Skip to Content
CKonnect
  • Home
  • CourseKonnect
    • e-learning
    • Udemy
    • learning (Old LMS)
  • Career
    • Life @CKonnect
    • All Jobs
  • Knowledge Base
    • PrivacyReads
    • Community
    • Newsletters
    • Priv ToolKit
  • Stay Tuned
    • ComplyKonnect
    • E-PrivJournals
    • Priv-Books
  • Connects
    • 1:1
  • Contact Us
CKonnect
    • Home
    • CourseKonnect
      • e-learning
      • Udemy
      • learning (Old LMS)
    • Career
      • Life @CKonnect
      • All Jobs
    • Knowledge Base
      • PrivacyReads
      • Community
      • Newsletters
      • Priv ToolKit
    • Stay Tuned
      • ComplyKonnect
      • E-PrivJournals
      • Priv-Books
    • Connects
      • 1:1
  • Contact Us

Welcome!

Share and discuss the best content and new marketing ideas, build your professional profile and become a better marketer together.

Sign up

You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
Data Privacy IDT Tech Privacy DSR Data Mapping
About this forum
You need to be registered to interact with the community.
All Posts People Badges
Tags (View all)
Data Privacy IDT Tech Privacy DSR Data Mapping
About this forum
CKonnect Community

Consent ≠ Catch-All License

Subscribe

Get notified when there's activity on this post

This question has been flagged
consent
1 Reply
410 Views
Avatar
CKonnect

“One Consent, Many Uses? Purpose Creep in Action”

A user gives their phone number to verify their identity (2FA). A month later, they get a WhatsApp ad from the same platform. No fresh consent.

📣 Do you think this is a legitimate reuse of data or a classic case of purpose creep?

💬 Jump in:

  • Should businesses take separate consents for marketing vs. security use cases?
  • How do you explain granular consent to a non-privacy person?

Let’s see how you’d handle this as a DPO or privacy consultant!

0
Avatar
Discard
Avatar
aftab.naukhaiz1997@gmail.com

This scenario is the classical example of purpose creep. The business is reusing the data for a purpose other than that for which the data was originally collected. This is the clear violation of the principle of purpose limitation, only processing personal data for specified, explicit and legitimate purposes.

  • Should businesses take separate consents for marketing vs. security use cases?


Yes, absolutely. One consent, one purpose, multiple consents Multiple purposes: this is termed as 'granular consent'. Granular consent is a fundamental requirement of modern privacy regulations like GDPR, DPDPA, and PDPA. Security and marketing are two different domains; both need separate consent. The consent for security is not used for marketing purposes.

  • How do you explain granular consent to a non-privacy person?


Think about the tailor shop. Instead of just a single "I agree to everything" form, a shop practising granular consent would give you a form with choices:

  •  I give my phone number so you can call me when my clothes are ready. (This is the main aim and a required permission.)
  •  I would like to get text messages about special festival discounts (like Diwali or Eid). (This is an extra, optional permission.)
  •  I agree to get a call to provide feedback on the stitching. (Another optional permission.)

The above illustration shows you have control over your data. You can check the boxes for the things you are okay with and leave the rest blank. This way, your number is used only for the things you approved, making it your choice, not the business's.

How I handle this as a DPO or privacy consultant

·   I would train the marketing team about the concept of purpose limitation.

·   I would enable the concept of privacy by design, as mentioned in the above example, where the tailor provides the detail form.

·   I would make the user aware in simple language how his/her consent is used and for what purpose without using difficult legal language.

·   I would audit where purpose creep is happening.

·   I would review the privacy policy, terms & conditions and consent management systems.

Follow

https://www.ckonnect.co.in/blog/privacy-team-pulse-7/purpose-creep-privacy-consent-misuse-69

0
Avatar
Discard
Enjoying the discussion? Don't just read, join in!

Create an account today to enjoy exclusive features and engage with our awesome community!

Sign up
Related Posts Replies Views Activity
Ghosting the Unsubscribe Button
consent
Avatar
Avatar
1
Dec 25
348
Follow us

Privacy Notice ​​Refund Policy

 Terms & Conditions

    ​    connect@ckonnect.co.in

How can we help?

konnect with us

Website Logo

Respecting your privacy is our priority.

Allow the use of cookies from this website on this browser?

We use cookies to provide improved experience on this website. You can learn more about our cookies and how we use them in our Cookie Policy.

Allow all cookiesOnly allow essential cookies