The organization must ensure that consent for processing personal data is obtained in a valid, informed, and verifiable manner. Consent should be given voluntarily, with a clear explanation of the processing purpose before it is collected, and must only be obtained from individuals with full legal capacity.
Each processing purpose requires separate consent, and the organization must maintain accurate records showing when, how, and for what purpose consent was provided.
Explicit consent must be obtained when processing sensitive or credit-related data, or when using automated decision-making that produces legal or significant effects on individuals.