Data protection
Consent record: how to prove you have permission to process the data
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
Direct answer: when you process data because the person has given you permission (for example, to send them your newsletter), the RGPD (the EU's general data protection regulation) requires you to be able to prove that permission: who gave it, when and what for (art. 7.1). The consent record is where you keep that proof. Without it, a "yes" you cannot prove is as if it never existed. Tranquilia records the consents you collect and leaves the proof in good order.
Contents
- What is the consent record?
- When do you need consent?
- What makes a consent valid
- What risk do you run if you cannot prove it?
- How Tranquilia solves it
- Frequently asked questions
- Official sources
What is the consent record?
It is the proof that you have permission. The RGPD's "proactive accountability" principle (art. 5.2) is not satisfied with you complying: it requires you to be able to prove that you comply. For consent, that means keeping the trail of every "yes": which person, for which purpose, on what date and with what wording they accepted it.
You do not need a complicated system. It can be a simple record, but it has to exist and be up to date.
When do you need consent?
Consent is only one of the RGPD's legal bases, not the only one. Many processing operations rely on a contract or on a legal obligation, and there you do not need to ask for permission. Consent is needed, above all, for things like:
- Sending advertising or newsletters to someone who is not already a customer.
- Using analytics or advertising cookies on your website.
- Publishing photos or images of people.
In those cases, the "yes" has to be real and provable.
What makes a consent valid
Art. 4.11 and art. 7 of the RGPD set the rules. A valid consent is:
- Freely given: without pressure and without making a service conditional on accepting something that is not needed.
- Specific: for a particular purpose, not an "I accept everything" in one block.
- Informed: the person knows what they are saying yes to.
- Unambiguous: a clear, affirmative act. A pre-ticked box is not valid, and neither is silence.
In addition, withdrawing consent has to be as easy as giving it (art. 7.3).
What risk do you run if you cannot prove it?
If someone complains that you sent them advertising without permission and you cannot prove that they said yes, the AEPD (Agencia Española de Protección de Datos, Spain's data protection authority) assumes that you did not have it. The burden of proof is yours, not the complainant's.
The RGPD sets the maximum penalties at two levels: up to 10 million euros or 2% of turnover, and up to 20 million or 4%, depending on the infringement (art. 83 RGPD); the higher figure applies. Sending advertising without provable consent is one of the most frequent grounds for complaints against SMEs: it is avoided by keeping the proof properly.
How Tranquilia solves it
When you collect a consent through the app, Tranquilia keeps the full trail (purpose, date and accepted wording) and leaves you the record tidy and exportable. That way, if someone complains, you have the proof to hand instead of searching through old emails.
Frequently asked questions
Is a box that is already ticked by default valid?
No. The RGPD requires a clear affirmative act: the person has to tick the box themselves. A pre-ticked box, or an "if you say nothing, I take it you accept", are not valid consents.
If I process data under a contract, do I also need to record consent?
Not for that processing. If the legal basis is the contract or a legal obligation, you do not ask for consent and therefore you do not record it. The record is for the processing operations that do rely on the person's permission.
How long do I keep the proof of consent?
For as long as the processing based on that permission lasts, and a reasonable time afterwards, in case you have to show that you had it. When the person withdraws consent, you stop processing the data, but you keep the proof that it existed at the time.
Official sources
- Reglamento (UE) 2016/679 (RGPD), articles 4.11, 5.2 and 7 (and art. 83, penalties) — text on EUR-Lex.
- Agencia Española de Protección de Datos (AEPD).
- BOE — Ley Orgánica 3/2018 (LOPDGDD), article 6 (consent).
General information on legislation. It does not replace the advice of a lawyer or the analysis of your specific case. If you have any doubts, consult your gestoría or a legal professional.
Review: Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.