Recital 42 Burden of proof and requirements for consent*

1Where processing is based on the data subject’s consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation. 2In particular in the context of a written declaration on another matter, safeguards should ensure that the data subject is aware of the fact that and the extent to which consent is given. 3In accordance with Council Directive 93/13/EEC¹ a declaration of consent pre-formulated by the controller should be provided in an intelligible and easily accessible form, using clear and plain language and it should not contain unfair terms. 4For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing for which the personal data are intended. 5Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.

¹ Council Directive 93/13/EEC of 5 April 1993 on unfair terms in consumer contracts (OJ L 95, 21.4.1993, p. 29).

* This title is an unofficial description.

All recitals

Need help with GDPR Compliance?
Contact VeraSafe’s Data Protection Experts Today

VeraSafe can help assess your compliance, and operationalize your GDPR compliance, including:

  • Data Mapping / Discovery
  • Gap Analysis
  • Privacy Policies