdraw consent
  • Art. 122 Art. 122 Store or read information on users' devices only with informed consent, except where strictly necessary
  • Art. 126 Art. 126 Process location data only anonymised or with prior revocable consent for a requested value-added service
  • Art. 130(1)-(2) Art. 130(1)-(2) Get consent before automated calls, email, fax, SMS or MMS marketing
  • 5(1) Art. 5(1) Obtain the legal representative's consent for data subjects under 16
  • 5(2) Art. 5(2) Obtain the legal representative's consent for persons under guardianship, administration or mentorship
  • 5(3) Art. 5(3) Accept withdrawal of consent from the representative and from a data subject of twelve or over
  • 3.1.1(a) 3.1.1(a) Consent is not the legal ground for most processing at work; default settings are not consent
  • 5.2(b) 5.2(b) No demand for access to what employees or applicants share on social networks
  • AUCDR-PS-3 Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants
  • AUCDR-PS-6 Privacy Safeguard 6 - Use or disclosure of CDR data
  • CASL-14 Installation of Computer Programs - Consent
  • CASL-2 Express Consent
  • 3.3(a) 3.3(a) Consent only exceptionally, and then from everyone entering the monitored area
  • 5.1(c) 5.1(c) Biometrics: a non-biometric alternative without restraint or extra cost, and a back-up
  • DGA-Art.20_21 Transparency and safeguarding requirements (Articles 20-21)
  • DGA-Art.23_24_25 Competent authority + monitoring + European Data Altruism Consent Form (Articles 23-25)
  • s26-2 s 26(2) Rely on employee consent only where it is genuinely voluntary, in the required form and with text-form notice
  • s51 s 51 Where the law allows consent, obtain valid consent and be able to prove it
  • RO-LAW190-016 Direct Marketing and Electronic Communications
  • RO-LAW190-017 Cookies and Online Tracking

SOC 2 · 2 controls

  • SOC2-P2.1 P2.1 Choice and consent
  • SOC2-P3.2 P3.2 Explicit consent before collecting information that requires it
  • UZB-DPL-02 Consent of the Data Subject
  • UZB-DPL-10 Data Subject Rights

APPI · 1 control

  • APPI-A18 Restriction on Handling Beyond the Purpose of Use

COPPA · 1 control

  • COPPA-312.5a Verifiable Parental Consent Requirement
  • SD134-4 Consent Requirements
  • CSL-Art41 Lawful Collection of Personal Information - Art. 41

EU AI Act · 1 control

  • EUAI-Art.61 Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes
  • DMA-Art.5 Article 5 self-executing obligations (Article 5)
  • EGY-PDPL-Art.2 Data subject rights and consent requirement
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 7(1)(b) s 7(1)(b) and (3) Recording a private conversation as a party: consent of all principal parties or a narrow exception
  • CIA-CONS-02 Consent for provision and use of credit information
  • 6 s 6 No listening device on a private conversation without every party's consent

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter II - Principles

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 85 it maps to, and the evidence behind each claim, over MCP and REST.