What is consent management?
What does consent management need to do?
Under Art. 4(11) GDPR, valid consent is freely given, specific, informed and unambiguous – given by a statement or a clear affirmative action. Pre-ticked boxes are not sufficient. The controller must be able to demonstrate consent (Art. 7(1) GDPR), and the person can withdraw it at any time; withdrawing must be as easy as giving consent (Art. 7(3) GDPR).
For campaigns, this means: consents apply per purpose and per channel. Consent to email advertising does not permit SMS. Many companies base letter advertising on legitimate interest (Art. 6(1)(f) GDPR); in that case, an objection under Art. 21 GDPR must be respected – after which the data may no longer be processed for direct marketing.
Good consent management therefore checks not only at import, but before every single send. It versions consent texts, stores timestamps and source, and implements withdrawals immediately across all campaigns and channels.
Marlene Hoffmann, 58, has allowed the bank to send her letters but has not given email consent. The reinvestment journey therefore automatically chooses the letter. If she later objects to advertising, all running journeys stop and she does not enter any new advertising campaign.
Distinction
| Term | Difference |
|---|---|
| Cookie banner / consent management platform | governs consent for cookies and tracking on the website (Section 25 TDDDG) |
| Preference centre | interface in which customers choose topics and channels – part of consent management |
| Suppression list | contains only exclusions, not consents with proof |
How the PBM Campaign Platform supports it
Consent is checked per channel before every send; opt-in and opt-out are documented; without email consent, the channel fallback switches to letter; a withdrawal immediately halts running journeys and blocks re-entry.
Related pages
-
Platform
Consent & compliance -
Trust Centre
Trust Centre -
Blog In preparation
[BLOG: GDPR-compliant marketing automation – what is really permitted]