सामग्री पर जाएँ
HexaTransfer
ब्लॉग पर वापस
GDPR और अनुपालन

सुरक्षित फ़ाइल ट्रांसफर के लिए GDPR सहमति प्रबंधन

फ़ाइल ट्रांसफर के लिए GDPR सहमति आवश्यकताओं में महारत हासिल करें, जिसमें कानूनी आधार, ऑप्ट-इन तंत्र, सहमति रिकॉर्ड और वापसी प्रक्रियाएँ शामिल हैं।

DPDP Act 2023 (डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम) consent को data processing के लिए एक वैध आधार के रूप में मान्यता देता है — लेकिन GDPR की तरह, यह सबसे अच्छा आधार नहीं है हर file transfer के लिए। GDPR Article 6(1)(a) के तहत consent अक्सर file transfers के लिए गलत lawful basis है। Contracts (6(1)(b)), legal obligations (6(1)(c)), और legitimate interests (6(1)(f)) बिना subjects को opt in करने के लिए कहे अधिकांश B2B file-sharing scenarios को cover करते हैं।

जब consent वास्तव में सही basis हो — marketing lists, newsletter signups, voluntary data contributions — तो Article 7 strict rules set करता है: freely given, specific, informed, unambiguous, और जितनी आसानी से दी जाती है उतनी आसानी से वापस लेने योग्य। Consent गलत होने पर पूरा transfer Article 5(1)(a) के तहत unlawful processing बन जाता है।

B2B Transfers के लिए Consent शायद ही कभी सही Basis है

एक freelancer client को 2 GB project delivery भेजता है — client की consent नहीं चाहिए, engagement का contract 6(1)(b) के तहत lawful basis है। एक law firm signed NDA counterparty को भेजती है — consent की आवश्यकता नहीं। एक clinical trial site pseudonymized data sponsor को transfer करती है — 6(1)(b) या special category data के लिए 9(2)(j) के तहत।

हर चीज़ के लिए consent default करना fragility create करता है: subjects Article 7(3) के तहत किसी भी समय withdraw कर सकते हैं, potentially आपको contractual obligations पूरा करने में असमर्थ छोड़ते हैं। सही basis एक बार चुनें, document करें, पूछना बंद करें।

Article 7 की Consent Requirements

Article 7(1) आपको prove करने के लिए कहता है consent दी गई थी। Article 7(2) कहता है consent requests clearly distinguishable, intelligible, और plain language में होनी चाहिए। Article 7(3) withdrawal की guarantee देता है जितनी आसानी से granting जितनी। Article 7(4) consent को invalid करता है जहाँ यह service delivery पर conditional है जिसे वास्तव में data की आवश्यकता नहीं है।

File transfers के लिए translated: आप "मैं marketing PDFs receive करने के लिए agree करता हूँ" को "मैं अपनी purchase receipt receive करने के लिए agree करता हूँ" के साथ bundle नहीं कर सकते। पहला consent है, दूसरा contractual performance है। उन्हें separate करें या Article 7(4) violate करते हैं।

Dark Patterns जो Consent तोड़ते हैं

Pre-ticked checkbox invalid है (Planet49 C-673/17, October 2019)। Non-essential cookies के लिए service refuse करने वाली cookie walls invalid हैं (EDPB guidance, May 2020)। "Accept all" और "Reject all" buttons equally prominent होने चाहिए (CNIL fines against Google और Facebook, December 2021, EUR 150M और EUR 60M)।

File transfers के लिए equivalent dark pattern marketing opt-in के साथ download access bundling है: "Download your file" essential है; "Subscribe to our newsletter" नहीं है। उन्हें कभी single button के पीछे merge न करें। Data Protection Board of India इसी तरह consent-based processing में dark patterns को scrutinize करता है।

Granular Consent और File Types

यदि आप ऐसा platform run करते हैं जहाँ users photos, documents, और video upload करते हैं, तो subjects को प्रत्येक data type के लिए granular consent चाहिए। Granularity purposes तक extend होती है: "partners के साथ share" की consent उन partners को नाम किए बिना Article 7 के "specific" test में fail करती है। Recipients की categories name करें — advertisers, analytics providers, sub-processors — और यदि नहीं कर सकते, तो proper balancing test के साथ legitimate interests पर fall back करें।

