[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fS0ffWUQ66g9S1lBi_uOvdp_SkSFV1Q-oF7YfSHl0xas":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"4441cd09-4162-4947-9e76-66d3deb397e6","cjeu-rules-orange-romanias-consent-practices-invalid-under-gdpr","2eeee616-0b62-41a0-9315-55bd3928efb7","CJEU Rules Orange Romania's Consent Practices Invalid Under GDPR","Orange Romania violated GDPR by using implied or coerced consent mechanisms — including pre-ticked boxes and burdensome opt-out processes — to collect and store copies of customer ID documents. The CJEU reaffirmed that valid consent must be freely given, specific, informed, and unambiguous, meaning any friction that discourages refusal automatically invalidates the consent. This ruling matters because organizations cannot treat consent as a checkbox formality; it must reflect a genuine, affirmative choice by the data subject. Businesses that embed consent into standard contract flows without a clear, equal opt-out risk significant regulatory exposure and reputational damage.","**Immediate actions:**\n- Audit all existing consent mechanisms across customer-facing contracts and digital forms to identify pre-ticked boxes or implied consent patterns.\n- Remove any consent clauses bundled into service agreements where refusal is made deliberately difficult or requires extra steps.\n\n**Long-term improvements:**\n- Implement a consent management platform (CMP) that records granular, timestamped proof of freely given consent for each data processing purpose.\n- Train customer-facing staff and legal\u002Fcompliance teams on GDPR Article 7 requirements, including the distinction between consent and legitimate interest.\n- Establish a periodic review cycle (at least annually) to reassess consent validity as regulatory guidance and business processes evolve.\n\n**Detection & governance measures:**\n- Appoint or empower a Data Protection Officer (DPO) to review all new consent workflows before deployment.\n- Integrate consent compliance checks into your third-party vendor and contract management processes to catch non-compliant practices early.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 4(11) — Definition of Consent","GDPR Article 7 — Conditions for Consent","GDPR Article 13 — Information to be Provided at Collection","GDPR Recital 32 — Unambiguous Consent","GDPR Recital 42 — Burden of Proof for Consent","NIST Privacy Framework PR.PO-P1 — Policies and Procedures for Data Processing","NIST SP 800-53 IP-1 — Consent","CIS Control 3 — Data Protection","ISO\u002FIEC 29101 — Privacy Architecture Framework","ITIL Service Design — Compliance Management","published","2026-09-16T08:20:50.55277+00:00","2026-09-16T08:20:50.266+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-61\u002F19_-_Orange_Romania&diff=53079&oldid=52149","cjeu-c-61-19-orange-romania-e4a889","CJEU - C-61\u002F19 - Orange Romania",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]