Consent

From MgmtWiki
Jump to: navigation, search

Full Title or Meme

Consent is a process that the User undertakes at a Web Site to agree to some conditions of use of that site. Only some Artifact of the process can be used as proof that consent was freely given.

Principles

  1. The only sin is for one human to use another human without their informed and willing consent.
  2. The only cowardice is for any human to allow one human to use another human without their informed and willing consent.

Context

Prior to 2019 consent of users to actions in cyberspace has been found in a Privacy Policy or Terms of Service which in many countries take on legal weight as a Contract of Adhesion. That legal basis is now being reimagined in many legal jurisdictions.

Problems

  • It's easy to say that the user should have control of their own data, it's hard to capture the fact. Facebook and Google refuse to provide their service if you don't given the consent to store your entire life online. That is not really a choice for most people that use the internet daily.
  • "Consent, in its purest form, could easily become a dystopian stick to control citizens with," Susan Morrow, doesn't pull her punches as she argues that GDPR hasn't resolved the conflict between choice and consent. [1]

Solutions

The Process

In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation. Consent is presumed not to be freely given if it does not allow separate consent to be given to different personal data processing operations despite it being appropriate in the individual case, or if the performance of a contract, including the provision of a service, is dependent on the consent despite such consent not being necessary for such performance.

The Office of the Privacy Commissioner of Canada has published Guidelines for obtaining meaningful consent[2] which "sets out practical and actionable guidance regarding what organizations should do to ensure that they obtain meaningful consent."

The Artifact

  • One source for a Consent artifact is the Indian Government[3] this document has the XML format of a consent artifact. Note: crore = ten million; one hundred lakhs, especially of rupees, units of measurement, or people.
  • The wiki page Consent Receipt describes an artifact that is created by the recipient of the User Information. The version 1.0 does not prove that consent was freely given.

References

  1. Susan Morrow, 50 shades of privacy: Consent and the fallacy that will prevent privacy for all. (2019-05) Information Age https://www.information-age.com/consent-privacy-gdpr-privacy-by-design-default-123482351/
  2. Privacy Commissioner of Canada, Guidelines for obtaining meaningful consent. https://www.priv.gc.ca/en/privacy-topics/collecting-personal-information/consent/gl_omc_201805/
  3. Ministry of Electronics & Information Technology, Electronic Consent Framework Technology Specifications, Version 1.1 Government of India (undated, retrieved on 2019-04-09) http://dla.gov.in/sites/default/files/pdf/MeitY-Consent-Tech-Framework%20v1.1.pdf

External Sources

  • R4 of FHIR Resource consent. 'A record of a healthcare consumer’s choices, which permits or denies identified recipient(s) or recipient role(s) to perform one or more actions within a given policy context, for specific purposes and periods of time.'
  • FHIR Consent Fields could be helpful in creating consents.
  • Web Authentication defines User Consent as when the user agrees with what they are being asked, i.e., it encompasses reading and understanding prompts. An authorization gesture is a Ceremony component often employed to indicate user consent.