Consent management policy
When consent is the basis, how it is asked for, recorded, proven and withdrawn, and how children's consent is handled.
How the register reads it
| Also called | consent procedure, consent records |
|---|---|
| Family | Privacy |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the data protection policy; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | never on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, data protection policy, is). |
| Template | Consent management policy. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.1.2.4 Determine when and how consent is to be obtainedThe organization must determine and document a process by which it can demonstrate whether, when and how consent to processing was obtained, clearly documenting when consent is needed and what obtaining it requires, correlating purposes with how consent is obtained, and taking into account jurisdiction specific requirements such as consent not being bundled with other agreements and additional requirements for particular collections or for particular individuals such as children.
Common gap: Consent bundled into terms of service acceptance, which several jurisdictions treat as no consent at all
Source: ISO/IEC 27701:2025
ISO 27701 A.1.2.5 Obtain and record consentThe organization must obtain and record consent according to its documented process, recording it so that on request it can produce the details of the consent given, including when it was given, the identity of the individual and the consent statement itself, having first provided the information required before consent, and the consent must be freely given, specific as to the purpose, and unambiguous and explicit.
Common gap: Consent recorded as a boolean flag with no record of what wording the person actually saw
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 7 Conditions for consentWhere processing rests on consent, be able to demonstrate that the data subject consented. Where the consent request forms part of a wider written declaration, present it in a manner clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language. Inform the data subject before consenting that consent may be withdrawn at any time, make withdrawal as easy as giving consent, and treat processing carried out before withdrawal as still lawful. Consent is not freely given where performance of a contract, including provision of a service, is made conditional on consent to processing that the contract does not require.
Common gap: Consent logged as a boolean with no record of the wording shown, so the organisation cannot demonstrate what was agreed to
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 8 Conditions applicable to child's consentWhere consent is the lawful basis and information society services are offered directly to a child, processing the child's personal data on the child's own consent is lawful only from age 16, or from the lower age a Member State has set in law, which may be no lower than 13. Below that age the processing is lawful only to the extent consent is given or authorised by the holder of parental responsibility, and the controller must make reasonable efforts to verify that it was, taking available technology into consideration.
Common gap: A self declared date of birth with no verification at all treated as reasonable effort
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register