Consent Management Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Consent Management flashcards as text
What is the primary purpose of consent management in data privacy?
Answer: To document and enforce user agreements for the collection and processing of personal data
Consent management ensures organizations obtain, record, and honor individuals' explicit agreement regarding how their personal data is collected and used.
Under GDPR Article 7, which of the following conditions makes consent valid?
Answer: Consent is freely given, specific, informed, and unambiguous
GDPR requires consent to be freely given, specific, informed, and unambiguous — meaning a clear affirmative action is required from the data subject.
What is 'granular consent' in the context of privacy engineering?
Answer: Separate consent obtained for each distinct processing purpose rather than a single blanket approval
Granular consent allows individuals to agree to specific processing purposes independently, rather than accepting all uses through a single checkbox.
What is the main function of a Consent Management Platform (CMP)?
Answer: To automate the collection, storage, and enforcement of user consent preferences
A CMP automates obtaining consent, maintains records of consent decisions, and enforces those preferences across systems and third-party integrations.
How does opt-in consent differ from opt-out consent?
Answer: Opt-in requires active affirmative action from the user; opt-out treats silence as agreement by default
Opt-in consent requires the user to actively agree before processing begins, while opt-out consent assumes agreement unless the user explicitly declines.
What does 'freely given' consent mean under major privacy regulations such as GDPR?
Answer: The data subject must have genuine choice and not face negative consequences for refusing consent
Freely given consent means the data subject has a real choice; if refusal leads to denial of service or other detriment, the consent is not considered valid.
When a user withdraws consent, how must an organization respond according to GDPR?
Answer: The organization must cease processing and, where applicable, delete the data, making withdrawal as easy as giving consent
GDPR requires organizations to stop processing upon withdrawal of consent and ensure the withdrawal mechanism is as straightforward as the consent mechanism itself.