Implicit Consent Documentation

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document outlines the criteria and rationale by which DCKAP Integrator determines that implicit consent exists for the collection, use, retention, disclosure, and disposal of personal information — particularly in the context of business-to-business integration flows where customer organisations configure data transfers on behalf of their end users.

2. DCKAP Integrator’s Role in Consent

DCKAP Integrator acts as a Data Processor (in GDPR terms), not a Data Controller. Customer organisations (Data Controllers) determine the lawful basis — including consent — for personal data processed through DCKAP Integrator. The following describes the implicit consent framework within this relationship.

3. Implicit Consent Criteria

3.1  Business-to-Business Processing (B2B Flows)

Implicit consent is deemed to exist for B2B data flows (e.g., transferring business contact information between ERP and eCommerce systems) when ALL of the following conditions are met:

  • The data relates to individuals acting in their professional/business capacity (e.g., procurement contacts, account managers).
  • The processing is necessary for the legitimate performance of a business contract or business relationship.
  • The data subject’s organisation has an existing relationship with the customer organisation configuring the integration.
  • The transfer does not involve special category data (health, financial, biometric, etc.).

3.2  End-Customer Order Data (B2C Flows)

For integration flows that process personal data of consumers (e.g., order and shipment data from an eCommerce store to an ERP), implicit consent criteria are:

  • The consumer has accepted the Data Controller’s (customer’s) privacy policy and terms of service at the point of purchase or account creation.
  • The privacy policy clearly states that order and account data is shared with fulfilment systems.
  • The transfer is necessary to fulfil the consumer’s order — it is not for secondary marketing or analytics purposes.
  • The customer organisation represents and warrants this in the DCKAP Data Processing Agreement (DPA).

4. DCKAP’s Contractual Basis for Processing

DocumentPurposeWho Executes
Master Service Agreement (MSA)Defines the commercial relationship and service scopeDCKAP + Customer
Data Processing Agreement (DPA)Defines processing instructions and GDPR obligationsDCKAP (Processor) + Customer (Controller)
Privacy PolicyInforms data subjects about DCKAP’s own data practicesPublished by DCKAP
Sub-Processor DisclosureLists third-party processors used by DCKAP (cloud providers, etc.)Published by DCKAP

5. Limitations of Implicit Consent

  • Implicit consent does NOT apply to: sensitive personal data, data used for profiling or automated decision-making, or data shared with third parties beyond what is required for integration functionality.
  • Any processing outside the scope of the DPA requires explicit written consent from the Data Controller.
  • DCKAP will not process personal data beyond what is necessary to execute the configured integration flows.

6. Placement in Product

Product LocationScreen / PageAudience
Privacy Policydckap.com/privacy → Consent & Legal Basis SectionAll Data Subjects, Regulators
Trust CenterLegal → Data Processing AgreementEnterprise Customers, DPOs
OnboardingDPA presented for acceptance during enterprise onboardingCustomer Legal / DPO
Compliance FolderSOC 2 Evidence → Privacy ControlsExternal Auditors