Ditto Posted November 11, 2021 Posted November 11, 2021 As I'm now I the main conduit between our organisation and our DPO, a number of interesting questions have come my way. One is around forms of consent and how to record it. Unfortunately my organisation is still skewed to paper records, so often they ask our 'clients' (under 18 children and young people) to sign a paper document to give consent to various data collection/sharing items. So the record we have is paper based. The document may additionally be signed by a parent. This can be scanned or photo'd and stored in our system against the client and the idea is that the original is shredded. We also record the answers against the clients account. Sometimes the document is a completed electronic Word document or PDF form where the client types in their name and date. It always amused me that people use a cursive font - I know that makes no difference, but that's an aside! The question on these two options is, is one better than the other and how do they sit from a GDPR perspective. Being a techie, I'd much rather a auditable, trackable electronic consent form, but the organisation isn't ready for that yet.
DavR Posted November 11, 2021 Posted November 11, 2021 I don't think one is inherently better than the other, by the sounds of it you're returning a document with consent(s) granted on it either way. As far as I know with GDPR you need to record the consent, who gave it, how, and when. We record all of this in our MIS. We're moving more towards Google Forms for this kind of thing, as it records all of that with a few name fields and a tick box. We create the forms, email them to parents, and they fill them in, no paper copies required.
Ditto Posted November 11, 2021 Author Posted November 11, 2021 I'd like to move to more electronic forms - it'll probably be MS Forms, but the concept is much the same. We'd probably have to still support some paper as electronic isn't viable for some parents.
enjay Posted November 12, 2021 Posted November 12, 2021 I agree with @DaveAshworth - you don't need to retain the actual method by which they consented, just that their consent was given (that said, the original is useful in case challenged, but a Word document with someone's name in a cursive font is easy enough to fake). Generally, we obtain consent via the payment system, which is easily recorded, easily queried and definitely from the consentee (he says, making up a word!). Otherwise, it is a Google/MS Form, but those are more commonly used for "yes I'm coming to parents evening" rather than "yes my son go take part in that event". There's also consent via paper for the rest of this year until our admissions finally goes paperless. Where relevant, the consent is then recorded in the MIS.
MatthewL Posted November 12, 2021 Posted November 12, 2021 All good and well people using cursive font, most now just use a normal one but we would only accept an electronic document like that from their email address, if it comes from anything else unless verified then no. Even if they complete it on paper which is the easiest way, scan/photo and record that electrically and shred the paper simple answer. People say that electronic isn't viable for some everyone has a smart phone these day so poor excuse. Having paper means its accessible and your not discriminating anyone but as long as there is an alternative means then I would say go with what works in getting consent then make it all electronic, no paper to go missing/get lost then.
enjay Posted November 12, 2021 Posted November 12, 2021 (edited) everyone has a smart phone these day so poor excuse. That's not true, and the belief everyone has a smart phone causes a lot of problems for those people who don't. Nothing wrong with using electronic as the main means of consent, and indeed with assuming 99.9% of people have a smart phone, but you definitely need an option for those who don't (and also potentially for those who are illiterate....) Edited November 12, 2021 by enjay 1
GrumbleDook Posted November 13, 2021 Posted November 13, 2021 I agree with @DaveAshworth - you don't need to retain the actual method by which they consented, just that their consent was given (that said, the original is useful in case challenged, but a Word document with someone's name in a cursive font is easy enough to fake). Generally, we obtain consent via the payment system, which is easily recorded, easily queried and definitely from the consentee (he says, making up a word!). Otherwise, it is a Google/MS Form, but those are more commonly used for "yes I'm coming to parents evening" rather than "yes my son go take part in that event". There's also consent via paper for the rest of this year until our admissions finally goes paperless. Where relevant, the consent is then recorded in the MIS. The following setsOut what is needed with respect to record keeping around Consent. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/ for more information. Keeping an actual record of the consent being given is a simple way to manage this, As it also supports the accuracy side of data protection. You do need to be carful of ROT though.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now