SEC08-03 Data Subjects' Choice and Consent
It refers to the process in which the data processor needs to obtain the explicit consent of the data subject (individual) before the personal data is collected, processed, or used, and the data subject has the right to choose whether to agree to the processing of the personal data.
- Risk level
High
- Key strategies
- Before the collection or use of personal data, notify users, obtain users' consent, and allow users to disable the collection and use of personal data.
- Before exporting an error report containing personal data from the data subject's system, provide a mechanism to notify the data subject and obtain his/her consent.
- If personal data is used for marketing, user profiling, or surveys, the data controller and equipment vendor must provide a mechanism to obtain data subjects' opt-in consent and allow them to withdraw their consents anytime.
- Before setting or reading cookies (for marketing or advertising) on the data subject's system, provide a mechanism to obtain the data subject's consent and allow the data subject to withdraw the consent any time.
- Obtain users' consent before modifying users' personal space (e.g., system or application configuration change, software download, and system or software upgrade).
- Guardians' consent must be obtained for services provided for minors or when personal information containing age information is collected.
- The data controller should provide a mechanism to record users' consent and consent withdrawal.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot