Viewing 4 replies - 1 through 4 (of 4 total)
  • Is this really true ? And for how long do you supposedly need to keep the information ?

    I have nothing but Google Analytics, and strictly required cookies on my sites, logs are autodeleted, so in reality this means that extended user data now has to be logged and stored in two places instead of one, and your own data with random private persons for all sites you visit ?

    To have this kind of evidence, you would need to keep atleast IP Address, Timestamp, and possibly even have to install click monitoring to prove that the user actually clicked the consent, unless a plugin does it for you (but that doesn’t make it less intrusive).

    This doesn’t seem very well thoughtout, and would make sites even more privacy intrusive, instead of the intended opposite.
    Surely there must be missing something here ?

    • This reply was modified 6 years, 5 months ago by shooz.
    Thread Starter dgoethals

    (@dgoethals)

    This is an extract of the original GDPR (https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=FR):
    Article 7

    Conditions for consent

    1. Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.

    From https://www.autoriteprotectiondonnees.be/comment-puis-je-d%C3%A9montrer-que-la-personne-concern%C3%A9e-donn%C3%A9-son-consentement:
    The responsible of the data processing should keep a trace of this consent and the information that is source of this consent.
    If the consent has been obtained online, the responsible may keep information related to the visit of the internet site. The way the consent has been obtained should also be kept along with the information provided to the concerned person.
    The responsible should not collect more information than necessary to prove a valid consent.

    I found no trace of the duration this information should be kept. Still searching…

    Yes, my understanding is that a record must be kept of consent to cookies being given and which cookies were consented to. This needs to be something like a log that can be downloaded as proof if required. I believe you have to keep this for the length of time you have set for your cookie notice to re-appear i.e. if set for 1 year then you keep that consent for 1 year.

    Will this feature be added soon to the plugin?

    Many thanks

    Plugin Author Moove Agency

    (@mooveagency)

    Hello,

    Thanks for using our plugin!

    We do not plan to add this feature as keeping a log about which user has opted-in would require us to store a lot of personal information about each user which would be the opposite to what the GDPR regulation is all about.

    Sorry we can’t be of more help.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘GDPR compliancy: Keep a trace of the consent’ is closed to new replies.