Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Two Consents necessary for use case 1 #8

Closed
GeertThijs opened this issue Dec 6, 2021 · 2 comments
Closed

Two Consents necessary for use case 1 #8

GeertThijs opened this issue Dec 6, 2021 · 2 comments

Comments

@GeertThijs
Copy link
Contributor

GeertThijs commented Dec 6, 2021

Description
In use case 1 Kate (the Datasubject) gives Consent (let's call it Consent1) to KBC to use her payslips for mortgage evaluation. And she gives another Consent (Consent2) to SDWorx (in the role of the outsourced HR of the company she really works for? or does she work for SDWorx?) to share her payslips for mortgage evaluation. As the GDPR requires a Consent to be specific, we have two Consents here in my opinion: one for using the payslips and one for sharing the payslips.
Moreover, I doubt that this is the typical case. I would think that Kate, in the case of applying for a mortgage loan, would provide KBC with her payslips herself. It would be more interesting to describe a more typical case in stead of an exception.
I also wonder how this use case 1 is handled: it is not SDWorx that asks for Consent2 here, it is KBC that (apart form asking Consent1 for using the data) asks for Consent2 and then somehow transfers it to SDWorx. And what if SDWorx indeed does the HR for the company she works for then SDWorx is only a Processor, and it's her company that should get her Consent2.

Solution
Describe use case 1 with two Consents in stead of one. Or simplify the use case so that only one Consent has to be given (Consent1) as Kate herself hands over her payslips.

@GeertThijs GeertThijs changed the title Two Consents necessary for use case 1? Two Consents necessary for use case 1 Dec 6, 2021
@GeertThijs
Copy link
Contributor Author

GeertThijs commented Dec 6, 2021

Simplified objectdiagram (but with the two Censents) to illustrate the proposed solution:
TwoConsents

@michaelgeamanu
Copy link
Collaborator

This topic was discussed with Geert Thijs. In this use case it is important to assume that the DataController (already controlling the data, SDWorx in this case) has the correct rights/consents in place to provide other DataControllers (KBC in this case) with data if they can show a consent linked to it.

Meaning that it could be possible that there are two consents in place, but only one is relevant in for this use case.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants