{"id":22881,"date":"2024-03-13T17:55:10","date_gmt":"2023-09-12T13:17:00","guid":{"rendered":"https:\/\/www.bloomreach.com\/library\/what-is-consent-management-the-ultimate-guide"},"modified":"2025-03-20T23:17:25","modified_gmt":"2025-03-20T23:17:25","slug":"consent-management","status":"publish","type":"library","link":"https:\/\/www.bloomreach.com\/en\/blog\/consent-management","title":{"rendered":"What Is Consent Management? The Ultimate Guide"},"content":{"rendered":"<p>With non-compliance fines soaring and customers more concerned about their personal data than ever, consent management should be on top of the priority list for every company in today&#8217;s market.<\/p>\n<p>Whether it\u2019s for your\u00a0<a href=\"https:\/\/www.bloomreach.com\/en\/blog\/customer-data-platform\" rel=\"noopener noreferrer\">customer data platform<\/a>\u00a0or a similar tool, it is important to have a comprehensive consent management plan that is easy for your customers to understand and compliant with necessary laws and regulations.<\/p>\n<p>Keep reading for everything you could possibly need to know about consent management and how it will affect your company.<\/p>\n<p><a href=\"https:\/\/www.bloomreach.com\/en\/blog\/2019\/07\/digital-commerce-explained\"><img decoding=\"async\" src=\"https:\/\/www.bloomreach.com\/wp-content\/uploads\/2024\/05\/blog_ecommerce-personalization.jpeg\" alt=\"Ecommerce Personalization\" \/><\/a><\/p>\n<h2>What Is Consent Management?<\/h2>\n<p>Consent management is a system or process for allowing customers to determine what personal data they are willing to share with a business.<\/p>\n<p>It has become so important worldwide because of the lawful requirement for websites to obtain user consent for collecting data through cookies while browsing.\u00a0Businesses all across the world are now responsible\u00a0for collecting and managing customer consent and adhering to <a href=\"https:\/\/www.bloomreach.com\/en\/legal\/bloomreach-engagement-dpa\">personal data processing<\/a> standards.<\/p>\n<p>Bloomreach breaks things down into three\u00a0<a href=\"https:\/\/documentation.bloomreach.com\/engagement\/docs\/consent-categories\" target=\"_blank\" rel=\"noopener noreferrer\">consent categories<\/a>\u00a0that make up consent management:<\/p>\n<ul>\n<li>general consent<\/li>\n<li>consent<\/li>\n<li>legitimate interest<\/li>\n<\/ul>\n<p>These must be considered before putting any customer&#8217;s personal data to use and embarking on marketing campaigns or email communication efforts.<\/p>\n<p>Consent management truly is a process that\u00a0<a href=\"https:\/\/auth0.com\/blog\/what-you-need-to-understand-about-consent-management\/\" target=\"_blank\" rel=\"noopener noreferrer\">guides compliance by informing users about data collection and usage practices<\/a>.\u00a0A good consent management process logs and tracks consent collection so that companies do not need to worry about being in compliance with worldwide laws and regulations. It enables brands to obtain explicit consent from their consumers, facilitates consent collection, and keeps all steps in line with data privacy laws.<\/p>\n<h2>What Is a Consent Management Platform?<\/h2>\n<p>Many businesses\u00a0rely on a consent management platform, or a marketing platform that incorporates consent management capabilities, to organize and monitor their customers&#8217; personal data.<\/p>\n<p>Consent management platforms are built to handle all aspects of compliance, helping brands automate the consent process, gain permission to track first-party data, and allow users to update their preferences easily.<b> <\/b>They enable you to glean insights from the moment a customer opts in, letting you track, monitor, and respond to the data subject\u2019s requests and consent preferences.<\/p>\n<h2>What Is the Difference Between Consent and Preference Management?<\/h2>\n<p>While consent management and preference management might sound the same, there are very distinct and important differences between the two. Both are critical parts of\u00a0<a href=\"https:\/\/www.marketingweek.com\/consent-management-preference-centres-difference\/\" target=\"_blank\" rel=\"noopener noreferrer\">creating a privacy-first and customer-centric strategy<\/a>\u00a0but it is important for businesses to understand the difference between the two concepts.<\/p>\n<p><strong>Marketers ask for customer consent in the consent management process to do things like collect, store, and process personal data.<\/strong> That personal data is then used for <a href=\"https:\/\/www.bloomreach.com\/en\/blog\/2019\/07\/digital-commerce-explained\" target=\"_blank\" rel=\"noopener\">personalized marketing campaigns<\/a> like <a href=\"https:\/\/www.bloomreach.com\/en\/products\/engagement\/ads-retargeting\" target=\"_blank\" rel=\"noopener\">retargeting<\/a> and <a href=\"https:\/\/www.bloomreach.com\/en\/products\/engagement\/email-marketing\" target=\"_blank\" rel=\"noopener\">email campaigns<\/a>.