惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
有赞技术团队
有赞技术团队
P
Proofpoint News Feed
IT之家
IT之家
B
Blog
博客园_首页
量子位
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
J
Java Code Geeks
H
Help Net Security
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
D
DataBreaches.Net
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
Inability to prove the validity of consent: the Garante f...
Veronica Walicki · 2023-03-09 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

The Italian Data Protection Authority (The Garante) released action against two insurance comparison sites, which were fined 120,000 euros because they failed to prove the validity of the consents they had obtained.

Avevano registrato migliaia di consensi per finalità di #marketing, ma a causa di un bug non sono riusciti a dimostrare la reale volontà degli utenti e che il consenso fosse stato davvero espresso. Il #GarantePrivacy sanziona per 120.000 euro due siti di comparazione di polizze👇

— Garante Privacy (@GPDP_IT) March 2, 2023

The ruling comes almost a year after the start of the investigation, which began with a number of reports and a complaint.

From the investigations conducted on the sites involved, the Garante noted that:

  • When filling out the information to receive the requested quote, some consents were marked as “mandatory” and others—such as consent to marketing activities—were pre-selected.
  • Once the user received the quote via email, he/she could view the result by clicking on a “Go to Quote” link. Once the link was clicked, all optional consents were saved as having been granted, even if the user hadn’t actively given their consent.

The company clarified that this happened because of a system bug and was not a voluntary action. However, for 9,700 users, consent that did not accurately reflect choice was recorded, and for 2,155 users, consent that was never granted had been saved. 

All this led the Garante to its final decision: a fine of 120,000 euros.

How was the GDPR violated?

Under the GDPR, consent is a matter of great importance and must meet specific requirements: it must be freely given, specific, informed and unambiguous. In the case presented here, it was not freely given consent, as some boxes on the form to request the quote were pre-selected.

The failure of the data controllers to demonstrate that the consents they had received were obtained in accordance with the GDPR’s requirements was the cause of the fine.

It is the responsibility of the controller to prepare unambiguous proof of consent that contains:

  • by whom and when consent was given;
  • what preferences were expressed;
  • legal or privacy notices in effect when consent was collected;
  • what form was completed when consent was given;
  • whether consent was withdrawn.

How to collect a proof of consent

Collecting a proof of consent that contains all these elements is not easy, however, there are solutions that can come to your aid, such as iubenda’s Consent Database!

Thanks to the Consent Database, you can adapt your forms and store a proof of consent as required by the GDPR:

  • it integrates seamlessly with your data collection forms (you can choose the option you prefer: frontend, backend, WordPress plugin or automation tools like Zapier and Make);
  • syncs with your legal documents;
  • includes an intuitive dashboard that allows you to retrieve consents at any time.

Collect GDPR consent for your forms

Try the Consent Database

💡 As you may know, many Data Protection Authorities across Europe (including the UK, France, Italy, Belgium, and more) have aligned their rules on cookies and trackers with the requirements of the GDPR. Then you may also need the Cookie and Consent Preference Logs, if you’re using non-technical cookies.