Reference (Include section and paragraph number):
3.2.1.4
Comment (Include rationale for comment):
The user typically would give consent for a certain usage of the attribute.
User may have expressly given consent to use his e-mail address for password reset e-mails.
It may be "Unknown" whther user has given consent to use his e-mail address for newsletters.
Etc.
Suggested Change:
Each attribute should get a multivalued set of (complex) Privacy-attributes. Imho these could be:
Individual Consented
Date Consented
Use
Cache Time to Live
Data deletion date
An additional attribute could be:
ConsentMethod with possible values like "Terms and Conditions", "Online click",... ( I haven't really thought thos through, yet)
Maybe in this way it would be better to see "Acceptable Additional Uses" as just another value for this multivalued "Privacy"-attribute set, having "Use"="Disclosure" and "Individual Consented"="No".
Organization: 2 Type:
Reference (Include section and paragraph number): 3.2.1.4 Comment (Include rationale for comment): The user typically would give consent for a certain usage of the attribute. User may have expressly given consent to use his e-mail address for password reset e-mails. It may be "Unknown" whther user has given consent to use his e-mail address for newsletters. Etc.
Suggested Change: Each attribute should get a multivalued set of (complex) Privacy-attributes. Imho these could be:
An additional attribute could be:
Maybe in this way it would be better to see "Acceptable Additional Uses" as just another value for this multivalued "Privacy"-attribute set, having "Use"="Disclosure" and "Individual Consented"="No".