This is the classical example of purpose creep. The business is reusing the data for a purpose other than that for which data is originally collected. This is the clear violation of principle of purpose limitation, only process personal data for specified, explicit and legitimate purpose.
- Should businesses take separate consents for marketing vs. security use cases?
Yes, absolutely. One consent one purpose, Multiple consent Multiple purpose this is termed as Granular Consent. Granular consent, is a fundamental requirement of modern privacy regulations like GDPR, DPDPA, and PDPA. Security and Marketing are two different domain both need a separate consent. The consent for security does not used for marketing purpose.
- How do you explain granular consent to a non-privacy person?
Think about the tailor shop. Instead of just a single "I agree to everything" form, a shop practicing granular consent would give you a form with choices:
- I give my phone number so you can call me when my clothes are ready. (This is the main aim and a required permission.)
- I would like to get text messages about special festival discounts (like Diwali or Eid). (This is an extra, optional permission.)
- I agree to get a call to provide feedback on the stitching. (Another optional permission.)
The above illustration shows you have control over your data. You can check the boxes for the things you are okay with and leave the rest blank. This way, your number is used only for the things you approved, making it your choice, not the business's.
How I handle this as a DPO or privacy consultant
· I would train the marketing team about the concept of purpose limitation.
· I would enable the concept of privacy by design, as mention in the above example tailor provide the detail form.
· I would aware user in simple language how his/her consent is used and for what purpose without using difficult legal language.
· I would audit where purpose creep is happing.
· I would review privacy policy, terms & condition and consent’s management systems.