The principle of accountability in the context of obtaining consent for the processing of personal data

04 November 2019

In the decision issued on September 10, 2019, imposing a fine on the company Morele.net sp. z o.o., the President of the Polish DPA highlighted an important issue regarding the method of obtaining consents in the context of accountability. It is worth recalling that according to the GDPR, if processing is based on consent, the data controller must be able to demonstrate that the data subject has given consent to the processing of their personal data (Article 7(1)).

How to Understand Accountability in the Context of Obtaining Consent?

According to the position stated in the aforementioned decision of the supervisory authority: “For evidential purposes, related to the burden of proof resting on the data controller under Article 7(1) of Regulation 2016/679, it is deemed appropriate to collect and retain information regarding who granted consent and what its content was, when it was granted, what information the data subject received when making the consent declaration, what information was provided about the method of expressing consent, and whether the consent was withdrawn and if so, when. The possession of the above-mentioned information by the data controller regarding the consent expressed by the data subject constitutes a specification of the general principle of accountability formulated in Article 5(2) of Regulation 2016/679. In cases where the data controller is unable to demonstrate that and what consent to the processing of data was expressed by the data subject, such consent may be challenged” (decision of the President of the Polish DPA of September 10, 2019, ZSPR.421.2.2019).

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay up to date.
RECEIVE PACKAGE
In the guidelines on consent under Regulation 2016/679, the Article 29 Working Party emphasized that data controllers may freely develop methods to ensure compliance with the principle of accountability in a manner consistent with their ongoing activities. At the same time, the obligation to demonstrate that the data controller obtained valid consent should not in itself lead to excessive processing of additional data. This means that data controllers should have enough data to be able to demonstrate that consent was obtained, but should not collect more information than is necessary (WP259 rev.01, p. 23).

The above is also confirmed by case law from the period of the "old" personal data protection regulations, namely the repealed Personal Data Protection Act of 1997. In a judgment dated June 10, 2009 (case reference: II SA/Wa 124/09), the Administrative Court in Warsaw stated that consent to the processing of personal data constitutes a declaration of will by the individual whose data is to be processed. It is not sufficient to merely notify about the intention to process personal data and the absence of objection from the concerned individual. Although the Personal Data Protection Act does not require that such consent be given in writing, the fact that consent has been granted must be unequivocal, and consequently, the data controller must demonstrate that it has indeed been granted (thesis, Legalis 237275).

For consent to be valid, it must also meet certain conditions. Such consent must be:

  • voluntary – meaning that the individual expressing consent must not feel compelled to do so and must not face negative consequences for not providing it (for example, one cannot condition the performance of a contract on the expression of consent),
  • specific – expressed for one or more specified purposes, which serves as a safeguard against the gradual expansion or blurring of the purposes for which the data is processed after the initial consent has been given (for example, one cannot collect consent for the processing of data for the purpose of presenting personalized movie suggestions and then use the data to send targeted advertisements from third parties),
  • informed – the individual expressing consent must have all necessary information, including who it is being given to and for what purpose, how long the data will be used, and the possibility of withdrawing consent at any time, even before giving consent,
  • unambiguous – it must always be given through an active action or statement (for example, it cannot be expressed by accepting a pre-checked checkbox).
READ MORE: Privacy Notices

How to implement the accountability principle?

The GDPR does not specify exactly how to demonstrate the acquisition of valid consent. However, as long as the data is being processed, there is an obligation to demonstrate that consent has been properly expressed. After the processing activities have concluded, evidence of consent should not be retained longer than absolutely necessary, including for the purpose of fulfilling a legal obligation or for the establishment, exercise, or defense of claims.

How can accountability be ensured in the context of obtaining consents? Examples of methods include:

  • archiving forms used to obtain consent for the processing of personal data (or creating a scan of the form),
  • retaining information about the session during which consent was given, along with documentation of the consent flow during that session, as well as creating a copy of the information presented at that time to the data subject (if consent was obtained through an IT system). Merely referring to the proper configuration of the website would be insufficient,
  • archiving email messages if consent was expressed through this means of communication,
  • recording the telephone conversation during which consent for the processing of personal data was obtained, and archiving the recording.

Example:
A hospital organizes a research program called “Project X,” for which dental documentation of real patients is necessary. Participants are recruited by phone from among patients who have voluntarily agreed to be placed on a list of candidates to whom inquiries can be directed for this purpose. The data controller asks the data subjects for their explicit consent to use their dental documentation. Consent is obtained during the phone call by recording the oral statement of the data subject, in which the individual confirms that they agree to the use of their data for the purposes of Project X (guidelines of the Article 29 Working Party on consent under Regulation 2016/679, WP259 rev.01, p. 23).

Representatives of doctrine (M. Sakowska-Baryła (ed.), General Data Protection Regulation. Commentary, Warsaw 2018) emphasize that: "the literature indicates that the data controller should archive consents expressed by all individuals to whom inquiries are directed. At the same time, the provisions of the GDPR do not specify a qualified form requirement for expressing consent, which allows for the possibility of it being expressed in any form."

Do you also prefer prevention over treatment?

For this reason, any measure that duly demonstrates that a specific individual has given informed, voluntary, and specific consent will be sufficient. These measures should be appropriate to the circumstances in which the request for consent, as well as the consent itself, were made. If this occurred electronically through the selection of a checkbox, an appropriate method would be to retain records on the data controller's server or logs that confirm the selection of the consent checkbox. In the case of consent given via email, the email itself will serve as proof of consent; similarly, in the case of consent expressed in writing, it will be appropriate to archive the original or a copy of such a document (as noted by M. Mazewski, The Right to Consent, pp. 53–54).

The GDPR does not specify the timeframes within which consent remains valid. If the processing operations change significantly, new consent must be obtained, and the fact of obtaining it and the required context must be re-registered. In summary, the data controller should be able to answer at any time the questions: who, when, what content of consent was expressed, and what information was provided to them at the time of giving consent. However, the manner of fulfilling this requirement remains at the discretion of the data controller.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.