Written consent is a formal consent method required for certain higher-risk processing activities under Russian law, including sensitive data, biometric data, some automated decisions, employee data, and certain cross-border transfers. It must capture identity details, purpose, data categories, processing method, validity period, and signature.
What Written Consent Means in Practice
Written consent is more than a signature line. It is a formal record that ties a person’s agreement to a specific processing purpose, data category, and lawful condition, so the controller can show consent was informed, scoped, and attributable.
For higher-risk processing, the written format matters because it creates a durable evidentiary trail. That record should be precise enough to show what was authorised, by whom, for how long, and under what processing conditions, rather than relying on vague or bundled approval.
In privacy operations, the distinction between consent and ordinary notice is important. Consent is an affirmative legal basis in the situations where law requires it, while notice only explains processing. A written instrument is therefore about proof and accountability, not just communication.
What Must Be Captured in the Record
A compliant written consent record typically identifies the data subject, the purpose of processing, the categories of personal data involved, the processing method, the validity period, and the signature or other formal acceptance mark. Those elements make the consent auditable and reduce disputes about scope.
The content also needs to match the risk level of the processing activity. If the data is sensitive, biometric, employee-related, or subject to cross-border transfer constraints, the written form should be specific enough that the scope cannot be stretched later beyond what was actually authorised.
That precision is especially important where consent is used as a legal basis alongside operational controls. A well-formed record helps privacy teams, legal teams, and system owners align on what the organisation may do, and what it must not do without renewed approval.
How Written Consent Relates to Privacy Governance
Written consent sits inside broader privacy governance, because it is only useful when organisations can connect it to retention rules, purpose limitation, and data minimisation. The record should support internal accountability, not become a box-ticking artifact that is filed and forgotten.
It also helps with subject-rights handling and review. When consent is documented clearly, an organisation can trace whether a specific processing activity still has a valid basis, whether the scope has changed, and whether the consent period has expired or needs refresh.
For cross-border or higher-risk processing, the written record can become part of the organisation’s evidence trail for lawful processing decisions. That is why good consent design is usually paired with clear privacy notices, internal approvals, and retention controls such as the EU General Data Protection Regulation (GDPR) and NHIMG’s Identity Data Privacy and Consent Guide.
Common Failure Modes and Compliance Gaps
Written consent fails when it is too generic, bundled with unrelated terms, or impossible to connect to a specific processing purpose. Another common weakness is treating a historical signature as perpetual authorisation even after the processing purpose, data scope, or legal basis has changed.
Problems also arise when the organisation can document consent but cannot prove the surrounding context. If the data categories, purpose, and validity period are not aligned to the actual processing activity, the written record may exist but still be legally weak.
Because written consent is often used for sensitive categories of data, poor record design can turn into a governance and exposure problem. A legally incomplete consent process can leave the organisation without a reliable basis for processing, especially where biometrics or cross-border handling raise the stakes.
Risk and Threat Considerations
Written consent creates risk when it is treated as a formality instead of a precise legal control. If the record is incomplete, outdated, or too broad, the organisation may process data without a defensible basis, and that can create regulatory, contractual, and trust exposure.
Failure mechanism: The organisation relies on a consent document that does not accurately reflect the actual data, purpose, duration, or transfer conditions, so downstream processing exceeds the authority the subject actually granted.
Impact: The result can be unlawful processing, invalid cross-border transfer decisions, disputed employee or customer authorisation, and a weaker position if regulators or data subjects challenge the processing.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art.5 — Principles Relating to Processing of Personal Data | Written consent must align with lawful, purpose-limited personal data processing. |
| Art.9 — Processing of Special Categories of Personal Data | The term explicitly covers sensitive data, including higher-risk categories. | |
| Art.35 — Data Protection Impact Assessment | Higher-risk processing that uses written consent often needs documented risk review. | |
| Recommendation — Tie consent records to the exact purpose and data scope under Article 5. Use explicit written consent controls when special-category data is processed. Run a DPIA when the written-consent scenario involves high-risk processing. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | Written consent is a privacy control supporting protected personal data handling. |
| Recommendation — Document consent handling as part of your PII protection controls. | ||
Practitioner Guidance
What to watch for: Make sure the consent record is specific enough to stand on its own if challenged later. If the same template is being reused for different data types, different purposes, or different jurisdictions, the form is probably too generic to be reliable.
Governance implication: Ownership should sit with privacy, legal, and the business process owner together, because written consent is both a legal artifact and an operational control. The key question is whether the document still matches the processing that actually happens.
Practitioner takeaway: Written consent is strongest when it is narrow, explicit, and traceable, and weakest when it is treated as a reusable approval slip.