Einwilligungsverwaltungsverordnung (EinwV, Consent Management Services Ordinance), Recognized Consent-Management Services
In force since .
A device storage and tracking consent rule binding public and private bodies.
- Obligation class
- Consent, Disclosure, Governance
As of .
What it requires
- Integrating a recognized consent-management service to ask for consent under section 25(1) of the TDDDG is voluntary (section 18(1)); you remain responsible for the General Data Protection Regulation (GDPR) information duties and the requirements for valid consent even where you integrate one (section 1(2)).
- If you integrate a recognized consent-management service, take the end users' settings into account, and where you have no consent from an end user through the integration, point to the end user's settings with the recognized service when you ask for consent (section 19(1)).
- If you integrate a recognized service and ask for end users' settings through it, you should, by technical and organizational measures reflecting the state of the art, take care that the end user's use of the service is taken into account when your digital service is called up and that it is checked whether settings are managed at the service (section 18(2)); you should also let the service store the consents you request, point end users at a visible and suitable place to the integration, cooperate with the service on the requirements of section 7, and give it the information required under Articles 7 and 12 to 14 of the GDPR in a machine-readable format (section 18(3)).
- If you manufacture or provide software for retrieving and presenting information from the internet, you should, within the technical possibilities, take care that it takes the integration of recognized services into account and does not suppress, delay, decrypt or otherwise alter a signal or end-user settings deposited through the recognized service or the provider of digital services (section 17).
- If you integrate a recognized service, you should not, without an objective reason, work toward end users using or excluding particular recognized services (section 20).
- To be recognized by the Federal Commissioner for Data Protection and Freedom of Information, a consent-management service must apply with a security concept (sections 8, 10 and 12) and meet the Part 2 requirements, among them: store the settings an end user made and transmit them to the provider on each further use, manage only consents for which the end user was informed in advance of the matters section 3(2) lists, and document the information on which a consent rests in a way that is easily accessible to the end user (section 3).
What this law does
The Einwilligungsverwaltungsverordnung regulates the requirements a consent-management service must meet to be recognized, the procedure for recognition by an independent body, and the technical and organizational measures that providers of digital services and manufacturers and providers of software for retrieving and presenting information from the internet should take so that end users' settings can be followed.
Section 1(2) leaves the provider of digital services responsible for meeting the information duties and the requirements for the validity of consent under the General Data Protection Regulation (GDPR). Section 8 makes the Federal Commissioner for Data Protection and Freedom of Information the independent body competent to recognize consent-management services. Section 10 provides that a consent-management service is recognized on application if it meets the requirements of Part 2 and has submitted a security concept.
Section 3(1) requires a recognized consent-management service to store the settings an end user made on first use of a digital service, and likewise where a provider asks for a consent it does not yet manage, and to transmit them to the provider of the digital service on each further use.
Under section 3(2), a recognized service manages only consents for which the provider of the digital service told the end user before consent at least who can store or access information, which information, for which purposes and for which periods, and that the consent can be withdrawn at any time. Under section 18(1), integrating a recognized consent-management service is voluntary for providers of digital services.
Section 19(1) requires a provider that integrates a recognized service to take the end users' settings into account, and, where it has no consent from an end user through the integration, to point to the end user's settings with the recognized service when it asks for consent.
Section 18(2) says that a provider that integrates a recognized service and asks for end users' settings through it should, by technical and organizational measures reflecting the state of the art, take care that the end user's use of the recognized service is taken into account when the digital service is called up and that it is checked whether settings are managed at the recognized service.
Section 18(3) says that such providers should make it possible for the consents they request to be stored by the recognized service, point end users to the integration at a visible and suitable place, cooperate with the recognized service on the requirements of section 7, and give it the information required under Articles 7 and 12 to 14 of the GDPR in a machine-readable format.
Section 17 says that, within the technical possibilities, manufacturers and providers of software for retrieving and presenting information from the internet should take care that the software takes the integration of recognized services into account and does not suppress, delay, decrypt or otherwise alter a signal or the end users' settings deposited through the recognized service or the provider of digital services.
Section 20 says that providers of digital services and manufacturers and providers of software that integrate a recognized service should not, without an objective reason, work toward end users using or excluding particular recognized services. The Ordinance was issued as Article 1 of the Ordinance of . It took effect on .
When LexLint raises it
When your app profile says your app tracks devices or distributes a software product.