<\/p>\n<p>Consent collection is also commonly known as \u201csubscribing\u201d or achieving &#8220;opt in&#8221; consent to receive communications from a company. If customers no longer want to hear from a company, they would change their \u201copt in\u201d consent to an \u201copt out\u201d and revoke consent for marketing communications.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.bloomreach.com\/wp-content\/uploads\/2024\/05\/consent-mangement-2.-1720x1100_body_request-2-2-1.jpg\" alt=\"A phone offering opt in consent for a customer to receive communications from a company.\" \/><\/p>\n<p>Consent management governs this collection of customer wishes and ensures that companies are staying compliant with the <a href=\"https:\/\/gdpr.eu\/what-is-gdpr\/\" target=\"_blank\" rel=\"noopener\">General Data Protection Regulation (GDPR)<\/a> by not contacting customers who do not wish to be contacted any longer.<\/p>\n<p>While it might sound similar, <strong>preference management actually refers to giving users the ability to make choices about the frequency of communication and topics, as well as which channels they\u2019d like to receive communications on<\/strong>. Customers can also freely give\u00a0<a href=\"https:\/\/www.bloomreach.com\/en\/blog\/importance-of-zero-party-data\" rel=\"noopener noreferrer\">zero-party data<\/a>\u00a0in the preference management process.<\/p>\n<p>While preference management is important, consent management is the topic at hand and it is important to understand when you must collect consent from customers.<\/p>\n<h3>When Should You Use Consent Management?<\/h3>\n<p>According to GDPR,\u00a0<a href=\"https:\/\/clearcode.cc\/blog\/consent-management-platform\/#when-is-user-consent-not-needed?\" target=\"_blank\" rel=\"noopener noreferrer\">consent is one of six lawful bases<\/a>\u00a0to process customer data.<\/p>\n<p>In most situations, the most optimal way for a business to process a customer&#8217;s personal data is to obtain consent. However, should that not be an option,\u00a0<a href=\"https:\/\/www.cmswire.com\/information-management\/what-is-a-consent-management-platform\/#:~:text=Consent%20management%20refers%20to%20a,easier%20to%20be%20GDPR%20compliant\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR does allow five other ways<\/a>\u00a0for a business to process collected data. They are:<\/p>\n<ul>\n<li><strong>Performance of contract.\u00a0<\/strong>If your business is providing a good or a service to a customer, for processing of a customer\u2019s data that you need for the performance of such a contract, the contract is the legal basis you rely on rather than consent. For example, if a customer orders a t-shirt from your ecommerce store, your business will need the customer\u2019s address to deliver the t-shirt and complete the order process. The customer does not need to explicitly consent to the processing of delivery data as the contract in place covers it.<\/li>\n<li><strong>Performance of public tasks.<\/strong>\u00a0Authorities performing duties that are within their everyday job descriptions do not need to comply with these consent management standards when they carry out tasks in the public interest or exercise official authority. However, unless you work for the government, the police, a hospital, or a school, it is likely this basis does not apply to you.<\/li>\n<li><strong>Legitimate interest.<\/strong>\u00a0This basis involves some gray areas. Your company may process a customer&#8217;s personal data without consent when there is a \u201cgenuine reason\u201d to do so. What that specifically means is up for legal interpretation and\u00a0<a href=\"https:\/\/www.huntonprivacyblog.com\/2020\/12\/01\/dutch-court-overturns-dpa-fine-on-legitimate-interest-legal-basis\/\" target=\"_blank\" rel=\"noopener noreferrer\">has already been debated in court.<\/a><\/li>\n<li><strong>Vital interest.\u00a0<\/strong>If customer data\u00a0processing is essential in the act of saving someone\u2019s life, such data processing is legally mandated under GDPR. Again, this does not apply to your everyday ecommerce business.<\/li>\n<li><strong>Legal obligation.\u00a0<\/strong>This basis applies when processing a particular type of data is legally mandated. An example here would be criminal records.<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/www.bloomreach.com\/wp-content\/uploads\/2024\/05\/consent-management-data-processing.png\" alt=\"The 5 ways to stay GDPR complaint without obtaining consent: performance of contract, performance of public tasks, legitimate interest, vital interest, and legal obligation.\" align=\"middle\" \/><\/p>\n<p>Many of these bases do not apply to typical ecommerce stores. Any business that is not referenced amongst the above exceptions lands right back where we started this discussion: It must obtain consent to legally process <a href=\"https:\/\/www.bloomreach.com\/en\/blog\/customer-data-management\">data customers\u2019<\/a> data and achieve GDPR compliance.<\/p>\n<h3>Why Do We Need Consent Management?