Securing consent ‘Consent’ as a ground for processing personal data lawfully should be used sparingly. Try and rely on another lawful ground first (click ‘here’ for more information on those grounds). Once you have identified your purpose for processing the personal data and you consider ‘consent’ is the only appropriate ground for processing it lawfully, consider the following guidance Responsible Complete Consent must be freely given, specific, informed and unambiguous Ensure your consent includes everything outlined in the template consent found ‘here’ Consider the different methods of securing consent, including email, in writing Send the suggested wording to the individual ensuring it’s prominent and not buried in terms and conditions Secure the consent with either their signature or other positive opt in Don’t make performance of the contract conditional on their consent Log their consent in an appropriate log including the name of the person consenting, when consent was given, the wording of the consent, how consent was given (signature/tick box), whether they have withdrawn consent Only process the data in accordance with the consent If you need to add another purpose for processing the data ask for further consent If they withdraw consent allow them to do so as soon as possible unless you have another lawful basis for processing their personal data (in which case inform them of that fact). Ensure that the appropriate processes are put in place to avoid processing their personal data in respect of the withdrawn consent Consider giving individuals the option of varying their consent using preferences or privacy dashboards Consider sending out reminders about the fact that individuals can withdraw their consent Review your consents regularly to ensure that the consents you have secured are still appropriate