The organization has identified the purposes of use of personal data where explicit consent is required as the legal basis for processing. In addition, the organization has defined methods for documenting the explicit consents received.
Explicity refers to the unequivocal way in which the data subject expresses his consent. Such consent can be given e.g. by traditional signature of the statement, electronic signature or acknowledgment after two-step identification.
Situations requiring specific identification may include e.g.
- Special personal data (e.g. health data) processing
- Data transferred to third countries (when other transfer criteria according to the GDPR cannot be met)
- Automatic decision-making or profiling