<\/h3>\n<p>The million-dollar question. Quite literally, for some companies.<\/p>\n<p>Consent management can seem like a big hassle and additional work that can be alleviated if there&#8217;s no consent management platform in place and the consent management process is just ignored, right?<\/p>\n<p>Ignore consent management at your own risk.\u00a0<a href=\"https:\/\/dataprivacymanager.net\/5-biggest-gdpr-fines-so-far-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR fines have skyrocketed<\/a>\u00a0over the past year as customers have begun to care much more deeply about businesses having their personal data.<\/p>\n<p>GDPR fines can reach \u00a320 million or 4% of the annual global turnover of a company for certain infractions. Here are two examples of GDPR fines that could have been avoided if these business had a consent management platform or better consent management plan in place:<\/p>\n<ul>\n<li>A \u00a316.7 million fine was given to mobile telecommunications operator Wind Tre, for\u00a0<a href=\"https:\/\/www.dataguidance.com\/news\/italy-garante-fines-wind-tre-%E2%82%AC167m-unlawful-direct-marketing-practices-highlights-consent\" target=\"_blank\" rel=\"noopener noreferrer\">\u201cunlawful direct marketing practices\u201d<\/a>. These practices included creating confusing interfaces that request consent from users, using personal data without the consent of the data subject, and willfully ignoring data protection laws.<\/li>\n<li><a href=\"https:\/\/www.dataguidance.com\/news\/baden-w%C3%BCrttemberg-lfdi-baden-w%C3%BCrttemberg-fines-aok-baden-w%C3%BCrttemberg-%E2%82%AC12m\" target=\"_blank\" rel=\"noopener noreferrer\">A \u00a31.24 million fine was levied<\/a>\u00a0on German health insurance organization AOK Baden-Wurttemberg in June 2020. It was determined that the company sent marketing messages to 500 people without consent from data subjects because proper measures were not taken to protect personal data.<\/li>\n<\/ul>\n<p>Why does consent management matter? Your company&#8217;s financial bottom line.<\/p>\n<p>Companies won\u2019t just feel the pain of these incidents financially. The \u201cclean-up process\u201d from a GDPR fine includes not only fixing the issue a company was fined for, but also earning back the trust of customers who learn about consent violations and now see the affected brand in a negative light.<\/p>\n<p>That process is easy for some customers and difficult for others. Take the necessary steps of having a reliable consent management platform in place to avoid potentially large fines and the decreased customer loyalty that may come with those fines.<\/p>\n<h3>Consent Management and GDPR Compliance<\/h3>\n<p>Now that you know that it can be disastrous to not be in compliance, how specifically can your business stay GDPR compliant when it comes to consent?<\/p>\n<p><a href=\"https:\/\/gdpr-info.eu\/art-7-gdpr\/\" target=\"_blank\" rel=\"noopener noreferrer\">Article seven of GDPR<\/a>\u00a0outlines all of the required conditions for consent and lays out exactly how companies are to stay compliant with data subject requests in this regard.<\/p>\n<p>Here is a brief summary of article seven to save you some technical reading:<\/p>\n<ul>\n<li>When collecting and processing a customer\u2019s personal data based on consent, your company must be able to prove that the customer has consented.<\/li>\n<li>If the customer\u2019s data consent is given in a written declaration that also concerns other matters, data subject requests for consent must be presented in a manner that is easily distinguishable from the other matters.<\/li>\n<li>The customer has the right to withdraw consent at any time. This will have no effect on the lawfulness of processing prior to consent being withdrawn. The withdrawal of consent should be as easy as the consent collection for customers. If consent is given with one click, customers should be able to take it away with one click as well.<\/li>\n<li>When assessing whether consent is freely given, utmost account shall be taken of whether the performance of a contract is conditional on consent to the processing of personal data that is not necessary for the performance of that contract.<\/li>\n<\/ul>\n<p>As the law changes, and new regulations pop up in different corners of the world, the consent process will change as well. That\u2019s why it is so important to have a <a href=\"https:\/\/www.bloomreach.com\/en\/privacy-at-bloomreach\" target=\"_blank\" rel=\"noopener noreferrer\">partner like Bloomreach<\/a> on your team keeping you up to date on all things consent management.<\/p>\n<h3>Bloomreach Leads the Way With Consent Management Platforms<\/h3>\n<p>As one of industry-leading marketing platforms,\u00a0<a href=\"https:\/\/www.bloomreach.com\/en\/products\/engagement\" target=\"_blank\" rel=\"noopener noreferrer\">Bloomreach Engagement<\/a>\u00a0has top-of-the-line\u00a0<a href=\"https:\/\/documentation.bloomreach.com\/engagement\/docs\/consent-management\" target=\"_blank\" rel=\"noopener noreferrer\">consent management features.