Accessibilitat

Obtain the user's consent when requesting personal data

The consent must be given through a clear affirmative action that reflects a free, specific, informed, and unequivocal manifestation of will of the interested party and must be granted for all treatment activities carried out. When the treatment has several purposes, the consent must be given for each of them. If it is to be given as a result of a request by electronic means, it must be clear, concise and not unnecessarily disturb the use of the service for which it is provided.

This express consent can be transferred to a web form through the implementation of checkboxes that are unchecked by default, this is vital, to be able to demonstrate this willingness on the part of the person to process their personal data.

Pre-branding, silence and inactivity of the interested party do not constitute a lawful processing of data, so that these formulas should not be used.

We have talked in the previous section about specific purposes, that is to say, when someone provides their data it is necessary to detail in a clear, unequivocal and transparent way what will be the conditions of data processing.

As it is an express consent linked to a specific purpose, it is necessary to demonstrate that it has been collected following these precepts and the burden of proof falls on the organization that collects and processes this data.

An example of how we can demonstrate that we have been authorized is that each registration generates an automatic response e-mail with the data of the person requested, their IP, acceptance, date, exact time and browser used. This e-mail must be kept as a justification in case of conflict with the user.

First layer of basic information

With the requirements and principles introduced by the RGPD with regard to the obligation to inform, simply referring to privacy policy from web forms is no longer sufficient to comply with these obligations.

The European Union's Data Protection Authorities recommend using a layer-by-layer information model, presenting a first layer, with basic data protection information and referring from this, simpler and more immediate, to a second layer with the remaining information.

In the Guide to "Compliment del Deure d’Informar"the AEPD states that this first information layer must meet the following requirements:

– Information must be made available to stakeholders at the time the data is requested, prior to collection or registration.

– This obligation must be fulfilled without any requirement, and the controller must be able to confirm afterwards that the obligation to report has been fulfilled.

– It must be clearly identified with a title such as 'Basic information on data protection'.

The controller must ensure that this information is 'in the field of view' of the data subject.

The interested parties must receive a copy containing this basic information.

Article 72 of the LOPDGDD classifies as a very serious infringement the failure to inform the data subject about the processing of his or her personal data as laid down in Articles 13 and 14 of Regulation (EU) 2016/679 (RGPD).