Policy Register

Consent management policy

When consent is the basis, how it is asked for, recorded, proven and withdrawn, and how children's consent is handled.

How the register reads it

Also calledconsent procedure, consent records
FamilyPrivacy
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the data protection policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe data protection officer or privacy lead.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, data protection policy, is).
TemplateConsent management policy.

Which standards require it, and what each expects it to contain

4 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27701:2025

ISO 27701 A.1.2.4 Determine when and how consent is to be obtained

The organization must determine and document a process by which it can demonstrate whether, when and how consent to processing was obtained, clearly documenting when consent is needed and what obtaining it requires, correlating purposes with how consent is obtained, and taking into account jurisdiction specific requirements such as consent not being bundled with other agreements and additional requirements for particular collections or for particular individuals such as children.

Evidence an auditor accepts: Documented consent process covering when consent is required and what valid consent demands; mapping from each purpose to whether and how consent is obtained; analysis of jurisdiction specific consent requirements and how the mechanism meets them
Common gap: Consent bundled into terms of service acceptance, which several jurisdictions treat as no consent at all
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.5 Obtain and record consent

The organization must obtain and record consent according to its documented process, recording it so that on request it can produce the details of the consent given, including when it was given, the identity of the individual and the consent statement itself, having first provided the information required before consent, and the consent must be freely given, specific as to the purpose, and unambiguous and explicit.

Evidence an auditor accepts: Consent records holding timestamp, individual identity and the exact statement consented to; the version of the information presented before consent, retained alongside; evidence consent was freely given, meaning a real alternative existed
Common gap: Consent recorded as a boolean flag with no record of what wording the person actually saw
Source: ISO/IEC 27701:2025

GDPR (Regulation (EU) 2016/679)

GDPR Art. 7 Conditions for consent

Where processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Inform the data subject before consenting that consent may be withdrawn at any time, make withdrawal as easy as giving consent, and treat processing carried out before withdrawal as still lawful. Consent is not freely given where performance of a contract, including provision of a service, is made conditional on consent to processing that the contract does not require.

Evidence an auditor accepts: Consent records capturing who consented, when, to what wording, and through what mechanism; the consent wording and interface as presented, versioned, so an old record can be tied to what was actually shown; the withdrawal mechanism, with evidence it works and takes no more steps than giving consent did
Common gap: Consent logged as a boolean with no record of the wording shown, so the organisation cannot demonstrate what was agreed to
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 8 Conditions applicable to child's consent

Where consent is the lawful basis and information society services are offered directly to a child, processing the child's personal data on the child's own consent is lawful only from age 16, or from the lower age a Member State has set in law, which may be no lower than 13. Below that age the processing is lawful only to the extent consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that it was, taking available technology into consideration.

Evidence an auditor accepts: The assessment of whether the service is an information society service offered directly to children; the age threshold applied per Member State, with evidence the applicable national lower age was checked rather than assumed; the age assurance mechanism, and the reasoning for why it is a reasonable effort given available technology
Common gap: A self declared date of birth with no verification at all treated as reasonable effort
Source: GDPR (Regulation (EU) 2016/679)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Security event reporting procedure · Cookie policy