Implicit Consent Documentation
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II |
1. Purpose
This document outlines the criteria and rationale by which DCKAP Integrator determines that implicit consent exists for the collection, use, retention, disclosure, and disposal of personal information — particularly in the context of business-to-business integration flows where customer organisations configure data transfers on behalf of their end users.
2. DCKAP Integrator’s Role in Consent
DCKAP Integrator acts as a Data Processor (in GDPR terms), not a Data Controller. Customer organisations (Data Controllers) determine the lawful basis — including consent — for personal data processed through DCKAP Integrator. The following describes the implicit consent framework within this relationship.
3. Implicit Consent Criteria
3.1 Business-to-Business Processing (B2B Flows)
Implicit consent is deemed to exist for B2B data flows (e.g., transferring business contact information between ERP and eCommerce systems) when ALL of the following conditions are met:
- The data relates to individuals acting in their professional/business capacity (e.g., procurement contacts, account managers).
- The processing is necessary for the legitimate performance of a business contract or business relationship.
- The data subject’s organisation has an existing relationship with the customer organisation configuring the integration.
- The transfer does not involve special category data (health, financial, biometric, etc.).
3.2 End-Customer Order Data (B2C Flows)
For integration flows that process personal data of consumers (e.g., order and shipment data from an eCommerce store to an ERP), implicit consent criteria are:
- The consumer has accepted the Data Controller’s (customer’s) privacy policy and terms of service at the point of purchase or account creation.
- The privacy policy clearly states that order and account data is shared with fulfilment systems.
- The transfer is necessary to fulfil the consumer’s order — it is not for secondary marketing or analytics purposes.
- The customer organisation represents and warrants this in the DCKAP Data Processing Agreement (DPA).
4. DCKAP’s Contractual Basis for Processing
| Document | Purpose | Who Executes |
|---|---|---|
| Master Service Agreement (MSA) | Defines the commercial relationship and service scope | DCKAP + Customer |
| Data Processing Agreement (DPA) | Defines processing instructions and GDPR obligations | DCKAP (Processor) + Customer (Controller) |
| Privacy Policy | Informs data subjects about DCKAP’s own data practices | Published by DCKAP |
| Sub-Processor Disclosure | Lists third-party processors used by DCKAP (cloud providers, etc.) | Published by DCKAP |
5. Limitations of Implicit Consent
- Implicit consent does NOT apply to: sensitive personal data, data used for profiling or automated decision-making, or data shared with third parties beyond what is required for integration functionality.
- Any processing outside the scope of the DPA requires explicit written consent from the Data Controller.
- DCKAP will not process personal data beyond what is necessary to execute the configured integration flows.
6. Placement in Product
| Product Location | Screen / Page | Audience |
|---|---|---|
| Privacy Policy | dckap.com/privacy → Consent & Legal Basis Section | All Data Subjects, Regulators |
| Trust Center | Legal → Data Processing Agreement | Enterprise Customers, DPOs |
| Onboarding | DPA presented for acceptance during enterprise onboarding | Customer Legal / DPO |
| Compliance Folder | SOC 2 Evidence → Privacy Controls | External Auditors |