Consent Records और Proof of Consent

Article 7(1) proof of controller पर burden डालता है। Consent record को minimum पाँच fields चाहिए: किसने consent दी (subject ID, email, या hashed identifier), कब (timestamp, timezone), किस पर (shown exact text), कैसे (form version, IP, web captures के लिए user agent), और कैसे withdraw करें (mechanism का reference)।

Tools जैसे OneTrust, Usercentrics, Didomi, और Cookiebot web captures handle करते हैं। In-product flows के लिए, append-only semantics के साथ अपना event log build करें। Retention consent की validity window plus statute of limitations (typically UK में छह साल, France में पाँच) से match करती है।

Granting जितनी आसानी से Withdrawal Workflows

Article 7(3) को withdrawal उतना ही आसान require करता है जितना consent। यदि consent single checkbox click था, तो withdrawal single click होनी चाहिए। तीन account menus के पीछे hidden preference centers fail करते हैं। Email-based unsubscribe links काम करते हैं यदि वे user को log in करने की आवश्यकता के बिना click पर withdrawal resolve करते हैं।

File transfers के लिए, withdrawal का typically मतलब है future transfers रोकना और Article 17(1)(b) के तहत past ones erase करना जहाँ consent एकमात्र basis था। आपका unsubscribe endpoint consent-revocation event और erasure job दोनों fire करना चाहिए।

Children's Consent और Parental Verification

Article 8 information society services के लिए parental consent required होने पर 16 को default age set करता है, जिसमें member states 13 तक lower कर सकते हैं। France 15 use करता है, Germany 16, Spain 14, Sweden और Portugal 13। Acceptable verification methods में credit card checks, national ID verification, signed consent forms, और parent के verified email के साथ double opt-in शामिल हैं।

यदि आपका file transfer platform education को target करता है, तो under-16 uploaders को consent-based processing के लिए parental consent obtain करनी होगी।

International Transfers के लिए Consent

Article 49(1)(a) non-adequate countries में transfers के लिए derogation के रूप में consent allow करता है, लेकिन केवल occasional, non-repetitive transfers के लिए। EDPB Guidelines 2/2018 "explicit consent" पर emphasize करती हैं — ordinary consent से higher bar — और subject को specific risks inform किया जाना चाहिए।

Routine file transfers के लिए US या other non-adequate jurisdictions में, SCCs plus Transfer Impact Assessment use करें। Consent एक emergency lever है, scaling strategy नहीं।

Terms बदलने पर Re-consent

यदि आप processing purposes बदलते हैं, नए recipients add करते हैं, या retention extend करते हैं, तो existing consents expanded processing cover नहीं कर सकतीं। Safest move fresh consent है updated disclosures के साथ। Test: क्या original consent दी गई होती यदि subject नए facts जानता? Doubt में re-consent करें। New processing शुरू होने से पहले re-consent flow trigger करें।

Technical Integration Patterns

File transfer product में, clean pattern एक consent microservice है जिसे हर upload, download, और notification call proceeding से पहले check करती है। Consent record एक UUID carry करता है जिसे हर file operation के audit logs में reference किया जाता है। Withdrawal future checks invalidate करता है और async erasure job trigger करता है।

HexaTransfer जैसी services contractual necessity पर transfers base करके complexity avoid करती हैं — sender initiate करता है, recipient download करता है, transfer contract के तहत दोनों implicit — और Article 6(1)(a) consent को optional newsletter signup के लिए reserve करती हैं।

DPDP Act 2023 और GDPR दोनों के तहत, सिद्धांत एक ही है: consent एक tool है, default नहीं। Operation के fit होने वाले lawful basis चुनें। शुरू करें https://hexatransfer.com — मुफ़्त, कोई खाता नहीं, 10 GB अधिकतम।

एंड-टू-एंड एन्क्रिप्शन के साथ बड़ी फ़ाइलें सुरक्षित रूप से भेजें

एंड-टू-एंड एन्क्रिप्शन के साथ 10 GB तक की फ़ाइलें मुफ़्त में ट्रांसफ़र करें। अकाउंट की आवश्यकता नहीं। अपलोड से पहले आपकी फ़ाइलें ब्राउज़र में एन्क्रिप्ट की जाती हैं — कोई और उन्हें पढ़ नहीं सकता।

फ़ाइल भेजें