On July 28 at 3:30 a.m. Japan time, I will give a presentation at Identiverse entitled “So You Want to Base on Consent?”

The title was inspired by Glenn Gould’s piece “So You Want to Write a Fugue?” While acknowledging that this is in some respects a reckless undertaking, I will discuss what should be done by drawing from ISO/IEC 29184.

The opening lyrics of “So You Want to Write a Fugue?” go like this.

So you want to write a fugue?
You’ve got the Urge to write a fugue,
You’ve got the nerve to write a fugue,
So go ahead.

Glenn Gould: So you want to write a fugue (1963)

Oh, so you want to write a fugue?
If you have the urge to write a fugue,
and the nerve to write a fugue,
then go ahead and try.

Above: my translation

After opening with those words, the piece introduces various fugal techniques within the music itself.

Watch this video on YouTube.
Playing the video connects to YouTube.
Glenn Gould: So you want to write a fugue? (1963)

This presentation replaces “want to write a fugue” with “want to base on consent.” In other words:

Oh, so you want to base it on consent?
If you have the urge to do it with consent,
and the nerve to carry it through with consent,
then go ahead and try.

As for the content… it is an English version of substantially the same presentation I gave at PWS on July 21. Please join if you are interested.

Monday, July 27, 12:30 – 12:55 (Mountain Time)

So You Want to Base on Consent?

Many people seem to believe that having their customers pressing “Agree” button is good enough to collect their “consent”. That’s actually not the case. Obtaining privacy consent has very high bar partly because that is the exception mechanism that you can resort to only when other lawful bases for the processing of personal data does not work.

This session will briefly touch on other lawful bases and what is needed for potentially valid consent, then goes on to explain the requirements for privacy notice and consent process set out in “ISO/IEC 29184 Online privacy notices and consent”.

ISO/IEC 29184 is an international standard that has been in making for the last 5 years. Stakeholders involved in the discussion included data protection authorities around the globe, technical community, lawyers, and businesses. It sets out the requirements for 1) What are needed to be in a privacy notice, 2) What are needed to be done in obtaining the consent, 3) What are needed to be done in the maintenance of privacy notices. For any business that wants to respect customer privacy, this document provides excellent guidance on what needs to be followed.
Speaker/s: Nat Sakimura
Topic: Privacy

Sub Topic: Standards, Architecture & Deployment, Consumer Identity, User Experience, Vision & Strategy

Related posts