Fluid Attacks logo
Contact Us
Young hacker smiling
Zero false positives

Expert intelligence + effective automation

Contact logo Contact Us

R311. Demonstrate user consent

This document contains the details of the security requirements related to the management and protection of data privacy in the organization. This requirement focuses on the importance of establishing a mechanism to demonstrate that the user has granted consent.


The system must establish a mechanism which allows demonstrating that users granted their consent to collection of their data.


Systems usually request information from the users or collect it based on their interactions with the application. Regulations demand that none of these collections occur without the user’s consent and that this consent be demonstrable afterwards. Therefore, the system must have a mechanism that allows demonstrating the grant of the consent.


  1. GDPR. Art. 7: Conditions for consent.(1). Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.

Service status - Terms of Use