CIPM CIPM Consent Management 1 — Questions and Answers
Question 1: Under GDPR, which conditions must ALL be met for consent to be considered lawful?
- Consent must be confirmed via email reply
- Consent must be freely given, specific, informed, and unambiguous (Correct answer)
- Consent can be implied through continued use of a service
- Consent can be bundled within the terms of service agreement
Correct answer: Consent must be freely given, specific, informed, and unambiguous
GDPR Article 7 requires valid consent to be freely given, specific, informed, and unambiguous, typically demonstrated through a clear affirmative act.
Question 2: What does 'freely given' consent mean in the GDPR framework?
- Consent provided at no financial cost to the individual
- Consent not conditioned on a service unless processing is necessary for that service (Correct answer)
- Consent given without any solicitation by the organization
- Consent provided in the individual's native language
Correct answer: Consent not conditioned on a service unless processing is necessary for that service
Freely given consent means there is no power imbalance and service delivery is not conditioned on consent to processing that is unnecessary for that service.
Question 3: Under GDPR, how must consent be obtained to process children's data for information society services?
- Written consent signed by the child only
- Parental or guardian consent for children under 16 (or lower national threshold) (Correct answer)
- School administrator authorization on behalf of the child
- Government-issued parental permission documentation
Correct answer: Parental or guardian consent for children under 16 (or lower national threshold)
GDPR requires parental or guardian consent for children under 16 for information society services, though member states may lower this threshold to 13.
Question 4: What is the primary purpose of a Consent Management Platform (CMP)?
- To encrypt personal data before it is stored
- To collect, store, and manage records of user consents (Correct answer)
- To automatically generate privacy notices for websites
- To monitor and respond to data breach incidents
Correct answer: To collect, store, and manage records of user consents
A CMP helps organizations obtain, record, and manage user consents, enabling them to demonstrate compliance and honor consent withdrawal requests.
Question 5: Under GDPR, can consent be used as a valid legal basis when there is a significant power imbalance between controller and data subject?
- Yes, as long as it is properly documented
- No, because consent cannot be considered freely given in such situations (Correct answer)
- Yes, if the data subject signs a formal written agreement
- Only if the arrangement is approved in advance by a supervisory authority
Correct answer: No, because consent cannot be considered freely given in such situations
When a clear power imbalance exists, such as between an employer and employee, consent is generally not considered freely given and thus is not a valid legal basis.
Question 6: Which of the following constitutes an 'unambiguous indication' of consent under GDPR?
- Pre-ticked checkboxes included in a registration form
- Silence or continued inactivity after viewing a notice
- Actively ticking an unticked checkbox (Correct answer)
- Scrolling past a privacy notice without stopping
Correct answer: Actively ticking an unticked checkbox
An unambiguous indication requires a clear affirmative act, such as ticking an unticked checkbox; passive behavior and pre-selected options do not meet this standard.
Under GDPR, which conditions must ALL be met for consent to be considered lawful?