<\/a>\u00a0We understand how important privacy is to both businesses and consumers, which is why our services are designed to provide your customers with magical experiences driven by the information they are happy to provide.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.bloomreach.com\/wp-content\/uploads\/2024\/05\/consent-management-2.-1720x1100_body_request-1-2-1.jpg\" alt=\"A look at Bloomreach Engagement\u2019s consent management platform illustrating the categories and interests that customers can organize.\" \/><\/p>\n<p>Bloomreach Engagement allows users to define their own consent categories for customers to subscribe to and set subscriptions based on legitimate interest. And it&#8217;s all simple to manage in our all-in-one platform \u2014 Engagement&#8217;s\u00a0<a href=\"https:\/\/www.bloomreach.com\/en\/blog\/going-beyond-a-customer-data-platform\" target=\"_blank\" rel=\"noopener\">single customer view (SCV)<\/a> not only provides a 360-degree understanding of a customer&#8217;s preferences and interactions with your brand, but it also offers a lifetime overview of each customer&#8217;s entire consent history, so users can see who gave or withdrew their consent when and where.<\/p>\n<p>Bloomreach makes it easy to manage consent, changing consent statuses, and different categories. The customer-facing consent management page is customizable, so you can create and configure consent categories however is best for your brand.<\/p>\n<p>Bloomreach works hard to stay up to date and ahead of the curve in data privacy regulations and consent management, which is why the company is a leader in security in the SaaS space.<\/p>\n<p>Need proof? Bloomreach\u00a0<a href=\"https:\/\/www.bloomreach.com\/en\/legal\/security\" target=\"_blank\" rel=\"noopener noreferrer\">holds top security certifications<\/a>\u00a0to help keep our customers as protected as possible.<\/p>\n<p>Bloomreach is committed to protecting your data and keeping it secure.\u00a0If you are ready to learn more, <a href=\"https:\/\/www.bloomreach.com\/en\/products\/engagement\">check out our product page<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With non-compliance fines soaring and customers more concerned about their personal data than ever, consent management should be on top of the priority list for every company in today&#8217;s market. Whether it\u2019s for your\u00a0customer data platform\u00a0or a similar tool, it is important to have a comprehensive consent management plan that is easy for your customers [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":21672,"template":"","ew-regions":[],"ew-solutions":[],"library_type":[513],"library_blog_tag":[449],"industry":[],"channel":[268],"topic":[],"class_list":["post-22881","library","type-library","status-publish","has-post-thumbnail","hentry","library_type-blog","library_blog_tag-privacy-and-security","channel-email"],"acf":{"library_blog_banner_content":"","library_blog_banner_cta1_text":"","library_blog_banner_cta1_href":"","library_blog_banner_cta1_new_tab":false,"library_blog_banner_cta2_text":"","library_blog_banner_cta2_href":"","library_blog_banner_cta2_new_tab":false,"library_blog_banner_bg_color":"#EAF7FE","library_blog_banner_cta_text_color":"#FFF","library_blog_banner_cta_bg_color":"#019ACE","library_blog_banner_cta2_text_color":"#000","library_blog_banner_cta2_bg_color":"#FFF","library_blog_chatgpt_content":"","library_blog_chatgpt_cta_href":"","library_blog_chatgpt_cta_text":"Ask ChatGPT"},"_links":{"self":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/library\/22881","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/library"}],"about":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/types\/library"}],"author":[{"embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/users\/13"}],"version-history":[{"count":1,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/library\/22881\/revisions"}],"predecessor-version":[{"id":59250,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/library\/22881\/revisions\/59250"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/media\/21672"}],"wp:attachment":[{"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/media?parent=22881"}],"wp:term":[{"taxonomy":"ew_regions","embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/ew-regions?post=22881"},{"taxonomy":"ew_solutions","embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/ew-solutions?post=22881"},{"taxonomy":"library_type","embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/library_type?post=22881"},{"taxonomy":"library_blog_tag","embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/library_blog_tag?post=22881"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/industry?post=22881"},{"taxonomy":"channel","embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/channel?post=22881"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.bloomreach.com\/en\/wp-json\/wp\/v2\/topic?post=22881"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}